Company Brain

Privacy Policy

Effective August 5, 2026

Company Brain is a shared knowledge base for your team. You connect it to an AI assistant, and the assistant reads from and writes to your organization’s brain on your behalf. This policy explains what we store to make that work, and what we do — and do not do — with it.

What we store

Account information. When you sign in with Google we receive your name, email address, and Google account identifier. We never see your password. We use this only to sign you in and to show your teammates who belongs to the organization.

Your content. The knowledge files your team captures — markdown documents about how your company works — along with each file’s version history and one-line summaries. This content belongs to your organization.

Connection records. When you connect an AI assistant, we store the assistant’s OAuth client registration and access credentials. Tokens are stored as SHA-256 hashes, never in the clear. We also keep invitation records while an invite to your organization is pending.

How we use it

To provide the service. Nothing else. We do not sell data, show ads, share content with data brokers, or use your content to train AI models.

Who can see your content

Only members of your organization. Every request is scoped to your organization on the server — there is no way to address another organization’s data through the product. Our operational logs never contain file contents.

When you connect an AI assistant (for example Claude or ChatGPT), the content our tools return is processed by that assistant under your agreement with its provider. You can revoke an assistant’s access from Settings at any time.

Where it lives

Data is stored in a PostgreSQL database hosted on Fly.io in Frankfurt, Germany (EU). Fly.io is our hosting provider; Google provides sign-in. Those are the only third parties involved in running the service.

Retention and deletion

We keep your content for as long as your organization uses the service, including version history so nothing is lost by accident. You can export your entire brain from the web app at any time. To delete your organization and all of its data, email us at cieslakjn@gmail.com from an owner’s account — deletion is permanent and covers content, version history, accounts, and connection records.

Security

All traffic is encrypted in transit with TLS. Access tokens and connector secrets are stored hashed. Sessions are signed. Every database query is scoped to a single organization.

Changes and contact

If this policy changes materially, we will note the new effective date here. Questions or requests: cieslakjn@gmail.com.