Privacy
brainmod is operated by Jestr (support@jestr.ai). This notice lists exactly what the brainmod server stores, why and for how long. Last updated 5 October 2026.
What brainmod never receives
- Your prompts, Claude Code transcripts, or Claude's replies.
- The contents of your files, or diffs of them.
- Tool inputs, except the tool's name and, for repos you opt in, the file it works on.
- Your Claude or Anthropic credentials.
If you never sign in, brainmod sends nothing at all: everything stays in the mod's local store on your machine.
What it stores when you sign in
| Data | Why | Kept |
|---|---|---|
| GitHub id, login, name, avatar URL | Your account, and how teammates recognise you. Sign-in asks GitHub for read:user only. | Until you ask us to delete your account |
| Presence: a random session id, machine name, repo name and a hash of its remote URL, branch, status (idle, thinking, tool name, asking), hashes of up to 30 files touched in the last 30 minutes | The band, and the collision hold | Expires about 2 minutes after the session's last heartbeat |
| File paths and the current edit target | Readable file names in teammates' bands | Only for repos you put in sharedFiles; same expiry as presence |
| Notes you or your Claude post (text, kind, area, repo) | Your personal brain, synced across your machines; team notes for the team | Until you delete them, or the team is deleted |
| Messages you send | Delivering them to a teammate's Claude or a team | 7 days |
| Teams, memberships, invite codes | Deciding who sees what | Invites 7 days; the rest until the team is deleted or you leave |
| Tokens and browser sessions, stored as SHA-256 hashes, with client name, machine name, created and last-used times | Signing your machines and browsers in, and letting you revoke them | Until revoked, or 90 days unused |
Who sees it
Your presence and the notes you promote are visible to the members of the teams you are in, checked on every request. Personal notes are visible only to you. Messages reach only the session, person or team you address, and only people who share a team with you. Jestr does not sell this data or use it for advertising.
Safeguards
- A secret scanner runs on every note and message, on your machine before upload and again on the server, and refuses anything that looks like a key, token, private key or password.
- File paths travel as hashes unless you opt a repo in.
- Tokens and session cookies are stored hashed. The session cookie is HttpOnly, Secure and SameSite=Lax.
- Rate limits per person: 240 requests a minute, 30 notes and 60 messages an hour, 20 invites a day.
Where it runs
The server runs on Amazon Web Services in Frankfurt (eu-central-1): AWS Lambda, API Gateway and DynamoDB. Sign-in uses GitHub. The site loads no third-party scripts, fonts or trackers and sets one cookie, bm_session, only when you sign in.
Your choices
- Revoke any machine or browser on your account page, or run
/brain logout. - Delete your notes with
/brain forgetor on the account page; leave any team on its page. - To export or delete your account and everything tied to it, email support@jestr.ai from the address on your GitHub account, or name your GitHub login. We answer within 30 days.
Questions about this notice: support@jestr.ai.