Privacy
Privacy Notice
Effective 22 September 2026 · Brida Reflex Free Preview
1. Controller
Brida OÜ, registry code 17445507, Tornimäe tn 5, Kesklinna linnaosa, Tallinn, Harju maakond 10145, Estonia, is the controller for personal data described in this notice. Privacy requests: hi@brida.ai.
2. Scope
This notice covers the Brida website, Brida Reflex Free Preview registration and accounts, hosted Reflex execution, API-key management and related operational communications. It does not change the separate privacy practices of third-party websites you choose to visit.
3. Data we process
- Account and Organization data: email address, display name, Organization name, membership and verification state.
- Authentication and security data: password hashes, session records, TOTP/security state if configured, rate-limit and abuse-prevention metadata. We do not store your plaintext password.
- API-key metadata: key identifier, prefix, scopes, status and timestamps. The plaintext API-key secret is returned when the key is created and is not stored as retrievable plaintext.
- Reflex data: the bounded state you submit for semantic evaluation and metadata needed to execute and reconcile a logical run.
- Operational metadata: request/trace identifiers, timestamps, selected Reflex/version, runtime/policy versions, result branch/confidence summary, usage/latency and bounded error categories. Central Reflex receipts are designed not to contain raw submitted state by default.
- Registration email data: email address, verification delivery state and provider message reference needed to send and troubleshoot verification mail.
4. Why we process it
We process account, authentication, API-key and Reflex execution data to provide the service and take steps you request before or under our service relationship. We process security, rate-limit, abuse-prevention, reliability and audit metadata for our legitimate interests in operating a secure and reliable service. We may process limited records to comply with legal obligations and to establish, exercise or defend legal claims.
5. AI processing
Hosted Reflex uses AI-based semantic evaluation. The current Preview sends eligible non-sensitive Reflex state through Vercel AI Gateway to TypeSafe AI's Jev evaluation model. Each provider request asks for Zero Data Retention and no-prompt-training controls. If the evaluator is unavailable, Reflex fails closed rather than silently sending the request to another model or provider.
This is not an EU-only or EU-residency promise. Service providers may process data outside the European Economic Area. Where EU data-protection law applies, Brida relies on the transfer mechanisms and safeguards applicable to the relevant processor or recipient.
6. Service providers and recipients
We use infrastructure and service providers only as needed to operate Reflex. Current launch categories include cloud/server hosting, edge/static hosting and transactional email, AI gateway infrastructure and the current semantic evaluation provider. Key launch providers include Hetzner, Cloudflare, Vercel and TypeSafe AI. We may also disclose data when required by law, to protect rights or security, or in connection with a lawful corporate transaction.
7. Retention
We keep personal data only for as long as needed for the purposes above, security, dispute handling and legal obligations. Unfinished registration and verification state expires and is cleaned up. Human sessions are time-bounded and revocable. API-key plaintext is not retained for later display. Reflex operational receipts are metadata-focused and raw submitted state is not included in central receipts by default. Account, Organization, security and immutable execution/accounting records may be retained while the account is active and for a reasonable period afterward where necessary for security, integrity, legal or audit purposes.
8. Cookies and analytics
Reflex account flows use strictly necessary first-party cookies for authentication and registration-completion security. The current Brida Reflex public pages do not use third-party advertising or behavioral analytics scripts. If that changes, this notice and any required consent controls will be updated before such processing is enabled.
9. Security
Brida uses technical and organizational controls including hashed credentials, one-time verification authority, server-owned API-key scopes, tenant/Organization checks, bounded request policies, metadata-only observability, revocation, rate limits and fail-closed provider execution. No security measure eliminates all risk, so do not submit information outside the stated Preview data class.
10. Automated decisions
Brida Reflex produces semantic evidence and recommendations. The hosted service does not itself make a decision that produces legal or similarly significant effects about you. Customers must keep consequential authorization and side effects outside Reflex and are responsible for any separate automated-decision process they build around the service.
11. Your rights
Where the GDPR applies, you may have rights to access, correct, erase or restrict personal data, object to certain processing, receive portable data where applicable, and withdraw consent where processing is based on consent. You may also lodge a complaint with the data-protection authority in your habitual residence, workplace or place of the alleged infringement, including the Estonian Data Protection Inspectorate where appropriate.
Send requests to hi@brida.ai. We may need to verify your identity before acting on a request.
12. Children
The hosted developer Preview is not directed to children. You must be at least 18 years old to create a self-service Preview account unless Brida has explicitly agreed another lawful arrangement.
13. Changes
We may update this notice as Reflex or its admitted providers change. The effective date above identifies the current version. We will describe material changes before or when they take effect as required by applicable law.