Introduction
This Data Policy provides detailed information about how 2ndBrain collects, processes, stores, and manages your data. We believe in complete transparency about our data practices, giving you full understanding and control over your information.
Your data is the foundation of your second brain. We treat it with the utmost respect and implement industry-leading practices to ensure its security, integrity, and availability.
Data Collection Practices
Content You Create and Save
- Web Content: Articles, videos, and pages you save via our browser extension
- Notes and Documents: Text, markdown, and rich content you create or import
- Highlights and Annotations: Selected text and your comments on saved content
- Tags and Collections: Organizational structures you create
- Connections: Links you create between different pieces of content
Metadata We Generate
- Timestamps: When content was saved, modified, or accessed
- Source Information: URLs, authors, publication dates of saved content
- Engagement Metrics: How often you interact with specific content
- Derived Insights: AI-generated summaries, tags, and connections
- Search History: Queries within your second brain (not web searches)
Technical Data
- Device information and browser type for compatibility
- IP address for security and regional compliance
- Session data for maintaining your login state
- Performance metrics to optimize the service
Data Storage Architecture
Primary Storage
Your data is stored using enterprise-grade infrastructure:
- Database: PostgreSQL on AWS RDS with automatic failover
- Files: Amazon S3 with server-side encryption (AES-256)
- Search Index: Elasticsearch for fast full-text search
- Cache: Redis for improved performance
Geographic Distribution
Data is stored in multiple regions for performance and reliability:
- Primary: US East (Virginia)
- Secondary: EU West (Ireland)
- Backup: US West (Oregon)
Backup and Recovery
- Automated daily backups retained for 30 days
- Point-in-time recovery available for the last 7 days
- Disaster recovery plan with 4-hour RTO (Recovery Time Objective)
- 99.9% uptime SLA for data availability
Data Processing Activities
Intelligent Processing
We process your data to provide smart features while respecting your privacy:
Content Analysis
Extract key concepts, entities, and topics from your saved content
Processing: Real-time, on-device when possible
Connection Discovery
Identify relationships between different pieces of content
Processing: Background, using vector embeddings
Smart Recommendations
Suggest relevant content based on your current context
Processing: Real-time, personalized ML model
Search Enhancement
Enable semantic search across all your content
Processing: Indexed, with natural language understanding
Data Minimization
We follow the principle of data minimization:
- Collect only data necessary for service functionality
- Automatically delete temporary data after processing
- Provide granular controls over data collection
- Regular audits to identify and remove unnecessary data
Data Sharing and Third Parties
Our Commitment
We NEVER sell, rent, or trade your personal data.
Limited Sharing Scenarios
Service Providers
We work with carefully selected partners who sign strict data protection agreements:
- AWS: Cloud infrastructure (SOC 2 Type II certified)
- Stripe: Payment processing (PCI DSS compliant)
- SendGrid: Transactional emails (GDPR compliant)
- Sentry: Error monitoring (anonymized data only)
Legal Obligations
We may disclose data when legally required:
- Valid court orders or subpoenas
- Government requests with proper legal authority
- To protect rights, property, or safety
- To investigate fraud or security issues
With Your Consent
- When you explicitly share content publicly
- When you connect third-party integrations
- For features that require collaboration
Data Retention Schedule
| Data Type | Retention Period | Deletion Method |
|---|
| Active user content | While account is active | User-initiated or account deletion |
| Deleted content | 30 days (recoverable) | Permanent deletion |
| Account data after deletion | 90 days | Complete purge |
| Backup data | 30 days rolling | Automatic rotation |
| Log files | 90 days | Automatic deletion |
| Analytics data | 12 months | Anonymization |
Data Portability and Export
Your Data, Your Control
We provide comprehensive data export options:
Full Account Export
- Complete data dump in JSON format
- All content, metadata, and settings
- Can be imported into other tools
Selective Export
- Export specific collections or tags
- Choose format: JSON, Markdown, CSV, HTML
- Include or exclude metadata
API Access
- RESTful API for programmatic access
- Bulk operations supported
- Rate-limited to prevent abuse
AI and Machine Learning
How We Use AI
Our AI enhances your second brain while protecting your privacy:
Personal AI Model
- Each user has a separate, isolated AI model
- Trained only on your own content
- Never shared with other users
- Deleted when you delete your account
Privacy-Preserving Techniques
- Federated Learning: Models improve without accessing raw data
- Differential Privacy: Statistical noise prevents individual identification
- On-Device Processing: Sensitive operations happen locally when possible
- Encrypted Computation: Process data without decrypting it
Opt-Out Options
You can disable AI features:
- Turn off AI-powered suggestions
- Disable automatic tagging
- Prevent content analysis
- Use 2ndBrain as a simple storage system
Compliance and Certifications
Regulatory Compliance
GDPR (Europe)
Full compliance with data subject rights, lawful basis for processing, and data protection by design
CCPA (California)
Transparency in data collection, right to deletion, and non-discrimination
PIPEDA (Canada)
Consent, limited collection, and individual access to personal information
Security Standards
- SOC 2 Type II (in progress)
- ISO 27001 (planned 2025)
- Regular penetration testing
- Bug bounty program
Data Breach Response
In the unlikely event of a data breach, we commit to:
Immediate Response
- Contain and assess the breach within 24 hours
- Notify affected users within 72 hours
- Report to relevant authorities as required by law
- Provide clear information about what happened and what data was affected
Support and Remediation
- Offer credit monitoring if financial data was compromised
- Provide detailed guidance on protective steps
- Implement additional security measures
- Conduct thorough post-incident review
Contact Our Data Team
For any questions or concerns about our data practices:
Data Protection Officer
Email: dpo@2ndbra.in
Response time: Within 48 hours
Privacy Team
Email: privacy@2ndbra.in
Security Issues
Email: security@2ndbra.in
For responsible disclosure of vulnerabilities