Privacy Policy

Last updated: February 21, 2026

1. Who We Are

Cerebruh is operated by Big Pager, Inc. ("we," "us," "our"). We act as the data controller for personal data processed through our service. You can reach us at hey@cerebruh.is.

2. What Data We Collect

We collect and process the following categories of personal data:

  • Account information: Email address and username, provided during registration.
  • Billing information: Payment details processed by Stripe. We do not store your card number.
  • Usage data: AI model usage metrics, feature usage, and session metadata for billing and service improvement.
  • Chat history: Conversations with your AI agent, stored on your dedicated server.
  • Connection tokens: Authentication tokens for connected services (Signal, Telegram, SMS, email, etc.), stored encrypted.
  • Agent data: Files, memory, and configuration on your dedicated server.

3. Legal Basis for Processing

We process your data on the following legal bases under GDPR:

  • Contract performance: To provide the Cerebruh service you signed up for (Art. 6(1)(b) GDPR).
  • Legitimate interest: For security, fraud prevention, and service improvement (Art. 6(1)(f) GDPR).
  • Consent: Where you explicitly agree, such as accepting our Terms of Service (Art. 6(1)(a) GDPR). You may withdraw consent at any time.
  • Legal obligation: To comply with tax, billing, and regulatory requirements (Art. 6(1)(c) GDPR).

4. How We Use Your Data

We use your personal data to:

  • Provide and operate the AI agent service
  • Authenticate you via magic link emails
  • Process billing and subscription management
  • Send service notifications (not marketing)
  • Route your conversations to AI model providers
  • Connect your agent to third-party services you authorize
  • Maintain security and prevent abuse

5. Sub-processors

We use the following third-party sub-processors to deliver our service. Each processes data only as necessary for its stated purpose:

ProviderPurpose
HetznerVM hosting (dedicated user servers, Germany)
NeonPostgreSQL database (account data, usage records)
VercelWeb application hosting and CDN
StripePayment processing and subscription management
TwilioSMS and voice communication
AnthropicAI model provider (processes conversations)
Amazon SESTransactional email delivery
CloudflareDNS management and security

6. Data Location

Your dedicated agent server runs on Hetzner Cloud infrastructure in Germany. Our application database is hosted by Neon on AWS infrastructure. Web application hosting is provided by Vercel with global CDN distribution. We ensure all data transfers comply with applicable data protection regulations.

7. Data Isolation

Each Cerebruh account runs on its own dedicated server with its own encrypted storage volume. Your agent data (conversations, files, memory) is not commingled with other users' data.

8. Data Retention

  • Active accounts: Data is retained for the duration of your subscription.
  • After cancellation: You have a 7-day grace period to export your data. After that, your dedicated server and storage volume are permanently destroyed.
  • Account metadata: Email, username, and billing records are retained as required for legal and tax compliance purposes, typically up to 7 years.
  • Usage data: Aggregated usage metrics may be retained for billing reconciliation.

9. Your Rights (GDPR)

If you are in the European Economic Area (EEA) or UK, you have the following rights under GDPR:

  • Right of access: Request a copy of all personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your personal data ("right to be forgotten").
  • Right to data portability: Receive your data in a structured, machine-readable format.
  • Right to restrict processing: Request that we limit how we use your data.
  • Right to object: Object to processing based on legitimate interests.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

How to exercise your rights: Email hey@cerebruh.is or use in-app features (account deletion and data export are available from your account page). We will respond within 30 days.

You also have the right to lodge a complaint with a supervisory authority in your jurisdiction.

10. Cookies

We use only functional cookies that are strictly necessary for the service:

  • Authentication cookie: An HTTP-only session cookie (JWT) to keep you logged in.
  • Theme preference: A cookie to remember your light/dark mode setting.

We do not use tracking cookies, analytics scripts, or third-party trackers. If we add analytics in the future, we will use a cookieless, privacy-respecting solution.

11. Children

Cerebruh is not intended for users under the age of 16. We do not knowingly collect personal data from children. If we learn that we have collected data from a child under 16, we will delete it promptly.

12. International Transfers

Some of our sub-processors are based outside the EEA. Where personal data is transferred internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or adequacy decisions as applicable.

13. Security

We implement appropriate technical and organizational measures to protect your data, including encrypted storage volumes, TLS for all connections, and access controls. However, no system is 100% secure, and we cannot guarantee absolute security.

14. Changes

We will notify you of material changes to this policy via email with at least 30 days' notice. The "last updated" date at the top reflects the most recent revision.

15. Contact

Big Pager, Inc.
Email: hey@cerebruh.is