brainmodbeta
privacy notice

Privacy

brainmod is operated by Jestr (support@jestr.ai). This notice lists exactly what the brainmod server stores, why and for how long. Last updated 5 October 2026.

What brainmod never receives

  • Your prompts, Claude Code transcripts, or Claude's replies.
  • The contents of your files, or diffs of them.
  • Tool inputs, except the tool's name and, for repos you opt in, the file it works on.
  • Your Claude or Anthropic credentials.

If you never sign in, brainmod sends nothing at all: everything stays in the mod's local store on your machine.

What it stores when you sign in

DataWhyKept
GitHub id, login, name, avatar URLYour account, and how teammates recognise you. Sign-in asks GitHub for read:user only.Until you ask us to delete your account
Presence: a random session id, machine name, repo name and a hash of its remote URL, branch, status (idle, thinking, tool name, asking), hashes of up to 30 files touched in the last 30 minutesThe band, and the collision holdExpires about 2 minutes after the session's last heartbeat
File paths and the current edit targetReadable file names in teammates' bandsOnly for repos you put in sharedFiles; same expiry as presence
Notes you or your Claude post (text, kind, area, repo)Your personal brain, synced across your machines; team notes for the teamUntil you delete them, or the team is deleted
Messages you sendDelivering them to a teammate's Claude or a team7 days
Teams, memberships, invite codesDeciding who sees whatInvites 7 days; the rest until the team is deleted or you leave
Tokens and browser sessions, stored as SHA-256 hashes, with client name, machine name, created and last-used timesSigning your machines and browsers in, and letting you revoke themUntil revoked, or 90 days unused

Who sees it

Your presence and the notes you promote are visible to the members of the teams you are in, checked on every request. Personal notes are visible only to you. Messages reach only the session, person or team you address, and only people who share a team with you. Jestr does not sell this data or use it for advertising.

Safeguards

  • A secret scanner runs on every note and message, on your machine before upload and again on the server, and refuses anything that looks like a key, token, private key or password.
  • File paths travel as hashes unless you opt a repo in.
  • Tokens and session cookies are stored hashed. The session cookie is HttpOnly, Secure and SameSite=Lax.
  • Rate limits per person: 240 requests a minute, 30 notes and 60 messages an hour, 20 invites a day.

Where it runs

The server runs on Amazon Web Services in Frankfurt (eu-central-1): AWS Lambda, API Gateway and DynamoDB. Sign-in uses GitHub. The site loads no third-party scripts, fonts or trackers and sets one cookie, bm_session, only when you sign in.

Your choices

  • Revoke any machine or browser on your account page, or run /brain logout.
  • Delete your notes with /brain forget or on the account page; leave any team on its page.
  • To export or delete your account and everything tied to it, email support@jestr.ai from the address on your GitHub account, or name your GitHub login. We answer within 30 days.

Questions about this notice: support@jestr.ai.