Privacy Policy

Last updated: April 2026

Brighter ("we", "our", "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our product and website at https://brighter.rocks.
1. Who We Are
Brighter is an AI-powered learning and mentoring product focused on Power BI and data analytics.
Data Controller:
Daria Guseva Brighter Analytics, VAT NIP 7011303570
Czerniakowska street, 174, Warsaw 00-440, Poland
Website: https://brighter.rocks
Email: info@brighter.rocks
If you have any questions about this policy or your data, please contact us at the address above.
2. Data We Collect
2.1 Information You Provide
• Email address (required for account access)
• Name or nickname (if provided)
• User-generated content, including: text inputs, questions, and chat history
• Uploaded files (.csv, .xlsx, .pbix, screenshots)
• Skill progress, test results, and practice outcomes
2.2 Technical Data
• IP address
• Browser type and device information
• Operating system
• Cookies and similar technologies
• A device identifier for the free guest chat, used only to apply the free-question limit and prevent abuse - never for advertising or profiling
2.3 Payment Information
Payments are processed by Stripe, Inc. We do not store your credit card details. We only receive:
• Payment status
• Transaction identifiers
• Subscription state
3. How We Use Your Data
We use your data to:
• Provide and operate the Brighter service
• Personalize learning recommendations and skill tracking
• Analyze usage to improve product quality and performance
• Maintain security and prevent fraud or abuse
• Process subscriptions and payments
• Communicate important service-related messages
We do not sell your personal data to third parties.
4. AI Usage & Model Training
Brighter uses AI features powered by third-party AI service providers (including Anthropic). Your data may be transmitted to these providers solely for the purpose of generating responses within the Service.
We do not use your personal data or uploaded files to train our own AI models or any public AI models. We may use anonymized and aggregated usage data (with all personal identifiers removed) to improve Brighter's product features and performance. This means:
• Personal identifiers are removed before any analysis
• Data cannot be linked back to you as an individual
• Raw files and identifiable content are never used directly for AI training
5. Data Sharing & Processors
We may share data with trusted third-party service providers acting as data processors under confidentiality and data protection agreements, including:
• Hosting and infrastructure: Railway (EU), MinIO object storage
• Product analytics: PostHog (loaded only after you accept analytics cookies)
• Advertising measurement: Meta Platforms, Reddit, Google Tag Manager (loaded only after you accept)
• Website hosting: Vercel, and Tilda for the legacy landing page
• Email delivery: Resend
• Backups: Backblaze B2
• Payment processor: Stripe, Inc. (https://stripe.com/privacy)
• AI service provider: Anthropic, PBC (https://www.anthropic.com/privacy)
We do not share your personal data with third parties for their own marketing purposes.
6. Cookies
We use cookies to:
• Ensure essential site functionality
• Analyze usage and improve performance
In accordance with the EU ePrivacy Directive and GDPR, we display a cookie consent banner when you first visit our website. You may accept or decline non-essential cookies when you first visit, and change that choice at any time from our Cookie Policy page. Until you accept, no analytics or advertising cookies are set.
For more information about the cookies we use, please see our Cookie Policy.
7. Data Retention
We retain personal data only as long as necessary to:
• Provide the Service
• Fulfill legal and operational obligations
• Maintain your learning history and progress
Account data is retained for the duration of your active subscription and for up to 90 days after account deletion, after which it is permanently deleted or anonymized. Financial records may be retained longer where required by applicable law (e.g., Polish accounting regulations require retention for 5 years).
You may request deletion of your data at any time by contacting us at info@brighter.rocks.
8. Your Rights (GDPR)
If you are located in the EU, EEA, or UK, you have the following rights under applicable data protection law:
• Right of access — request a copy of the personal data we hold about you
• Right to rectification — request correction of inaccurate or incomplete data
• Right to erasure — request deletion of your personal data ("right to be forgotten")
• Right to restriction of processing — request that we limit how we process your data
• Right to data portability — receive your data in a structured, machine-readable format
• Right to object — object to processing based on legitimate interests
• Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing
To exercise any of these rights, contact us at info@brighter.rocks. We will respond within 30 days.
You also have the right to lodge a complaint with your local data protection supervisory authority:
• Poland: Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warsaw — www.uodo.gov.pl
• UK: Information Commissioner's Office (ICO) — www.ico.org.uk
• Other EU countries: your national data protection authority
9. Data Security
We use technical and organizational measures to protect your data, including:
• Encrypted connections (HTTPS)
• Access controls and authentication
• Secure cloud infrastructure
No system is 100% secure, but we take reasonable and appropriate steps to protect your information against unauthorized access, alteration, disclosure, or destruction. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay.
10. International Transfers
Your data may be processed outside your country of residence, including in the United States, where some of our third-party service providers (such as Anthropic and Stripe) are located.
Where we transfer personal data outside the European Economic Area, we ensure that appropriate safeguards are in place in accordance with GDPR, including the use of Standard Contractual Clauses (SCCs) approved by the European Commission, or reliance on adequacy decisions where applicable.
11. Children's Privacy
The Service is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected data from a child, please contact us at info@brighter.rocks and we will delete such data promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by displaying a prominent notice on our website at least 14 days before the changes take effect. The latest version will always be available at /privacy.
13. Contact Us
For any privacy-related questions, data requests, or complaints:
Daria Guseva Brighter Analytics, VAT NIP 7011303570
Czerniakowska street, 174, Warsaw 00-440, Poland
Email: info@brighter.rocks
Website: https://brighter.rocks