Privacy Policy
Last updated: June 19, 2026
This Privacy Policy explains what information SourceBrain ("we", "us") collects, how we use it, and the choices you have. It applies to the SourceBrain web app, API, and command-line tool.
Information we collect
- Account information. Your email address, and, for password-based accounts, a securely hashed password (we never store your password in plain text).
- Single sign-on (optional). If you sign in with GitHub or Google, we receive your verified email address and basic profile from that provider in order to create or identify your account. We do not post on your behalf, and we do not access your repositories, files, or contacts.
- Content you create. The lessons you write (their paths, Markdown content, version history, and any notes) along with the workspaces, memberships, and invitations you set up.
- Billing information. Payments are processed by Stripe. We store your plan and Stripe customer/subscription identifiers; we do not receive or store full payment card numbers.
- Technical information. An authentication token stored in your browser to keep you signed in, short-lived cookies used only during the sign-in process, and standard server logs (such as IP address and request metadata).
How we use your information
- To provide, maintain, and secure the service and your account.
- To authenticate you and synchronize your knowledge base across the CLI and web.
- To process payments and manage subscriptions.
- To respond to support requests and important service notices.
We do not sell your personal information or your content.
Third-party services
We share data with these providers only as needed to run the service:
- Stripe: payment processing and subscription management.
- GitHub and Google: only if you choose to sign in with them, and only to verify your identity.
- Embeddings provider (optional). If semantic search is enabled for a workspace, the text of that workspace's lessons is sent to a third-party embeddings API (such as OpenAI or Voyage AI) to generate the vectors that power search. If semantic search is not enabled, lesson content is not sent to any such provider.
- Hosting infrastructure: to operate our servers and database.
Data retention
We keep your content for as long as your account and workspaces exist. You can delete a lesson, delete a workspace (which permanently removes its lessons and history), or contact us to delete your account. You can export your content at any time with sourcebrain context.
Security
Passwords are hashed with bcrypt, traffic is served over HTTPS, and access to a workspace is limited to its members. No system is perfectly secure, but we work to protect your data.
Your choices
- Access or export your content via the app or CLI.
- Delete lessons, workspaces, or your account.
- Disconnect SSO by using password sign-in instead.
Children
SourceBrain is not directed to children under 13, and we do not knowingly collect their data.
Changes
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above.
Contact
Questions about this policy? Email support@sourcebrain.io.