Privacy policy

Privacy policy

Privacy policy

Last updated: 24 March, 2026.


DistriBrain ("we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your information when you use our platform, website (distribrain.com), and services.


  1. Information We Collect

1.1. Account Information. When you create an account, we collect your email address and authentication credentials. If you sign in via Google, we receive your name and email from Google — we do not receive or store your Google password.

1.2. Payment Information. Payments are processed by Stripe. We do not store your credit card details. Stripe retains your payment information in accordance with its own privacy policy.

1.3. Usage Metadata. We collect aggregate usage data such as API token consumption, model selection, and instance uptime to operate billing and display usage dashboards.

1.4. Technical Data. We may collect IP addresses, browser type, and device information for security, diagnostics, and abuse prevention.

1.5. Cookies. We use essential cookies for authentication and session management. We do not use third-party advertising or tracking cookies.


  1. Information We Do Not Collect

2.1. Conversation Content. We do not read, store, or log the conversations between you and your AI agent. Your conversation history resides solely within your dedicated instance.

2.2. Instance Data. Files, configurations, and memory stored within your AI agent instance are not accessed by us except as described in Section 5.


  1. How We Use Your Information

We use your information to:

  • Provision and operate your AI agent instance.

  • Process payments and manage your subscription.

  • Display usage and billing information on your dashboard.

  • Send transactional communications (account verification, payment receipts, service notices).

  • Maintain security and prevent abuse.

  • Improve our platform and services.

We do not use your information for advertising or profiling.


  1. Data Sharing

We do not sell, rent, or trade your personal information. We share data only with:

4.1. Stripe — for payment processing.

4.2. Supabase — for authentication and account data storage.

4.3. Google Cloud Platform — for infrastructure hosting (your instance runs on dedicated Google Compute Engine VMs in Singapore).

4.4. Cloudflare — for secure tunneling and DDoS protection.

4.5. AI Model Providers (Tier 1 only). If you are on a Managed plan, your AI prompts and responses are routed through third-party model providers (such as DeepSeek, Anthropic, and OpenAI) to generate responses. These providers process your prompts under their own privacy policies. We do not control their data retention practices.

4.6. Legal Obligations. We may disclose information if required by law, regulation, or legal process.


  1. Data Access & Isolation

Each customer instance runs on dedicated, isolated infrastructure. We do not share compute resources between customers. We do not access your instance data unless:

  • You explicitly request technical support and grant consent.

  • Required by law or to prevent imminent harm.


  1. Data Retention

6.1. Account Data. Retained for the duration of your account. You may request deletion at any time.

6.2. Instance Data. Upon subscription termination, your instance and all associated data (conversations, files, configuration) are permanently deleted within 30 days.

6.3. Billing Records. Payment records are retained as required by applicable tax and accounting laws.


  1. Data Security

We implement industry-standard security measures including:

  • Encryption in transit (TLS/HTTPS for all connections).

  • Instance isolation (dedicated VMs, no shared tenancy).

  • Network-level access control (loopback binding, Cloudflare tunnel).

  • Authentication via Supabase Auth with support for OAuth and email verification.

No system is perfectly secure. We cannot guarantee absolute security but will notify affected users promptly in the event of a data breach.


  1. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you.

  • Correct inaccurate personal data.

  • Delete your personal data and account.

  • Export your data in a portable format.

  • Withdraw consent for optional data processing.

To exercise any of these rights, contact us at support@distribrain.com.


  1. International Data Transfers

Our infrastructure is hosted in Singapore (Google Cloud asia-southeast1). If you access our services from outside Singapore, your data may be transferred to and processed in Singapore. By using our services, you consent to this transfer.


  1. Children's Privacy

DistriBrain is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware of such collection, we will delete the information promptly.


  1. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or dashboard notification at least 14 days before taking effect. The "Last updated" date at the top reflects the most recent revision.


  1. Contact

For questions about this Privacy Policy, please contact us at:


Email: support@distribrain.com

Website: https://www.distribrain.com