Privacy Policy & Data Sovereignty Charter
Governing personal data handling, cryptographic delivery tokens, and transaction logging across brainos.site.
[ 01 ] Corporate Entity & Jurisdiction of Processing
This Privacy Policy constitutes an official statutory charter executed by Brain OS (“the Enterprise”, “We”, “Our”) governing the processing, transmission, and protection of personal data collected via the domain brainos.site. This instrument complies strictly with the Digital Personal Data Protection Act, 2023 (India), the General Data Protection Regulation (Regulation (EU) 2016/679 - GDPR), and international cryptographic fair information practices.
[ 02 ] Strict Data Minimization & Tokenized Payment Processing
We adhere strictly to the principle of absolute Data Minimization. We collect strictly the minimum transactional data required to execute contract fulfillment: the Licensee's Full Legal Name and authenticated Delivery Email Address. All payment rails operate under PCI-DSS Level 1 certified cryptographic infrastructure managed exclusively by Razorpay Software Private Limited.
At no point does Brain OS collect, view, process, or store raw credit/debit card numbers, CVVs, expiration dates, UPI personal identification numbers (PINs), or bank account login credentials. All fiscal handshakes are tokenized using 256-bit AES encryption with HMAC-SHA256 signature verification.
[ 03 ] 100% Offline Hardware Sovereignty & Zero Note Telemetry
The foundational architecture of Brain OS is built upon Privacy-by-Design. The product deliverable consists entirely of client-side Markdown (.md) documents and JSON canvas files stored in an unencrypted .ZIP archive. The files execute locally within the Licensee's native operating environment (e.g. Obsidian).
[ 04 ] Third-Party Artificial Intelligence Provider Isolation
When the Licensee ingests the Master AI Connection Engine into large language models (including Anthropic Claude, OpenAI ChatGPT, Google Gemini, or Ollama offline runtimes), all communication occurs directly between the Licensee's client device and the respective AI infrastructure provider. Brain OS operates zero intermediary data relay proxies and intercepts zero conversational prompts or proprietary trade secrets.
[ 05 ] Statutory Anti-Brokerage & Data Erasure Protocols
The Enterprise unconditionally covenants that customer transaction records shall never be sold, leased, rented, barter-exchanged, or disseminated to third-party data brokers, marketing consortia, or programmatic ad exchanges. Licensees maintain the statutory right under Indian DPDPA 2023 and EU GDPR to request permanent purging of historical fulfillment logs by submitting an authenticated request to support@brainos.site with the subject “Data Erasure Request”.
[ 06 ] Cryptographic Download Token Verification & Security Logs
Our web servers maintain basic operational security access logs (recording client IP address, user-agent string, and timestamp of download token access) exclusively for cryptographic download token verification and prevention of distributed denial-of-service (DDoS) abuse. These logs are permanently purged on rolling 30-day schedules and are never correlated with vault reading habits.