Updated: June 2026
Privacy Policy
How MyBrain handles your data — and why we handle so little of it.
MyBrain is in controlled beta. This policy reflects the product at this stage and will be updated as it evolves — the revision date above always indicates the version in force. This is a translation of the Portuguese original; if the two diverge, the Portuguese version prevails.
MyBrain holds your intellectual memory. There is no way to do that without you trusting us with your data, and that trust is the most important asset we have. This policy explains, with as little legalese as the law allows, what we collect, what for, who we share it with and what your rights are. It covers the website, the waitlist and the app during the controlled beta.
1.Who controls your data
The service is operated by MyBrain ("we"), the controller of your personal data under Brazil's LGPD and, where applicable, the EU GDPR. The full identification of the controlling company can be requested at any time at privacy@mybrain.ai.
For anything concerning your data, or to exercise your rights, talk to our privacy team, which also acts as the Data Protection Officer (DPO): privacy@mybrain.ai.
2.What data we collect
Data you provide
- Account and sign-in: your name, your email and the details of the login you choose — LinkedIn, Google or a code sent by email.
- Your content: everything you capture — text, notes, documents, audio and voice interviews with Maia — and everything you add to your MyBrain. It is the heart of the product and gets the strongest protection in this policy (sections 4 and 5).
- Content from apps you connect: if you connect services such as Notion, Google Drive, Dropbox, OneDrive, Box or your email, we import only what you authorize, within the permission granted, and you can disconnect whenever you want.
- Content you import from other AI tools: you can bring in your history from assistants such as ChatGPT or Gemini. You represent that you hold the rights to that content (see the Terms of Use).
- Communications: what you exchange with the team in support and in beta feedback conversations. We record a voice conversation only with your consent, asked for in every session.
Data from public sources: during onboarding, with your authorization, we look up public information about you (on LinkedIn, for example) to suggest sources for your MyBrain — and you approve item by item what goes in.
Data generated by usage: usage telemetry (which features you use, when), performance metrics and error logs — designed to record events, not the content of your captures — plus technical data (IP, device, browser, operating system, language).
What we do not collect: we do not ask for or deliberately collect sensitive data (racial origin, religious belief, political opinion, health, biometrics). If you capture something sensitive in your MyBrain, we handle it with the protections in section 5 and never use it for any purpose of our own.
3.What we use your data for — purposes and legal bases
| Purpose | Data | Legal basis (LGPD art. 7 / GDPR art. 6) |
|---|---|---|
| Creating and running your account (capturing, organizing and returning your knowledge) | Account, content, content from connected apps | Performance of a contract |
| Processing your content with AI to answer your queries | Content (pseudonymized — section 5) | Performance of a contract |
| Looking up public knowledge to suggest sources during onboarding | Public data about you | Consent |
| Waitlist, invitations and beta participation (feedback, interviews, voice recordings) | Account, communications, audio | Consent |
| Improving the product, fixing errors and ensuring security | Telemetry, technical data | Legitimate interest |
| Communications about the product and the beta | Consent (opt out at any time) | |
| Complying with legal obligations and responding to authorities | As required by the obligation | Legal obligation |
4.What we never do with your data
- We do not sell or rent your personal data or your content.
- We do not use your data for advertising, nor do we let third parties do it on MyBrain's behalf.
- We do not use your content to train AI models — neither ours nor third parties'. We work only with providers whose policies forbid using customer data for training.
- We do not access your content, unless you request support and authorize it, or we are under a legal obligation.
The exception is up to you. If you turn on the option to use your own key for an external AI model (section 5), that flow then follows the terms of the provider you chose, and the commitments above no longer apply to it. We tell you clearly before you turn it on.
5.AI and processing of your content
MyBrain organizes your knowledge in a graph of its own. The language model is only the query interface: it serves the graph, which is why your content does not have to become training data for the product to work.
We work in layers, from least to most exposure. The most sensitive tasks run as close to you as possible — on your device or on our infrastructure — and we are expanding that share. When an external model is necessary (for example, to chat with your MyBrain), the content first goes through pseudonymization. One rule guides everything: public content may go to an external model; your private content never goes out raw.
What pseudonymization is, in plain language. We detect and replace the data that identifies people — names, tax IDs, emails, phone numbers, addresses, organizations — with neutral markers. "Maria" becomes "PERSON_07". The external model works with the markers and never receives the real data; the mapping stays on your side and on our infrastructure, and the answer is reassembled only inside MyBrain. Because that mapping exists, the data is not made anonymous irreversibly — which is why we use the correct term, pseudonymization, and treat it with the protections in this policy.
Where we are in the beta. Today, pseudonymization protects your content in the flows where it would go to an external model, especially the conversation with your MyBrain. Part of the heavier capture processing still uses external models, always under that protection, and we are migrating that processing to our own infrastructure. As we advance, we update this page.
Your key, your rules. You can connect your own key from an external provider and use it directly — a deliberate trade of more capability for less protection. The option is off by default. Whenever an action leaves the protected environment (using an external model, opening a link, attaching something public, browsing the web), we ask for your permission at that moment, with the choices allow once, always allow or do not allow.
7.How long we keep it
We keep your data for as long as necessary for the purposes in this policy. You can delete your account at any time in the product's data controls; deletion erases your data within 30 days, backups included, except what we must retain under a legal obligation or for the regular exercise of rights. Waitlist data that never becomes an account is kept for up to 12 months after the last contact.
8.Your rights
Under art. 18 of the LGPD, you may request: confirmation that processing takes place; access; correction; anonymization, blocking or deletion of unnecessary data or data processed in breach of the law; deletion of data processed on the basis of consent; information about sharing; and withdrawal of consent. You also control your MyBrain directly in the product: you can review, correct and delete pieces of knowledge that do not represent you.
Exporting your data: during the beta, upon request, we send a copy of your data in a readable format within 15 days.
To exercise any right, write to privacy@mybrain.ai. We answer within 7 days. You may also petition Brazil's National Data Protection Authority (ANPD) or, in the European Union, your local supervisory authority.
9.How we protect your data
We adopt technical and organizational measures appropriate to the nature of the data: encryption in transit and at rest, the pseudonymization layer for external AI, role-based access control, and telemetry that records usage events, not the content of your captures. No system is invulnerable, which is why we describe our stage and next steps honestly. In the event of a security incident with risk to your rights, we notify you and the competent authority — the ANPD under art. 48 of the LGPD and, where EU users are affected, the supervisory authority within 72 hours, under art. 33 of the GDPR.
11.Children and adolescents
MyBrain is not intended for people under 18 and we do not deliberately collect data from minors. By creating an account, you declare that you are 18 or older. If we identify an account belonging to a minor, we close it and delete the data.
12.Changes to this policy
We may update this policy to reflect changes in the product or in the law. The date at the top indicates the version in force. We notify you of relevant changes by email; changes that depend on consent only take effect after you consent, and we record the acceptance with date, time and the version of the documents then in force.
13.Contact
Questions about this policy, your data or your rights: privacy@mybrain.ai.
14.If you are in the European Union (GDPR)
If you are in the European Economic Area or the United Kingdom, in addition to the rights above you have the right to object to processing based on legitimate interest and to direct marketing (art. 21), to restrict processing (art. 18) and not to be subject to a decision based solely on automated processing with significant effect (art. 22). The legal bases correspond to arts. 6 and 9 of the GDPR. Transfers of data outside the European Economic Area rely on the European Commission's Standard Contractual Clauses, with a transfer impact assessment. In the event of a data breach with risk to your rights, we notify the competent supervisory authority within 72 hours (art. 33). For any of these rights, talk to privacy@mybrain.ai.