AIVM Brain
Back homeHow it worksCompareBlogGuidesPricing
Log inJoin waitlist
Back homeHow it worksCompareBlogGuidesPricingLog inJoin waitlist

Legal

Privacy Policy

Last updated 4 August 2026

In short. AIVM Brain connects to tools you already use, indexes what you point it at, and answers questions about it while respecting the permissions those tools already enforce. We hold your content so we can do that, and for no other purpose.

We do not sell personal data, we do not use your content or data from connected sources to train any AI model, and we do not use it for advertising. You can delete your account and its data yourself at any time.

This summary is a reading aid. The sections below are the operative text.

  • 1. Who we are
  • 2. What we collect
  • 3. Google user data
  • 4. How we use data
  • 5. Legal bases
  • 6. AI processing
  • 7. Sharing and subprocessors
  • 8. Storage and security
  • 9. Retention
  • 10. Your rights and deletion
  • 11. International transfers
  • 12. Children
  • 13. Changes
  • 14. Contact

1. Who we are

AIVM Brain (“Brain”, “we”, “us”) is a governed memory and retrieval platform for teams and their AI agents. This policy explains what we do with personal data and with the content you connect to the service.

This policy covers the Brain web application, its API, and the MCP endpoint that external AI agents connect to.

Controller and jurisdiction. The legal entity operating Brain, its registered address, and the governing jurisdiction must be stated here before this policy is relied upon. Where Brain processes content on behalf of a business customer, we act as a processor and that customer is the controller.

2. What we collect

Account data

Your email address, and a display name and organisation name if you provide one. We do not collect or store passwords for user accounts — sign-in uses a single-use, time-limited link sent to your email, and we store only a hashed form of that token, never the link itself.

Content you connect or create

Documents, files, messages and other material you upload, author in the product, or import from a connected source; the text extracted from those files; and the entities and relationships derived from them to build your knowledge graph.

Connected source credentials

Access and refresh tokens for sources you connect. These are encrypted at rest and are never returned to the browser or to any connected agent.

Usage and audit records

Records of activity in the product — who accessed what, when, which agent asked what, and whether a request was allowed or refused. Access records are deliberately content-blind: they record that an access happened, not the content involved.

Billing data

Plan, subscription status and usage counts. Card details are handled by our payment processor and are never stored on our systems.

Technical data

IP address, browser and device information, and product analytics used to understand how the product is used and to diagnose faults.

3. Google user data

If you connect Google Drive, we request read-only access in order to import the documents you choose to bring into your brain. We use that access to list files and read their contents so they can be indexed, searched and cited back to you.

We request your Google email address and basic profile identifier solely to identify the connected account.

Limited Use disclosure. Brain’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use Google user data to train generalised AI or machine learning models; we do not transfer it to others except as necessary to provide or improve the features you are using, to comply with applicable law, or as part of a merger or acquisition; we do not use it for advertising; and no human reads it except with your explicit consent, to resolve a specific support issue you have raised, for security purposes, or where required by law.

You can disconnect Google Drive at any time from the connectors screen in your dashboard, which revokes our stored tokens. You can also revoke access directly at your Google account permissions page. Disconnecting stops further syncing; to remove content already imported, delete it in the product or delete your account.

4. How we use data

  • To operate the service: sign you in, sync connected sources, index content and answer questions about it.
  • To enforce access control, so each person and agent sees only what they are cleared to see.
  • To maintain the audit record that lets you prove what was accessed.
  • To bill you and to enforce plan limits.
  • To diagnose faults, prevent abuse, and keep the service secure.
  • To communicate with you about the service.

We do not sell personal data. We do not use your content or data from connected sources for advertising, and we do not use it to train AI models.

5. Legal bases

Where the UK GDPR or EU GDPR applies, we rely on:

  • Contract — to provide the service you have signed up for.
  • Legitimate interests — to secure the service, prevent abuse, and improve it, balanced against your rights.
  • Consent — where you connect a third-party source, and for any optional communications.
  • Legal obligation — for tax, accounting and lawful requests.

6. AI processing

Answering a question sends the relevant excerpts of your content, and your question, to a large language model provider so the answer can be generated. Only material you are permitted to see is included.

You may supply your own model provider key, in which case that processing happens under your own agreement with that provider and your content is not sent through ours. Where you use the managed option, we send it to our model provider under terms that prohibit using it to train their models.

Content that our data-loss-prevention rules classify as sensitive is masked before it leaves our systems.

7. Sharing and subprocessors

We share data only with service providers that help us run Brain, under contracts limiting them to that purpose:

ProviderPurposeData involved
Amazon Web ServicesApplication hosting and databaseAll service data
WasabiObject storage for uploaded and imported filesFile contents
AnthropicLarge language model for answers and summariesQuestion and relevant content excerpts
OpenAIEmbeddings and optional model providerContent excerpts
StripePayments and subscriptionsBilling details and payment data
ResendTransactional email, including sign-in linksEmail address and message content
PostHogProduct analyticsUsage events and technical data

We may also disclose data where required by law, to enforce our terms, or in connection with a merger or acquisition — in which case we will tell you before your data becomes subject to a different privacy policy.

8. Storage and security

  • Data is encrypted in transit (TLS) and at rest.
  • Credentials for connected sources are encrypted with a separate key and are never returned to a browser or an agent.
  • Every tenant’s data is scoped by identity on every query, and access decisions are enforced server-side rather than in the client.
  • Access is written to a hash-chained, append-only record designed so that tampering is detectable.
  • An agent connected to your brain acts strictly as the member whose key it holds, and can never see more than that member can.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal data we will notify you and any applicable regulator as required by law.

9. Retention

  • Content — kept until you delete it, or until your account is deleted.
  • Account data — kept while your account is active.
  • Audit records — retained after deletion of the underlying content, because their purpose is to evidence what happened. They are content-blind by design.
  • Billing records — retained as long as tax and accounting law requires.
  • Backups — deleted data persists in encrypted backups for a limited period before being overwritten.

10. Your rights and deletion

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to it. To exercise any of these, contact us using the details below.

Deleting your data yourself

  • Individual items — delete files and documents from the Library at any time.
  • A connected source — disconnect it from the connectors screen, which revokes our stored credentials.
  • Your whole account — delete it from your account settings. This permanently removes your files, documents, connectors, keys and usage records. If you belong to a team workspace or organisation you will be asked to leave or delete those first, because that content may belong to others.

If you are a member of a team workspace, your administrator may also control content in that workspace; requests about it may need to go through them.

If you are in the UK or EEA you have the right to complain to your data protection authority.

11. International transfers

Our providers may process data outside your country, including in the United States. Where data leaves the UK or EEA we rely on appropriate safeguards, such as the UK International Data Transfer Agreement or the European Commission’s Standard Contractual Clauses.

12. Children

Brain is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.

13. Changes

We may update this policy. If a change materially affects how we handle your data we will tell you by email or in the product before it takes effect. The date at the top of this page always reflects the current version.

14. Contact

Questions, or to exercise any right above: privacy@aivm.io.

Product

  • How it works
  • Pricing
  • Live demo

Learn

  • AI Brain
  • Second brain guide
  • Brains for AI agents
  • Compare
  • Guides

Community

  • GitHub
  • Back home

Legal

  • Terms
  • Privacy
2026© 2026 ChainGPT AI S.A. · ChainGPT.org