⚠️ Scheduled upgrade in progress — brethof-brain is moving to its new architecture. Signups and new installs are paused for the moment; nothing is lost and everything returns shortly.

Privacy Policy

brethof-brain · Last updated: August 22, 2026

1. Who we are

brethof-brain is operated by Brethof AI, based in Poland (EU). We are the data controller for your account data and the processor for the content your agents store. Contact: [email protected].

2. What we store

  • Account data — email, hashed password, two-factor secret, plan and billing status, API key hashes.
  • Memory content — the conversations your agents send us (the archive), the curated memories and memory graph derived from them, and anything your agents save explicitly. This can contain whatever you discuss with your agents — treat it accordingly, it is under your control.
  • Usage metrics — storage size, monthly message counts, and processing volume per account, used for plan enforcement and the usage alerts you configure.

The brethof.ai website itself does not run advertising or cross-site tracking. For visitor statistics we use Cloudflare Web Analytics, which is cookieless: it stores nothing on your device, cannot follow you between sites, and reports only aggregate figures such as page views and country. Login state is a session token stored in your browser.

Cookies. Visit this site normally and no cookie is set at all. The single exception is a partner (affiliate) link: if you arrive through one, we ask you first. Only if you agree do we load our payment provider's referral script, which stores one cookie and derives a device identifier so the partner is credited if you subscribe; that information is shared with Lemon Squeezy for that purpose alone. Decline and nothing is stored, and we do not ask again.

3. How your content is protected

  • Isolation — each customer's memory lives in its own database. No shared tables, no cross-tenant queries.
  • Encryption — encrypted in transit (TLS) and twice at rest: full-volume encryption underneath, and your database under its own per-customer encryption key on top. Deleting your account destroys your key — deletion is cryptographic. Details and honest limits on the Security page.
  • Backups — nightly, encrypted before they leave our machines, stored off-site in the EU on a rolling schedule, and kept for up to three months.
  • Access — only your API keys can reach your memory. Our staff access customer content only when required to operate the service or when you ask us to.

4. How your content is processed

The service processes your content automatically to provide memory: indexing and embedding for search, which is computed on our own servers and never leaves them, and AI curation — deciding what is worth keeping, updating what changed, and removing what turned out to be wrong. Only curation sends content to an outside provider, and only the passage being curated, one operation at a time. We do not train models on your content, and we never sell or share it for advertising.

Sub-processors

These are every third party that can touch your data, what they do, and where. We will update this list before adding a new one.

Provider Purpose Location
Hostinger International The servers the service runs on, and transactional email (verification, usage alerts) Frankfurt, Germany (EU)
Hetzner Online Off-site backup storage. Backups are encrypted before they leave our servers Falkenstein, Germany (EU)
Ollama The AI model that performs curation. Ollama’s published terms state that inputs and outputs are processed transiently, are never used to train models, and that you retain ownership of your content United States
Cloudflare DNS, TLS, protection against attack, and cookieless visitor statistics. Sees traffic in transit, not stored memory Global network (US company)
Lemon Squeezy Payments, as merchant of record. Never receives your memory; we never see your card details United States

Your memory is stored and searched entirely inside the EU. The one thing that leaves is curation: the passage being curated is sent to Ollama in the United States, processed, and returned. Their published policy is that this content is transient and never trained on — that is their commitment, stated in their own terms, and we describe it here as such rather than as a promise of ours to give. If you need curation never to leave the EU, that is available on a dedicated deployment; talk to us.

5. Retention and deletion

  • While your account is active, memory is kept until you delete it, and deletions take effect immediately in live systems. Saved memories — individual records, or a whole project — can be deleted at any time, at any age.
  • Your conversation history is deliberately hard to destroy, and that is a safety feature. AI agents act on this memory continuously. An agent can make a mistake, follow a malicious instruction hidden in something it read, or delete the wrong thing long before you notice. Because the raw history survives, anything the curated layer loses can be rebuilt from it. So history is removed only in bulk, per project, and only the part older than 90 days. No agent can erase a single message, and no agent can touch the last three months at all — that floor, and the bulk-only shape, are the protection. You remain free to delete an entire project or your whole account, which removes everything at once and is not subject to that floor.
  • If an account goes quiet — one schedule, and the same one whether a free account stops signing in or a paid account stops paying. On day 7 the database moves off our live systems into encrypted cold storage; nothing is lost and you need do nothing, because the next sign-in or API call restores it automatically, in seconds. On day 23 we email you the deletion date, with a one-click link to download everything. On day 30 it is permanently deleted, backups included, and cannot be recovered by you or by us. Both days are counted from the day the account went quiet, not from archiving. Nothing is ever deleted silently: you are emailed when it is archived, a week before deletion, and once after.
  • When a paid subscription lapses, the Brain pauses immediately — there is no grace period, and you should not plan around one. Your memory is not deleted at that moment — the schedule above begins instead, and paying again at any point before day 30 restores everything automatically. The two are separate: the service stops at once, the data survives to day 30. An active subscription is never archived or deleted for being quiet, however long it sits — storage is what you are paying for.
  • Deleting your memory account removes your tenant database from live systems immediately and deletes its encrypted backups with it. Deletion is permanent — we cannot restore a deleted account, for you or for anyone who asks us to. Any remaining copies are erased as our backup systems cycle, within 30 days at the most. Invoicing records are retained as required by tax law.

You can download your complete raw conversation history at any time from your account panel (“Download my data”) or via the API.

6. Your rights (GDPR)

You have the right to access, rectify, export, and erase your data, to restrict or object to processing, and to lodge a complaint with a supervisory authority (in Poland: UODO). Most of these you can exercise directly — your agents can read and delete everything through the service itself. For exports or anything you cannot do from your account, email [email protected] and we will respond within 30 days.

7. Changes

Material changes to this policy are announced by email to account holders at least 14 days in advance.

Hear it when it ships

New releases, real benchmarks and the occasional deep-dive. No spam, unsubscribe in one click.

Everything we build

External:   YouTube · GitHub