Legal

Sub-processors

Every third party that touches customer data, what each one receives, and where it is processed. Also, notably, the ones we do not use.

Effective Version 1.0

We use the third parties below to provide Brain. We will update this page before adding a new one. To be notified of changes, email hello@brayn.tech.

Who receives what

Sub-processorWhat it doesWhat it receivesWhere
OpenRouterRoutes our language-model requests and embeddingsThe full text of your conversations, message bodies, thread titles and author display namesUnited States, routing onward
DeepSeek (reached via OpenRouter)The model that processes that textThe same contentVaries — see below
ClerkAuthentication, user and organisation recordsName, email, authentication metadata, IP address, consent timestampUnited States
Our hosting providerRuns the server holding the database, queue and applicationAll stored customer dataLondon, United Kingdom
Let's EncryptIssues our TLS certificatesDomain names only — no customer dataUnited States

The routing caveat

OpenRouter is a router, not a single model provider. The provider that ultimately serves a given request, and the country it is served from, can vary per request. We currently configure DeepSeek models. If you need inference pinned to a specific provider or region, contact us before connecting a source.

Not sub-processors

Worth stating plainly, because it is unusual:

  • Nango — we run the OAuth broker ourselves, on our own server. Nango Cloud is not used. Your source access tokens are held by our self-hosted instance and are never sent to a third-party OAuth service.
  • No analytics provider. No Google Analytics, PostHog, Mixpanel, Amplitude, Segment or Plausible.
  • No error-monitoring or session-replay provider. No Sentry, Datadog, Hotjar, FullStory or LogRocket.
  • No email provider of our own. Brain sends no transactional email; account emails come from Clerk.
  • No payment processor. Brain is free and there is no billing system.
  • No CDN beyond the host serving Clerk's own authentication assets.

Your own sources are not sub-processors

Slack, GitHub, Jira, Zendesk, Google, ClickUp and Discourse are systems you already control and that we read from at your instruction. We do not send data to them.