Privacy Policy
for the platform "Brainstorm Reactor"
Convenience Translation — This English version is provided for informational purposes only. The legally binding version is the original German text (Datenschutzerklärung). In the event of any conflict or discrepancy, the German version shall prevail.
The protection of your business and personal data is the fundamental architectural principle of our software. We process data exclusively on the basis of applicable legal provisions, in particular the European General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), and the Austrian Telecommunications Act 2021 (TKG 2021). Our systems are consistently built according to the principle of maximum data minimization (“Privacy by Design”).
1. Data Controller
The data controller within the meaning of the GDPR is:
2. Infrastructure and Server Locations (European Union)
Our core IT infrastructure — consisting of application logic, database, and product analytics — is operated exclusively on servers within the European Union. No transfer of this core system data to third countries takes place:
- –Application Server (Vercel): Frankfurt am Main, Germany (Region:
eu-central-1/fra1). - –Database & File Storage (Supabase): Dublin, Ireland, EU (Region:
eu-west-1). - –Product Analytics (PostHog): Frankfurt am Main, Germany (EU Cloud).
3. Third-Party Providers and EU-US Data Privacy Framework
For highly specialized sub-services (authentication, payment processing, and AI routing), we work with service providers whose infrastructure is partially located in the USA. This data transfer is legally secured by the EU-US Data Privacy Framework (DPF) — the adequacy decision of the European Commission of 10 July 2023. We transmit to these services exclusively the data that is strictly necessary for the fulfillment of the respective technical purpose:
- –User Authentication (Clerk): Processes exclusively login tokens and basic session data for access control and account management. No access to your system inputs (prompts) or content usage data occurs.
- –Payment Processing (LemonSqueezy): Processes purely transactional payment and billing data for contract fulfillment (legal basis: Art. 6(1)(b) GDPR).
4. AI Model Routing and Zero-Data-Retention
To provide the cognitive workflows, your inputs (prompts) are forwarded to the APIs of external AI providers (e.g., Google Gemini, Anthropic Claude). This forwarding occurs via specialized routing services (currently: OpenRouter and, for the EU Privacy Gateway, Opper.ai). We maintain a Data Processing Agreement (DPA) according to Art. 28 GDPR with these routing services. A current list of their sub-processors is publicly available.
A strict zero-data-retention architecture applies, guaranteeing the protection of your trade secrets and data:
- –No Logging at the Routing Service: Content data logging is technically hard-disabled on our routing account (opt-out). The service acts as a pure transit layer; your prompts and generated outputs are only transiently passed through RAM and are not permanently stored in databases.
- –No AI Model Training: Since processing occurs through the commercial B2B API endpoints of the respective base model providers (OpenAI, Anthropic, Google), your inputs are subject to their strict API policies. Your prompts, uploaded documents, and results are contractually guaranteed not to be used for training, fine-tuning, or further development of the underlying AIs. Providers may, however, keep temporary abuse-monitoring logs in accordance with their respective API policies, which are deleted automatically.
Additionally, the platform offers an optional pseudonymization tool (“EU Privacy Gateway”). When activated, user input passes through an automated real-time analysis layer powered by a specialized LLM system hosted exclusively within the European Union before being forwarded to the target language model. This system identifies personally identifiable data (names, addresses, phone numbers, tax IDs, payment information) and replaces it with secure placeholder tokens. Masking occurs prior to prompt processing — the target model receives only the pseudonymized text. This service is provided by the sub-processor Opper.ai (server location: EU).
Activation of this tool is optional and occurs exclusively through explicit user interaction. In standard operation, PII masking is not active.
4a. Live Audio Transcription
The platform offers an optional live audio transcription feature. When activated, the browser’s Web API accesses the microphone on your device. This access occurs exclusively after explicit permission via the native browser permission dialog (legal basis: Art. 6(1)(a) GDPR, § 165(1) TKG 2021).
Audio data is transmitted in real time to a specialized transcription service with server infrastructure located in the European Union. Processing is exclusively ephemeral — no permanent storage of raw audio data occurs, neither on our servers nor at the transcription provider. The service converts audio into text and discards the audio stream immediately after processing.
Structured text fragments derived from the transcription (summaries, key terms) may optionally be stored within the active session at the user’s discretion. The underlying voice recording is not persisted.
Biometric Exclusion: No biometric identification, no emotion recognition, and no voice profiling takes place (Art. 5(1)(f) Regulation (EU) 2024/1689).
5. Cookies and Device Access (§ 165(3) TKG 2021)
This platform uses exclusively essential, technically strictly necessary cookies and session tokens (local storage) from the authentication provider Clerk. These are strictly required to maintain your secure login and ensure authorized access to your account.
Pursuant to § 165(3) TKG 2021, no prior consent is required for the use of these purely functional and technically necessary storage elements. For analytics, user tracking, or marketing purposes, we expressly use no cookies, no client-side tracking scripts, and no browser fingerprinting technologies on your device. A so-called “cookie banner” is therefore legally unnecessary and architecturally not present.
6. Server-Side Product Analytics and Telemetry (Cookieless)
For service provision, error analysis in multi-step workflows, and the continuous evidence-based development of our software architecture, we capture technical interaction data (telemetry). This is done in accordance with the following technical and legal premises:
- –100% Server-Side Capture: Telemetry data capture occurs purely server-side (server-to-server). No analytics scripts are executed in your browser. When you initiate a process, our server generates abstract event messages and forwards them to the analytics database in Frankfurt am Main (PostHog EU). No access to your device occurs.
- –Strict Pseudonymization (Zero PII):
- –No IP Addresses: Your IP address is never stored in the analytics database. Transmission to the analytics server technically enforces immediate IP anonymization (overwritten with
127.0.0.1). - –No Real Names: No personally identifiable data (such as email addresses or names) is passed to the analytics system.
- –Rotating Identifier: For purely logical session linking (e.g., to track process failures), our system generates an abstract 8-character cryptographic hash value. This rotates automatically and irrevocably every 30 days. Building profiles over longer periods or subsequent re-identification of your person is thereby mathematically and technically excluded.
- –No IP Addresses: Your IP address is never stored in the analytics database. Transmission to the analytics server technically enforces immediate IP anonymization (overwritten with
Data Processor and International Transfer: For the evaluation of this telemetry data, we use PostHog, Inc. (San Francisco, USA) as a data processor pursuant to Art. 28 GDPR. Data is processed exclusively on servers in the PostHog EU Cloud (data center Frankfurt am Main, Germany). We have concluded a Data Processing Agreement (DPA) with the provider. For potential administrative access to the EU infrastructure by the US parent company, we rely on the adequacy decision of the EU Commission for the EU-US Data Privacy Framework (DPF), under which PostHog Inc. is fully certified.
Legal Basis and Purpose Limitation: The processing of this highly aggregated and pseudonymized metadata is based on our overriding legitimate interest pursuant to Art. 6(1)(f) GDPR. This consists of ensuring technical system stability (error resolution) and resource-efficient development of the software architecture. Disclosure of telemetry data to additional third parties, linking with external data sources, or use for marketing purposes is technically and contractually completely excluded.
Right to Object (Art. 21 GDPR): You have the right to object to this processing based on legitimate interests at any time on grounds relating to your particular situation. To exercise this right, please contact us at hello@brainstormreactor.com.
7. Your Rights as a Data Subject
Under the GDPR, you have comprehensive rights regarding your personal data processed by us:
- –Right of Access (Art. 15 GDPR)
- –Right to Rectification (Art. 16 GDPR)
- –Right to Erasure (Art. 17 GDPR)
- –Right to Restriction of Processing (Art. 18 GDPR)
- –Right to Data Portability (Art. 20 GDPR)
- –Right to Object to processing based on legitimate interest (Art. 21 GDPR)
To exercise your rights or for specific data protection inquiries, please contact us informally by email at: hello@brainstormreactor.com
Since our product analytics employs complete pseudonymization (Art. 11 GDPR), access requests specifically concerning this telemetry metadata may require additional technical information from you to map the rotating hash. This does not affect your unrestricted rights regarding your account data held by our authentication provider Clerk.
If you believe that the processing of your data violates data protection law or your data protection rights have been infringed in any way, you have the right to lodge a complaint with the competent supervisory authority. In Austria, this is the Austrian Data Protection Authority (DSB), Barichgasse 40-42, 1030 Vienna (www.dsb.gv.at).