Brain Scanner · legal
Privacy Notice
Version beta-1.6
Brain Scanner Open Beta Privacy Notice
Version beta-1.6. Published September 7, 2026.
This notice explains what personal data and project data Brain Scanner, operated by Kevin Olozada Santos ("Brain Scanner", "we", "us") collects when you use the hosted Brain Scanner open beta at brainscanner.dev and its connector (the "Service"), why we collect it, how long we keep it, who can see it, and what choices you have. It forms part of the Open Beta Evaluation Agreement.
1. Who is responsible
- The controller of personal data processed through the Service is Brain Scanner, operated by Kevin Olozada Santos, Florida, United States. A postal address is available on request.
- Privacy questions and requests: support@brainscanner.dev.
2. The short version
- The hosted MCP service is designed to receive privacy-filtered Project Intelligence, not source-file contents, secrets, raw logs, source-code diffs, or repository credentials. Your Agent and local Brain Scanner tools may read source, inspect repositories, and execute supported local actions in your environment. Their access depends on the permissions of the Agent and local processes; the hosted connector grant neither grants nor removes that access.
- Reports and findings contain text you or your agent choose to submit. Successful project writes also generate retained Change Review entries with summaries and selected before-and-after values. Deleting an individual item does not erase its earlier history or recovery copies; see section 10.
- We collect the minimum account data needed to run the beta: your email address, a password we store only as a salted hash, your account status, and a record of the terms you accepted.
- We keep short-lived security logs, and during the beta we collect bounded first-party product events only when you opt in so the owner can see whether the Service works. There is no advertising, no sale of data, and no third-party analytics.
- Your data is hosted on Google Cloud in the United States.
- You can ask us to access, export, correct, or delete your data at any time.
3. What we collect
Account and access data:
- Your email address, whether you have confirmed it, and a salted PBKDF2 hash of your password. We never store the password itself. To confirm the address we email you a single-use link; if someone tries to sign up with an address that already has an account, we email that address a notice instead of telling the requester.
- Your account status, including any suspension or closure decision.
- Consent records: which version and content digest of the terms and this notice you accepted, and when.
- Session cookies and anti-forgery tokens needed to keep you logged in securely.
- Connector authorization records: which agent clients you authorized, their scopes, when they were granted, and when they were revoked.
Security and operational data:
- The IP address and browser or client identification sent with each request, used for rate limiting, abuse prevention, and security audit.
- Sanitized audit metadata for each operation: the acting account, the project, the operation name, the time, the result, and opaque correlation identifiers. Audit records never contain request bodies or project content. Change Review is separate project-history storage and can contain the selected project fields described below.
Project data submitted by you or your agent, and generated history:
- Opaque project, node, edge, finding, session, and event identifiers.
- Graph structure: node and edge types, relationships, status values, counts, timestamps, digests, confidence, and provenance.
- Bounded labels and summaries, limited in length and character set and treated as untrusted assertions.
- Repository-relative file paths and, for every file-backed node, the absolute path of that file on the machine that mapped it. These paths are stored so that your browser can open the file locally; they may reveal a folder name or a username on your machine, so map projects from a location you are comfortable recording.
- Roadmap assessments, readiness calculations, change reviews, findings, queued tasks, chat handoffs, instructions, and activity assertions your agent records.
- The Git revision identifier your agent reports as the mapped revision.
- Authored reports and bug records: titles, summaries, report bodies, finding notes, severity, status, linked project items, and resolution evidence. A report body can contain up to 20,000 characters; a finding note can contain up to 2,000. These are project content, even though they are filtered and bounded. Do not include raw source, logs, credentials, or other prohibited data in them.
- Automatic Change Review history for successful writes to your registered projects: operation names, recorded times, project and record identifiers, agent session or execution references, versions, status, summaries, and selected prior and new field values. This includes report and finding text, task and session outcomes, and compact graph publication records with versions, digests, counts, and submitted change narratives.
- History previews shorten long text fields to 1,000 characters and long string lists to 100 items; shortened values include their original length and a digest. The full current report and some retry records can hold more than the preview. This limit is not a promise that only 1,000 characters are stored anywhere in the Service.
- Pending history writes and retry records can retain selected prior values or committed result copies to prevent duplicate writes and preserve the original change. An explicit existing-state backfill can add currently stored records and retained graph publications to history; it is labeled and does not reconstruct missing earlier versions.
Beta product data:
- Bounded first-party product events such as feature used, scan started, scan completed or failed, time to first result, and session timings, linked to your account.
- Optional accuracy ratings and correction text you submit through result-validation prompts. Correction text is screened and length-limited. Do not enter code, paths, project names, credentials, or secrets in it.
Open diagnostic tier:
- The public diagnostic workflow uses an opaque, short-lived guest identity and does not require an account. It receives only a closed, sanitized diagnostic projection. The workspace owner reviews the rendered report before the guest can see it.
Communications:
- Support requests and bug reports you send through the dashboard or by email, including the text you provide and the account associated with the request. Keep source code, credentials, and other sensitive material out of these messages.
- Optional email preferences, owner-maintained beta cohort labels and follow-up notes, feedback status, and outbound message drafts, recipient addresses, sent message text, and delivery-attempt history. These records support beta operation and responses to your requests.
Data excluded from project-mapping and diagnostic submissions:
- Do not submit source code bodies, snippets, comments, diffs, patches, file contents, command output, logs, stack traces, environment values, secrets, credentials, tokens, keys, cookies, connection strings, or cloud-provider credentials through project mappings, reports, findings, other project records, or diagnostic payloads. This restriction does not describe the account and connector authentication data listed above. The connector schema rejects unknown fields and known prohibited data classes, and we exclude bounded text from general logs and analytics. Filtering reduces risk but cannot guarantee that free text you or your agent write is free of sensitive material, so please keep it out.
- We do not collect payment details. The beta is free and no billing provider is connected.
Local processing and permissions:
- Local Brain Scanner tools and your Agent can read source files and Git changes, write local application state, open an editor, and run supported local programs such as selected tests. Your Agent may have broader capabilities that you separately authorize. Local processing is distinct from submitting information to the hosted service.
- A local process or the test code it runs may access files, environment values, credential helpers, and credentials available under its operating-system and Agent permissions. The hosted metadata restrictions are not a local sandbox and do not make those resources inaccessible. Configure local permissions for the work you intend to authorize.
- Your Agent or model provider may process information under its own settings and privacy terms. This notice describes Brain Scanner's hosted collection; it does not establish what another provider receives.
- Ordinary hosted MCP authorization does not enable direct repository-source ingestion. Any separately offered repository-source integration requires its own repository authorization and a collection notice covering source processing and integration credentials.
4. Where the data comes from
- From you, when you sign up, log in, accept terms, adjust settings, or send us messages.
- From your dashboard submissions and automatically from successful project changes, to maintain the history described above.
- From the agent you run on your own machine, when it maps or updates a project through the connector. Your agent obtains its access to your repository from your own machine and accounts, not from us.
- Automatically from your browser and client, in the form of cookies, request headers, and IP addresses.
5. Why we use it and our legal bases
- To provide the Service you requested, including authentication, storing and displaying your project maps and authored reports, coordinating queued tasks, maintaining change history, and safely replaying interrupted writes. Legal basis where required: performance of the agreement.
- To keep the Service secure, prevent abuse, enforce capacity limits, and investigate incidents. Legal basis: our legitimate interest in protecting the Service and its participants.
- To evaluate and improve the beta using optional account-linked product events, timings, scan outcomes and accuracy ratings you choose to submit. Legal basis: your separate consent through Account → Privacy settings. Measurement is off until you opt in, including for existing accounts. Withdrawing stops future browser and connector measurement and removes active measurement records; recovery copies have the separate limits in section 10. Declining does not prevent using the Service or submitting a bug report.
- To handle support and bug reports you deliberately send, and record basic account onboarding milestones so we can support your account. Legal basis: our legitimate interest in resolving reported problems and operating the beta. These operational records are separate from optional product measurement; you may object to processing based on legitimate interests. Optional follow-up email still requires the separate email preference.
- To communicate with you about your access, security issues, and changes to the Service. Legal basis: performance of the agreement and legitimate interest.
- To send optional beta announcements and follow-up emails only when you opt in. Legal basis where required: your consent. You can withdraw through Account email preferences or the unsubscribe link in each optional email. Verification, recovery, security, and account-onboarding messages are separate.
- To comply with applicable legal obligations (legal obligation where recognised under the applicable data-protection law), and to establish, exercise, or defend legal claims (our legitimate interest in protecting legal rights).
- We do not use third-party advertising or behavioral advertising profiles, sell your data, share it with data brokers, or use it to train machine-learning models. Optional emails may describe and promote Brain Scanner features, subject to your choice above.
- We do not make decisions about you by solely automated means that have legal or similarly significant effects. Signup is subject to email verification, capacity, abuse-prevention checks, and the current admission settings; suspensions and closures are decided by a person.
6. Cookies and data stored in your browser
- We use strictly necessary cookies only: a session cookie that keeps you signed in and an anti-forgery token. They are not used for tracking and there are no advertising or analytics cookies.
- The dashboard stores copies of project data in IndexedDB and local storage so that pages load faster. That project data is also held by the Service as described above. Convenience settings you enter, such as your editor choice, a checkout folder, and a repository web address, are browser-local settings.
- Only after you enable optional product measurement in Account → Privacy settings, first-party measurement uses session storage for a temporary session identifier, timing values, and event-deduplication markers. These are separate from necessary authentication cookies. Uncheck the same setting and save to withdraw at any time. On the next dashboard load or when a dashboard tab becomes visible again, it clears the measurement storage if permission is off; the server also rejects new measurement requests without permission. Your choice and its time and notice version are recorded with your account. Browser storage restrictions do not enable measurement.
- Signing out ends the browser login, but does not reliably remove every stored cache or convenience setting in every sign-out flow. On a shared device, clear site data through your browser settings to remove local copies.
- You can clear all of this through your browser settings.
7. Who can see your data
- The owner and operators of the Service, who need access to run it, respond to requests, and investigate security issues. During the beta this is a very small group.
- Service providers that host or support the Service, listed in section 8. They act on our instructions and are bound by data-processing terms.
- Authorities, if the law requires us to disclose data or if disclosure is needed to protect rights, safety, or the integrity of the Service. Where lawful, we will tell you first.
- A successor, if the Service or the business is transferred. This notice will continue to apply to your data until you are told otherwise.
- Your account and agents you authorize can access project data within their granted permissions. Change Review uses the same project ownership boundary; its retained entries do not make a project public. Projects are not shared between participants, and there is no public directory of participants.
8. Service providers and hosting
- Google Cloud Platform (Google LLC, United States): application hosting on Cloud Run, encrypted object storage for project intelligence and account records, scheduled expiry tasks, container image storage, and platform logging. Data is stored in the us-central1 region (Iowa, United States).
- Spacemail (Spaceship, Inc., United States): delivers verification, recovery, account-onboarding, and other account messages, plus optional beta announcements and follow-ups for participants who opt in. It receives recipient addresses and message text; messages do not use open-tracking pixels or advertising-tracking links.
- GitHub (GitHub, Inc., United States): only if you choose to connect the optional GitHub App integration. The integration is read-only, limited to repositories you select, and can be removed from your GitHub account at any time.
- The AI agents you connect (for example Codex or Claude) are operated by you under your own accounts with those providers. Their handling of your data is governed by their own terms and privacy notices, not by this notice.
- The current list is also maintained in the repository file SUBPROCESSORS.md. We must update this notice before adding a provider that processes personal data and obtain any authorization required for the change.
9. International transfers
- The Service is hosted in the United States. If you use it from another country, your data is transferred to and processed in the United States.
- Acceptance of this notice does not waive mandatory privacy rights or independently authorize a transfer that requires separate legal safeguards.
10. How long we keep it
- Active account, approval, consent, and account-linked owner follow-up and email records are retained during your participation and removed on account deletion. A deletion receipt retains its time, counts, accepted document versions and digests, and a digest derived from your email, rather than the email itself. This is pseudonymous, not anonymous. The current store keeps at most 500 receipts and has no automatic age-based purge. Recovery copies have the separate limits below.
- Project graph snapshots: the current version plus up to 10 previous versions, and never longer than 14 days for previous versions. Deleting a project or your account removes the active objects.
- Reports, findings, sessions, activity, tasks, assessments, validation assertions, and Change Review history: retained with the project unless removed through a supported deletion operation or privacy request. The current implementation does not automatically expire these records after 30 days.
- Change Review keeps earlier entries after an individual item is edited or deleted. Compact graph publication records remain after detailed graph snapshots expire. The journal currently accepts up to 10,000 entries per project and stops accepting additional entries at capacity instead of silently discarding old history. Deleting the whole project removes its active journal and project records; account deletion removes active project data. Recovery copies are subject to the separate limits below.
- Queue history: follows the project records it summarizes. Purging a terminal task removes that task from the queue history, but does not erase an earlier Change Review entry, linked finding, or recovery copy.
- Generated exports: up to 24 hours.
- Open diagnostic jobs: 24 hours without a report; a report awaiting owner approval, 30 minutes; an approved report, 48 hours.
- Beta product events and correction text: for the duration of the beta, removed from active measurement storage when you withdraw measurement consent or delete your account, and purged in full by the owner at the end of the beta. Recovery copies have the separate limits below.
- Security audit metadata: 90 days.
- General metadata replay records use a seven-day expiry and may contain committed result fields. Report and browser-finding retry records can contain complete committed report or finding values, including earlier versions; these records and pending history snapshots have no automatic time-based expiry in the current implementation and remain with the project. Removing an individual item does not remove these retry copies.
- Recovery storage: the current project-state bucket retains previous object generations through object versioning and has no age-based lifecycle deletion rule. Those generations can remain until explicitly removed; there is no automatic 14-day expiry. Once an object generation is explicitly deleted, the current soft-delete recovery window is seven days. Removing active project or account data does not immediately erase these recovery copies. Privacy deletion requests should include historical and recovery copies; contact support@brainscanner.dev so we can assess and address those copies as well as active records.
- Prohibited project data is not intentionally retained. Schema checks and filtering reject known prohibited inputs, but bounded free text may still contain sensitive material. If prohibited project data is discovered, we delete it as soon as we become aware.
11. How we protect it
- All connections use authenticated TLS. Stored project intelligence and account records are encrypted at rest.
- Every request is authorized from the authenticated account and server-side ownership records. Identifiers supplied in a request never grant access on their own.
- Read, write, export, and destructive-delete are separate permissions, and destructive operations require explicit consent through the connector.
- The connector accepts only known fields, rejects prohibited data classes, and applies size and rate limits.
- Passwords are stored as salted PBKDF2 hashes. Sessions expire and can be revoked.
- Audit logs contain metadata only, never project content.
- We test changes and maintain a deployment rollback path.
- No system is perfectly secure. If we learn of a breach affecting your personal data, we will notify you and any required authority without undue delay and within the timeframes the law requires.
12. Your rights and choices
Depending on where you live, you may have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data corrected;
- have your data deleted;
- receive your data in a portable format;
- restrict or object to certain processing, including processing based on legitimate interest;
- withdraw consent where processing is based on consent, without affecting processing that happened before;
- not be discriminated against for exercising your rights;
- complain to a supervisory authority, for example your national data protection authority in the EEA, the Information Commissioner's Office in the United Kingdom, or your state attorney general in the United States.
To exercise a right, contact support@brainscanner.dev, writing from the email address on your account, or use the Account page in the dashboard to request account deletion. Self-service project or account deletion removes active project records; historical recovery copies follow section 10 and may require an additional privacy request. We normally respond without undue delay and within one calendar month. Where the applicable law permits more time for a complex request or several requests, we will explain the reason and the extension within the initial month; the extension is no more than two further months. We may request proportionate information to verify identity where reasonably necessary. You do not need to use legal language, and writing from your account email is helpful but is not the only way to make a valid request. Requests are normally free; a fee or refusal is possible only where the applicable law permits it, with an explanation and complaint rights. Deleting your account revokes connector access and starts deletion of your project intelligence on the schedule above.
For California residents: we do not sell or share personal information as those terms are defined in California law, and we do not use or disclose sensitive personal information for purposes beyond those permitted by law. The rights above include the rights to know, delete, correct, and to limit use of sensitive personal information.
For UK data-protection complaints, contact support@brainscanner.dev so we can investigate, or contact the [Information Commissioner’s Office](https://ico.org.uk/make-a-complaint/). You can complain to the ICO without first obtaining our permission. You can object at any time to direct marketing; withdrawing optional email consent stops those messages. Withdrawal does not make earlier lawful processing unlawful.
You must provide an email address, account credentials and required verification information to create a hosted account. Project metadata is needed for a requested hosted map. Ratings, corrections, product measurement consent and optional email consent are voluntary. Declining optional processing does not change access eligibility.
13. Children
- The Service is for adults. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.
14. Changes to this notice
- We publish the current notice at /privacy and preserve digest-addressed versions. Signup records the exact version presented then; publishing a new notice neither rewrites that record nor establishes consent to a new use of existing data. This update introduces a separate, optional measurement choice and clarifies rights; accepting terms or acknowledging this notice is not consent to optional measurement or promotional email. Before a future change requires new consent or other notice, we must provide that notice and obtain the required consent; the current service does not automatically collect renewed acceptance from existing accounts.
15. Contact
- Privacy requests, questions, and security reports: support@brainscanner.dev.
- Provider: Brain Scanner, operated by Kevin Olozada Santos, Florida, United States. A postal address is available on request.