Version: v1.0
Effective Date: September 1, 2026
Last Updated: August 29, 2026
Language: EN
Information Brownexus processes
Brownexus may process account information, profile information, company/workspace information, security program information, assets, risks, controls, evidence, uploaded documentation references, billing metadata, usage events, technical logs, support communications, and Brownie AI interactions.
Purposes
Brownexus uses information to provide and secure the service, authenticate users, manage workspaces, process billing, send transactional emails, support customers, improve product reliability, detect abuse, and comply with legal obligations.
Service providers
Brownexus uses Supabase for authentication and database services, Stripe for payment processing, Vercel for hosting/deployment, Resend or configured email infrastructure for transactional email, and AI providers when Brownie features are used.
Payments and sensitive card data
Stripe collects and processes payment method details. Brownexus stores only safe billing references such as customer IDs, subscription IDs, payment method IDs, brand, last4, and expiration metadata when available. Brownexus does not store full card numbers or CVV.
Security and retention
Brownexus uses access controls, organization separation, HTTPS in production, and operational logging. Data is retained as needed to provide the service, meet billing/support obligations, maintain security logs, comply with law, and honor deletion requests where applicable.
Choices, deletion, and contact
Users may update account information, request deletion, cancel subscriptions, or contact support. Some records may be retained for security, billing, backup, dispute, legal, or audit reasons. Contact support@brownexus.com.
Children, international processing, and changes
Brownexus is not intended for children. Data may be processed in locations where Brownexus or its service providers operate. Policy changes will be reflected by version or date updates.