brightstack AI, Inc.

Privacy Policy

How brightstack collects, uses, and protects your information.

Effective
April 27, 2026
Last updated
April 27, 2026

brightstack AI, Inc. (brightstack, "we", "us", or "our") is committed to respecting your privacy and keeping secure any information you share with us. This Privacy Policy explains how we collect, use, disclose, and process your personal data when you use our software, platform, APIs, documentation, the website at https://brightstack.ai, the application at https://app.brightstack.ai, and all related software made available by brightstack (collectively, the "Service").

It also tells you how you can access and update your personal information and describes the data protection rights that may be available under your country's or state's laws. By accessing or using the Service, you acknowledge you have been informed of and consent to our practices with regard to your personal information and data.

This Privacy Policy does not apply where brightstack acts as a data processor and processes personal data on behalf of commercial customers, for example if your employer has provisioned a brightstack account for you to use at work. Our use of that data is governed by our customer agreements and our Data Processing Addendum.

1. Introduction

brightstack is an AI productivity platform for engineering leaders. The Service ingests information you provide and information you authorize us to access from third-party tools (for example, Google Workspace) to surface signals, summaries, and recommendations that help you run your team.

We designed the Service so that personal data is used only to deliver the features you ask for. We do not sell personal data, we do not use it for cross-context behavioral advertising, and we do not train AI models on your content unless you explicitly opt in.

2. Personal data we collect

We collect the following categories of personal data.

A. Personal data you provide to us directly

  • Account information. Identifiers such as your name, email address, employer, role, and profile photo when you create an account, sign in, or communicate with us.
  • Payment information. Billing details collected by our payment processor when you purchase a paid plan. We do not store full card numbers on our systems.
  • Inputs and outputs. Content you submit to the Service ("Inputs") and responses we generate based on your Inputs ("Outputs"). If you include personal data in Inputs or reference external content, we will collect it and it may appear in Outputs.
  • Communications. Your name, contact information, and the contents of messages you send to us.
  • Feedback. Ideas, suggestions, ratings, and bug reports you submit. We may store the entire exchange that produced the feedback.

B. Personal data we receive from your use of the Service

  • Device information. Device type, browser, operating system, and mobile network or ISP, sent automatically by your device.
  • Log information. IP address, browser type and settings, error logs, and how you interact with the Service.
  • Usage data. Dates and times of access, browsing history within the Service, search activity, links you click, and pages you view.
  • Cookies and similar technologies. See our Cookie Policy.
  • Approximate location. Derived from your IP address, used for security signals (for example, detecting unusual logins).

C. Personal data we receive from third-party services you connect

When you authorize brightstack to access third-party tools (for example, Google Workspace, Slack, Linear, GitHub, or your calendar), we receive data from those services as needed to power the features you enable. The exact data depends on the connection you authorize and the scopes you grant. See Section 5 (Google user data) for our detailed Google disclosures.

D. Information we do not collect

brightstack does not knowingly collect sensitive or special category personal information, such as genetic data, biometric data for the purpose of uniquely identifying a natural person, health information, or religious information. brightstack does not knowingly collect information from or direct any of our Service or content to children under the age of 18. If we learn or have reason to suspect that a user is under 18, we will investigate and, if appropriate, delete the personal data and the account.

3. How we use personal data

We use personal data for the following purposes:

  • To provide, maintain, and secure the Service.
  • To create, manage, and administer your account, including facilitating payments and responding to inquiries.
  • To improve and develop the Service, including debugging and identifying or repairing issues that impair functionality.
  • To communicate with you about the Service, including operational notices, security alerts, and (if you opt in) product updates and events.
  • To prevent, detect, and investigate fraud, abuse, security incidents, and violations of our Terms of Service.
  • To comply with legal obligations and protect the rights, safety, privacy, and property of users, brightstack, or third parties.
  • To investigate and resolve disputes or security issues.
No model training on your content by default. We do not use Inputs, Outputs, or any data we receive from connected third-party services to train, fine-tune, or evaluate AI models, and we do not allow third parties to do so, unless: (1) the data is flagged for security review (in which case we may analyze it to detect and enforce our Terms of Service), (2) you explicitly report it to us as Feedback, or (3) you have explicitly opted in to such use. You can manage these preferences in the Service.

We may aggregate or de-identify personal data so that it no longer identifies you, and use that information for the purposes described above, such as analyzing how the Service is used, improving features, and conducting research. We will maintain de-identified information in its de-identified form and will not attempt to re-identify it, except as required by law.

4. How we share personal data

We may disclose your personal data in the following circumstances:

  • Service providers and business partners (subprocessors). Third-party vendors that support our business operations and help us deliver and improve the Service, including hosting, cloud infrastructure, AI inference, observability, customer support, payment processing, and IT providers. These parties process personal data only as necessary to perform services on our behalf, consistent with our and your instructions and applicable law. The current list is published at our Subprocessors page.
  • Business transfers. In the event of a merger, acquisition, restructuring, bankruptcy, or other corporate transaction, personal data may be disclosed to counterparties and advisers as part of due diligence or transferred as part of the transaction.
  • Legal compliance and protection of rights. We may disclose personal data to government authorities or other third parties if we believe doing so is necessary to (i) comply with applicable laws, regulations, or legal processes, (ii) respond to lawful requests or investigations, (iii) protect the safety, rights, or property of any person, (iv) prevent fraud, security incidents, or other unlawful activity, (v) enforce our Terms of Service, or (vi) protect brightstack against legal liability.
  • Affiliates. Entities that control, are controlled by, or are under common control with us, in a manner consistent with this Privacy Policy.
  • Third-party services and integrations. If you choose to connect or interact with third-party services through the Service, your data may be shared with them as needed to deliver that integration, governed by their own terms and privacy policies.
  • Business account administrators. If you create or use an account associated with an organization (for example, your employer), administrators may access and manage your use of the Service.
  • With your consent. We may disclose personal data when you give us permission to do so.

5. Google user data

When you authorize brightstack to connect to Google Workspace (Gmail, Calendar, Drive, Contacts, or related Google services), we access information from Google APIs strictly to provide the features you enable. We follow the principle of least privilege and request only the scopes required for each feature.

What Google data we access

  • Gmail metadata and message content for users who enable email triage, summarization, or related features. Used in-product only; never used for advertising.
  • Google Calendar events and metadata for users who enable scheduling, meeting prep, or workload analysis features.
  • Google profile and email address for sign-in and account creation.

How we store Google user data

  • At-rest data is stored encrypted in our primary database (Neon, AES-256) and limited to what the active feature requires.
  • Ephemeral cache (Upstash Redis) holds short-lived results to keep the Service responsive; entries expire automatically.
  • OAuth tokens are encrypted at rest with envelope encryption.
  • All data in transit is encrypted with TLS 1.2 or higher.

How we share Google user data

We do not share Google user data with anyone other than the subprocessors listed on our Subprocessors page, and only as needed to operate the Service. We do not sell Google user data, do not use it for advertising, and do not allow humans to read it except (a) with your explicit permission, (b) to comply with applicable law or valid legal process, or (c) where strictly necessary for security or to address an abuse, error, or technical issue.

Limited Use disclosure. brightstack's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking access

You can revoke brightstack's access to your Google account at any time by disconnecting the integration in-product or via your Google account permissions. On revocation, we delete OAuth tokens and initiate deletion of associated data per Section 6.

6. Retention and deletion

brightstack retains your personal data only for as long as necessary to operate the Service effectively and to support legitimate business needs such as legal compliance, safety, dispute resolution, and enforcement of our agreements. The appropriate retention period varies depending on the purpose for which the personal data was collected, its sensitivity, potential risks, and any applicable legal requirements.

You can request deletion of your account and associated personal data at any time:

  1. Use the in-product "Delete account" control in your account settings, or
  2. Email [email protected] with the subject "Delete my account."

Once a deletion request is received, your account is soft-deleted immediately and is no longer accessible. Active-system data is hard-deleted within 30 days. Encrypted backups are retired on their normal rotation, no later than 90 days after the deletion request. We may retain a minimal record of the deletion event itself to demonstrate compliance.

7. Security

We implement commercially reasonable technical and organizational measures designed to protect personal data from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. These include encryption in transit and at rest, least-privilege access control, multi-factor authentication on production systems, audit logging, secure software development practices, and vendor reviews.

No method of transmission over the Internet or method of electronic storage is completely secure. You should use caution when deciding what information to share with the Service. We are not responsible for any circumvention of privacy settings or security features on the Service or on third-party websites linked through the Service.

8. Your rights and choices

Depending on where you live and the laws that apply in your country of residence, you may have certain rights in relation to your personal data, including the right to access, delete, correct, or transfer your personal data; to object to or restrict how we process it; or to withdraw your consent where processing is based on consent. You may also have the right to lodge a complaint with your local data protection authority.

To exercise any of these rights, you or your authorized agent may contact us at [email protected]. We may request information to verify your identity before processing your request. If we deny your request, you may appeal by emailing the same address. brightstack will not discriminate against you for exercising any privacy rights available under applicable law.

  • Right to know what categories of personal data we collect, the purposes for which we use it, and the types of third parties with whom we share it.
  • Access and portability. You can request a copy of the personal data we hold about you and, where applicable, ask us to provide it in a portable format.
  • Deletion of personal data collected from you in connection with your use of the Service, subject to certain exceptions.
  • Correction of inaccurate personal data we maintain about you. While we make reasonable efforts to address correction requests, due to the nature of AI models we cannot guarantee the accuracy of Outputs generated by the Service.
  • Objection to certain types of processing. Where applicable, we will stop processing unless we have legitimate legal grounds to continue.
  • Restriction of our processing in limited circumstances, such as while a correction request is pending.
  • Withdrawal of consent, where the legal basis for our processing is consent. Withdrawal does not affect the lawfulness of prior processing.
  • No solely automated decisions. brightstack does not make decisions based solely on automated processing that have legal or similarly significant effects on you.
  • No sale or targeted advertising. We do not "sell" or "share" personal data for cross-contextual behavioral advertising, and we do not process personal data for "targeted advertising" purposes (as those terms are defined under applicable US state privacy laws). We do not process sensitive personal data for the purposes of inferring characteristics about a consumer.

brightstack processes your personal data on servers located in various jurisdictions, including in the United States. While data protection laws vary by country, we apply the protections outlined in this policy to your personal data regardless of where it is processed, and we only transfer data in accordance with legally valid transfer mechanisms. For users in the European Economic Area (EEA), United Kingdom, or Switzerland, when you access our Service, your personal data may be transferred to our United States servers and other countries outside the EEA, UK, and Switzerland. Where information is transferred outside those regions, we require an adequate level of data protection (typically the European Commission's Standard Contractual Clauses).

9. Jurisdiction-specific disclosures

EEA, United Kingdom, and Switzerland

For individuals in the EEA, UK, and Switzerland, brightstack is the controller of personal data described in this Privacy Policy when we collect it for our own purposes. We process personal data on the following legal bases: (a) performance of a contract with you, (b) our legitimate interests in operating, securing, and improving the Service, (c) compliance with legal obligations, and (d) your consent (which you may withdraw at any time).

You have the right to lodge a complaint with your local data protection authority. For UK users, you may contact the Information Commissioner's Office (ICO).

California (CCPA / CPRA)

California residents have the rights described in Section 8. We have not "sold" or "shared" personal information for cross-contextual behavioral advertising in the prior 12 months, and we do not knowingly sell or share personal information of consumers under 16. The categories of personal information we collect, the sources, the purposes, and the categories of third parties with whom we share are described in Sections 2-4.

Other US states (Virginia, Colorado, Connecticut, Texas, Utah, Oregon)

Residents of states with comprehensive consumer privacy laws have the rights described in Section 8. To exercise these rights, contact [email protected].

10. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will publish an updated version and effective date at the top of this page, unless another type of notice is legally required. Your continued use of the Service after any change in this Privacy Policy will constitute your acceptance of such change.

11. Contact us

If you have any questions about this Privacy Policy or our privacy practices, contact us at [email protected].

brightstack AI, Inc.