Privacy Policy
A promise, not a policy. Last updated 6 July 2026.
Privacy is a design constraint of BraneWave, not a feature added afterwards. These are the guarantees we make to every reader and every author, and they are enforced in the platform's code — not just in this document.
Our ten guarantees
- Private from employers. If you use a twin through your employer's organisation account, your employer cannot read your conversations. Organisation admins see usage counts only — never message content.
- Private from other authors. An author can only see conversations held with their own twin.
- Private from other readers. Only you can see your conversation history.
- Authors can see their own twin's conversations. This is disclosed before you start chatting, and it is how authors keep their twins accurate.
- Operator access is limited and logged. BraneWave staff access conversation data only where strictly necessary (security incidents, legal obligation), and every access is logged.
- No training on your data. Your conversations and uploads are never used to train or fine-tune any AI model — by us or by our LLM providers, whose API terms exclude training use.
- No selling of data. We do not sell, licence, or transfer your data to third parties for commercial purposes. Ever.
- Deletion within 30 days. Delete your account or request erasure (GDPR/UK GDPR) and all your personal data and conversations are permanently deleted within 30 days, with email confirmation.
- Data stays in the UK/EU. All data is processed and stored in the United Kingdom or European Economic Area.
- Annual transparency report. We publish every government or law-enforcement data request we receive, and every change to this privacy model, in our transparency report.
What we collect
Your account details (email, name), your conversations with twins, content authors upload to train their own twins, and billing records handled by Stripe. Logs are stripped of personal information — message content and email addresses are never written to logs.
Your rights
Under UK GDPR you may request access to, correction of, or erasure of your personal data at any time. Erasure requests are honoured within 30 days.
Questions
Contact us through your account, or read the full technical privacy model in our transparency report.