Privacy Policy
Last updated: March 2026
Introduction
Cerebro ("we", "us", "our", or "Company") operates the meetcerebro.com website and mobile application (the "Service"). This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data.
We use your data to provide and improve the Service. By using Cerebro, you agree to the collection and use of information in accordance with this policy.
What Data Do We Collect?
- Account Information: Email address, name, password hash, and authentication tokens.
- Profile Data: Job title, company, bio, contact details (phone, LinkedIn URL, website, etc.), and profile photos.
- Contact Data: Information about the contacts you upload or add to Cerebro, including names, emails, companies, and notes you create.
- Conversation Data: Messages you send in Cerebro's AI chat and conversation history.
- Usage Data: Analytics on features you use, scan counts, contact imports, and engagement metrics (via anonymized events).
- OAuth Data: When you connect LinkedIn or Google, we store your access tokens for integrations (LinkedIn data export, Google Contacts import, OAuth sign-in).
Lawful Basis (GDPR)
Under GDPR, we process personal data based on the following lawful bases:
- Consent: Account registration, profile creation, and contact data storage.
- Legitimate Interest: Security, fraud prevention, and service improvement analytics.
- Performance of Contract: Delivery of the Service and subscription management.
AI Processors & Third Parties
Cerebro uses the following AI and external services:
- xAI Grok: Contact enrichment (work history, skills, recent news). Data sent for processing; not used for training.
- OpenRouter: AI chat completions. Contact context sent to power conversational search. Not used for training your data.
- Google Cloud Vision: OCR for business card scanning. Images sent for text extraction; not retained by Google.
- Stripe: Payment processing. Handles subscriptions; PCI compliant.
- Railway: Infrastructure hosting (US-based).
We do not: Sell your data, train on your contacts, or share data with marketing partners. We use only what's necessary to power your features.
Data Retention
- Active Account: All data is retained as long as your account is active.
- Deleted Account: Upon deletion, we soft-delete your account (set deleted_at timestamp). Personal data is anonymized (email → deleted+ID@cerebro.app, name → "Deleted User"). All contacts, conversations, and user-generated data are cascading-deleted. Anonymized records retained for 30 days before hard deletion.
- Backups: Encrypted backups retained for 7-30 days (varies by region); deleted backups are overwritten.
Your Rights (GDPR & CCPA)
You have the right to:
- Access: Request a copy of your data. Use Settings → Download Data or email privacy@meetcerebro.com.
- Rectification: Correct inaccurate data in your profile or contacts.
- Erasure (Right to be Forgotten): Delete your account and all data. Use Settings → Delete Account or email us.
- Portability: Export your contacts as CSV from Settings → Export Contacts.
- Object: Opt-out of marketing emails and non-essential analytics.
- Restrict Processing: Request limited data processing (contact support).
To exercise these rights, email privacy@meetcerebro.com with your request and proof of identity.
Cookies & Tracking
Session Cookies: We use secure, HTTP-only cookies for authentication and session management only. No tracking pixels, third-party analytics, or ad networks.
Local Storage: Contact cache and offline data stored locally on your device (not transmitted to servers).
Security
- HTTPS/TLS for all data in transit.
- Passwords hashed with bcrypt (not stored in plaintext).
- OAuth tokens encrypted at rest.
- Database backups encrypted and access-controlled.
- PII fields (emails, passwords) indexed for NULL but not logged.
- Regular security audits planned (SOC 2 Type II in Q2 2026).
Children (COPPA)
Cerebro is not intended for children under 13. If we discover we have collected personal data from a child under 13, we will delete it promptly. Contact privacy@meetcerebro.com if you believe a child's data has been collected.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last Updated" date. Your continued use of the Service following such notification constitutes your acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at:
Cerebro
Email: privacy@meetcerebro.com
Website: meetcerebro.com
Response time: 30 days (or as required by law)
Data Processing Agreement
If you are subject to GDPR as a data subject, you may request a Data Processing Agreement (DPA) addendum if you process personal data on behalf of Cerebro. Contact privacy@meetcerebro.com.
This Privacy Policy is GDPR-compliant and covers the lawful basis for data processing. We take your privacy seriously. Questions? We're here to help.