BrainPost Privacy Policy
Last updated 29 September 2026
This Privacy Policy explains what personal data BrainPost collects, why, who we share it with, how long we keep it, and the choices and rights you have. It applies to our website at https://brainpostio.com, our web app at https://app.brainpostio.com and related services (the "Service").
BrainPost does not sell your personal data, and we do not use it for third-party advertising.
1. Who we are
The Service is provided by Brainpost, LLC, a Delaware limited liability company ("BrainPost", "we", "us" or "our").
For all privacy matters, email privacy@brainpostio.com. Email is the main way to reach us.
This policy should be read with our Terms and Conditions and Cookie Policy.
2. Our role: controller or processor
When we are the controller. For account, billing, referral, website, support, security and marketing data, BrainPost decides how and why the data is used. We are the "controller" (or "business" under California law).
When we act for our customers. Agencies, freelancers and businesses may use BrainPost to manage content and social accounts for their own clients. When they put their clients' personal data into a workspace (for example, a client's social account data, audience metrics, or people shown in media), that customer is usually the controller and BrainPost acts as their processor or service provider. We process that data only to provide the Service under our customer's instructions. If you are a client of one of our customers, please contact that customer first about your data; we will help them respond.
Data Processing Addendum. Business customers who need one can request our Data Processing Addendum (DPA) at privacy@brainpostio.com.
3. Age
BrainPost is for people aged 18 and over and for business use. We do not knowingly collect personal data from anyone under 18. If you believe a minor has given us personal data, contact us and we will delete it.
4. Personal data we collect
We collect data you give us, data created when you use the Service, and data from services you connect.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Name, email, password (stored hashed, never in plain text), phone number (optional), profile photo, language, timezone, theme preference | You |
| Google Sign-In | Basic Google profile: name, email address and profile picture | Google, when you choose to sign in with Google |
| Workspace and brand | Workspace name, logo, website (optional), industry, business description, brand colours, brand tone | You |
| Onboarding | How you heard about BrainPost, intended uses, job role (optional), marketing email preference | You |
| Content | Posts, captions, comments, approvals, uploaded images, videos and files, AI prompts and AI output, CSV imports | You and your team |
| Connected social accounts | Access tokens, account and profile details (such as handle, name, profile picture, page or channel ID), post content and performance metrics, audience metrics such as followers, impressions and engagement | Instagram, Facebook, LinkedIn, TikTok, X, YouTube and other platforms you connect |
| Team | Invitee email addresses, roles, member status, activity log entries (name, action, IP address) | You, your team and our systems |
| Billing | Billing email, purchase history, invoices. Card details are collected and held by Stripe, not by us | You and Stripe |
| Referral and payout | Referral relationships, commissions, PayPal email, or for bank transfer: account holder name, bank country, IBAN or account number, SWIFT/BIC or routing number | You and our systems |
| Technical and usage | IP address, device and browser type, pages and features used, log data, error reports, security check results from Cloudflare Turnstile | Your device and our systems |
| Cookies | See our Cookie Policy | Your browser |
| Support | First name, last name, email and message sent through our contact form or by email | You |
| Newsletter | Email address entered in the subscribe form on our website | You |
Data about other people. If you upload content showing other people, invite teammates, or manage a client's accounts, you are responsible for having a lawful basis and giving any notice needed to share their data with us.
Sensitive data. The Service is not designed for sensitive data (such as health, religious or biometric data). Please do not put it in your prompts or content unless you need to and have a lawful basis.
5. How we use your data and our legal bases
Laws such as the EU and UK GDPR and the Nigeria Data Protection Act 2023 (NDPA) require a legal basis for each use. Ours are below.
| Purpose | Examples | Legal basis |
|---|---|---|
| Provide the Service | Create and run your account and workspaces, store content, schedule and publish posts, show analytics, process CSV files | Performance of our contract with you |
| AI features | Generate captions, images and video in your brand style, produce analyses and recommendations, run the assistant | Performance of contract |
| Payments and credits | Process purchases, track credits, issue invoices | Performance of contract; legal obligation (tax and accounting) |
| Referral programme | Track referrals, calculate and pay commissions, prevent abuse | Performance of contract; legitimate interests (fraud prevention) |
| Service messages | Invitations, approval requests, reconnect alerts, security notices, receipts | Performance of contract; legitimate interests |
| Security and fraud prevention | Turnstile checks, activity logs, detecting abuse of credits or referrals | Legitimate interests; legal obligation |
| Support | Answer questions and restore accounts | Performance of contract; legitimate interests |
| Improve the Service | Fix bugs, understand which features are used, plan new features | Legitimate interests |
| Marketing emails and newsletter | Product updates and tips | Consent (you can withdraw it at any time) |
| Legal compliance | Respond to lawful requests, enforce our Terms, keep required records | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have balanced them against your rights. You can object at any time (see Section 12).
6. AI and your data
What we send to AI providers. To run AI features, we send the minimum inputs needed for the task. These can include your prompts, workspace and brand details, post content, uploaded media and analytics data.
Our AI providers. We currently use models from OpenAI, Anthropic, Google, and models available through Higgsfield. They process inputs to return output to us, under their own terms and our agreements with them.
Training. BrainPost uses your workspace data, such as your brand details and past content, to tailor AI output for your workspace only. We do not use one customer's content to improve results for other customers. We use our AI providers' business or API services, under which they process inputs to return output to us, under their own terms and our agreements with them.
No automated decisions with legal effect. AI recommendations such as best times to post are suggestions. We do not make decisions based solely on automated processing that have legal or similarly significant effects on you.
Turning off the assistant. Each user can turn off the in-app AI assistant. The assistant can see what you can see in the app, but never billing or settings.
7. Data from Google and YouTube
If you sign in with Google or connect a YouTube channel, BrainPost's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- we use Google user data only to provide and improve the user-facing features of BrainPost that you see in the app;
- we do not sell it, use it for advertising, or let humans read it unless you ask us to (for example, for support), it is needed for security or legal reasons, or it is aggregated and anonymised;
- we do not use it to train generalised AI or machine-learning models.
YouTube features are governed by YouTube's Terms of Service and the Google Privacy Policy. You can revoke access at https://myaccount.google.com/permissions.
We handle data from Meta, TikTok, LinkedIn and X according to each platform's developer terms, and only to provide the features you use.
8. Who we share data with
We share personal data only as described here. We do not sell it or share it for cross-context behavioural advertising.
| Recipient | Why | Data involved |
|---|---|---|
| Hosting and cloud infrastructure providers | Store and run the Service | All Service data |
| AI model providers (OpenAI, Anthropic, Google, Higgsfield) | Generate content, analyses and assistant replies | Prompts, brand details, content, media, analytics used for the task |
| Social platforms you connect (Meta, LinkedIn, TikTok, X, YouTube/Google, and Pinterest and Threads when available) | Publish posts and fetch analytics at your request | Post content, media, access tokens |
| Google Sign-In; Google Fonts on our website (your browser sends your IP address to Google) | Basic profile; IP address and browser details | |
| Cloudflare | Turnstile bot protection | IP address, device and browser signals |
| Stripe | Process payments and taxes, issue receipts | Billing email, purchase details, card details (held by Stripe) |
| PayPal and banks | Pay referral commissions | Name, PayPal email or bank details, payout amount |
| Email delivery providers | Send invitations, notifications and marketing emails | Name, email address, message content |
| Other users in your workspace | Collaboration | Your name, photo, role, comments, approvals, activity log entries including IP address |
| People you share with | Files you share with another workspace or by public link | The shared files |
| Referrers | Show referral status | Your name in masked form (for example, "Ra*** P."), join date, status, first-purchase amount |
| Professional advisers and authorities | Legal, tax and accounting advice; responding to lawful requests; protecting rights and safety | As needed |
| A buyer or successor | If BrainPost is merged, acquired or sells assets | Data needed to continue the Service, with notice to you |
Our service providers may only use personal data to provide services to us, under contracts that require confidentiality and security. Social platforms and Stripe also act as independent controllers under their own privacy policies.
9. International transfers
BrainPost is a United States company. We and our providers may process data in the United States and other countries. These countries may not have the same data protection laws as yours.
When we transfer personal data out of the EU, UK, Switzerland or Nigeria, we use appropriate safeguards, such as:
- the European Commission's Standard Contractual Clauses;
- the UK International Data Transfer Addendum;
- the EU-US Data Privacy Framework, where the recipient is certified;
- for Nigeria, safeguards recognised under Part VIII of the NDPA, such as contractual clauses, or your consent where appropriate.
You can ask for more information about these safeguards at privacy@brainpostio.com.
10. How long we keep data
| Data | How long |
|---|---|
| Account, workspace and content | While your account is active |
| Deleted accounts | 30-day restore window, then permanently deleted |
| Workspace activity log (including IP addresses) | 12 months |
| Backups | Purged within 30 days of deletion from live systems |
| Invoices and purchase records | As long as tax and accounting law requires |
| Referral and payout records | As long as needed to pay commissions, handle disputes and meet tax law |
| Connected account tokens | Until you disconnect the channel or delete the workspace |
| Newsletter and marketing lists | Until you unsubscribe; we keep a suppression record so we do not email you again |
| Server and security logs 90 days |
We may keep data longer where the law requires it, or to resolve disputes and enforce our agreements. Content you have already published to social platforms stays there under those platforms' policies; delete it on the platform if you want it removed.
11. Security
We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss and misuse. No system is completely secure. If a data breach affects you, we will notify you and the relevant regulators as the law requires, including the Nigeria Data Protection Commission within 72 hours where the NDPA applies.
You can help by using a strong, unique password and revoking access for people who no longer need it.
12. Your rights
Everyone. Wherever you live, you can:
- access and correct your profile and workspace details in Settings;
- export content by CSV or download your files;
- delete your account in Settings (30-day restore window applies);
- disconnect social accounts at any time;
- opt out of marketing in Settings or with the unsubscribe link;
- turn off the AI assistant.
EU, UK, Switzerland and Nigeria. Under the GDPR, UK GDPR and NDPA you also have the right to:
- request a copy of your personal data and information about how we use it;
- have inaccurate data corrected;
- have data erased;
- restrict our processing;
- object to processing based on legitimate interests, and to direct marketing at any time;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting earlier processing;
- not be subject to decisions based solely on automated processing with legal or similar effects;
- complain to a regulator: your local EU data protection authority; the UK Information Commissioner's Office (ico.org.uk); or the Nigeria Data Protection Commission (ndpc.gov.ng). We would appreciate the chance to resolve your concern first.
California and other US states. Residents of California and other states with privacy laws may have the right to:
- know what personal information we collect, use and disclose;
- access, correct and delete it;
- opt out of the sale or sharing of personal information, and of targeted advertising;
- limit use of sensitive personal information;
- not be discriminated against for using these rights;
- appeal our decision on your request, by replying to our response.
Do not sell or share. BrainPost does not sell personal information or share it for cross-context behavioural advertising, and has not done so in the past 12 months. We do not knowingly sell or share the personal information of anyone under 16. We honour Global Privacy Control signals as an opt-out where required. The categories we collect are described in Section 4, the purposes in Section 5, and the recipients in Section 8. We do not use sensitive personal information to infer characteristics about you.
You may use an authorised agent to make a request. We may ask the agent for proof of authority and ask you to verify your identity.
13. How to make a request
Email privacy@brainpostio.com from the email address on your account, and tell us what you are asking for. We may need to verify your identity before acting.
We respond within the time the law requires: within 30 days in most cases (one month under the GDPR and UK GDPR; 45 days under California law), extendable where the law allows for complex requests. We will tell you if we need an extension. Requests are free unless they are clearly unfounded or excessive.
If we process your data on behalf of an agency or business customer, we will pass your request to them and help them respond.
14. Changes to this policy
We may update this policy from time to time. We will change the "Last updated" date and, for material changes, notify you by email or in the app before they take effect.
15. Contact us
Brainpost, LLC, a Delaware limited liability company
- Privacy and legal: privacy@brainpostio.com
- Support: support@brainpostio.com
- Website: https://brainpostio.com
See also our Terms and Conditions and Cookie Policy.
