Second Brain Pro

Privacy Policy

Privacy Policy

Second Brain Pro · Controller: aiAdaptiv (aiadaptiv.com) · privacy@aiadaptiv.com Effective: 7 October 2026 · Version 1.0

What we collect

DataWhy
Email, auth IDs (Clerk)Account & sign‑in
Your Markdown notesTo run the vault / MCP for you
Billing metadata (Stripe)Payments — we never see full card numbers
Usage logs (tool name, time, IP, client name — never note text)Security, limits, debugging
Support emailsHelping you

Legal bases (GDPR)

Contract (Art. 6(1)(b)) for account, vault, billing. Legitimate interests (Art. 6(1)(f)) for security logs. Legal obligation for invoices. Consent where we use optional analytics cookies.

Who we share with

Only processors needed to run the product — see /subprocessors. Stripe is an independent controller for the sale when Managed Payments is on. AI apps you connect (Claude, ChatGPT, etc.) get note content only because you connected them — that is between you and them.

We do not sell personal data.

Retention

Vault: while subscribed, then ~30 days to export, then deleted from live systems. Accounting records: as required by Polish tax law. Security logs: ~90 days.

Your rights

Access, rectify, erase, portability (ZIP export), object, withdraw consent. Email privacy@aiadaptiv.com. You can complain to UODO (Poland) or your local EU authority.

Security

TLS, encrypted storage, DB row‑level tenant isolation, hashed connection URLs, least‑privilege DB roles. No system is perfect — we notify as required if a breach risks your rights.

Contact

aiAdaptiv · privacy@aiadaptiv.com · aiadaptiv.com