Data Processing Agreement
Last updated: July 28, 2026
1. Introduction
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you and CorpusBrain (“we”, “us”, or “our”) and describes how we process personal data on your behalf when you use the CorpusBrain service. Capitalized terms not defined here have the meanings given in the Terms of Service or applicable data protection law.
2. Roles
- Controller: You, the account owner, decide what personal data (if any) to upload to your private knowledge base and the purposes for which it is used.
- Processor: CorpusBrain processes personal data only to provide, secure, and improve the service, and only in accordance with your documented instructions.
3. What we process
We may process the following categories of personal data:
- Account data: email address, name, and avatar.
- Content data: documents, files, chat messages, and any other content you choose to upload.
- Usage data: product analytics events collected via PostHog to operate and improve the service.
- Billing data: subscription status and payment information handled by Stripe.
4. Purpose and restrictions
We process personal data solely to:
- Provide the CorpusBrain service.
- Maintain security, availability, and performance.
- Comply with legal obligations and enforce our agreements.
We do not use your content to train third-party or proprietary AI models, sell personal data, or process it for any purpose beyond what is necessary to deliver the service.
5. Subprocessors
We use carefully selected subprocessors to host and operate the service. As of the date above, the primary subprocessors are:
- Supabase — cloud database and object storage.
- Cloudflare — edge hosting, caching, and R2 object storage.
- OpenAI — LLM and embedding generation (we do not authorize OpenAI to train on your data).
- Stripe — payment processing and subscription management.
- PostHog — product analytics and event tracking.
- Clerk — authentication and user identity management.
6. Security
We implement appropriate technical and organizational measures to protect personal data, including encryption in transit (TLS 1.3), encryption at rest (AES-256), row-level database isolation, access controls, and regular security reviews.
7. International transfers
Your data may be processed in jurisdictions other than your own. We rely on standard contractual clauses, adequacy decisions, and other lawful transfer mechanisms approved under applicable data protection law.
8. Data subject rights
We assist you in responding to requests from data subjects to access, correct, delete, or restrict processing of their personal data. Account owners can export or delete their data at any time from the Settings page.
9. Term and termination
This DPA remains in effect for as long as you use the service. Upon account deletion, we remove your content from live systems promptly, subject to any legal retention obligations.
10. Contact
Questions about this DPA? Reach out at privacy@corpusbrain.com.