Data involved
- Account and workspace information: account email and profile details, identifiers, membership and access information, and connection details needed for the service.
- Content you provide: documents, uploaded files, messages, instructions, and tool requests and results. Conversations and tool calls can be stored with their workspace context.
- Derived content: extracted text, attachment descriptions or summaries, document chunks and search embeddings used to organize and retrieve information.
- Operational and support information: request identifiers, provider and model details, status, timing, token usage, error information and messages you send to support.
Why data is processed
Brainfab uses this information to maintain accounts and access, store and retrieve workspace content, process requested AI operations and connected-service actions, and investigate support or operational problems. Share only information needed for the task and that you are authorized to provide.
Storage and AI providers
Supabase provides account authentication, and uploaded files are stored in Supabase Storage. Workspace records are stored in the service database. Selected supported images and text can be sent to the OpenAI API to generate attachment descriptions or summaries. Document chunks and search queries can be sent to OpenAI or Google Vertex AI to create embeddings; document embeddings are stored for retrieval.
AI conversations can send messages, instructions, available tool definitions and tool results to the configured model endpoint. The information sent depends on the selected workflow and provider configuration. A connected host, such as ChatGPT, also handles information under its own policies.
Provider processing and retention depend on the provider, endpoint and applicable account settings. Removing content from Brainfab does not by itself establish that every provider copy or operational record has been erased.
Storage and removal
Workspace records, files and derived information are stored to support continued use of the service. Removing an attachment updates its record and schedules storage cleanup; physical file removal may finish later and can require retry or investigation.
Account removal starts with a support request. Submitting the request does not itself confirm removal of files, derived records, provider copies or operational records. Ask support which data your request covers, what has been removed and what remains. This page does not promise a fixed deletion deadline or one retention period for every category.
Your choices and requests
- Limit the content and permissions you provide to each workflow.
- Use available document and attachment controls to manage your workspace content.
- Review or revoke connection access using the controls available in the host or connected service. Disconnecting a service is separate from deleting previously stored data.
- Contact support@brainfab.com to ask about access, correction, removal or the processing of your information. Support may need to verify your identity and authority over the account or workspace.
Sensitive information
Do not put passwords, API keys, access tokens, payment-card credentials or identity documents in support messages or ordinary task content. Before providing sensitive or third-party information, establish that you have permission and that the specific workflow is appropriate for it.