Privacy at Brad

This is a plain-language summary of how Brad handles the data your team brings to it. It is a summary, not a final legal agreement — a formal privacy policy and data-processing terms are being prepared. Where we can state something plainly today, we do; where something is still in progress, we say so.

Your data is yours

When your team uses Brad, we hold the documents and messages you bring to it — uploaded files, connected channels, and the account details needed to run your workspace.

Your project's content belongs to you. We treat it as a record to connect and protect, not a dataset to repurpose. We do not sell it, and we do not use it to train any general-purpose AI model.

How we use it

We use your content to power Brad — to read, connect, search, and answer across your project. We use account and usage information to operate the service and keep it secure.

Brad’s answers are generated by reading your documents with established AI providers (OpenAI and Anthropic) through their metered business APIs. Inputs and outputs sent through those APIs are not used to train the providers’ public models — that is their standard API policy — and our production system is built to route customer inference only through those metered APIs.

Access and isolation

Access to a project's information follows workspace membership and the share links you create. Workspaces are isolated from one another at the database level — a project's content is reachable by the people on that project, plus anyone you deliberately share a document with. One workspace cannot reach another's records.

The public pages on this site (what you're reading now, and the marketing and use-case pages) require no sign-in and contain no customer project data. Project data lives inside your authenticated workspace, reachable only by signing in or through a share link you were explicitly sent.

How it's protected

Your documents are encrypted at rest (AES-256) by the storage that holds them — Supabase (our database and file storage) and Cloudflare R2 (inbound attachments and files from sources you connect) — and travel over encrypted (TLS/HTTPS) connections. We rely on these providers’ platform encryption and limit access to your workspace to the people who belong to it.

We use a small set of established subprocessors, each for a specific purpose — hosting, AI inference, search indexing, storage, billing, background jobs, sign-in verification, and email. Our security and subprocessors pages name them, describe what each is for, and carry a dated list; ask us for a formal copy.

Our database is backed up daily, access by our own team follows least privilege, and we maintain an incident-response process for security issues. Our security page covers each of these in plain language, including the file-object backup work still underway.

Text messaging privacy

When you text GotBrad, we use your mobile number, message content, and delivery metadata to answer you, maintain the conversation, provide support, prevent abuse, and operate the service. Message and data rates may apply. You can reply STOP at any time to stop SMS messages and HELP for help.

We do not sell or rent mobile numbers. We do not share mobile information, text-messaging originator opt-in data, or consent with third parties or affiliates for their marketing or promotional purposes. We may share data with service providers such as Twilio only as needed to deliver and secure the messaging service, subject to their contractual restrictions.

Removing your data

You can delete your workspace yourself, at any time, from Account → Settings → Security. Deletion is irreversible: it permanently removes all documents, members, API keys, and the graph record we built from your data — including the bytes in file storage and the fast-read graph projection. If the workspace has an active Stripe subscription, Brad attempts to cancel it during deletion; Stripe customer, invoice, and subscription history may be retained for accounting and tax purposes and does not contain project-document content. To prevent accidental deletion, the control requires the workspace owner to type the exact workspace name before the action is enabled, and the server enforces the same check independently of the UI.

Our data-retention schedule: while your workspace is active, we hold your project data for as long as you keep the workspace. If you delete it, the deletion runs immediately — it purges your database rows, the file bytes in storage, and staged inbound attachments — and we do not retain those live records afterward. A routine database backup taken before you deleted may still hold a copy until it ages out of the backup window on its normal rotation. We retain Stripe billing records (customer identity, invoices, subscription history) for accounting and tax purposes, as required by law, even after a workspace is deleted; those records contain no project-document content. Overlord-event logs (our internal observability record) are scrubbed at workspace deletion by default. Commission or referral ledger entries are anonymized (the live tenant reference is nulled, but the row remains for accounting).

Honest scope

This summary describes our approach and what is true today, not a list of guarantees or certifications. A formal privacy policy and data-processing terms are in progress. We have not pursued a formal certification such as SOC 2 and won’t claim one until we have it. If your organization needs specific documentation — a DPA, a subprocessor list, security details — contact us and we will tell you plainly what we can and cannot provide.

See Brad on your project

Brad connects the plans, contracts, change orders, photos, and conversations on your job into one source of truth. Join the waitlist and bring a project you want to untangle.

Join the waitlist