← Back

Privacy Policy (Draft)

⚠️ This is a draft pending legal review. What follows was written by checking the actual code; if you find anything that does not match, please tell us at the contact below.

Operator: Brains4GoodLife · Representative: Charlie Shine · Business registration no.: 504-35-63547 · Effective date: 1 October 2026 (previous version 2 September 2026)

1. Why we process data

We process personal data only for these purposes, and will tell you and ask for consent before that changes.

2. What we collect

ItemRequired?
Age confirmation (self-declared "14 or older" checkbox)Required
Session cookie (a signed value, issued without any email)Required
IP address - used only while processing, for bot-blocking and rate limits; never stored in the clear. Statistics keep only a hash that changes daily and weeklyRequired
Usage statistics - feature names, screen paths, country, device type, referrer, browser language. Never the content of your conversations Statistics are not linked to the session cookie.Required
Content you post in Rooms or the GalleryOnly if you use those features
Web push subscription (an address issued by your browser)Only if you turn notifications on

We do not collect email addresses. An earlier version listed email as an optional item; in fact the entry screen stopped asking for it, and only the wording was left behind (corrected 2 September 2026). There is no sign-up either.

3. What we do not process (the point of this service)

Your personal conversations and memories are stored only on your device and are never sent to our servers. If you use your own API key, AI replies go from your device directly to the AI provider (for example Google Gemini) and never pass through the Operator. However, if you use the "no-setup" brain, that prompt does pass through the Operator's Cloudflare Worker to Cloudflare Workers AI. Even then the Operator does not store it. For fully device-to-provider delivery, add your own key in Settings.

4. Rooms and Gallery - the exception

Unlike personal conversations, what you post in Rooms and the Gallery is stored on Cloudflare servers and shared with other members. It passes an automatic filter before storage, and when a report is filed, only the Room identifier, the author identifier and the reason are sent to Discord as a review alert — the text of the post is not sent. Do not post anything there that you would not want shared. For a shared-chat link, the app locks the conversation with a code on your device before storing it on the server, so the operator cannot read it and only someone with both the link and the code can view it. A link you deliberately make public (no code) can be read by anyone who has the address, so please be careful.

5. How long we keep it

Each item is deleted automatically after the period below. These are the actual configured values.

ItemRetention
Session cookieUp to 30 days
Bot-blocking and rate-limit countersUp to 2 hours
Usage statistics (Cloudflare Analytics Engine)3 months (Cloudflare policy)
Conversations saved as a share link7 days for shared chats · 30 days for published web apps
Report/block records (for admin review)90 days
Web push subscription90 days
Call-setup signalling10 minutes
Memories posted in a RoomThe most recent 300 per Room and for up to 90 days; older ones are deleted automatically. The author can delete their own post, and a post is hidden automatically once 3 different members report it
Room reports · Gallery reportsThe most recent 200 each; older ones deleted automatically
Room listThe most recent 1,000; older ones deleted automatically
Gallery worksThe most recent 500; older ones deleted automatically
List of blocked email addresses (only addresses the operator added by hand; the entry screen no longer asks for email, this is a leftover of an earlier feature)Until the block is lifted

6. How we destroy data

Personal data is destroyed without delay once its retention period ends or its purpose is fulfilled.

7. Processors and third parties

ProviderRole
Cloudflare, Inc.Hosting · bot-blocking (Turnstile) · storage for Rooms and Gallery · usage statistics · generating AI replies for the "no-setup" brain
Discord Inc.Review notifications for reports (room and author identifiers and report reason only; post text and title are not sent)
The AI provider you choose (e.g. Google LLC)Generating AI replies - sent from your device directly to them, never through the Operator

We do not provide or sell personal data to third parties for any other purpose.

8. Transfers outside Korea

These providers keep servers abroad, so personal data is transferred out of Korea. Details for each recipient:

Cloudflare, Inc.

CountryUnited States and its global edge network
When and howSent over the network as you use the Service
ItemsConnection details · session cookie · Room and Gallery posts · usage statistics · your prompt if you use the "no-setup" brain
RetentionAs in section 5
Contactprivacy@cloudflare.com

Discord Inc.

CountryUnited States
When and howSent over the network when a report is made
ItemsRoom/Gallery identifier, author identifier, reason (post text and titles are not sent)
RetentionDeleted by the operator after handling; until then it remains on Discord

The AI provider you choose (e.g. Google LLC)

CountryUnited States and elsewhere
When and howSent directly from your device when you ask a question - never through the Operator
ItemsThe prompt you typed
RetentionPer that provider's policy

How to refuse: if you do not want data transferred abroad, you may stop using the Service. Hosting and bot-blocking are essential to providing it, so those cannot be refused separately. However, you can avoid transfers to an AI provider by adding your own key in Settings (device-to-provider) or not using that feature, and transfers for Rooms and the Gallery by not using those features.

9. Security measures

10. Cookies and automatic collection

The Service uses one session cookie only (up to 30 days, HttpOnly/Secure/SameSite). We use no advertising or behavioural-tracking cookies and no third-party analytics scripts.

How to refuse: you can block cookies in your browser settings. Blocking the session cookie means your entry will not persist, which makes the Service hard to use.

11. Children under 14

This Service is not intended for anyone under 14, and we do not knowingly collect their personal data. If we learn that we hold data from a child under 14, we will delete it without delay.

12. Your rights and how to use them

You may at any time ask to access, correct, delete, or suspend the processing of your personal data, and withdraw consent. Contact us at section 13 and we will act within 10 days and tell you the result. You may also act through a legal representative or an agent. We will not treat you unfavourably for making such a request.

Note that this Service has no sign-up, so we hold nothing that identifies you. If you ask us to delete something you posted in a Room or the Gallery, please include something we can find it by - the room number, or the text of the post.

13. Privacy officer

Privacy officer: Charlie Shine
Contact: shcbrain@hanmail.net

Send any privacy question, complaint, or request for redress to this address and we will answer without delay.

14. Where else to get help

If you need help with a privacy violation, you can contact these bodies in Korea. They are independent of the Operator.

If your rights are infringed by a decision or inaction regarding a request under Articles 35, 36 or 37 of the Personal Information Protection Act, you may file an administrative appeal (Central Administrative Appeals Commission, 110, www.simpan.go.kr).

15. Changes to this policy

When this policy changes, the new text and its effective date will be posted on this page at least 7 days beforehand (at least 30 days for changes that disadvantage users).