Privacy Policy
Effective Date: July 28, 2026 • Version 1.2
At codbrain (operated under codbrain.online), we build autonomous knowledge infrastructure for AI coding agents. We uphold an uncompromised privacy standard: your operational credentials never touch our servers, and your private business data is mathematically isolated.
Zero-Credential Retention Architecture
codbrain is designed strictly as an MCP knowledge & doctrine provider. We do not store, proxy, or request your API credentials (including Meta Ads tokens, Vercel tokens, Shopify/YouCan keys, or fulfillment provider tokens).
- Your local AI agent executes actions on your local machine using your own environment variables.
- Any payload containing credentials or secret patterns is rejected outright before server-side parsing.
1. Data Isolation & PostgreSQL RLS
Your private business notes, execution logs, and custom workflows created via brain_note or brain_recall are stored in isolated PostgreSQL tables protected by Row Level Security (RLS). Each seller profile is strictly scoped to its authenticated API key owner. Even application administrators cannot access raw private notes.
2. Anonymized Knowledge Distillation
To improve common operational procedures (such as media buyer patterns or COD unit economics), codbrain aggregates operational signals using multi-seller consensus algorithms (findSignals).
Distillation Principle: Knowledge is abstracted, never copied. Brand names, specific URLs, product SKUs, and individual price points are automatically stripped during signal evaluation. A pattern is only considered valid when observed across independent, decoupled seller accounts.
3. Telemetry & Protocol Logs
We collect minimal protocol telemetry to monitor server health, rate limiting, and prevent protocol abuse:
- API Key identifier (hashed)
- MCP Tool invoked (e.g.
get_procedure) - Execution duration and status HTTP status code
- Anonymized aggregate error frequencies
4. Encryption & Infrastructure Security
All data transmitted between your local AI agent (Claude Code, Cursor, Codex) and codbrain servers is encrypted using standard TLS 1.3 encryption. Stored application databases are encrypted at rest using AES-256 standards.
5. Contact & Privacy Inquiries
If you have any questions regarding data protection, vulnerability disclosures, or data deletion requests, please contact our security team directly:
Security Lead: security@codbrain.online