Privacy Policy
How we collect, use, and protect your personal data under the General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
Last updated: 21 July 2026
1. Data Controller
- Company: YOUNG HUMAN S.L.
- Tax ID (CIF/NIF): B10690097
- Address: Los Pasitos 35-3, 35140 Mogán, Las Palmas, Spain
- Email: [email protected]
- Data Protection Officer: [email protected]
2. Data We Collect
We collect personal data that you provide directly and data collected automatically through our services:
Data You Provide
- Waitlist registration: email address, name (optional), company name (optional)
- Account creation: email address, name, authentication data (managed by Clerk)
- Workspace data: Chain entries (decisions, standards, business rules, etc.) that you create in your workspace
- CI code-review data: when a workspace owner enables Product Brain review, the pull-request title and body, code diff, a bounded semantic representation used for retrieval, and the selected Chain entries used by the review model
- Support communications: messages you send to us via email or community forums
- Product feedback: bug reports, friction notes, ideas, or praise about how Product Brain itself behaves — including feedback submitted automatically by AI agents connected to your workspace. See section 3 for how this is processed, screened, and made visible back to you.
Data Collected Automatically
- Analytics data: on public marketing pages, aggregate page views and named call-to-action events may be collected via PostHog using memory-only persistence, without a durable visitor identifier, session recording, or automatic click/form capture. In the signed-in application, product analytics may include feature usage and session data as described below.
- Technical data: browser type, operating system, IP address (anonymized where possible)
3. Legal Basis for Processing
We process your personal data under the following legal bases (Article 6 GDPR):
- Consent (Art. 6.1.a): analytics cookies and marketing communications. You may withdraw consent at any time.
- Contract performance (Art. 6.1.b): providing the Product Brain service, managing your workspace, processing waitlist registration.
- Legitimate interest (Art. 6.1.f): improving the service, preventing fraud, ensuring security. We balance our interests against your rights and only process data where the impact on you is minimal.
Product feedback — including feedback submitted automatically by AI agents connected to your workspace — is vendor-directed telemetry about the product’s own behavior, processed under our legitimate interest in improving the service (Art. 6.1.f). This paragraph is a transparency notice under Art. 13/14, not a request for consent. Every submission is screened — including a transmission of the raw submission text to our external AI processor (see section 8, OpenRouter/Anthropic) to re-express it as product behavior only — before it enters our default triage queue, and any workspace admin or owner can disable agent-submitted feedback at any time in workspace settings — that switch is your objection route under Art. 21. You, and every member of your workspace, can always see everything sent to the builders from your workspace — as they see it, including the screened, generalized version once a submission has been rewritten — in Settings → “Feedback from this workspace.”
4. How We Use Your Data
- To provide and maintain the Product Brain service
- To process your waitlist registration and notify you of availability
- To understand usage patterns and improve the product (only with consent)
- To communicate service updates and security notices
- To comply with legal obligations
We do not train AI models on your data. Your workspace content (Chain entries) is used exclusively to provide the service to you. We do not share, sell, or use your workspace data for any other purpose.
5. Data Retention
- Waitlist data: retained until you are onboarded or request deletion
- Account data: retained for the duration of your account, plus 30 days after deletion for recovery purposes
- Workspace data: retained for the duration of your account, deleted upon account closure (subject to backup retention of up to 90 days)
- CI code-review transit data: Product Brain processes pull-request inputs and selected Chain context for the review request and does not intentionally retain those inputs after returning the result. Review comments remain in GitHub under your repository's retention settings. Third-party AI providers may process transit data under their published retention terms.
- Analytics data: anonymized or deleted after 26 months
- Legal compliance data: retained as required by applicable law (e.g., tax records for 6 years under Spanish law)
6. Your Rights
Under GDPR (Articles 15–22) and the LOPDGDD, you have the following rights:
- Right of access: obtain a copy of your personal data
- Right to rectification: correct inaccurate data
- Right to erasure: request deletion of your data (“right to be forgotten”)
- Right to data portability: receive your data in a machine-readable format
- Right to restrict processing: limit how we use your data
- Right to object: object to processing based on legitimate interest
- Right to withdraw consent: at any time, without affecting the lawfulness of prior processing
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.
7. Cookies
We use cookies and similar technologies on this website. For detailed information about what cookies we use, why, and how to manage them, please see our Cookie Policy.
On public marketing pages, PostHog uses memory-only persistence for aggregate pageviews and selected CTA events, so no analytics cookie or localStorage identifier survives a page refresh. Session recording and autocapture are disabled. In the signed-in application, PostHog may use cookies or localStorage for product analytics and feature flags as described in sections 2–4; see the Cookie Policy for storage details.
8. Third-Party Services
We use the following third-party services to operate Product Brain:
- Convex (database) — stores workspace data. Data processed in the US under Standard Contractual Clauses (SCCs).
- Clerk (authentication) — manages sign-in and user identity. Data processed in the US under SCCs.
- PostHog (analytics) — product analytics and feature flags in the app. On public marketing pages, PostHog is initialized in memory-only mode for aggregate pageviews and named CTA events, with no durable analytics identifier, session recording, or autocapture. EU-hosted instance preferred where available; otherwise US with SCCs.
- OpenRouter / Anthropic / OpenAI (AI processing) — processes Chain entries when you use AI-assisted features (MCP server, Brain Chat); separately processes the raw text of every product feedback submission (see section 3) — including agent-submitted feedback — to screen and re-express it as product behavior only before it reaches our default triage queue; and processes pull-request text, code diffs, bounded retrieval text, and selected Chain entries when CI code review is enabled. Data is processed in the US under SCCs. Providers commit to not training on customer data.
- Sentry (error monitoring) — diagnoses failures. The in-browser Sentry SDK is loaded only in the signed-in application — it is not initialized on public marketing pages, so no error tracking runs in your browser there. Server-side monitoring does cover all requests, including marketing pages, in two ways: when a page fails to render, the error and its request context (such as the URL) are reported; and a sampled share of successful requests (10% by default) sends a performance trace carrying the request URL and timing. We do not enable Sentry’s “send default PII” option, so IP addresses and user identifiers are not attached to those reports.
- Google Fonts (typography) — our primary typefaces (Inter, JetBrains Mono) are self-hosted and served from our own domain, but three families (Source Serif 4, IBM Plex Sans, IBM Plex Mono) are still loaded from Google’s font CDN on every page, including public marketing pages. Your browser contacts Google directly to fetch them, and Google receives your IP address and user-agent as part of that request. Self-hosting the remaining families is tracked as follow-up work.
- Railway (hosting) — hosts the application. Data processed in the US under SCCs.
- Cloudflare (CDN/DNS) — provides DNS, caching, and security services.
9. International Data Transfers
Some of our third-party service providers process data outside the European Economic Area (EEA). In all cases, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Assessment of the legal framework in the receiving country
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption in transit (TLS) and at rest
- Access controls and authentication requirements
- Regular security reviews
- Workspace isolation (your data is not accessible to other workspaces)
11. Children
Product Brain is not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at [email protected] and we will delete the data promptly.
12. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated via email or a prominent notice on our website. The “Last updated” date at the top of this page indicates when the policy was last revised.
Data Protection Inquiries
For any questions about this privacy policy or to exercise your data protection rights, contact our Data Protection Officer at [email protected].