Privacy Policy
This Privacy Policy explains what personal data TerraBrains (“TerraBrains”, “we”, “us”) collects, why we collect it, and the choices you have. It covers our public website and the TerraBrains application. It works alongside our Terms of Service, Data Processing Addendum and Security pages.
Who we are
TerraBrains is operated by HOUSEBRAINS.AI PRIVATE LIMITED (CIN U62013KA2026PTC216643), a company incorporated in India under the Companies Act, 2013, with its registered office at 217, Ground Floor, Thammanna Building, T Dasarahalli, Peenya, Bangalore North, Bengaluru 560057, Karnataka, India.
We act in two distinct roles. For account, profile and billing data we are the data controller. For the geotechnical project data you upload into your workspace we are a data processor, acting only on your instructions — your organisation is the controller of that content. Our Data Processing Addendum governs that relationship.
For privacy questions, contact our privacy team at privacy@terrabrains.ai. HOUSEBRAINS.AI PRIVATE LIMITED is the entity responsible for your personal data and handles data-protection requests at that address.
Data we collect
- Account & profile — your name, work email, organisation, role, and an optional professional licence number (e.g. PE / CEng / MICE / MIE) you may add to sign reports.
- Project & geotechnical data — boreholes, samples, lab results, analyses, photos, reports and any files you or your team upload. This may include personal data of your own staff or clients that you choose to store; you control this content.
- Usage & audit logs — actions taken in the app, recorded to a tamper-evident SHA-256 audit chain, plus standard server logs (IP address, device/browser, timestamps) used for security and debugging.
- Billing — your plan, subscription and trial status, and the records needed for invoicing. Card details are collected and processed by our payment processor and are not stored on our servers.
How we use your data
- Provide, operate and secure the service and your workspace.
- Authenticate you and enforce role-based access and tenant isolation.
- Run the geotechnical analyses, reports and AI features you request.
- Maintain the audit chain for traceability and compliance.
- Process subscriptions, trials and invoices.
- Send service, security and account notices.
- Detect, investigate and prevent abuse, fraud and security incidents.
We do not sell your data, and we do not use it for advertising or cross-customer profiling.
Legal bases (GDPR)
Where the GDPR or equivalent law applies, we rely on:
- Contract — to provide the service you sign up for (account, billing, core features).
- Legitimate interests — to secure the platform, prevent abuse and improve reliability, balanced against your rights.
- Legal obligation — to keep records (e.g. tax and accounting) where the law requires.
- Consent — where we ask for it explicitly; you can withdraw it at any time.
For customer project data we process it under your instructions as your processor, governed by our Data Processing Addendum.
Sub-processors
We use a small number of trusted infrastructure providers, each processing data only to deliver their part of the platform:
- Supabase — managed PostgreSQL database, authentication and file storage.
- Amazon Web Services (AWS) — web application hosting and delivery (App Runner behind CloudFront) and AWS Bedrock AI inference, run in the tenant’s designated AWS region.
- Dodo Payments — merchant-of-record for global subscription billing and tax handling.
- Resend — transactional email (sign-in, billing and security notices).
A current sub-processor list forms part of our Data Processing Addendum. Primary data hosting region: the United States — managed database and file storage on Supabase’s cloud, and AI inference on AWS Bedrock in the US East (N. Virginia / us-east-1) region; web delivery is via AWS CloudFront’s global edge. Enterprise customers can arrange regional data residency, including India, by arrangement (see Security).
What makes our data handling different
- Your data is never used to train third-party AI models.We use AWS Bedrock foundation models for inference only; your content is not contributed to any model’s training data.
- AI inference runs in your AWS region.Your project data does not leave the tenant’s designated AWS region for AI processing.
- Every record is SHA-256 audit-chained. Each signable action is hashed and chained to the previous one by a database trigger, making tampering mathematically detectable.
Data location & retention
Your data is stored on Supabase and AWS infrastructure as described above. We retain account and project data for as long as your workspace is active.
When you delete your account (see below), we immediately anonymise the personal data on your profile — including your name, email and licence number. Records that form part of the immutable audit chain are retained in anonymised form to preserve the integrity of the chain and of any signed reports already issued. Retention schedule: active workspace data is kept for the life of your subscription; on account deletion, profile personal data is anonymised immediately; encrypted database backups roll off within about 30 days; billing, tax and statutory records are retained for as long as Indian law requires (generally up to 8 years); and audit-chain hashes tied to signed reports are retained (anonymised) indefinitely to keep those reports independently verifiable.
Security
We protect data with, among other measures:
- Postgres Row-Level Security (with FORCE RLS) on every tenant table, so isolation is enforced in the database, not just the app.
- Encryption in transit (TLS) and at rest, via our infrastructure providers.
- Time-based one-time-password (TOTP) MFA, with step-up MFA required to sign and stamp reports and for privileged roles.
We do not currently hold SOC 2 or ISO 27001 certification and do not claim to. We describe our actual controls on our Security page and are happy to walk procurement teams through them.
Your rights
Depending on where you live (for example under the GDPR or similar laws), you may have the right to access, correct, export, restrict or delete your personal data, and to object to certain processing.
- Access & export — you can export your workspace data from within the app.
- Deletion — signed-in users can self-serve a full account deletion at Settings → Delete account; it runs immediately, anonymises your personal data and signs you out.
- Other requests — to exercise any right, or to delete a workspace you do not own, email privacy@terrabrains.ai.
Where we process data as a processor on behalf of a customer, we will refer your request to that customer (the controller). You may also lodge a complaint with your local data-protection authority.
Cookies
We use only essential, session cookies needed to keep you signed in and maintain your session, set by our authentication provider. We do not use advertising or cross-site tracking cookies, and we do not run third-party analytics trackers.
Children
TerraBrains is a professional engineering tool intended for business use. It is not directed at children, and we do not knowingly collect personal data from anyone under 16.
International transfers
Our providers may process data in regions outside your own. Where required, such transfers are covered by appropriate safeguards. Transfer mechanism: European Commission Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), together with the data processing addenda of our sub-processors (Supabase, AWS, Dodo Payments and Resend).
Changes to this policy
We may update this policy as the product and our legal review evolve. Material changes will be announced in-app or by email, and the “last updated” date above will change.
Contact
Questions or requests: privacy@terrabrains.ai. Legal entity and data-protection contact: HOUSEBRAINS.AI PRIVATE LIMITED (CIN U62013KA2026PTC216643), registered office 217, Ground Floor, Thammanna Building, T Dasarahalli, Peenya, Bangalore North, Bengaluru 560057, Karnataka, India / privacy@terrabrains.ai.