Create your brainattic workspace
Name your workspace, then choose how you want to sign in — your workspace is ready in under a minute.
Already have an account? Sign in
Terms of service
Version: 2026-07-26
brainattic is currently a free pilot. No fees or service-level commitments apply during the pilot. These Terms explain the business-use rules, ownership, support posture, and deletion lifecycle for the Service.
1. These Terms and who they bind
These Terms of Service ("Terms") govern access to and use of the brainattic service and the brainattic.ai website (together, the "Service"), provided by Finite Software Systems Ltd. (ФИНИТ Софтуер Системс ЕООД), Company No. 175276896, VAT BG175276896, 4 Gorotzvet Street, Sofia, Bulgaria ("FSS", "we", "us").
The Service is offered to organisations ("Customer", "you") and the individuals they authorise to use it ("Authorised Users"). By accepting these Terms during registration or a later re-acceptance flow, accessing the Service, or permitting your Authorised Users to use it, you agree to these Terms. The Service is for business use by persons aged 18 or over; it is not offered to consumers or children. If you accept on behalf of an organisation, you warrant that you have authority to bind it.
2. The Service
brainattic is a multi-tenant knowledge-base service that your team and the AI agents you connect can read from and write to over the Model Context Protocol (MCP). It is available through the web application and may be used through third-party AI clients. We may modify, improve, add, or remove features over time, subject to the notice commitments in these Terms.
3. Free pilot and future fees
The Service is currently offered as a free pilot. It is provided on an "as is" and "as available" basis, may contain limitations, and features may change or be withdrawn while in pilot. No fees apply during the pilot. We may introduce paid plans in future, but will communicate commercial terms before they apply. Continued use of a paid offering would require your agreement to the applicable order or subscription terms.
4. Accounts and access
You must provide accurate registration information and keep it current. Authorised Users authenticate individually, using a password or an identity-provider sign-in method that we make available, such as Google, Facebook, or Apple. You are responsible for safeguarding brainattic credentials and any provider account used to access the Service, for choosing appropriate workspace roles, and for activity by your Authorised Users and connected agents. You must promptly notify us of unauthorised access and ensure that your Authorised Users comply with these Terms.
5. Your content
As between the parties, you retain all rights in the content your organisation creates or uploads to the Service ("Customer Content"). You grant FSS a limited, non-exclusive, worldwide licence to host, store, process, transmit, index, and display Customer Content solely to provide, secure, maintain, back up, and support the Service. You are responsible for your Customer Content and for having the rights and lawful basis required for it, including for any personal data it contains (see §9).
FSS does not use Customer Content to train third-party AI models or for advertising. The AI client you choose acts under your relationship with its provider and may receive content that you instruct brainattic to return to that client.
6. Our intellectual property
FSS and its licensors own all rights in the Service — the platform, software, documentation, and the brainattic name, logo, and brand. Except for the limited right to use the Service under these Terms, no rights are granted to you. If you give us feedback or suggestions, you grant us a perpetual, royalty-free licence to use them without restriction.
7. Acceptable use
You and your Authorised Users must not:
- use the Service for anything unlawful, infringing, harmful, deceptive, or that violates the rights or privacy of others;
- attempt to breach or probe security, gain unauthorised access, reverse engineer except as permitted by mandatory law, or circumvent usage limits, tenant isolation, or an AI platform's safety controls or system instructions;
- upload malware, transmit harmful code or spam, or overload or disrupt the Service;
- use the Service to build a competing product, or resell it, without our written agreement; or
- violate the usage policies of an AI platform through which you use brainattic, including the applicable Anthropic, OpenAI, or Mistral AI policies.
We may suspend or limit access, with notice where practicable, to address a security risk, a violation of this section, a legal requirement, or a threat to the Service or others.
8. Third-party services and AI platforms
brainattic can be used through third-party AI clients such as Claude, ChatGPT, or Mistral; you may enable optional integrations such as Slack or SMS delivery through a mobile carrier; and we may offer sign-in through identity providers such as Google, Facebook, or Apple. Your use of those services is governed by their own terms and privacy policies. Identity providers act as separate controllers for their sign-in services and are not FSS Sub-processors under the DPA. We are not responsible for third-party services, and your relationship with their providers is your own.
9. Data protection
Our processing of personal data is described in the Privacy Policy. Where we process personal data contained in Customer Content on your behalf, we do so as your processor under the Data Processing Agreement ("DPA"), which forms part of these Terms. You are the controller of that data and are responsible for your lawful basis and the instructions you give us. FSS acts separately as controller for account, identity, authentication, security, support, marketing, and contract-acceptance records as described in the Privacy Policy.
10. Confidentiality
Each party may receive the other's non-public information ("Confidential Information"). Each party will protect the other's Confidential Information with reasonable care and use it only to perform under these Terms. This does not apply to information that is or becomes public without breach, was already known, is independently developed, or must be disclosed by law, with notice where permitted.
11. Support and availability
During the pilot we provide reasonable-efforts support through brainattic.ai/support and hello@brainattic.ai. We do not commit to any uptime, response-time, or service-level guarantee, and the Service may be unavailable during maintenance or for reasons beyond our control. The support page explains safe reporting and routes privacy enquiries to privacy@brainattic.ai.
12. Warranties and disclaimers
To the maximum extent permitted by law, the Service is provided "as is" and "as available", and FSS disclaims all implied warranties, including merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service will be uninterrupted, error-free, or secure, or that search results or AI-assisted outputs will be accurate or complete — you are responsible for reviewing results before relying on them. Nothing in this section limits warranties that cannot be excluded under mandatory Bulgarian or EU law.
13. Limitation of liability
To the maximum extent permitted by law:
- neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, data, or goodwill; and
- each party's total aggregate liability arising out of or relating to these Terms is limited to the greater of (a) the fees you paid in the 12 months before the event giving rise to the claim, or (b) €100 (so, during the free pilot, €100).
These limits do not apply to liability that cannot be limited under applicable law, including liability for fraud or fraudulent misrepresentation, wilful misconduct, death or personal injury caused by negligence, and each party's respective liabilities under data-protection law as allocated in the DPA.
14. Indemnification
You will defend and indemnify FSS against third-party claims, and resulting losses, arising from your Customer Content or from your breach of these Terms, the acceptable-use section, or applicable law.
15. Term, closure, and deletion
These Terms apply while you use the Service. During the free pilot, either party may terminate at any time. On termination, your right to access the Service ends.
If an authorised Customer administrator requests immediate workspace deletion, FSS removes the live Customer Content and tenant data through the verified deletion process and does not create a recovery archive. Separately, a workspace may enter the dormancy process after six months without meaningful web or MCP activity. FSS then gives a 60-day warning and export opportunity before removing the live workspace. Only in that dormancy path, FSS keeps an encrypted recovery archive for 30 days after live removal, then permanently deletes it.
After either closure path, a disabled residual tenant record and sanitized audit and legal-acceptance evidence may remain for no more than 90 days after closure, solely for security investigation, abuse prevention, service-integrity verification, and the establishment, exercise, or defence of legal claims. The closure finalizer then permanently deletes those records. A documented legal hold or applicable law may require longer retention. If billing is introduced, statutory billing and accounting records will be retained separately for the legally required period and will never be used to preserve Customer Content.
Sections that by their nature should survive — including §§5–6, 9–10, 12–14, and 18 — survive termination.
16. Changes to the Service and these Terms
We may modify the Service and these Terms. We will publish updated Terms with their version, publication date, and effective date. For a material change, we will normally publish the new version at least 14 days before it becomes effective, give notice through the Service or by email, and require acceptance where appropriate. An acceptance of a future-effective version also covers the version it expressly supersedes during the notice period. If you do not agree, you must stop using the Service before the new version takes effect.
17. Governing law and disputes
These Terms are governed by the laws of the Republic of Bulgaria, without regard to conflict-of-laws rules. The competent courts of Sofia, Bulgaria have exclusive jurisdiction, without prejudice to mandatory rights that applicable law gives you.
18. General
These Terms, together with the Privacy Policy and the DPA, are the entire agreement between the parties regarding the Service and supersede prior discussions. We may assign these Terms to an affiliate or successor; you may not assign them without our consent. No waiver is implied by delay. If a provision is unenforceable, the rest remains in effect. Neither party is liable for delays caused by events beyond its reasonable control. The parties are independent contractors. There are no third-party beneficiaries. Notices to us: hello@brainattic.ai; notices to you: the contact associated with your account.
19. Contact
Finite Software Systems Ltd. — 4 Gorotzvet Street, Sofia, Bulgaria · Support · hello@brainattic.ai
Privacy policy
Version: 2026-07-28
brainattic is a knowledge-base service that your team — and the AI agents you connect — read from and write to. We keep core Service data on FSS-controlled infrastructure in the European Union, do not send Customer Content to a third-party AI model, and collect only what we need to run, secure, and support the Service.
1. Who we are
The Service and the brainattic.ai website are operated by Finite Software Systems Ltd. (Bulgarian: ФИНИТ Софтуер Системс ЕООД) ("FSS", "we", "us"), the provider of the brainattic product.
- Registered office: 4 Gorotzvet Street, Sofia, Bulgaria
- Company No. (ЕИК): 175276896 · VAT: BG175276896
- Privacy contact: privacy@brainattic.ai
- Data Protection Officer: none appointed (not required at our scale); privacy enquiries are handled through the contact above.
- Supervisory authority: Commission for Personal Data Protection (CPDP), Sofia, Bulgaria — www.cpdp.bg
2. Scope
This notice covers (a) the brainattic.ai website and its public contact and registration surfaces and (b) the brainattic Service — the knowledge-base web application and the connector that exposes it to AI clients over the Model Context Protocol (MCP). brainattic is a business-to-business service for organisations and their authorised users aged 18 or over. It is not directed to consumers or children.
3. Controller and processor — who decides what
The split matters because it determines who is responsible for which data:
- Customer Content and customer-directed service records — documents, attachments, search queries, reminders, and in-product audit entries created through your organisation's use of brainattic, including personal data you choose to put in them. Here your organisation is the controller and FSS is a processor acting on documented instructions. This processing is governed by our Data Processing Agreement.
- Account, identity, authentication, access-control, contract-acceptance, website, support, marketing, and operational security data — described below. Here FSS is the controller because FSS determines why and how that data is used to operate, secure, administer, and support the Service.
4. What we process
Account and identity data (FSS as controller). Name, work email, organisation, a securely hashed password where you set one, provider account identifiers and identity claims returned by a sign-in provider (such as name, email, and email-verification status), workspace membership and role, and OAuth/session tokens used to authenticate and authorise you.
Customer Content (FSS as processor). Documents, attachments, vector embeddings derived from content, search queries, reminders, and in-product audit entries — plus personal data your organisation chooses to include.
Reminder-delivery data (FSS as processor). The content and destination needed for a channel your organisation enables: an email address, a Slack member ID, or a mobile phone number.
Contract and registration evidence (FSS as controller). Company/workspace name, the policy bundle, document versions and content hashes presented to you, locale, acceptance time and source, and limited request metadata such as IP address, user agent, and request/correlation identifier. We use this evidence to establish and administer the customer relationship and demonstrate what was accepted.
Technical and security data (FSS as controller). IP address, timestamps, endpoint/request and status, correlation identifier, and basic device/browser metadata in operational and security logs. We use it to keep the Service reliable, investigate abuse, and protect tenants.
Website, support, and marketing data (FSS as controller). Information you submit through the pilot/contact form, registration flow, or a support request, such as work email, company/workspace name, affected client, and the safe description you provide.
reCAPTCHA security data (FSS as controller; Google as processor). Google reCAPTCHA protects the public contact form and, where shown, the public self-registration form against spam, fraud, and abuse. It processes IP address, device/browser or application signals, interaction signals, and a short-lived verification token. Google Cloud EMEA Limited processes that data on FSS's behalf. This is FSS-controlled website/account-security data, not Customer Personal Data processed on a Customer's instructions.
Cookies and security technologies. We use strictly necessary session and CSRF cookies and Google reCAPTCHA's _GRECAPTCHA security cookie. We use no analytics, advertising, or behavioural-tracking cookies. See the Cookie Statement.
What we do not collect. We do not request or store the broader content of your AI conversations or prompts. When you use brainattic through an AI client, the connector receives only the input needed for the action you request and returns a tenant-scoped result. We do not ingest the rest of your chat history, transcripts, or precise location.
5. How the connector handles data
brainattic exposes MCP tools that read and write your knowledge base under your instruction. Each tool processes only the inputs required for that call and returns only the data needed for the result. Tools are permission-gated, tenant-scoped, and paginated; write actions are explicit. An Authorised User who has not accepted a required material policy version may be prevented from using tenant-data MCP operations until acceptance is completed in the web application.
6. Why we process data and our legal bases (GDPR Art. 6)
| Purpose | Role and legal basis |
|---|---|
| Provide Customer Content functions, search, retrieval, exports, and reminders | FSS as processor on the Customer's documented instructions — GDPR Art. 28 |
| Create and operate accounts, authenticate users, administer access, and keep contract-acceptance evidence | FSS as controller — performance of a contract or steps before one, Art. 6(1)(b); legitimate interests in contract administration, Art. 6(1)(f) |
| Secure the website and Service, prevent abuse, and keep operational logs, including reCAPTCHA where enabled | FSS as controller — legitimate interests in security and abuse prevention, Art. 6(1)(f) |
| Respond to contact-form and support enquiries | Legitimate interests or steps before a contract, Art. 6(1)(f)/(b) |
| Meet legal obligations and establish, exercise, or defend legal claims | Legal obligation, Art. 6(1)(c), or legitimate interests, Art. 6(1)(f) |
We do not sell personal data or carry out advertising profiling or automated eligibility decisions.
7. AI models and clients
brainattic does not send Customer Content to a third-party AI model. The AI client you choose, such as Claude, ChatGPT, or Mistral, connects to brainattic as your client. Your use of that AI is governed by your relationship with its provider. That provider is not our Sub-processor, and we are not theirs, for this purpose. The client may receive content that you direct brainattic to return.
8. Who else is involved
The core Service is self-hosted on FSS-controlled infrastructure in the EU, including document storage, search and embeddings, email, and FSS's authorisation server. The following external parties may be involved:
| Party | Role | Data involved | Location | When |
|---|---|---|---|---|
| Telepoint EAD | Data-centre colocation (physical facility; no logical access to data) | Hardware housing stored data | Sofia, Bulgaria (EU) | Always |
| A1 Bulgaria EAD (SPNET) | Internet connectivity / IP transit | Encrypted data in transit | Bulgaria (EU) | Always |
| Google Cloud EMEA Limited | Processor to FSS — reCAPTCHA security | IP address, device/browser or application signals, interaction signals, and a short-lived verification token | EEA and other countries where Google or its Subprocessors maintain facilities, subject to Google Cloud transfer safeguards | When a protected public form is loaded or submitted |
| Google Ireland Limited | Separate controller — optional Google sign-in | Provider identifier and identity claims you authorise Google to return | Ireland and Google's international operations | Only if you choose Google sign-in |
| Meta Platforms Ireland Limited | Separate controller — optional Facebook sign-in | Provider identifier and identity claims you authorise Meta to return | Ireland and Meta's international operations | Only if you choose Facebook sign-in |
| Apple Distribution International Limited (with Apple Inc. where applicable) | Separate controller — optional Sign in with Apple | Provider identifier and identity claims you authorise Apple to return, including an email address or private-relay address | Ireland / United States | Only if you choose Sign in with Apple |
| Slack Technologies, LLC (a Salesforce company) | Sub-processor — optional Slack reminder delivery | Reminder content and recipient Slack member ID | United States | Only if your organisation enables Slack reminders |
| Yettel Bulgaria EAD | Sub-processor — optional SMS reminder delivery | Recipient phone number and message content | Bulgaria (EU) | Only if your organisation enables SMS reminders |
Google Cloud EMEA Limited acts as our processor for reCAPTCHA data used to protect the public contact and self-registration forms. This processing is outside the customer DPA and its Annex III because FSS controls it for its own website and account-security purpose. Google, Meta, and Apple act as separate controllers for their optional sign-in services and are outside Annex III for that distinct reason.
9. International transfers
FSS stores core Service data on infrastructure in Bulgaria, European Union. Processing outside the EEA may occur when your organisation enables Slack delivery in the United States, you choose an identity provider whose international operations process the sign-in interaction, or Google processes reCAPTCHA data in a country where Google or its Subprocessors maintain facilities. Restricted reCAPTCHA transfers rely on the mechanisms and safeguards in the Google Cloud Data Processing Addendum, including an applicable alternative transfer solution or Standard Contractual Clauses. Other recipients must use an appropriate GDPR Chapter V mechanism where required. SMS delivery through Yettel stays within the EU.
10. How long we keep data
| Data | Retention |
|---|---|
| Customer Content and live tenant data | While the workspace is active. An authorised immediate-deletion request, executed by FSS, removes live data without creating a recovery archive. Under the customer-initiated closure path, live removal occurs only after a cancellable 14-day window, during which every workspace administrator is notified and any of them may cancel the closure; no recovery archive is created. Under the dormancy path, live removal occurs only after six months without meaningful web or MCP activity plus a 60-day warning/export opportunity. |
| Dormancy recovery archive | Encrypted and kept for 30 days after live removal, then permanently deleted. No archive is created for an immediate customer-requested deletion. |
| Sanitized post-closure audit and legal-acceptance evidence | For no more than 90 days after tenant closure, then permanently deleted with the residual closed-tenant record, unless applicable law or a documented legal hold requires longer retention. |
| Rolling infrastructure backups | Up to 30 days, then overwritten under the backup cycle. |
| Application and security logs | 30 days. |
| reCAPTCHA data retained by FSS | The verification token and Google's raw response are not retained. Limited operational metadata — timestamp, outcome, score if returned, action, hostname, and request/correlation identifier — may be kept for up to 30 days. |
| Incomplete registration reservations | Automatically deleted after the short registration-intent window expires. |
| Contact-form submissions and related correspondence | 12 months, unless a longer period is needed for an ongoing relationship or legal claim. |
| Billing and accounting records | No fees apply during the free pilot. If billing is introduced, records required by tax or accounting law will be retained separately for the applicable statutory period and will never be used to preserve Customer Content. |
During the bounded 90-day post-closure period, the tenant remains disabled. Retained records are sanitized and used only for security investigation, abuse prevention, service-integrity verification, contract evidence, and the establishment, exercise, or defence of legal claims. A legal hold must be explicit and documented; it is not the default. When the hold or legal duty ends, deletion resumes.
11. How we protect data
We use TLS encryption in transit, role-based access controls and least-privilege administration, logical isolation of customer tenants, network segmentation, and physical security at our data-centre facility. Our practices are aligned with the principles of ISO/IEC 27001, ISO/IEC 20000, and ISO 9001; FSS was previously certified to these standards, but certifications are not currently maintained. Operational logs do not contain document bodies or broader AI prompts. We do not log or persist the reCAPTCHA token or Google's raw verification response.
12. Your rights
Subject to the GDPR, you may have rights of access, rectification, erasure, restriction, and data portability, and the right to object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it. To exercise rights concerning data for which FSS is controller, email privacy@brainattic.ai; we normally respond within one month.
For Customer Content for which your organisation is controller, direct your request to that organisation; we will assist it as processor. For data processed independently by Google, Meta, or Apple during sign-in, exercise your rights with the relevant provider. For reCAPTCHA data, FSS remains your controller contact and Google processes the data on our behalf.
You may complain to the Commission for Personal Data Protection (CPDP), www.cpdp.bg, or another competent EU supervisory authority.
13. Children
brainattic is intended for business users aged 18 or over. It is not directed to children, and we do not knowingly process children's personal data through the public registration flow.
14. Changes to this notice
We may update this policy. We publish each version with its publication and effective dates. For material changes, we normally give at least 14 days' notice and notify customers through the Service or by email. We may require renewed acceptance before tenant-data web or MCP access continues after the effective date.
15. Contact
Privacy and data-protection enquiries: privacy@brainattic.ai. Product support: brainattic.ai/support or hello@brainattic.ai.
Finite Software Systems Ltd. — 4 Gorotzvet Street, Sofia, Bulgaria.