Privacy Policy

Last updated 23 August 2026

The short version

LLMBrain is a hosted service, so unlike a local tool it genuinely holds your content: the project docs, issues, decisions and skills your coding agents read and write. That is the product. We store it to serve it back to you and to the people you share it with, and for nothing else — we do not sell it, we do not advertise, and we never train machine learning models on it.

One third party sees your text: the embedding provider that makes search work. It is named below, along with everything else we hold.

This website asks once whether it may use Google Analytics, and loads nothing at all until you say yes. Decline and no analytics script is fetched and no analytics cookie is set — that is the whole difference the banner makes.

Who we are

LLMBrain is made by LOGZAI SRL, a limited liability company registered in Romania (“we”, “us”). We are the data controller for the personal data described in this policy.

  • Registered office: Fagarasi 19, Dumbravita, Romania
  • Tax identification number (CUI): 53038901
  • Trade Register number: J2025094020008
  • EUID: ROONRC.J2025094020008

You can reach us about anything on this page at hello@llmbrain.dev.

Your account

To use LLMBrain you need an account, and an account means we hold a small amount of information about you:

  • Your email address, name and handle. The handle is how teammates address projects you share with them, so it is visible to anyone you share with.
  • Your password, hashed. We store an argon2 hash, never the password itself. If you sign in with Google we store no password at all.
  • Your API keys, hashed. A key is shown to you once, at creation; we keep only a SHA-256 hash of it plus its first few characters, so a key you lose cannot be recovered — only revoked and replaced. We record when each key was last used, which is what lets you spot one you no longer recognise.

You create your own account on the dashboard, either with an email address and a password or by signing in with Google. If you use Google, we receive your verified email address and your name from Google and store those; we never see your Google password, and we store no password of our own for such an account unless you later set one.

What your agents write

The substance of LLMBrain is the content you and your coding agents store in it: project descriptions, repository URLs, architecture and data-model docs, status notes, issues and their comments, milestones, decisions, labels and skills. Some of it is written by you in the dashboard; most of it is written by an agent acting on your behalf, through the MCP server or the API, using a key you issued.

We treat everything an agent writes with your key as content you submitted yourself. You are responsible for what ends up there — which matters, because an agent writes what it finds. Two practical consequences:

  • Do not store secrets. Credentials, tokens and private keys do not belong in a brain that exists to be read back and searched. The bundled skill instructs agents not to store them, but the instruction is not an enforcement.
  • Personal data about other people — a colleague named in an issue, a customer described in a requirement — is yours to justify. For that content you are the controller and we are your processor: we hold it, serve it back and delete it on your instruction, and we do nothing else with it.

We access this content only to run the service: to serve it back to you, to index it for search, and — rarely, and only where we cannot diagnose a fault any other way — to investigate a problem you have reported to us.

Sharing and who can see your work

A project or a skill is private to your account until you share it. When you grant someone access, they see that project’s content and your handle, at the level you granted — read or write. You can revoke a grant at any time, and revoking takes effect on the next request they make.

We do not make your projects public, list them anywhere, or show them to anyone you have not shared them with.

Where your data lives

LLMBrain runs on servers we operate at Hetzner Online GmbH, in their Helsinki, Finland region — inside the EU, so your content is not transferred abroad simply by being stored. Everything described above lives in a single PostgreSQL database on that infrastructure, and traffic between your agents and the service is encrypted in transit. Hetzner acts as our processor under its own privacy policy.

Our servers keep ordinary request logs — including IP addresses — for a short period in order to run the service and protect it from abuse. We do not use those logs to build any profile of you.

Backups exist so that a failure does not cost you your brain. Content deleted from the live service can therefore persist in a backup for a short while before ageing out.

This website

The marketing site you are reading uses Google Analytics, and only if you accept it. The first time you visit, a banner asks; until you answer, and for as long as your answer is no, the analytics script is never fetched and no analytics cookie exists. That is a real difference rather than a legal formality: we gate the loading of the script itself, instead of loading it in a “consent denied” mode that still contacts Google on every page.

If you accept, we see the ordinary aggregate picture — which pages are read, roughly where visitors come from, which links get clicked — and we use it for one purpose: deciding what to write and explain next. We have not enabled Google’s advertising or cross-device features, we run no ads, and we do not connect anything measured here to your LLMBrain account. Google processes this data under its own privacy policy. Unlike the content inside the product, which stays on our servers in Helsinki, accepting analytics means this measurement is transferred outside the EU — to Google, in the United States, under the safeguards it offers for that transfer. Declining is how you avoid it entirely.

Your choice is remembered in your browser, not on our servers, and you can change it whenever you like: Cookie settings in the footer reopens the banner. One honest detail about changing your mind: declining after having accepted stops anything further being sent, but a script your browser has already fetched is only fully gone once you reload — so reload the page, or simply carry on, and the next page you open loads nothing at all. Clearing this site’s storage in your browser resets the question.

There is no form on this site any more. Creating an account happens on the dashboard, and what you enter there is covered by the sections above.

Cookies

This website sets no cookies until you accept analytics. It has no login, no basket and no session to remember, so without your consent there is nothing for it to store — the banner itself remembers your answer in local storage rather than in a cookie.

If you do accept, Google Analytics sets its own cookies in your browser — _ga and _ga_<id> — which give you a random identifier so that repeat visits are not counted as new visitors. They last up to two years, hold no name or email address, and are used for nothing but the aggregate statistics described above. Declining, or choosing Cookie settings in the footer and declining later, means they are never set; ones already set are removed when you clear this site’s cookies in your browser.

The dashboard is a different application and needs to remember that you are signed in. It keeps your session token in your browser’s local storage rather than in a cookie, and it sets one small cookie — sidebar_state — recording whether you collapsed the sidebar. Both are strictly necessary for the dashboard to work as you asked it to; neither is analytics, and neither is shared with anyone. Signing out clears the session token.

If you sign in with Google

Signing in with Google is optional and exists so that you do not need a second password. When you use it, Google tells us your email address and whether it is verified, and we match that against an existing account — nothing more. We ask Google for no access to your Gmail, Drive or contacts, and we store no Google token after the sign-in completes.

Google handles its side under its own privacy policy.

If you email us

If you write to us — a bug report, a feature suggestion, a question — we hold that message and your email address for as long as needed to deal with it and to keep a record of the decision. We use it only to reply and to improve LLMBrain. We do not add you to any marketing list.

How long we keep things

Your content stays until you delete it. Deleting a project deletes its docs, issues, comments, decisions and search index entries with it, and closing your account deletes the account and everything under it. Ask us and we will do it; you do not need a reason.

Backups age out on their own cycle, and we keep the minimum record needed to show that a request was made and honoured.

What we never do

  • We do not sell or rent your personal data.
  • We do not train machine learning models on your content — not our own, and we do not permit our providers to. Embedding text so that search can find it is indexing, not training.
  • We do not read your projects for our own purposes, mine them for product ideas, or show them to anyone you have not shared them with.
  • We do not serve advertising, run ad networks, or use advertising or cross-device tracking features anywhere — including in the analytics on this website, where those features are switched off.
  • We build no profile of you as an individual. The website analytics you can accept above are read as aggregates only, and we never join them to your LLMBrain account, your email address, or anything your agents store.

Your rights

We are established in Romania, so the EU GDPR applies to what we do — and equivalent rights apply if you are in the UK. You have the right to access your personal data, correct it, have it deleted, restrict or object to our use of it, and receive a copy of it in a portable form. Write to hello@llmbrain.dev and we will respond within one month.

Our lawful basis is the contract between us for everything needed to provide the service — your account, your content, search, sharing — and our legitimate interest in keeping the service secure and available for the rest.

If you are unhappy with how we have handled your data, you can complain to our supervisory authority, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), Romania’s national data protection authority — dataprotection.ro. If you live elsewhere in the EU, you may also complain to your own national authority.

Children

LLMBrain is a professional developer tool and is not directed at children. We do not knowingly collect personal data from children, and accounts are meant for adults.

Romania has not lowered the age set by Article 8 of the GDPR, so where consent is the basis for anything we do, it is only valid from the age of 16. If you believe a child has given us personal data, write to hello@llmbrain.dev and we will delete it.

Changes to this policy

LLMBrain is in active development, and this policy will change as the product does — particularly if we add a new provider that touches your content, or features such as team accounts or paid plans. We will update the date at the top of this page whenever it changes, and tell account holders about anything significant.

Contact

Questions about this policy, or about privacy in LLMBrain generally: hello@llmbrain.dev.