BrainPost

BrainPost Privacy Policy

Last updated 29 September 2026

This Privacy Policy explains what personal data BrainPost collects, why, who we share it with, how long we keep it, and the choices and rights you have. It applies to our website at https://brainpostio.com, our web app at https://app.brainpostio.com and related services (the "Service").

BrainPost does not sell your personal data, and we do not use it for third-party advertising.

1. Who we are

The Service is provided by Brainpost, LLC, a Delaware limited liability company ("BrainPost", "we", "us" or "our").

For all privacy matters, email privacy@brainpostio.com. Email is the main way to reach us.

This policy should be read with our Terms and Conditions and Cookie Policy.

2. Our role: controller or processor

When we are the controller. For account, billing, referral, website, support, security and marketing data, BrainPost decides how and why the data is used. We are the "controller" (or "business" under California law).

When we act for our customers. Agencies, freelancers and businesses may use BrainPost to manage content and social accounts for their own clients. When they put their clients' personal data into a workspace (for example, a client's social account data, audience metrics, or people shown in media), that customer is usually the controller and BrainPost acts as their processor or service provider. We process that data only to provide the Service under our customer's instructions. If you are a client of one of our customers, please contact that customer first about your data; we will help them respond.

Data Processing Addendum. Business customers who need one can request our Data Processing Addendum (DPA) at privacy@brainpostio.com.

3. Age

BrainPost is for people aged 18 and over and for business use. We do not knowingly collect personal data from anyone under 18. If you believe a minor has given us personal data, contact us and we will delete it.

4. Personal data we collect

We collect data you give us, data created when you use the Service, and data from services you connect.

Data about other people. If you upload content showing other people, invite teammates, or manage a client's accounts, you are responsible for having a lawful basis and giving any notice needed to share their data with us.

Sensitive data. The Service is not designed for sensitive data (such as health, religious or biometric data). Please do not put it in your prompts or content unless you need to and have a lawful basis.

5. How we use your data and our legal bases

Laws such as the EU and UK GDPR and the Nigeria Data Protection Act 2023 (NDPA) require a legal basis for each use. Ours are below.

Where we rely on legitimate interests, we have balanced them against your rights. You can object at any time (see Section 12).

6. AI and your data

What we send to AI providers. To run AI features, we send the minimum inputs needed for the task. These can include your prompts, workspace and brand details, post content, uploaded media and analytics data.

Our AI providers. We currently use models from OpenAI, Anthropic, Google, and models available through Higgsfield. They process inputs to return output to us, under their own terms and our agreements with them.

Training. BrainPost uses your workspace data, such as your brand details and past content, to tailor AI output for your workspace only. We do not use one customer's content to improve results for other customers. We use our AI providers' business or API services, under which they process inputs to return output to us, under their own terms and our agreements with them.

No automated decisions with legal effect. AI recommendations such as best times to post are suggestions. We do not make decisions based solely on automated processing that have legal or similarly significant effects on you.

Turning off the assistant. Each user can turn off the in-app AI assistant. The assistant can see what you can see in the app, but never billing or settings.

7. Data from Google and YouTube

If you sign in with Google or connect a YouTube channel, BrainPost's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • we use Google user data only to provide and improve the user-facing features of BrainPost that you see in the app;
  • we do not sell it, use it for advertising, or let humans read it unless you ask us to (for example, for support), it is needed for security or legal reasons, or it is aggregated and anonymised;
  • we do not use it to train generalised AI or machine-learning models.

YouTube features are governed by YouTube's Terms of Service and the Google Privacy Policy. You can revoke access at https://myaccount.google.com/permissions.

We handle data from Meta, TikTok, LinkedIn and X according to each platform's developer terms, and only to provide the features you use.

8. Who we share data with

We share personal data only as described here. We do not sell it or share it for cross-context behavioural advertising.

Our service providers may only use personal data to provide services to us, under contracts that require confidentiality and security. Social platforms and Stripe also act as independent controllers under their own privacy policies.

9. International transfers

BrainPost is a United States company. We and our providers may process data in the United States and other countries. These countries may not have the same data protection laws as yours.

When we transfer personal data out of the EU, UK, Switzerland or Nigeria, we use appropriate safeguards, such as:

  • the European Commission's Standard Contractual Clauses;
  • the UK International Data Transfer Addendum;
  • the EU-US Data Privacy Framework, where the recipient is certified;
  • for Nigeria, safeguards recognised under Part VIII of the NDPA, such as contractual clauses, or your consent where appropriate.

You can ask for more information about these safeguards at privacy@brainpostio.com.

10. How long we keep data

We may keep data longer where the law requires it, or to resolve disputes and enforce our agreements. Content you have already published to social platforms stays there under those platforms' policies; delete it on the platform if you want it removed.

11. Security

We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss and misuse. No system is completely secure. If a data breach affects you, we will notify you and the relevant regulators as the law requires, including the Nigeria Data Protection Commission within 72 hours where the NDPA applies.

You can help by using a strong, unique password and revoking access for people who no longer need it.

12. Your rights

Everyone. Wherever you live, you can:

  • access and correct your profile and workspace details in Settings;
  • export content by CSV or download your files;
  • delete your account in Settings (30-day restore window applies);
  • disconnect social accounts at any time;
  • opt out of marketing in Settings or with the unsubscribe link;
  • turn off the AI assistant.

EU, UK, Switzerland and Nigeria. Under the GDPR, UK GDPR and NDPA you also have the right to:

  • request a copy of your personal data and information about how we use it;
  • have inaccurate data corrected;
  • have data erased;
  • restrict our processing;
  • object to processing based on legitimate interests, and to direct marketing at any time;
  • receive your data in a portable, machine-readable format;
  • withdraw consent at any time, without affecting earlier processing;
  • not be subject to decisions based solely on automated processing with legal or similar effects;
  • complain to a regulator: your local EU data protection authority; the UK Information Commissioner's Office (ico.org.uk); or the Nigeria Data Protection Commission (ndpc.gov.ng). We would appreciate the chance to resolve your concern first.

California and other US states. Residents of California and other states with privacy laws may have the right to:

  • know what personal information we collect, use and disclose;
  • access, correct and delete it;
  • opt out of the sale or sharing of personal information, and of targeted advertising;
  • limit use of sensitive personal information;
  • not be discriminated against for using these rights;
  • appeal our decision on your request, by replying to our response.

Do not sell or share. BrainPost does not sell personal information or share it for cross-context behavioural advertising, and has not done so in the past 12 months. We do not knowingly sell or share the personal information of anyone under 16. We honour Global Privacy Control signals as an opt-out where required. The categories we collect are described in Section 4, the purposes in Section 5, and the recipients in Section 8. We do not use sensitive personal information to infer characteristics about you.

You may use an authorised agent to make a request. We may ask the agent for proof of authority and ask you to verify your identity.

13. How to make a request

Email privacy@brainpostio.com from the email address on your account, and tell us what you are asking for. We may need to verify your identity before acting.

We respond within the time the law requires: within 30 days in most cases (one month under the GDPR and UK GDPR; 45 days under California law), extendable where the law allows for complex requests. We will tell you if we need an extension. Requests are free unless they are clearly unfounded or excessive.

If we process your data on behalf of an agency or business customer, we will pass your request to them and help them respond.

14. Changes to this policy

We may update this policy from time to time. We will change the "Last updated" date and, for material changes, notify you by email or in the app before they take effect.

15. Contact us

Brainpost, LLC, a Delaware limited liability company

See also our Terms and Conditions and Cookie Policy.