Legal
Privacy Policy
Last updated 6 August 2026
The short version: we store what the product needs to work, we send your source material to an AI provider so it can be read, we do not sell anything to anyone, and analytics stays off until you switch it on.
Who is responsible
The data controller is the individual operating mozg, reachable at egorfdrv@gmail.com. Write there for any request in this policy — access, export, correction, deletion, or a complaint.
What we store, and why
- Account — email, name and avatar (from GitHub or Google if you sign in that way), your handle, plan and balance. Needed to have an account at all. Legal basis: performing our contract with you.
- Brain material — the pages, files, screenshots and text you add, plus the notes distilled from them and their search vectors. This is the product. Whatever you put in it, we hold.
- Agent calls— which tool was called, on which brain, the query text, how many results came back, and whether it failed. This is what meters usage, what fills your activity view, and what tells a brain's owner which questions it cannot answer. Legal basis: contract and our legitimate interest in running a service that can be debugged.
- Errors — when something fails, the message and stack trace, and the account it happened to. Kept so failures can be fixed rather than guessed at.
- Learning progress — which cards you have seen and when they are due, your study days, and the achievements you earned. Only if you use learn.
- Money — top-ups, purchases, payouts and the ledger behind your balance. Kept for as long as accounting law requires, which is longer than account deletion.
- Messages — anything you write to us in chat, and push subscriptions if you enable notifications.
We do not run advertising, we do not build profiles for sale, and we do not use your private brains' content to train anything.
Who it is sent to
These are the only third parties that see any of it:
- Anthropic (or an Anthropic-compatible provider we route through) — receives the source material being read, and exam questions and answers. This is how a brain is built. Providers are used under their API terms, which exclude training on API traffic.
- Our own embedding service — self-hosted, on our infrastructure. Your text does not leave it.
- GitHub / Google — only if you use them to sign in, and only to confirm who you are.
- Resend — sends the emails we have to send (verification, a receipt, an alert).
- NOWPayments — processes crypto top-ups. They see the payment, not your brains.
- S3-compatible object storage — holds the files and images you upload.
- PostHog — product analytics, and only if you accepted analytics cookies. See the Cookie Policy.
Public brains are public
Publishing a brain puts its title, goal, note titles, exam results and your handle on a page anyone can read and search engines can index. Uploads are scanned for secrets and what we find is redacted, but treat that as a safety net rather than a guarantee: do not put anything in a public brain you would not put on a public page.
How long
Account and brain data live until you delete them. Call and error records are kept while they are useful for debugging and metering, and pruned after that. Financial records are kept as long as the law requires. Ask us to delete your account and everything not legally pinned goes within 30 days.
Your rights
If you are in the EU/EEA or the UK you have the right to access, correct, export, delete and restrict your data, to object to processing based on legitimate interest, and to complain to your data protection authority. Everywhere else, we apply the same rights anyway — it is simpler than two behaviours, and fairer. Email egorfdrv@gmail.com; we answer within 30 days.
Security, honestly
Traffic is encrypted, secrets are encrypted at rest, tokens are hashed, and uploads are scanned before they become notes. mozg is a small operation in beta: keep your own copy of anything you cannot afford to lose.
Children
The service is not for people under 16. We do not knowingly hold their data.
Changes
Material changes get an entry on the changelog before they take effect, and the date at the top of this page moves.
See also the Terms of Service and the Cookie Policy.