Sub-processors
Last updated: August 17, 2026 Status: Reviewed by counsel (sections 1–6 in April 2026; section 2a hosted-deployment sub-processors, the Google and Apify rows, and the Resend row update reviewed June 2026). The August 17, 2026 correction to the database row in section 2a is pending counsel review.
A sub-processor is a third party that processes your personal information on our behalf (or that you direct Brin to send data to through configuration). Brin is designed to minimize sub-processors — most of the application runs entirely on your own device. This page lists every third party that may receive any of your data when you use Brin as intended.
If we add a new sub-processor, we will update this page, update the "Last updated" date, and bump the LEGAL_POLICY_VERSION constant so you are notified on your next session.
1. Sub-processors required for core AI features
These sub-processors are used only when you configure their API keys in Brin. Without the API key, the corresponding feature is disabled and no data is sent.
| Provider | Purpose | Categories of data processed | Location | Privacy / DPA link |
|---|---|---|---|---|
| Anthropic, PBC | Powers John (Chief of Staff chat, planning, coaching), knowledge base extraction, and other text generation features | Prompts you submit (which may include excerpts from your conversation history, goals, projects, and recent context), your Anthropic API key | United States | Privacy Policy · Usage Policies · Commercial Terms |
| OpenAI, L.L.C. | Powers voice mode (real-time speech-to-text and text-to-speech) | Audio you record, the resulting text transcript, your OpenAI API key | United States | Privacy Policy · Enterprise Privacy · Usage Policies |
2. Optional sub-processors (only if you configure them)
These are only involved if you explicitly enable and configure them.
| Provider | Purpose | Categories of data processed | Location | Privacy link |
|---|---|---|---|---|
| n8n GmbH (or a self-hosted n8n instance you control) | Workflow automation webhooks if you enable n8n integration | Only the specific webhook payloads Brin sends — you control what each workflow receives | Germany (n8n Cloud) or self-hosted location of your choice | Privacy Policy |
| Slack Technologies, LLC | Slack notifications if you configure a Slack webhook URL | Only the specific message payloads you configure Brin to send | United States | Privacy Policy |
If you do not configure these integrations, no data is sent to them.
2a. Sub-processors used by the hosted (SaaS) deployment
When you use Brin via our hosted product (app.brincc.com), the following additional sub-processors are involved. If you self-host Brin in appliance mode, this section does not apply.
| Provider | Purpose | Categories of data processed | Location | Privacy / Terms |
|---|---|---|---|---|
| Anthropic, PBC | Powers John + every specialist worker's chat. The platform provides the API key in the hosted deployment, so you do not configure your own. | Same as Section 1: prompts and conversational context | United States | Privacy Policy |
| ElevenLabs Inc. | Conversational AI voice agents for John and every specialist (text-to-speech + speech-to-text inside the live voice session). | Audio you record during voice mode, transcript text, session metadata | United States | Privacy Policy · Terms |
| OpenAI, L.L.C. | Speech-to-text (Whisper) for one-off voice transcription paths outside the ElevenLabs session. | Audio you record, the resulting text | United States | Privacy Policy |
| Railway Corporation | Application hosting for the Brin Flask backend. | Data in transit through the application while serving your requests. | United States | Privacy Policy |
| Supabase Inc. | Managed PostgreSQL database for the hosted product. This is where your workspace data is stored. | All data you create in Brin (workspace content, account details, leads, email history, audit logs). | United States | Privacy Policy |
| Vercel Inc. | Frontend hosting (Next.js) for app.brincc.com. |
HTTP request metadata (IP, user agent). No user content stored. | United States | Privacy Policy |
| Resend, Inc. | Transactional email (welcome, password reset, system notifications) and Lead Center outreach plus inbound reply routing. | Recipient/sender email address, message subject and body, including your leads' replies to your outreach | United States | Privacy Policy |
| Stripe, Inc. | Subscription billing and payment processing (only if you are on a paid plan). | Stripe customer id, plan tier, payment method (held by Stripe; we never see card numbers) | United States | Privacy Policy |
| Google LLC | Sending email from your connected Gmail account (Lead Center). Brin holds a send-only OAuth credential; it cannot read your mailbox. | The emails you review and send through Brin (recipient, subject, body); OAuth tokens | United States | Privacy Policy · API Services User Data Policy |
| Apify Technologies s.r.o. | The Discover lead finder (Lead Center): sourcing publicly listed business information when you run a prospect search. | Your search terms (service category, area, optional keyword). Results are public business listings. Your stored lead data is never sent. | Czech Republic / United States | Privacy Policy |
If you are using Brin via the hosted product and want to limit which of these processors touch your data, contact privacy@brinsolutions.com.
3. Sub-processors that do not receive user content
For completeness, these providers are involved in building and distributing Brin but do not receive any of your personal data, tasks, notes, or knowledge base content:
| Provider | Purpose |
|---|---|
| GitHub, Inc. | Source code hosting for Brin. No customer data is stored in GitHub. |
| Fonts: Google Fonts | Serves the Inter typeface on marketing and legal pages. When you visit an Brin web page that loads Google Fonts, Google receives your IP address for the font download. No Brin data is sent. |
4. How to reduce your sub-processor footprint
If you want to minimize the number of third parties that touch your data:
- Remove the OpenAI API key in Settings → Integrations. Voice mode will be disabled, but everything else keeps working.
- Remove the Anthropic API key in Settings → Integrations. John and all AI features will be disabled. Brin will still function as a local kanban, knowledge base, and task manager.
- Don't configure n8n or Slack. If you don't enter a webhook URL, nothing is sent to them.
5. Notification of changes
We commit to:
- Updating this page whenever we add, remove, or replace a sub-processor
- Updating the "Last updated" date at the top
- Bumping the
LEGAL_POLICY_VERSIONconstant inside Brin so you are re-prompted to acknowledge the change
For material changes, we will also notify the waitlist and any contact addresses we have on file.
6. Contact
Questions about sub-processors:
- Email: privacy@brinsolutions.com
- Philippines DPO: dpo@brinsolutions.com
