1. Scope and roles
This Privacy Policy applies to CRE Brain, the shared-firm-memory service operated by Pacific Software Ventures (“PSV,” “we,” “us,” or “our”), including its website, dashboard, remote connector, and related support.
CRE Brain is a business service provided to invited organizations. The organization that gives you access generally decides what business content belongs in its CRE Brain workspace and who receives a seat. For that workspace content, PSV acts on the organization’s instructions. If an order form, data-processing agreement, or other written agreement conflicts with this policy, that agreement controls for the affected organization.
2. Information we process
Account and membership information
We process your name, verified email address, authentication identifiers, organization membership, and invitation status so we can authenticate you and place you in the right private workspace. Our authentication provider, Clerk, handles sign-in and session information.
Firm knowledge and evidence
CRE Brain stores the durable findings users choose to capture, such as deal facts, decisions, lender quotes, pass reasons, market observations, confidence labels, tags, dates, authorship, and relationships between records. Evidence review can also store a short supporting excerpt, along with a note of which document it came from, which version of that document, and where in it the excerpt sits. When a document is submitted for ingestion, CRE Brain also retains a bounded portion of its extracted text (up to the first 50,000 characters) so reviewers can see a claim in its source context. The document file itself is not copied into the CRE Brain database.
Usage and diagnostic information
We process limited operational information needed to run and protect the service, such as which connector tool was called, the client that called it, whether the call succeeded, result counts, duration, and explicit feedback a user asks us to record. We do not use private workspace content for advertising.
If a CRE Brain search finds nothing, a sanitized version of the missed search query may be retained for coverage analysis. This helps an organization see which subjects its shared record does not yet answer; it is not used for advertising or general model training.
Information from your device and browser
Like most online services, our infrastructure receives technical request information such as IP address, browser or client type, timestamps, and security logs. Essential cookies and similar storage are used for authentication and session continuity. CRE Brain does not use advertising cookies.
3. How we use information
We use information to:
- authenticate invited users and enforce organization and record visibility;
- store, search, retrieve, cite, correct, review, export, and delete firm knowledge;
- return relevant private context when an authorized user invokes CRE Brain in an AI assistant;
- operate governed evidence, feedback, and shared-skill improvement workflows;
- secure, troubleshoot, maintain, and improve the reliability of the service; and
- comply with law and enforce our agreements.
No sale and no model training. We do not sell personal information or firm knowledge, and we do not use a customer’s CRE Brain records to train a general-purpose AI model. The AI model used during document ingestion runs as inference only (see Section 4).
5. Access and visibility
CRE Brain is invitation-only. Signing in does not create a seat. Every request has to match an existing person and organization, and every query is limited to that organization’s own records. Nothing outside the application itself can read a workspace’s stored knowledge.
A team-visible record can be accessed by the organization’s invited users. A record that its author explicitly marks private is available to that author alone, and is left out of shared dashboards and out of anything a teammate retrieves. Promoting a private record to firm policy deliberately makes it team-visible. Users should store only information they are authorized to share at the visibility they select.
6. Retention and controls
Unless an organization’s written agreement, a legal hold, or applicable law requires a different period, our standard retention schedule is:
- Workspace knowledge and evidence
- Retained while the organization’s workspace is active. After a verified workspace deletion request, active records are deleted within 30 days. Residual encrypted backup copies age out on the infrastructure provider’s backup cycle and are not restored to active service except for disaster recovery.
- Tool-call audit metadata and missed-search coverage data
- Retained for 90 days, then deleted or aggregated without the user or query text needed to identify the event.
- Evidence, feedback, evaluation, and review ledgers
- Retained with the workspace because they prove who proposed, reviewed, approved, or rejected a change. They follow the same 30-day deletion window after workspace termination unless a customer agreement or legal obligation requires longer.
- Account and membership data
- Retained while access is active and for up to 90 days after access ends for security, support, and dispute resolution. Shared records may keep the former member’s display name as authorship provenance until the workspace itself is deleted.
- Invitations and credentials
- Invitation links expire after seven days. Revoked or expired credential hashes are retained for up to 30 additional days to prevent replay and investigate abuse; Team Brain stores OAuth access and refresh credentials only as irreversible hashes.
We may retain the minimum information required to establish, exercise, or defend legal claims, comply with law, investigate abuse, or enforce an agreement for the period that purpose requires. The organization’s written agreement may set shorter or longer periods.
- Export: an authenticated user can download all records visible to that user from the Account area, including authorship, dates, tags, and record relationships.
- Correct: a new record can supersede an outdated record while preserving an audit trail.
- Delete a memory: an author can explicitly ask the connector to forget a specific record they wrote. This removes it from live recall and is irreversible for the shared team record.
- End access: removing or unbinding a seat ends that user’s browser and connector access. Records written for the shared organization remain part of its institutional history unless the organization directs otherwise.
An organization administrator can contact us to request workspace-level access, correction, export, or deletion assistance.
7. Security
We use administrative, technical, and organizational safeguards designed for private business information. These include encrypted network transport, invitation-only access, queries limited to one organization, author-level checks on private records, private results that are never cached, verification of the inputs that write to memory, and hashed invitation and sign-in credentials. Sign-in credentials are stored only as irreversible hashes, never in readable form.
No service can guarantee absolute security. If you believe a credential or workspace may have been exposed, do not send the credential to us. Contact support promptly so it can be revoked and investigated.
8. Choices and rights
Depending on your location, you may have rights concerning personal information, such as rights to access, correct, delete, or receive a copy of it. Because CRE Brain is provided through your organization, your organization may need to handle or authorize requests about workspace content. We will assist it as required by applicable law and contract.
To make a privacy request, email paul@pacificsoftwareventures.com. We may need to verify your identity and relationship to the organization before acting. CRE Brain is a business service and is not directed to children.
9. Changes and contact
We may update this policy as CRE Brain or applicable requirements change. The effective date above identifies the current version. If a change materially affects how existing workspace information is handled, we will provide notice through the service or the organization’s designated contact when appropriate.
Questions about privacy or data handling can go directly to Pacific Software Ventures.
Email privacy support