Effective July 30, 2026
Live inference data is the prompt, relevant files, and model response needed to perform a request. Customer-stored data includes transcripts, team memory, task details, review discussions, and uploaded datasets that support later work. Operational data includes account, team, permission, billing, usage, security, and audit records.
Stripe handles card details. Brett does not receive or store full card numbers.
Brett sends live inference data to the model provider needed to answer the request, currently through OpenRouter or Fireworks AI. Brett restricts these calls to configured zero-retention destinations. Where a provider accepts a per-request control, Brett asks for no prompt or response storage and no training use. Where retention is controlled at the account or contract level, Brett refuses the call unless that mode is explicitly enabled in our deployment. An unknown destination is refused.
Provider zero data retention applies to that live provider request. It does not mean Brett stores nothing. Customer-stored data is governed separately below.
Brett encrypts transcript, memory, task-event, and uploaded-dataset content before it reaches the database. The Brett server holds the encryption key and decrypts content in temporary memory when an authorized feature needs it. This protects database copies; it is not end-to-end encryption from your team against Brett.
Team owners and admins can set retention periods, stop new transcript, memory, or dataset storage, export stored content, delete one memory, or delete a whole data class. Task-event content is removed by replacing it with a tombstone so the event chain can still prove that an action occurred.
We do not sell customer data. We do not use your code, prompts, transcripts, memory, or decisions to train a shared model or to build features for another customer. An optional fine-tuning run is different: a team owner or admin deliberately starts it using that team's selected data, and the resulting model is assigned only to that team. Because training requires retained data, it is not a zero-retention inference request.
A developer can read their own sessions. Access to another member's transcript requires an authorized review path, and the access is recorded. Team owners and admins control members, permissions, storage policy, exports, and deletion. Our personnel access customer content only to operate or secure the service, respond to a support request, or comply with law.
Supabase provides database and authentication services. Railway hosts the Brett server. Vercel hosts the website. Stripe processes payments. OpenRouter and Fireworks AI process model requests as described above. These providers process data only for the service function assigned to them and under their applicable terms.
Customer-stored content follows the retention policy shown in the team dashboard. Deletion removes active content from Brett's database; infrastructure backups expire under the provider's backup schedule. Content-free deletion, policy, and security records may remain. Billing and tax records remain as required for accounting or law. Account deletion requests can be sent to support@choosebrett.com.
We use cookies for authentication and session state. We do not run advertising trackers. We will post updates here and announce material changes. Questions or data requests: support@choosebrett.com.