Privacy Policy
Last updated 15 August 2026 · Light Within Life PTE. LTD., Singapore
This page describes what actually happens to your data in the product as it is built today — not what we intend to build. Where we can't do something, it says so. If anything here doesn't match what the product does, that's a bug: write to support@chiefbrain.ai and we'll either fix the product or fix this page.
Who you're dealing with
ChiefBrain is operated by Light Within Life PTE. LTD., a company registered in Singapore. For anything about your data — questions, corrections, deletion — write to support@chiefbrain.ai. A person reads it.
What we hold
| Kind | What's actually stored |
|---|---|
| Account | Email address, display name, and — depending on how you sign in — phone number, Google account link, or WeChat openid/unionid. Plus region, time zone, and whether you've seen the tour. |
| Login codes | Six-digit one-time codes, stored until they expire (5 minutes for SMS, 10 minutes for email). They are not written to our server logs. |
| Your work | Everything on your desk: what you type, what the Brain replies, the files you upload, the files it produces, and a record of each run. |
| Long-term memory | Short facts the Brain keeps from past runs so it doesn't ask you the same thing twice. You can read the whole list and delete any line of it — see below. |
| Billing | Your plan, quota, subscription status, Stripe customer ID, and a payment record per charge (amount, currency, provider reference). We never receive your card number — Stripe holds it. |
| Support messages | If you use the form on the Help page: your name, email, topic, message, language, and the IP address the message came from. |
| Delivery records | For every code or notice we send: channel, the address or number it went to, which template, whether it succeeded, and the provider's reference — so that "I never got the code" is answerable. |
| Company data source audit | If your employer connects a shared folder: who read, when, how many bytes, allowed or refused. File paths and search terms are stored as SHA-256 hashes plus a length, not as plain text — an earlier version stored them in the clear and we changed it. |
| Server logs | Kept 7 days, then discarded by the system, not by hand. |
Where it lives
Our servers, database and object storage are in Hong Kong (Alibaba Cloud, region cn-hongkong). The website itself is served by Vercel. So wherever you are — Europe, the United States, mainland China — your data is processed in Hong Kong. If that is not acceptable to your organisation, don't connect anything sensitive; tell us and we'll say plainly whether we can meet your requirement rather than working around the question.
Today all customers share one host, one database and one storage bucket. That is a real concentration of risk and we're telling you about it rather than letting you assume otherwise.
Who else touches it
These are the only outside services your content can reach. This list is generated from what the code actually calls, not from a template.
| Service | What it gets |
|---|---|
| Vercel | Hosts the website, and runs the AI Gateway that is the single exit from our servers to any model. |
| OpenAI (through that gateway) | The text of your task and whatever context the run needs, in order to produce an answer. |
| Alibaba Cloud | Servers, database and object storage in Hong Kong. Separately: SMS login codes inside mainland China, and speech-to-text when you dictate instead of typing (the audio clip is sent, transcribed, and the text comes back). |
| Resend | Email — login codes, receipts, notices. Gets your email address and the message. |
| Stripe | Card payments outside mainland China. Gets your payment details directly; we don't. |
We do not sell your data, and we do not hand it to advertisers or data brokers. There is no advertising product here to feed.
How long we keep it
- Desk files and run records — for as long as your account exists. Conversation transcripts follow a retention you choose yourself in Settings: keep forever (the default), 30 days, 90 days, or a year. There is also a button that clears every transcript right now; it does not touch the files the work produced.
- Long-term memory — until you delete it. Settings shows the full list; you can remove one fact or all of them.
- Server logs — 7 days.
- Login codes — minutes, then they expire.
- Everything else (billing records, support messages, delivery records) — until you ask us to remove it, or we no longer need it to run the business.
What you can do right now
These are buttons that exist in the product today, not rights you have to email us to exercise:
- Read every fact the Brain has remembered about you, and delete any of them.
- Choose how long transcripts live, or wipe them all immediately.
- Switch off your company's shared data source for yourself — when it's off, no query about your work leaves the desk at all.
- Delete your account and everything attached to it.
For anything not on that list — a copy of your data, a correction, a question about a specific record — email support@chiefbrain.ai.
Deleting your account
Deletion is self-serve: Settings → Delete account. It is not a request that goes into a queue. When you confirm, we destroy your container and its volume (every file on your desk), delete the snapshot objects in storage, and delete your rows across the database — runs, artifacts, run events, skills, streaks, entitlements, bridge audit, security events, source preferences, organisation membership, desks, sessions, linked sign-in accounts, and the account row itself.
You get back a per-table count of what was removed. If any single table fails, the response says so explicitly instead of reporting success — quietly keeping your data would be the worst outcome.
If your company connects a shared folder
An administrator can connect a folder on a company machine so the Brain can answer questions from it. What that means in practice:
- The folder is not uploaded. It stays on that machine. Only when someone asks a related question do we read the one or two relevant files.
- The part that gets read does leave that machine. Its text is sent to our servers and on to the model, because that is the only way to answer. We say this plainly because it decides whether you should use the feature. Anyone who tells you otherwise is not being straight with you.
- The text of those files is not written into transcripts — only the path and byte count is. An earlier version did store the text, and we found it, fixed it, and cleared the history.
- Content read from a company folder is not turned into long-term memory. Any run that touched the folder is excluded from memory entirely.
- Only text files (
.md,.txt,.csv) inside the authorised folder can be read, and only for reading — the feature has no code that writes, changes or deletes anything. Files whose contents look like credentials are refused outright.
What we don't do — said plainly
A privacy policy that only lists reassurances is not worth reading. Here is the other half:
- No end-to-end encryption. Traffic is encrypted in transit (TLS). But your content is readable on our servers, and our administrators technically have access to the database and the machines. That is true of essentially every SaaS product; we're not going to pretend it isn't true of this one.
- We don't claim encryption at rest. If we turn it on, this line changes and says so.
- No SOC 2, no ISO 27001. No third-party compliance audit has been done. If you need one to sign, we don't have it yet.
- We can't make promises on the model provider's behalf. Producing an answer means sending content to a third-party model. We use business API channels, and we do not train any model ourselves — we have no training pipeline at all. But a guarantee about what another company does with data is theirs to give, not ours, and we won't repeat it as if it were ours.
- We can't protect a machine that's already compromised. If the computer running a company data source is itself breached, nothing on our side helps.
Children
ChiefBrain is a work tool built for adults. It isn't designed or marketed for children, and we don't knowingly create accounts for them. If you believe a child has an account, write to us and we'll delete it.
A specific minimum age depends on where you live and is one of the items still with our counsel — see below.
Not yet stated
Some parts of a privacy policy carry legal effect and have to be settled by a lawyer for each jurisdiction. We are not going to invent them and present them as if they were reviewed. Still outstanding:
- Our registered address and company registration number
- The legal basis we rely on for processing, and the mechanism for transferring data out of your region into Hong Kong
- How the statutory rights you may have (access, correction, portability, erasure, objection) are formally described and the deadline we commit to
- Which country's law governs this policy, and where disputes are heard
- A named contact for data protection, and any regional representative
Until those are published, nothing on this page limits any right you already have under the law that applies to you, and the practical route to all of them is the same: support@chiefbrain.ai.
When this page changes
The date at the top moves whenever the text does. If a change makes a material difference to what happens to your data, we'll tell you rather than quietly editing the page.