Superbrain / Your information

App privacy policy.

What you share with Axo, where it goes, and the choices you have.

Development version · Updated

About this policy

This policy describes the current Superbrain app and private testing service, including text conversations with its AI companion, Axo. Superbrain is in development; it is not yet a publicly released Android app.

Development draft. The developer’s identity and privacy contact are awaiting confirmation. This version is published on the Superbrain introduction website for review and is not a finalized policy for a public app release.

Account and conversation information is processed by the Superbrain developer described in the contact section. Google, OpenAI, and our hosting providers also process information as explained below.

Information we process

Account and sign-in
Google and Firebase Authentication process your sign-in identity, which can include your account ID, email address, name, profile picture, and authentication information. Superbrain uses an account identifier to associate you with your records. Our app server does not maintain a separate copy of your Google profile name or photo.
Conversations and memory
The text you send, Axo’s replies, conversation timestamps, saved memories, memory revisions, and memory suggestions. We also create summaries and other representations of earlier conversation context so Axo can continue a conversation. Messages can contain personal or sensitive information you choose to share.
Service operation
Request identifiers, response status, errors, model and prompt versions, token usage, and estimated processing costs. Infrastructure providers may process IP addresses, browser or device information, and technical request logs to deliver and protect their services.
Requests to the developer
If you contact us, the contact information and correspondence you provide, including information needed to identify your account and handle your request.

Unsent drafts stay in your browser until you send them. Submitted messages are processed with relevant context as described below. Drafts and unresolved message retries are kept in browser session storage. Avoid including passwords, payment details, government identification numbers, or other people’s sensitive information in a conversation.

Why we process it

We use account and conversation information to authenticate you, generate replies, restore your history, recall relevant context, and provide the memory controls you request. Operational records help us prevent duplicate requests, manage usage limits, diagnose failures, and keep the service working.

The current app has no advertising or analytics SDK. It does not collect payment-card information or offer subscriptions. We do not use the app to sell personal information or target advertising.

Where European data protection law applies, the intended bases for core service processing are providing the service you request and our legitimate interests in secure, reliable operation. Legal obligations can also require processing. These bases and any consent requirements will be finalized for the public release; this draft does not establish consent for additional uses.

AI and service providers

OpenAI Replies and context processing
Our server sends your message and relevant context to the OpenAI API. Context can include earlier messages, approved memories, and conversation summaries. Summarizing earlier conversations can involve a separate AI request. If semantic recall is enabled, relevant text is also sent to OpenAI to generate embeddings used to find related context.
Google / Firebase Authentication
Google sign-in and Firebase Authentication identify your account and manage authentication. Their services receive the information needed for sign-in and security. See Firebase’s privacy and security information and Google’s privacy policy.
Railway App hosting and database
Railway hosts the app server, background processing, and database holding application records. See Railway’s privacy policy.

OpenAI states that API inputs and outputs are not used to train its models by default, unless a customer opts in. Superbrain requests disable stored Responses API conversation state. This is not zero retention: provider security logs may include content and are normally retained for up to 30 days, with exceptions. Temporary prompt caches and endpoint-specific retention can also apply. See OpenAI’s current API data controls.

Service providers may process data outside your country, including in the United States. Exact processing locations, applicable transfer safeguards, and provider account settings are still being confirmed for public release. We do not promise that all processing stays in the EU.

We may also disclose information when required by law or necessary to investigate misuse and protect the service or others. Conversations are not displayed publicly by the app.

Your memory controls

Saved personal memories require an explicit save request or your approval of a suggestion. Automatic conversation summaries are separate from saved personal memories.

  • /memories lists your saved memories.
  • /remember key: value saves or replaces a memory under that key.
  • /forget key removes that memory, its revisions, and related suggestions.
  • /suggestions lists suggestions; you can approve or dismiss them through chat.

Forgetting a memory does not erase your conversation history. Earlier messages, existing summaries, and information already sent to a provider remain separate records. We keep the forgotten key and time of removal to prevent delayed suggestions from saving it again.

Retention and deletion

Conversations, summaries, saved memories, and operational records remain in the app database until removed through the relevant control or account-data deletion. The current testing service does not automatically expire inactive accounts or purge old conversations on a fixed schedule.

The app’s account-data deletion operation removes records from the active application database. It retains a minimal internal account identifier and deletion time to prevent the deleted account from being silently recreated. This operation does not, by itself, delete your Firebase authentication identity, a provider’s security logs, or copies in backups.

Complete account deletion requires handling those systems separately. Backup expiry, infrastructure-log retention, deletion-request handling, and the retention period for the minimal deletion record are still being finalized. This draft does not promise immediate deletion from every system or a fixed completion period.

The current chat screen does not yet offer account export or account deletion controls. For requests about access, export, correction, or deletion, use the privacy contact once confirmed. Closing the app or clearing browser storage does not delete server-side records.

Storage and security

The app uses browser session storage for authentication state, drafts, and pending sends. Firebase and Google can also use storage or cookies as part of their sign-in services. Clearing local storage can end your session and remove drafts; it does not remove stored conversations.

Hosted connections use HTTPS. The server checks authentication and account ownership before allowing access to conversations and memory. Provider credentials remain on the server. Conversation content is processed by the app server and AI provider, so the service is not end-to-end encrypted.

No transmission or storage method guarantees absolute security. Use a device and Google account you trust, particularly if you discuss personal information.

Your privacy rights

Depending on your location, you may have rights to access, correct, erase, receive a portable copy of, or restrict processing of your personal information, and to object to certain processing. Where processing relies on consent, you can withdraw it without changing the lawfulness of earlier processing.

You can raise a request with the privacy contact below. We may need to verify account ownership before disclosing or deleting information. Do not send your password or authentication token. You may also complain to your local data protection authority.

Axo generates conversational replies. The current app does not use those replies to make decisions about your eligibility for employment, lending, housing, or similar services.

Features in development

Android voice messages, spoken replies, photos and screenshots, external knowledge search, notifications, and subscriptions are planned features. They are not current data-collection features of this text-chat version. We will update this policy and provide any required disclosure and permission request before enabling them.

Superbrain has not launched a public service for children. Age eligibility and any parental-consent requirements are still being determined before public release.

This website

The Superbrain introduction website and this policy page do not provide live chat or collect waitlist email addresses. We have not added advertising, analytics scripts, or tracking cookies. Fonts, artwork, and the 3D preview are served from the site.

The public website is hosted on Railway. A separate private preview is hosted through OpenAI Sites. These providers and their delivery infrastructure may process technical request information to deliver and secure the site; the private Sites preview also uses sign-in services. See Railway’s privacy policy and OpenAI’s privacy policy.

Contact and policy changes

Developer / data controller
Awaiting confirmation
Privacy contact
Awaiting confirmation

A working privacy contact will be added before this policy is finalized or the app is released publicly.

We will update this page when the app or its data handling changes. The date at the top identifies the latest version. Material new uses will be explained before they take effect, with consent requested where required.

Return to Superbrain