brightstack AI, Inc.
Privacy Policy
How brightstack collects, uses, and protects your information.
- Effective
- April 27, 2026
- Last updated
- April 27, 2026
brightstack AI, Inc. (brightstack, "we", "us", or "our") is committed to respecting your privacy and keeping secure any information you share with us. This Privacy Policy explains how we collect, use, disclose, and process your personal data when you use our software, platform, APIs, documentation, the website at https://brightstack.ai, the application at https://app.brightstack.ai, and all related software made available by brightstack (collectively, the "Service").
It also tells you how you can access and update your personal information and describes the data protection rights that may be available under your country's or state's laws. By accessing or using the Service, you acknowledge you have been informed of and consent to our practices with regard to your personal information and data.
This Privacy Policy does not apply where brightstack acts as a data processor and processes personal data on behalf of commercial customers, for example if your employer has provisioned a brightstack account for you to use at work. Our use of that data is governed by our customer agreements and our Data Processing Addendum.
1. Introduction
brightstack is an AI productivity platform for engineering leaders. The Service ingests information you provide and information you authorize us to access from third-party tools (for example, Google Workspace) to surface signals, summaries, and recommendations that help you run your team.
We designed the Service so that personal data is used only to deliver the features you ask for. We do not sell personal data, we do not use it for cross-context behavioral advertising, and we do not train AI models on your content unless you explicitly opt in.
2. Personal data we collect
We collect the following categories of personal data.
A. Personal data you provide to us directly
- Account information. Identifiers such as your name, email address, employer, role, and profile photo when you create an account, sign in, or communicate with us.
- Payment information. Billing details collected by our payment processor when you purchase a paid plan. We do not store full card numbers on our systems.
- Inputs and outputs. Content you submit to the Service ("Inputs") and responses we generate based on your Inputs ("Outputs"). If you include personal data in Inputs or reference external content, we will collect it and it may appear in Outputs.
- Communications. Your name, contact information, and the contents of messages you send to us.
- Feedback. Ideas, suggestions, ratings, and bug reports you submit. We may store the entire exchange that produced the feedback.
B. Personal data we receive from your use of the Service
- Device information. Device type, browser, operating system, and mobile network or ISP, sent automatically by your device.
- Log information. IP address, browser type and settings, error logs, and how you interact with the Service.
- Usage data. Dates and times of access, browsing history within the Service, search activity, links you click, and pages you view.
- Cookies and similar technologies. See our Cookie Policy.
- Approximate location. Derived from your IP address, used for security signals (for example, detecting unusual logins).
C. Personal data we receive from third-party services you connect
When you authorize brightstack to access third-party tools (for example, Google Workspace, Slack, Linear, GitHub, or your calendar), we receive data from those services as needed to power the features you enable. The exact data depends on the connection you authorize and the scopes you grant. See Section 5 (Google user data) for our detailed Google disclosures.
D. Information we do not collect
brightstack does not knowingly collect sensitive or special category personal information, such as genetic data, biometric data for the purpose of uniquely identifying a natural person, health information, or religious information. brightstack does not knowingly collect information from or direct any of our Service or content to children under the age of 18. If we learn or have reason to suspect that a user is under 18, we will investigate and, if appropriate, delete the personal data and the account.
3. How we use personal data
We use personal data for the following purposes:
- To provide, maintain, and secure the Service.
- To create, manage, and administer your account, including facilitating payments and responding to inquiries.
- To improve and develop the Service, including debugging and identifying or repairing issues that impair functionality.
- To communicate with you about the Service, including operational notices, security alerts, and (if you opt in) product updates and events.
- To prevent, detect, and investigate fraud, abuse, security incidents, and violations of our Terms of Service.
- To comply with legal obligations and protect the rights, safety, privacy, and property of users, brightstack, or third parties.
- To investigate and resolve disputes or security issues.
We may aggregate or de-identify personal data so that it no longer identifies you, and use that information for the purposes described above, such as analyzing how the Service is used, improving features, and conducting research. We will maintain de-identified information in its de-identified form and will not attempt to re-identify it, except as required by law.
5. Google user data
When you authorize brightstack to connect to Google Workspace (Gmail, Calendar, Drive, Contacts, or related Google services), we access information from Google APIs strictly to provide the features you enable. We follow the principle of least privilege and request only the scopes required for each feature.
What Google data we access
- Gmail metadata and message content for users who enable email triage, summarization, or related features. Used in-product only; never used for advertising.
- Google Calendar events and metadata for users who enable scheduling, meeting prep, or workload analysis features.
- Google profile and email address for sign-in and account creation.
How we store Google user data
- At-rest data is stored encrypted in our primary database (Neon, AES-256) and limited to what the active feature requires.
- Ephemeral cache (Upstash Redis) holds short-lived results to keep the Service responsive; entries expire automatically.
- OAuth tokens are encrypted at rest with envelope encryption.
- All data in transit is encrypted with TLS 1.2 or higher.
How we share Google user data
We do not share Google user data with anyone other than the subprocessors listed on our Subprocessors page, and only as needed to operate the Service. We do not sell Google user data, do not use it for advertising, and do not allow humans to read it except (a) with your explicit permission, (b) to comply with applicable law or valid legal process, or (c) where strictly necessary for security or to address an abuse, error, or technical issue.
Revoking access
You can revoke brightstack's access to your Google account at any time by disconnecting the integration in-product or via your Google account permissions. On revocation, we delete OAuth tokens and initiate deletion of associated data per Section 6.
6. Retention and deletion
brightstack retains your personal data only for as long as necessary to operate the Service effectively and to support legitimate business needs such as legal compliance, safety, dispute resolution, and enforcement of our agreements. The appropriate retention period varies depending on the purpose for which the personal data was collected, its sensitivity, potential risks, and any applicable legal requirements.
You can request deletion of your account and associated personal data at any time:
- Use the in-product "Delete account" control in your account settings, or
- Email [email protected] with the subject "Delete my account."
Once a deletion request is received, your account is soft-deleted immediately and is no longer accessible. Active-system data is hard-deleted within 30 days. Encrypted backups are retired on their normal rotation, no later than 90 days after the deletion request. We may retain a minimal record of the deletion event itself to demonstrate compliance.
7. Security
We implement commercially reasonable technical and organizational measures designed to protect personal data from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. These include encryption in transit and at rest, least-privilege access control, multi-factor authentication on production systems, audit logging, secure software development practices, and vendor reviews.
No method of transmission over the Internet or method of electronic storage is completely secure. You should use caution when deciding what information to share with the Service. We are not responsible for any circumvention of privacy settings or security features on the Service or on third-party websites linked through the Service.
8. Your rights and choices
Depending on where you live and the laws that apply in your country of residence, you may have certain rights in relation to your personal data, including the right to access, delete, correct, or transfer your personal data; to object to or restrict how we process it; or to withdraw your consent where processing is based on consent. You may also have the right to lodge a complaint with your local data protection authority.
To exercise any of these rights, you or your authorized agent may contact us at [email protected]. We may request information to verify your identity before processing your request. If we deny your request, you may appeal by emailing the same address. brightstack will not discriminate against you for exercising any privacy rights available under applicable law.
- Right to know what categories of personal data we collect, the purposes for which we use it, and the types of third parties with whom we share it.
- Access and portability. You can request a copy of the personal data we hold about you and, where applicable, ask us to provide it in a portable format.
- Deletion of personal data collected from you in connection with your use of the Service, subject to certain exceptions.
- Correction of inaccurate personal data we maintain about you. While we make reasonable efforts to address correction requests, due to the nature of AI models we cannot guarantee the accuracy of Outputs generated by the Service.
- Objection to certain types of processing. Where applicable, we will stop processing unless we have legitimate legal grounds to continue.
- Restriction of our processing in limited circumstances, such as while a correction request is pending.
- Withdrawal of consent, where the legal basis for our processing is consent. Withdrawal does not affect the lawfulness of prior processing.
- No solely automated decisions. brightstack does not make decisions based solely on automated processing that have legal or similarly significant effects on you.
- No sale or targeted advertising. We do not "sell" or "share" personal data for cross-contextual behavioral advertising, and we do not process personal data for "targeted advertising" purposes (as those terms are defined under applicable US state privacy laws). We do not process sensitive personal data for the purposes of inferring characteristics about a consumer.
brightstack processes your personal data on servers located in various jurisdictions, including in the United States. While data protection laws vary by country, we apply the protections outlined in this policy to your personal data regardless of where it is processed, and we only transfer data in accordance with legally valid transfer mechanisms. For users in the European Economic Area (EEA), United Kingdom, or Switzerland, when you access our Service, your personal data may be transferred to our United States servers and other countries outside the EEA, UK, and Switzerland. Where information is transferred outside those regions, we require an adequate level of data protection (typically the European Commission's Standard Contractual Clauses).
9. Jurisdiction-specific disclosures
EEA, United Kingdom, and Switzerland
For individuals in the EEA, UK, and Switzerland, brightstack is the controller of personal data described in this Privacy Policy when we collect it for our own purposes. We process personal data on the following legal bases: (a) performance of a contract with you, (b) our legitimate interests in operating, securing, and improving the Service, (c) compliance with legal obligations, and (d) your consent (which you may withdraw at any time).
You have the right to lodge a complaint with your local data protection authority. For UK users, you may contact the Information Commissioner's Office (ICO).
California (CCPA / CPRA)
California residents have the rights described in Section 8. We have not "sold" or "shared" personal information for cross-contextual behavioral advertising in the prior 12 months, and we do not knowingly sell or share personal information of consumers under 16. The categories of personal information we collect, the sources, the purposes, and the categories of third parties with whom we share are described in Sections 2-4.
Other US states (Virginia, Colorado, Connecticut, Texas, Utah, Oregon)
Residents of states with comprehensive consumer privacy laws have the rights described in Section 8. To exercise these rights, contact [email protected].
10. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will publish an updated version and effective date at the top of this page, unless another type of notice is legally required. Your continued use of the Service after any change in this Privacy Policy will constitute your acceptance of such change.
11. Contact us
If you have any questions about this Privacy Policy or our privacy practices, contact us at [email protected].
brightstack AI, Inc.