Legal
Privacy policy
What this site stores, when it starts, and how to change your mind — opt-in analytics, a cookieless visit count, and no account system in the app.
Brainstorm is a local-first product, and this site follows the same posture: collect as little as possible, keep what is collected boring, ask before storing anything, and never trade your attention or your data. This page describes everything the site at https://getbrainstorm.online does with data. The Brainstorm app itself stores your data on your machine and has no account system; nothing on this page is about the app.
What we collect
Counting visits — no consent needed, because there is nothing to consent to
Separately from the analytics above, we count page views. This one runs for everyone, and we want to be plain about why that is not a loophole: it sets no cookie, writes nothing to your device, and creates no identifier that could be used to recognise you on a later visit. There is nothing stored, so there is nothing to ask permission for.
It exists because consent-based analytics cannot answer a simple question honestly — how many people visited. It only ever sees the people who said yes, so its totals are a fraction of unknown size. Rather than quietly treat that fraction as the whole, we measure the total separately and keep the two apart: this one counts, the one above explains.
It is run by Vercel, who already host this site and therefore already receive every request you make to it — no new company learns anything new, and no request leaves for another domain. What is recorded is the page path, the referrer, and coarse device and country information derived from the request itself. Never an IP address stored against you, never a profile, never anything you type.
The legal basis is our legitimate interest in knowing whether the site works, under GDPR Art. 6(1)(f). Because nothing is stored on your device, the ePrivacy consent rules that cover the analytics above do not apply here.
Usage analytics — only if you say yes
We would like to count visits and see which pages get read. We use Amplitude for that, on its EU servers, and it runs only if you answer yes to the question at the bottom of the page. Until you do, the analytics code is never downloaded, never runs, and writes nothing to your device — the choice is opt-in, not a switch on something already loaded.
If you say yes, two things are stored on your device, in localStorage rather than in cookies. First, a random device id and session id generated by Amplitude: they identify a browser, not a person, and are never joined to a name or an email. Second, our own record of your answer — the word "granted" or "denied" and the date you gave it — under the key bs-consent. If you say no, only the second one is stored, so we know not to ask again.
What gets sent while it is on: the page you are on, its title and referrer, your browser's language and screen size, and named events for the things worth counting — a download click (which platform, which build) and a newsletter or waitlist signup. Amplitude derives an approximate country from your IP address. We never send your email address, your name, or anything you type into a field.
The legal basis is your consent, under GDPR Art. 6(1)(a) and the ePrivacy rules that cover storing anything on your device. Amplitude Inc. acts as our processor under a data-processing agreement, with the data held in the EU. Event data is kept for 12 months and then deleted. Your answer is remembered for 12 months, after which we ask again.
You can change your answer at any time — the "Privacy choices" link in the footer of every page reopens the question. Saying no there stops the tracking immediately and deletes the stored device id from your browser.
If your browser sends a Global Privacy Control or Do Not Track signal, we take that as a no: the question is never shown, nothing is loaded, and nothing is stored.
Your email address, if you give it to us
If you join the waitlist or subscribe to product updates, we store the email address you submit in a database (hosted by Turso) and use it for exactly one thing: sending you Brainstorm product updates. We do not share it, sell it, or enrich it. To have it removed, email founder@getbrainstorm.online and we will delete it.
A theme preference
If you switch between light and dark theme, the choice is stored in a bs-theme cookie so the site and the docs open in the theme you picked. It contains the word "light" or "dark" and nothing else. It is functional, not tracking, and it is set whether or not you consent to analytics.
Server logs
The site is hosted on Vercel, which keeps standard, short-lived request logs (IP address, user agent) for operations and abuse prevention, acting as our processor.
What loads from third parties
The product-tour video embeds from youtube-nocookie.com and only loads after you press play; until then no request goes to YouTube. The footer shows badges from launch directories we are listed on (VerifiedDR, Endors, KittyLaunch, ListBulb, Product Watch, StartupBase) — loading those images sends the standard request data (IP address, user agent) to those hosts, as with any image on the web. Apart from Amplitude, and only after you say yes, the only other script on this site is the visit counter described above — served from our own domain by our host, so it contacts no other company. Downloads are served from GitHub Releases.
Your rights
Under the GDPR and similar laws you can ask what we hold about you, ask for it to be corrected or deleted, object to processing, and withdraw consent as easily as you gave it. Withdrawal is the footer link described above and takes effect at once. For the waitlist, deletion is the whole story — your email address is the only personal data we hold. Write to founder@getbrainstorm.online or open an issue on GitLab.
Changes
If this policy changes, the date above changes with it, and the history is public in the site's source repository.