Brenian

Privacy Policy

Last updated 11 September 2026

This policy says what Brenian keeps about you, where it lives, who can see it, and how to get rid of it. It is written to be read.

What we keep, and where

Your account — name, email address, a salted hash of your password, whether your address is verified, your admin role if you have one, and your privacy choices. Kept in our central database.

Your credits — a ledger of grants, purchases and per-turn charges, including which model ran and how many tokens it used. Kept centrally. Stripe holds your payment details; we keep only Stripe's identifiers.

Your sessions and files — everything you say to your agent, everything it says and does, and every file it makes. Kept only in your own workspace: an isolated container with its own storage, assigned to your account alone. Our central systems route your requests to it and never store its contents. When a session has not been used for 90 days, its step-by-step log and scratch files are cleared to save space; the conversation and the results it made are kept until you delete them.

What your agent learned — short notes about which tools and methods worked in your sessions, each with the session ids it came from. Kept in your own workspace, and used in your later sessions. Settings shows every note: you can correct one, stop it being used, or forget it.

API keys — a hash of each key you mint (the key itself is shown once and not kept), its name, and the subject it is bound to if any.

What leaves your workspace

To answer you, your agent sends prompts — which include what you wrote and what it has read so far — to language models. Brenian uses only models that DigitalOcean hosts on its own infrastructure, under terms that do not allow training on your prompts. Your agent may also fetch web pages and call search engines on your instruction; those sites see the requests your agent makes, as they would from any browser.

Shared learnings

After a session with tool activity finishes, your workspace reviews how the work went and may extract short lessons about tools and methods — "browser mode is needed for pages rendered with JavaScript", for example. Only the lesson text and the session's internal id are sent to our central systems, along with an anonymized reference to your account that cannot be turned back into your identity. Never your messages, your files, your results, or anything that names or describes you; the extraction is instructed to reject lessons about a person or a task, and lessons reach other users' agents only after independent confirmation from several different accounts or review by an administrator.

You can opt out in Settings. With the switch off, nothing is sent to our central systems; your workspace still keeps its own notes for your sessions, and your agent still benefits from lessons others have shared.

Correcting or forgetting a note in Settings also withdraws what your sessions contributed to the shared version of it, so it stops counting toward anyone else's agent.

Who can see what

You. Our administrators can see your account record, your credit ledger, and — to support you or to operate the platform — the state of your workspace, including its sessions. They do not read sessions as a matter of course, and access is logged. No one else sees your data unless the law compels us, in which case we will tell you if we may.

Sites you publish

A site your agent publishes lives at an address under brenian.app, on a domain separate from this app. It is private to you until you share it. When someone visits a site, our servers see the request as any web server would — the address it came from, the page asked for, the time — and keep that in the same request logs described below, with no cookies set for the visitor and no tracking scripts, because published sites are not allowed to load anything from anywhere else. A shared link contains a token; anyone holding it can open the site until you revoke the link. A site's content is whatever your agent put in it: it is your content, and the sources it drew from are listed on the site itself. Deleting a site removes every published version.

Logs and security

Our request logs record the path, timing and outcome of each request with an anonymized account reference, never your email or the content of what you sent. Passwords, session tokens, API keys and email links are hashed at rest. Traffic is encrypted in transit.

Cookies

Brenian sets no cookies. Your login is a token kept in your browser's local storage for this site only, and a few display preferences are kept the same way.

Deleting your data

Settings → Delete account removes your account, your sessions, keys, credit ledger and your entire workspace, and forfeits unused credits. This cannot be undone. Lessons already shared from your sessions are not about you and are not removed, because they contain nothing of yours; if you believe one does, write to us and we will remove it.

Children

Brenian is not for anyone under 18, and we do not knowingly keep data about children.

Changes and contact

If this policy changes in a way that matters, we will tell you by email or in the app first. Questions or requests about your data: hello@brenian.com.