Brevitas Systems

Privacy Policy

Effective and last updated: July 15, 2026

This Privacy Policy explains how Brevitas Systems (“Brevitas,” “we,” “us,” or “our”) handles personal information when you visit brevitassystems.com or use our software, APIs, dashboard, SDKs, hosted proxy, and related services (the “Services”).

Information we collect

Account and contact information. We collect identifiers and commercial information you provide, such as your email address, authentication information, company or project details, support messages, waitlist responses, purchases, and marketing preferences. Authentication providers process passwords; we do not receive passwords in readable form.

Service content. Depending on the feature and configuration you use, the Services may process and store prompts, messages, model inputs and outputs, cached responses, configuration data, repository labels, and other content you submit. Hosted proxy traffic is necessarily visible to our systems while in transit. Some SDK or direct modes may process content locally and send us only usage metadata.

Usage and technical information. We collect token counts, savings estimates, model and provider identifiers, feature usage, API request timing and status, device/browser type, approximate location derived from IP address, logs, and security information. Our routine usage records are designed to contain measurements and labels rather than raw prompts, responses, source code, file paths, Git remotes, or provider credentials. Web servers may temporarily process IP addresses for delivery, abuse prevention, and security.

Website analytics and session replay. We use PostHog to automatically measure page views, referral sources, approximate location, device and browser information, interactions, session duration, signup and product funnels, performance, and errors. PostHog may assign an anonymous identifier before you create an account. After you sign in, we may associate analytics with your account identifier and email so we can understand the customer journey and support the Service. Session replay is configured to mask all inputs and designated account, financial, API-key, provider-key, Playground, and other sensitive elements. We disable collection of network request and response contents and remove URL query strings and fragments before analytics data is sent.

Payment information. If you buy a paid Service, our payment processor collects payment-card and billing information. We generally receive transaction, subscription, and limited billing details rather than full card numbers.

How we use information

We use information to provide, secure, maintain, troubleshoot, analyze, and improve the Services; authenticate users; process transactions; measure usage and estimated savings; operate caching and compression features; communicate with you; respond to support and privacy requests; prevent fraud and abuse; comply with law; and enforce our agreements. We may create aggregated or de-identified information and use it for lawful business purposes, and we take reasonable measures not to reidentify it. We do not use customer content to train general-purpose AI models unless we first clearly disclose that practice and obtain any consent required by law.

How we disclose information

We may disclose information to service providers that host, secure, support, email, analyze, or process payments for the Services. Current categories include Supabase for authentication and databases; Vercel and Railway for hosting; IONOS and Mailgun for email; payment processors when billing is enabled; and AI model providers you select or direct us to use. Their handling is governed by their own terms and our agreements with them.

PostHog provides our product analytics and session replay and processes this information in the United States for our configured project. Access to identifiable analytics and recordings is restricted to authorized Brevitas operators.

We may also disclose information when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or complete a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets. We do not sell personal information for money. We do not knowingly share personal information for cross-context behavioral advertising.

Retention and security

We retain each category of personal information only as long as reasonably necessary and proportionate for the purposes described here, considering the account relationship, feature configuration, cache settings, sensitivity of the information, security needs, legal obligations, and limitation periods. Cached content may remain until expiration, deletion, account closure, or backup rotation. Security, billing, consent, and dispute records may be kept longer where necessary to protect the Services, prove transactions or consent, comply with law, or establish or defend legal claims. Deletion from backups may be delayed until ordinary backup rotation. You may request applicable retention details or deletion at the address below.

We use reasonable administrative, technical, and organizational safeguards. No system or transmission is completely secure, and we cannot guarantee absolute security. Do not submit information that you are not authorized to provide.

Your choices and U.S. privacy rights

You may request access to, correction of, or deletion of your personal information, or ask for a portable copy. You may opt out of marketing email using its unsubscribe link. Depending on where you live, you may also have rights to know the categories, sources, purposes, and recipients of personal information; limit certain uses of sensitive information; opt out of sale, sharing, or targeted advertising; and appeal a denied request. We will not discriminate against you for exercising a privacy right.

Analytics and masked replay start automatically unless a recognized Global Privacy Control or Do Not Track signal is active. You can use the “Privacy choices” control on any page to turn analytics off or back on. Turning analytics off stops future capture and clears the analytics identifier stored in that browser. Your choice applies across the public site and dashboard and is not changed when you sign up or sign in.

To submit a request, email james@brevitassystems.com. We may verify your identity and authority before acting. Authorized agents may submit requests where permitted by law. Because we do not currently sell or share personal information for cross-context behavioral advertising, we do not offer a “Do Not Sell or Share” link. We will update this policy and provide required controls if that changes.

Sensitive information, children, and international use

The Services are not designed to process protected health information, government identifiers, financial-account credentials, precise geolocation, biometric data, information about children, or similarly sensitive or regulated information. Do not submit such information unless Brevitas has expressly agreed in writing that the applicable Service and safeguards are suitable. We do not intend to infer sensitive characteristics from personal information.

The Services are for adults age 18 or older. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us so we can delete it. The Services are operated in the United States, and information may be processed there and in other countries where our providers operate. Third-party websites, models, and services have their own privacy practices, which we do not control.

Changes and contact

We may update this policy. We will post the revised version and update its date, and provide additional notice when required by law. Questions and privacy requests may be sent to james@brevitassystems.com. Brevitas Systems is based in California, United States.