Welcome to Bricktry ("Bricktry", "we", "us", or "our"), operated by Bricktry Technologies at https://bricktry.com. This Privacy Policy details our comprehensive standards and protocols for collecting, utilizing, processing, storing, and safeguarding personal data, developer source code, and project telemetry when you visit our website, access our AI Studio, engage autonomous software engineering agents, configure human-pairing developer sprints, connect external code repositories, utilize our AI-Native SEO Engine, or participate in our Referral and Affiliate Partner Program.
We recognize the critical sensitivity of proprietary source code, software architecture, and commercial data. Bricktry is engineered around strict single-tenant workspace boundaries, strong cryptographic encryption, and a firm commitment that your proprietary client code and private repositories are never used to train public artificial intelligence models without your express consent.
1. Scope and Controller Information
This Privacy Policy applies to all services, software applications, APIs, sandboxes, developer tools, and web portals operated by Bricktry Technologies (collectively, the "Platform" or "Services"). For the purposes of the General Data Protection Regulation (GDPR), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), the UK Data Protection Act, and the Indian Digital Personal Data Protection Act (DPDP Act 2023), Bricktry Technologies serves as the Data Controller regarding personal data collected directly through our website, user registration, billing, and affiliate management systems.
When you ingest custom codebases, customer databases, or third-party datasets into Bricktry for auditing, refactoring, or deployment, you act as the Data Controller and Bricktry acts as a Data Processor operating under strict contractual obligations.
2. Information We Collect
We collect information across several categories in order to deliver, secure, and continuously optimize our developer platform:
A. Information You Voluntarily Provide
- Account & Identity Data: Full name, professional email address, account password hash, organization or company name, designation, phone number, and communication preferences provided during registration and onboarding.
- Project Inputs & Technical Artifacts: Git repository links, uploaded project files and archives (.zip, .json, .csv, .pdf, .md, images), architectural diagrams, user journey specifications, feature prompts, debugging instructions, and Jira or Notion backlog tickets submitted to our AI Studio.
- Billing & Payment Metadata: Billing contact name, company tax identification numbers (e.g., GSTIN, VAT, EU Tax ID, EIN), billing address, and payment transaction identifiers. All credit/debit card numbers and sensitive banking credentials are encrypted and processed directly by PCI-DSS Level 1 certified payment processors (including Stripe and Razorpay); Bricktry never stores raw payment card numbers.
- Affiliate & Partner KYC Documents: To comply with financial regulations and anti-money laundering (AML) mandates, referral partners provide legal identity proofs (such as PAN Card, Aadhaar Card, Passport, Driver's License, or National Tax ID), document identification numbers, legal names, and payout account details (UPI ID, PayPal email, or bank transfer routing information).
- Customer Support & Communications: Messages, feedback, inquiries, error reports, and logs submitted via our help desk, contact forms, or direct email correspondences.
B. Information Collected Automatically
- Device & Network Telemetry: Internet Protocol (IP) address, browser family and version, operating system, screen resolution, hardware architecture, language settings, and referring URLs.
- Platform Usage & Sandbox Metrics: Session timestamps, navigation pathways, features utilized, agent execution runtimes, code compilation statuses, sandbox resource utilization, and live preview rendering events.
- System Audit Logs: Security event records, authentication attempts, password modifications, API key generation, role-based permission alterations, and administrative KYC verification approvals or rejections.
C. Information from Third-Party Integrations
- Google Search Console API: For users configuring our AI-Native SEO Engine, we pull real-time search performance metrics including search queries, impressions, clicks, click-through rates (CTR), and average ranking positions for your verified web properties.
- Git Hosting Services (GitHub / GitLab): When connecting your repository, we receive OAuth tokens, repository metadata, branch structures, and commit histories strictly to analyze, audit, and commit authorized pull requests.
- Sprint & Backlog Platforms (Jira / Notion): Task titles, acceptance criteria, issue statuses, and assignee metadata imported to orchestrate human-pairing sprints and autonomous agent tasks.
3. How We Use Your Information
We process collected data exclusively for legitimate commercial, engineering, and compliance purposes:
- Platform Delivery & Sandbox Execution: To initialize developer workspaces, parse code abstract syntax trees (AST), execute static code analyses, run isolated test containers, and provide instantaneous live previews.
- Autonomous Agent Operations: To empower specialized AI agents (such as Architectural Auditors, Full-Stack Bug Fixers, and SEO Strategists) to diagnose bugs, write verified patches, and modernize code architectures.
- Human-Pairing Engineering Workflows: To coordinate senior platform engineers assigned to your "Dedicated AI Dev Pair", "Weekly AI Dev Sprint", or "Annual AI Dev Partner" packages.
- AI-Native SEO Optimization: To analyze keyword performance, discover search intent gaps, auto-generate meta structures, create valid JSON-LD schemas, and provide actionable ranking intelligence.
- Billing & Account Administration: To calculate recurring subscription fees, allocate monthly Lab and AI usage credits, invoice accounts, and maintain accurate accounting ledgers.
- Affiliate Management & KYC Verification: To track referral conversions, prevent affiliate self-dealing fraud, verify identity proofs, and disburse earned commissions.
- Security, Fraud Prevention & Integrity: To monitor for malicious code injection, prevent denial-of-service attempts, detect unauthorized access, and protect platform stability.
- Regulatory & Legal Compliance: To satisfy statutory bookkeeping, tax filing, and statutory regulatory inquiries.
4. Code Privacy & Artificial Intelligence Commitments
We understand that proprietary source code is your most valuable business asset. Bricktry implements industry-leading safeguards regarding software privacy and artificial intelligence:
- Zero Model Training on Private Source Code: Bricktry does not use your proprietary source code, private git repositories, database schemas, or project prompts to train, fine-tune, or calibrate public artificial intelligence models.
- Ephemeral Agent Sandboxes: When an AI agent performs code audits, refactoring, or bug fixes, files are processed in isolated, transient environments with strict access controls.
- Enterprise LLM Data Protection: All external Large Language Model (LLM) API providers utilized by Bricktry operate under enterprise agreements that prohibit the retention or use of customer inputs and outputs for model training.
- Customer Ownership of Generated Deliverables: All code, scripts, patches, and configurations generated for your project remain your exclusive intellectual property.
5. Google API Services & Search Console Data Disclosure
Bricktry's integration with Google Search Console enables our AI-Native SEO Engine to display authentic search performance metrics directly within your administrative dashboard. In accordance with Google's policies:
- Compliance with Google API Services User Data Policy: Bricktry's use and transfer to any other application of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- No Sale or Third-Party Monetization: We will never sell, lease, transfer, or distribute your Google Search Console data to data brokers, advertising networks, or unauthorized third parties.
- Internal Operational Use Only: Search query metrics, click rates, impressions, and rankings are accessed solely to compute SEO diagnostic reports and recommendations for your verified domains.
6. Legal Bases for Data Processing (GDPR & Global Standards)
For individuals residing in the European Economic Area (EEA), the United Kingdom, Switzerland, or applicable jurisdictions, our legal bases for processing personal data include:
- Contractual Necessity (Art. 6(1)(b) GDPR): Processing required to establish your account, execute service agreements, deliver purchased subscriptions, and provide engineering pair workflows.
- Legitimate Interests (Art. 6(1)(f) GDPR): Operating our business, securing our infrastructure against cyber attacks, preventing fraud, troubleshooting runtime exceptions, and improving developer tooling.
- Legal Obligation (Art. 6(1)(c) GDPR): Complying with financial accounting requirements, anti-fraud rules, statutory tax filings, and KYC obligations for affiliate disbursements.
- Consent (Art. 6(1)(a) GDPR): Where you have provided clear, affirmative consent, such as opting into optional analytical cookies or subscribing to promotional communications.
7. Data Sharing and Third-Party Sub-Processors
We never monetize, rent, or sell your personal data. We disclose information only to vetted third-party service providers ("Sub-processors") who assist in operating our infrastructure under strict data protection agreements:
- Cloud Hosting & Storage: Amazon Web Services (AWS) — hosting our compute servers (EC2), scalable object storage (S3), and relational databases within secure, encrypted data centers.
- Payment Processing: Stripe, Razorpay, and PayPal — providing encrypted, PCI-compliant payment gateways and automated subscription billing.
- AI Compute & Inference: Enterprise tier artificial intelligence providers accessed via secure encrypted endpoints with strict zero-data-retention guarantees.
- Transactional Communications: Enterprise mail delivery networks for two-factor authentication, account alerts, password resets, and audit notifications.
- Legal & Regulatory Authorities: We may disclose data if legally compelled by a valid subpoena, court order, or binding request from law enforcement authorities.
8. Cookies and Tracking Technologies
Bricktry utilizes cookies, local storage, and similar technologies to ensure seamless platform operation. You can configure and review your cookie preferences at any time via our Cookie Banner:
- Strictly Necessary Cookies: Essential for session authentication, CSRF security verification, load balancing, and single-tenant workspace isolation. The platform cannot function properly without these cookies.
- Functional & Preference Cookies: Remembering your UI theme (dark/light mode), sidebar states, and language selections.
- Performance & Analytics Cookies: Anonymous aggregated telemetry to track site speed, server response times, and feature adoption. Analytics cookies remain disabled until you affirmatively consent.
9. Security Architecture and Data Retention
We implement rigorous technical and organizational security measures to protect your personal data and proprietary code from unauthorized access, alteration, disclosure, or destruction:
- Cryptographic Encryption: All network traffic is encrypted in transit using Transport Layer Security (TLS 1.3 / HTTPS). Sensitive database columns and stored files are encrypted at rest using AES-256 encryption.
- Access Controls & Audit Logging: Access to production servers is strictly limited to authorized engineering personnel using multi-factor authentication (MFA) and SSH keypairs. All administrative actions are recorded in immutable audit logs.
- Data Retention Timelines: Active project files and repositories are retained for the duration of your active subscription. Upon account closure or explicit deletion request, sandbox files and authentication tokens are expunged within thirty (30) days. Financial records, tax invoices, and KYC audit logs are preserved for seven (7) years to comply with statutory legal mandates.
10. Your International Privacy Rights
Depending on your jurisdiction (including the EU/EEA, UK, California, Virginia, India, and other regions), you possess statutory privacy rights:
- Right of Access & Portability: You may request a complete copy of the personal information we hold about you in a structured, portable, machine-readable format.
- Right to Rectification: You may update or correct inaccurate personal details directly within your Account Settings or by contacting support.
- Right to Erasure ("Right to Be Forgotten"): You may request that we delete your personal account data and associated project files, subject to statutory retention exceptions.
- Right to Restrict or Object to Processing: You may object to or restrict processing of your personal information under certain circumstances.
- California Consumer Rights (CCPA / CPRA): California residents have the right to know what personal information is collected, request deletion, and not be discriminated against for exercising privacy rights. Bricktry does not sell or share personal information for cross-context behavioral advertising.
- Indian DPDP Act Rights: Indian citizens have the right to access a summary of personal data processed, request correction or erasure, nominate another individual in the event of incapacity, and utilize our grievance redressal mechanism.
To exercise any of these rights, please email our Data Protection team at privacy@bricktry.com. We will verify your identity and respond within thirty (30) days.
11. Children's Privacy
Bricktry is an enterprise engineering platform designed strictly for professional software developers, engineering teams, and businesses. Our Services are not directed to individuals under eighteen (18) years of age, and we do not knowingly solicit or collect personal information from minors.
12. Revisions to This Privacy Policy
We may amend this Privacy Policy periodically to reflect technological enhancements, operational changes, or evolving legal frameworks. When material revisions occur, we will provide prominent notice through an administrative dashboard alert, email communication, or an updated "Last updated" date at the top of this document. Continued use of Bricktry after such updates represents acknowledgment of the amended policy.
13. Contact Us & Grievance Redressal
If you have inquiries, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us:
- Data Protection Officer & Privacy Desk: privacy@bricktry.com
- General Customer Support: support@bricktry.com
- Entity: Bricktry Technologies — Platform Operations
- Official Website: https://bricktry.com