Privacy Policy
Last updated: June 10, 2026
This Privacy Policy describes how BrainTrail ("we", "us", "our") handles information when you use the BrainTrail browser extension or visit braintrail.app (together, the "Service").
BrainTrail is built and operated by Enrik, an independent developer based in Greece, working as a sole proprietor. For any privacy questions or requests, contact us at braintrail.app@gmail.com.
We've tried to write this in plain language. If anything is unclear, please email us.
Quick summary
- The BrainTrail extension stores your browsing data locally on your device. We do not see it, collect it, or transmit it to our servers.
- If you join our waitlist or sign up for an account, we collect only what's needed to provide that service (your email).
- We never sell your data. We never share it for advertising. We never use it to train AI models.
- You can export or delete your data at any time.
What data the extension collects
The BrainTrail extension records the following information on your device only:
- Pages you visit while the extension is active (URL, title, timestamp)
- Time spent on each page and domain
- Notes you save through the extension
- Pins, tags, and other organisation you add
This data is stored locally in your browser's storage. We do not have access to it. It does not leave your device unless you explicitly export it or, in the future, opt into BrainTrail Pro (described below).
You can pause tracking at any time from the extension's settings, or clear all stored data with one click.
What data the website collects
When you visit braintrail.app, our hosting provider (Vercel) automatically logs your IP address, browser type, and the pages you visit. This is standard for any website and is used to keep the site operational and detect abuse. We do not currently run advertising or third-party analytics on the marketing site.
If you submit your email address through the waitlist form (on the website or in the extension), we store the following in our database:
- Your email address
- The source of the signup (e.g. "extension_onboarding" or "website")
- Your browser's user agent string
- The timestamp of your signup
We use this only to contact you when BrainTrail Pro becomes available. You can request deletion at any time by emailing us.
Future Pro tier (not currently active)
When BrainTrail Pro launches, signing up will create an account with us and enable optional cloud features. This will involve:
- Account data: your email, an encrypted password (or OAuth tokens if you sign in with Google), and your subscription status
- Synced content: your trails, notes, and time tracking data, copied from your device to our servers so you can access them on other devices
- AI processing: when you use AI features (semantic search, summaries), the relevant data is sent to OpenAI for processing. OpenAI's terms apply to that processing; we never share your data with OpenAI for training purposes
- Payment data: if you subscribe, payments are processed by Stripe. We do not see or store your card details
We will update this policy with full details when Pro launches. Until then, none of this applies.
How we use this data
We use the limited data we collect only to:
- Operate and maintain the Service
- Respond to your requests and support questions
- Notify you when BrainTrail Pro is available (waitlist only)
- Detect and prevent abuse, fraud, or security issues
- Comply with legal obligations
We do not sell your data. We do not share it with advertisers. We do not use it to train AI models.
Who can see this data
The waitlist data described above is accessible only to:
- Us (the BrainTrail operator)
- Our database provider, Supabase (servers located in Ireland, EU)
- Our hosting provider, Vercel (for the website itself)
Once Pro launches, additional processors (OpenAI for AI features, Stripe for payments, Google for OAuth sign-in if you choose it) will see only the specific data needed for their part of the service.
We may also share data if legally required (e.g. a valid court order) or to protect the rights, safety, or property of BrainTrail or others.
Your rights under GDPR
Because BrainTrail is operated from Greece (EU) and serves users in Europe, you have rights under the General Data Protection Regulation:
- Access: ask what data we hold about you
- Correction: ask us to fix incorrect data
- Deletion: ask us to delete your data
- Portability: receive your data in a machine-readable format
- Objection: object to specific uses of your data
- Withdrawal of consent: change your mind at any time
To exercise any of these rights, email braintrail.app@gmail.com. We will respond within 30 days.
If you believe we've mishandled your data, you also have the right to complain to the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα) at www.dpa.gr.
How long we keep data
- Extension data on your device: until you delete it or uninstall the extension
- Waitlist email: until you ask us to delete it, or until two years after Pro launches (whichever comes first)
- Server logs: a limited retention period set by our hosting provider, typically 30 days
Children
BrainTrail is not intended for users under 16 years of age. We do not knowingly collect data from anyone under 16. If you believe a minor has provided us with data, email us and we will delete it.
International transfers
If you are accessing BrainTrail from outside the EU, please note that data is processed in EU-based servers (primarily Ireland for Supabase). By using the Service, you consent to this processing.
Security
We use industry-standard security practices: encrypted connections (HTTPS), authenticated database access (Supabase Row Level Security), and access limited to those who need it. However, no system is completely secure. If we discover a breach affecting your data, we will notify you within 72 hours as required by GDPR.
Changes to this policy
We may update this Privacy Policy as BrainTrail evolves. When we do, we'll update the "Last updated" date at the top. For material changes, we'll also notify users by email (if we have one) or via a notice on the extension and website.
Contact
For any questions, requests, or concerns about this policy or how we handle your data:
Email: braintrail.app@gmail.com
Operator: Enrik (sole proprietor), Greece