Security & PrivacyUpdated: June 2026
Use AI without training your replacement.
MyBrain holds what lives in your mind. That only works if you trust where it's being held.
This is the plain-language version of our commitments. The document that governs legally is the Privacy Policy. MyBrain is in controlled beta: where we are still building, we say we are still building.
This page explains, without legalese, what we do with your data, what we will never do, and what we are still building.
1.The essentials
- Your content never trains AI models. Neither ours nor third parties'. What you write is yours — raw material for your identity, not for our product.
- We protect your content before sending it to external AI. We replace the data that identifies people with neutral markers before any processing by outside AI, and the mapping to the real data stays on your side alone. (This is called pseudonymization; we explain it below.)
- We don't sell your data. We don't show ads. Our model is you paying for the product — not you being the product.
- You are in charge of your data. Access, correction, and deletion guaranteed by the LGPD, handled directly by our team.
2.How MyBrain works
Every AI product should answer this question before asking for your data. Here is our answer.
MyBrain is not a layer on top of ChatGPT. Your knowledge lives in a graph — the network of entities and relationships that forms your MyBrain, built from what you capture. The language model is only the query interface: it serves the graph, not the other way around.
This matters for your privacy for a concrete reason: because the knowledge lives in the graph, and not in a model's memory, your content does not have to become training data for the product to work. It is an architecture decision, not a marketing promise.
We work in layers, from least to most exposure. The most sensitive tasks run close to you, on your device or on our infrastructure. When an external model is necessary — for example, to chat with your MyBrain — whatever leaves first passes through the pseudonymization layer described below. Today, part of the heavier processing still uses external models, always under that protection, and we are expanding how much runs on our own infrastructure.
3.What we never do
- We never use your content to train AI models — ours or third parties'.
- We never sell or rent your data.
- We never show ads or share data with advertisers.
- We never read your content, unless you request support and authorize it.
- We never let external providers use your content for their own purposes: we work only with providers who forbid using customer data for training.
The exception is up to you. If you turn on "your own key" mode (below), that flow then follows the terms of the provider you chose, and these rules no longer apply to it. We tell you first.
4.Pseudonymization: how we protect your content from external AI
Before any passage of your content is processed by an external model, it goes through our pseudonymization layer: a system that detects and replaces the data that identifies people — names, tax IDs, emails, phone numbers, addresses, organizations — with neutral markers. In practice, "Maria" becomes "PERSON_07". The external model answers without ever receiving the real data; the mapping between marker and real value stays on your side and on our infrastructure, and the answer is reassembled only inside MyBrain.
We use the technically correct term — pseudonymization, not "anonymization" — because that mapping exists: it is what allows the answer to be reassembled for you. The data is therefore not made irreversible; it remains protected and under the rules of our Privacy Policy. We would rather be precise than promise more than we deliver.
One rule guides everything: public content may go to a high-quality external model; your private content never goes out raw — it is either pseudonymized or processed internally.
Stage transparency (beta). Today, pseudonymization protects your content in the flows where it would go to an external model — especially the conversation with your MyBrain. Part of the heavier capture processing, such as organizing your knowledge in the graph, still goes through external models, always under that protection, and we are migrating that processing to our own infrastructure so that less and less content has to leave. Numeric representations of your text (embeddings), which do not identify you, may be generated by external services. As we expand what runs internally, we update this page.
5.Your key, your rules
You can connect your own key from an external AI provider and use it directly through MyBrain. It is a deliberate trade: more capability, less protection. In that mode, your content goes to the provider under their terms, without our pseudonymization. That is why the option is off by default and only turns on with a clear notice of what changes.
The same applies to every action that leaves the protected environment — using an external model, opening a link, attaching something public, browsing the web: we ask for your permission at that moment, with the choices allow once, always allow or do not allow. The choice is yours, and you can change it later.
6.Where your content comes from
Beyond what you write directly in MyBrain, you can bring knowledge from other places — and we want to be clear about it:
- Apps you connect (Notion, Google Drive, Dropbox, OneDrive, Box, email): we import only what you authorize, within the permission granted, and you can disconnect whenever you want.
- Voice interviews with Maia and quick capture: your audio is transcribed and treated as your content; we record a session only with your consent, asked for every time.
- Imports from other AI tools: you can migrate your history from assistants such as ChatGPT or Gemini into your MyBrain.
- Public knowledge sweep (onboarding): with your authorization, we look up public information about you (on LinkedIn, for example) to suggest sources, and you approve item by item.
7.Who receives what
| Who | What they receive | What for |
|---|---|---|
| External AI model providers | Pseudonymized passages of your content, on demand from your query | Generating answers and processing captures |
| Cloud: AWS and Google Cloud | Your encrypted data | Storage and operation |
| Product analytics tools | Usage events without content (sanitized telemetry) | Understanding usage and improving |
None of these providers may use your data for their own purposes. The full list of sub-processors can be requested at privacy@mybrain.ai.
8.Infrastructure and encryption
- Your data is encrypted in transit and at rest.
- Hosted on AWS and Google Cloud. Because part of the infrastructure and of the providers sits outside Brazil, there is international transfer, handled as described in the Privacy Policy (arts. 33–36 of the LGPD).
- Telemetry is sanitized: logs and usage events carry no content from your captures.
- Internal access restricted by role.
9.Your rights (LGPD)
The LGPD guarantees you access, correction, deletion, portability, and information about how your data is processed. During the beta it works like this: write to privacy@mybrain.ai with your request, and we answer within 7 days. A copy of your data in a readable format goes out within 15 days. No labyrinthine form: in the beta, the people who answer are the people who build the product — the same team that acts as the Data Protection Officer (DPO).
You also control your MyBrain directly in the product: you can delete your account (in the data-control area) and review, correct, or delete pieces of knowledge that do not represent you.
10.Where we are on the path
MyBrain is in controlled beta, opening in waves to a few people at a time. We would rather tell you where we are than fake a maturity we do not have:
- Our own processing: we are migrating part of the processing to our infrastructure, so that less and less content has to leave.
- SOC 2 / ISO 27001 certification: we do not have it yet. It is on the roadmap as the product grows.
- Authentication: login with LinkedIn, Google, or a code sent by email.
- On-screen transparency (seeing every external call in the interface): planned; for now, this page plays that role.
A beta with limited seats and close contact: in some cases with individual onboarding and, over the course of the program, with feedback interviews after use — to hear what worked and what did not.
11.Questions and contact
A question that is not here? Write to support@mybrain.ai. Anything about your data and your rights goes to privacy@mybrain.ai.