Privacy
CyberFox Brain is in early access. This is a plain-language, accurate statement of what we store today and how to reach us about it.
Who operates this
CyberFox Brain is operated by Maxwell Henderson. Questions about your data can be sent to hello@cyberfoxai.com.
What we store
- Account data: your name, email address, sign-in method, and any optional role, workflow, or “how did you hear about us?” answer you choose to provide.
- Note data: the content of the notes in your brains, and who belongs to each brain and their role.
- Version data: every past revision of a note, kept so it can be restored.
- Activity data: an append-only log of who made each write to a note or brain, and when.
- Token data: the OAuth grants and connector sessions that let your AI host authenticate to your brain.
- Telemetry: standard request and error logs kept by our hosting providers to run and secure the service. If you opt in, PostHog receives a pseudonymous account ID and a small allowlist of product events. It never receives your email, name, brain ID, note content, note title/path, prompts, tool input/output, or model output from this integration.
Where it lives
Supabase hosts the database: notes, versions, membership, and the activity log. Cloudflare runs the connector your AI client talks to, and holds OAuth grants in Workers KV. Vercel hosts the web app you sign into to manage brains, access, and exports. If you opt in to product analytics, PostHog processes the limited event data described above. These providers are subprocessors for the data they receive.
What members and the operator can access
Within a brain, your role controls what you can see and change: an owner or editor can read and write notes, a viewer can only read. Outside of your brains’ membership, the operator can access data stored in Supabase, Cloudflare, and Vercel as needed to run, secure, and troubleshoot the service, and to respond to a support request.
What a connected AI host receives
When you connect Claude, ChatGPT, or another MCP-capable host to CyberFox Brain, that host can read and write the notes your account has access to, through the tools it chooses to call. The host provider handles that content under its own terms once it reaches them, the same as any other tool result it processes.
Recovering a mistake, and disaster recovery
These are two different things. Ordinary mistakes, like an AI overwriting a note you wanted to keep, are recovered through saved note revisions: every past version of a note is kept and can be restored on request. Separately, the database is backed up automatically every day, with backups retained for 7 days. There is no point-in-time recovery: a disaster restore can only go back to one of those daily backups, not to an arbitrary moment. You can also export any brain as a zip at any time, and you should keep your own copies.
What the activity log covers
The append-only activity log records writes: who created, edited, or deleted a note or changed a membership, and when. It does not record reads. A credential that only has read access leaves no entry in this log.
Access control, not encryption
Brain roles (owner, editor, viewer) control who can read or write within a brain. This is access control, not end-to-end encryption: CyberFox Brain and its hosting providers can technically access note content to operate the service.
Analytics and product updates are optional
Analytics and product-update emails are separate choices. Both are off by default, can be changed in Settings, and analytics stops immediately when you turn it off. Choosing not to participate does not limit use of CyberFox Brain.
Deleting notes, brains, and your account
These are three different operations, retained differently.
- Deleting a note is a soft delete: the note is hidden but recoverable through undelete, and its revisions are kept.
- Deleting a brain is permanent: its notes, versions, and membership are removed and cannot be recovered. We ask you to type the brain’s name to confirm before this happens.
- Deleting your account is handled on request. Email hello@cyberfoxai.com and we will remove your account data, growth-profile choices, and OAuth grants according to the account-deletion process.
Support
For any question about your data, including a deletion request, email hello@cyberfoxai.com.