Privacy.
Controller: The Brainer OÜ, Lahepea 9, 10617 Tallinn, Estonia. Email edit@thebrainer.co. This notice covers thebrainer.co, the Smart Edit control plane and the edit.js script.
Visitors of a site that uses Smart Edit
Nothing. For a visitor who is not an editor, the script reads one key in the browser's local storage and stops. It sets no cookies, loads no further resources and sends no requests. We learn nothing about visitors of your clients' sites.
Editors
| What | Why | How long |
|---|---|---|
| Name and email address, entered by the builder | To issue and revoke editor links and to show who changed what | Until the builder removes the editor or the site |
| Editor token in the editor's browser (local storage) | So the editor does not need to log in again | Until revoked or cleared by the editor |
| Edit requests, the visible text and structure of the page being edited, uploaded images | To interpret the request and save the change | Requests and page descriptions: 30 days in logs. Saved changes and uploads: as part of the site's version history, for the life of the site |
| IP address and browser type in server logs | Security and abuse prevention | 30 days |
Edit requests together with the page's text blocks and layout description are sent to Anthropic PBC (USA) to interpret the request, under their commercial terms, which exclude training on customer data. Uploaded images are not sent to the model.
Builders
| What | Why | How long |
|---|---|---|
| Name, email, studio, website, what you build with, sites per year (founding reservation) | To run the Founding 100 programme and tell you when keys open | Until you ask us to delete it, or 24 months after your last activity |
| Account email, registered sites, editor lists, write-back credentials (repository tokens, deploy hooks) | To provide the service | While the account exists; credentials are deleted when you disconnect them |
| Payment details | Billing | Held by Stripe, not by us. We keep invoices as the law requires (7 years) |
| Emails between us | Support | 3 years |
Who else processes data
- DigitalOcean (servers in the EU, Frankfurt and London) for the control plane and hosted sites.
- Anthropic PBC for interpreting edit requests.
- Stripe for payments.
- Our transactional email provider for service emails.
- GitHub, Netlify, Vercel or Cloudflare only if you connect them for write-back, and only to write saved changes.
Data leaves the EU only for the model provider and, if you connect them, the write-back services. Transfers rely on the EU standard contractual clauses and, where applicable, the EU–US Data Privacy Framework.
Legal bases
Performance of a contract for builders and editors; legitimate interest for security logs and for the founding programme communications; consent where we ask for it. We do not send marketing email without asking. We do not sell data and do not use it to train models.
Your rights
You can ask what we hold about you, have it corrected or deleted, receive a copy, or object to a use, by email to edit@thebrainer.co. Editors' requests are usually handled together with the builder who added them. You can also complain to the Estonian Data Protection Inspectorate (AKI) or your local authority.
Cookies
thebrainer.co sets no cookies and runs no analytics. The founding form sends what you type to our server, nothing else. Editors' browsers keep a token in local storage, which is not a cookie and is not sent to any third party.