Back to Home
2ndBrain Legal

Data Policy

Effective Date: 6/30/2026

Introduction

This Data Policy provides detailed information about how 2ndBrain collects, processes, stores, and manages your data. We believe in complete transparency about our data practices, giving you full understanding and control over your information.

Your data is the foundation of your second brain. We treat it with the utmost respect and implement industry-leading practices to ensure its security, integrity, and availability.

Data Collection Practices

Content You Create and Save

  • Web Content: Articles, videos, and pages you save via our browser extension
  • Notes and Documents: Text, markdown, and rich content you create or import
  • Highlights and Annotations: Selected text and your comments on saved content
  • Tags and Collections: Organizational structures you create
  • Connections: Links you create between different pieces of content

Metadata We Generate

  • Timestamps: When content was saved, modified, or accessed
  • Source Information: URLs, authors, publication dates of saved content
  • Engagement Metrics: How often you interact with specific content
  • Derived Insights: AI-generated summaries, tags, and connections
  • Search History: Queries within your second brain (not web searches)

Technical Data

  • Device information and browser type for compatibility
  • IP address for security and regional compliance
  • Session data for maintaining your login state
  • Performance metrics to optimize the service

Data Storage Architecture

Primary Storage

Your data is stored using enterprise-grade infrastructure:

  • Database: PostgreSQL on AWS RDS with automatic failover
  • Files: Amazon S3 with server-side encryption (AES-256)
  • Search Index: Elasticsearch for fast full-text search
  • Cache: Redis for improved performance

Geographic Distribution

Data is stored in multiple regions for performance and reliability:

  • Primary: US East (Virginia)
  • Secondary: EU West (Ireland)
  • Backup: US West (Oregon)

Backup and Recovery

  • Automated daily backups retained for 30 days
  • Point-in-time recovery available for the last 7 days
  • Disaster recovery plan with 4-hour RTO (Recovery Time Objective)
  • 99.9% uptime SLA for data availability

Data Processing Activities

Intelligent Processing

We process your data to provide smart features while respecting your privacy:

Content Analysis

Extract key concepts, entities, and topics from your saved content

Processing: Real-time, on-device when possible

Connection Discovery

Identify relationships between different pieces of content

Processing: Background, using vector embeddings

Smart Recommendations

Suggest relevant content based on your current context

Processing: Real-time, personalized ML model

Search Enhancement

Enable semantic search across all your content

Processing: Indexed, with natural language understanding

Data Minimization

We follow the principle of data minimization:

  • Collect only data necessary for service functionality
  • Automatically delete temporary data after processing
  • Provide granular controls over data collection
  • Regular audits to identify and remove unnecessary data

Data Sharing and Third Parties

Our Commitment

We NEVER sell, rent, or trade your personal data.

Limited Sharing Scenarios

Service Providers

We work with carefully selected partners who sign strict data protection agreements:

  • AWS: Cloud infrastructure (SOC 2 Type II certified)
  • Stripe: Payment processing (PCI DSS compliant)
  • SendGrid: Transactional emails (GDPR compliant)
  • Sentry: Error monitoring (anonymized data only)

Legal Obligations

We may disclose data when legally required:

  • Valid court orders or subpoenas
  • Government requests with proper legal authority
  • To protect rights, property, or safety
  • To investigate fraud or security issues

With Your Consent

  • When you explicitly share content publicly
  • When you connect third-party integrations
  • For features that require collaboration

Data Retention Schedule

Data TypeRetention PeriodDeletion Method
Active user contentWhile account is activeUser-initiated or account deletion
Deleted content30 days (recoverable)Permanent deletion
Account data after deletion90 daysComplete purge
Backup data30 days rollingAutomatic rotation
Log files90 daysAutomatic deletion
Analytics data12 monthsAnonymization

Data Portability and Export

Your Data, Your Control

We provide comprehensive data export options:

Full Account Export

  • Complete data dump in JSON format
  • All content, metadata, and settings
  • Can be imported into other tools

Selective Export

  • Export specific collections or tags
  • Choose format: JSON, Markdown, CSV, HTML
  • Include or exclude metadata

API Access

  • RESTful API for programmatic access
  • Bulk operations supported
  • Rate-limited to prevent abuse

AI and Machine Learning

How We Use AI

Our AI enhances your second brain while protecting your privacy:

Personal AI Model

  • Each user has a separate, isolated AI model
  • Trained only on your own content
  • Never shared with other users
  • Deleted when you delete your account

Privacy-Preserving Techniques

  • Federated Learning: Models improve without accessing raw data
  • Differential Privacy: Statistical noise prevents individual identification
  • On-Device Processing: Sensitive operations happen locally when possible
  • Encrypted Computation: Process data without decrypting it

Opt-Out Options

You can disable AI features:

  • Turn off AI-powered suggestions
  • Disable automatic tagging
  • Prevent content analysis
  • Use 2ndBrain as a simple storage system

Compliance and Certifications

Regulatory Compliance

GDPR (Europe)

Full compliance with data subject rights, lawful basis for processing, and data protection by design

CCPA (California)

Transparency in data collection, right to deletion, and non-discrimination

PIPEDA (Canada)

Consent, limited collection, and individual access to personal information

Security Standards

  • SOC 2 Type II (in progress)
  • ISO 27001 (planned 2025)
  • Regular penetration testing
  • Bug bounty program

Data Breach Response

In the unlikely event of a data breach, we commit to:

Immediate Response

  • Contain and assess the breach within 24 hours
  • Notify affected users within 72 hours
  • Report to relevant authorities as required by law
  • Provide clear information about what happened and what data was affected

Support and Remediation

  • Offer credit monitoring if financial data was compromised
  • Provide detailed guidance on protective steps
  • Implement additional security measures
  • Conduct thorough post-incident review

Contact Our Data Team

For any questions or concerns about our data practices:

Data Protection Officer

Email: dpo@2ndbra.in

Response time: Within 48 hours

Privacy Team

Email: privacy@2ndbra.in

Security Issues

Email: security@2ndbra.in

For responsible disclosure of vulnerabilities

Last updated: 6/30/2026