Privacy Policy
Second Brain Pro · Controller: aiAdaptiv (aiadaptiv.com) · privacy@aiadaptiv.com Effective: 7 October 2026 · Version 1.0
What we collect
| Data | Why |
|---|---|
| Email, auth IDs (Clerk) | Account & sign‑in |
| Your Markdown notes | To run the vault / MCP for you |
| Billing metadata (Stripe) | Payments — we never see full card numbers |
| Usage logs (tool name, time, IP, client name — never note text) | Security, limits, debugging |
| Support emails | Helping you |
Legal bases (GDPR)
Contract (Art. 6(1)(b)) for account, vault, billing. Legitimate interests (Art. 6(1)(f)) for security logs. Legal obligation for invoices. Consent where we use optional analytics cookies.
Who we share with
Only processors needed to run the product — see /subprocessors. Stripe is an independent controller for the sale when Managed Payments is on. AI apps you connect (Claude, ChatGPT, etc.) get note content only because you connected them — that is between you and them.
We do not sell personal data.
Retention
Vault: while subscribed, then ~30 days to export, then deleted from live systems. Accounting records: as required by Polish tax law. Security logs: ~90 days.
Your rights
Access, rectify, erase, portability (ZIP export), object, withdraw consent. Email privacy@aiadaptiv.com. You can complain to UODO (Poland) or your local EU authority.
Security
TLS, encrypted storage, DB row‑level tenant isolation, hashed connection URLs, least‑privilege DB roles. No system is perfect — we notify as required if a breach risks your rights.
Contact
aiAdaptiv · privacy@aiadaptiv.com · aiadaptiv.com