Skip to document

Privacy

Your firm’s memory stays your firm’s memory.

This policy explains what CRE Brain receives, where it goes, how access works, and the controls available to people and organizations using the service.

Effective and last updated August 18, 2026

1. Scope and roles

This Privacy Policy applies to CRE Brain, the shared-firm-memory service operated by Pacific Software Ventures (“PSV,” “we,” “us,” or “our”), including its website, dashboard, remote connector, and related support.

CRE Brain is a business service provided to invited organizations. The organization that gives you access generally decides what business content belongs in its CRE Brain workspace and who receives a seat. For that workspace content, PSV acts on the organization’s instructions. If an order form, data-processing agreement, or other written agreement conflicts with this policy, that agreement controls for the affected organization.

2. Information we process

Account and membership information

We process your name, verified email address, authentication identifiers, organization membership, and invitation status so we can authenticate you and place you in the right private workspace. Our authentication provider, Clerk, handles sign-in and session information.

Firm knowledge and evidence

CRE Brain stores the durable findings users choose to capture, such as deal facts, decisions, lender quotes, pass reasons, market observations, confidence labels, tags, dates, authorship, and relationships between records. Evidence review can also store a short supporting excerpt, along with a note of which document it came from, which version of that document, and where in it the excerpt sits. When a document is submitted for ingestion, CRE Brain also retains a bounded portion of its extracted text (up to the first 50,000 characters) so reviewers can see a claim in its source context. The document file itself is not copied into the CRE Brain database.

Usage and diagnostic information

We process limited operational information needed to run and protect the service, such as which connector tool was called, the client that called it, whether the call succeeded, result counts, duration, and explicit feedback a user asks us to record. We do not use private workspace content for advertising.

If a CRE Brain search finds nothing, a sanitized version of the missed search query may be retained for coverage analysis. This helps an organization see which subjects its shared record does not yet answer; it is not used for advertising or general model training.

Information from your device and browser

Like most online services, our infrastructure receives technical request information such as IP address, browser or client type, timestamps, and security logs. Essential cookies and similar storage are used for authentication and session continuity. CRE Brain does not use advertising cookies.

3. How we use information

We use information to:

  • authenticate invited users and enforce organization and record visibility;
  • store, search, retrieve, cite, correct, review, export, and delete firm knowledge;
  • return relevant private context when an authorized user invokes CRE Brain in an AI assistant;
  • operate governed evidence, feedback, and shared-skill improvement workflows;
  • secure, troubleshoot, maintain, and improve the reliability of the service; and
  • comply with law and enforce our agreements.

No sale and no model training. We do not sell personal information or firm knowledge, and we do not use a customer’s CRE Brain records to train a general-purpose AI model. The AI model used during document ingestion runs as inference only (see Section 4).

4. Service providers and AI hosts

We disclose information only as needed to provide the service, follow an organization’s instructions, protect the service, complete a business transaction subject to appropriate safeguards, or comply with law. Our core service providers include:

Supabase
Hosts the CRE Brain database on AWS in the United States. Stored note text is indexed for meaning-based search inside that same project, never sent elsewhere to be indexed.
Vercel
Hosts the CRE Brain website, dashboard, and connector.
Amazon Web Services (Bedrock)
Hosts the AI model that reads documents submitted for ingestion. It receives a document’s extracted text and bounded excerpts of related workspace records, and returns draft suggestions for human review. This is inference only: under AWS’s Bedrock terms, these inputs and outputs are not used to train models and are not shared with model providers.
Clerk
Provides authentication and processes sign-in identity and verified email data.
OpenFreeMap
Supplies public basemap tiles when a user opens the map. The tile host can observe the requested map area, IP address, browser information, and the CRE Brain origin, but we do not append firm record text or identity to tile requests.
Mapbox
If an organization enables address geocoding, receives an asset’s street address when an import contains no coordinate. It does not receive register figures, notes, tags, or user identity from that lookup.

ChatGPT, Claude, Codex, and other connected assistants

When an authorized user asks an AI host to use CRE Brain, the records needed to answer that request are returned into that user’s conversation. The AI host processes that conversation under its own terms, privacy policy, and organization-level controls. Team Brain does not control an AI host’s retention or training settings, so organizations should configure those services consistently with their own policies.

5. Access and visibility

CRE Brain is invitation-only. Signing in does not create a seat. Every request has to match an existing person and organization, and every query is limited to that organization’s own records. Nothing outside the application itself can read a workspace’s stored knowledge.

A team-visible record can be accessed by the organization’s invited users. A record that its author explicitly marks private is available to that author alone, and is left out of shared dashboards and out of anything a teammate retrieves. Promoting a private record to firm policy deliberately makes it team-visible. Users should store only information they are authorized to share at the visibility they select.

6. Retention and controls

Unless an organization’s written agreement, a legal hold, or applicable law requires a different period, our standard retention schedule is:

Workspace knowledge and evidence
Retained while the organization’s workspace is active. After a verified workspace deletion request, active records are deleted within 30 days. Residual encrypted backup copies age out on the infrastructure provider’s backup cycle and are not restored to active service except for disaster recovery.
Tool-call audit metadata and missed-search coverage data
Retained for 90 days, then deleted or aggregated without the user or query text needed to identify the event.
Evidence, feedback, evaluation, and review ledgers
Retained with the workspace because they prove who proposed, reviewed, approved, or rejected a change. They follow the same 30-day deletion window after workspace termination unless a customer agreement or legal obligation requires longer.
Account and membership data
Retained while access is active and for up to 90 days after access ends for security, support, and dispute resolution. Shared records may keep the former member’s display name as authorship provenance until the workspace itself is deleted.
Invitations and credentials
Invitation links expire after seven days. Revoked or expired credential hashes are retained for up to 30 additional days to prevent replay and investigate abuse; Team Brain stores OAuth access and refresh credentials only as irreversible hashes.

We may retain the minimum information required to establish, exercise, or defend legal claims, comply with law, investigate abuse, or enforce an agreement for the period that purpose requires. The organization’s written agreement may set shorter or longer periods.

  • Export: an authenticated user can download all records visible to that user from the Account area, including authorship, dates, tags, and record relationships.
  • Correct: a new record can supersede an outdated record while preserving an audit trail.
  • Delete a memory: an author can explicitly ask the connector to forget a specific record they wrote. This removes it from live recall and is irreversible for the shared team record.
  • End access: removing or unbinding a seat ends that user’s browser and connector access. Records written for the shared organization remain part of its institutional history unless the organization directs otherwise.

An organization administrator can contact us to request workspace-level access, correction, export, or deletion assistance.

7. Security

We use administrative, technical, and organizational safeguards designed for private business information. These include encrypted network transport, invitation-only access, queries limited to one organization, author-level checks on private records, private results that are never cached, verification of the inputs that write to memory, and hashed invitation and sign-in credentials. Sign-in credentials are stored only as irreversible hashes, never in readable form.

No service can guarantee absolute security. If you believe a credential or workspace may have been exposed, do not send the credential to us. Contact support promptly so it can be revoked and investigated.

8. Choices and rights

Depending on your location, you may have rights concerning personal information, such as rights to access, correct, delete, or receive a copy of it. Because CRE Brain is provided through your organization, your organization may need to handle or authorize requests about workspace content. We will assist it as required by applicable law and contract.

To make a privacy request, email paul@pacificsoftwareventures.com. We may need to verify your identity and relationship to the organization before acting. CRE Brain is a business service and is not directed to children.

9. Changes and contact

We may update this policy as CRE Brain or applicable requirements change. The effective date above identifies the current version. If a change materially affects how existing workspace information is handled, we will provide notice through the service or the organization’s designated contact when appropriate.

Questions about privacy or data handling can go directly to Pacific Software Ventures.

Email privacy support