Privacy Notice
Last updated: 3 September 2026
How Community Brain handles personal data. Community Brain is a collective-memory AI service that communities run for their members, built and operated by Zwerm.
Every community running a Community Brain world also has an organiser. Where a community has signed a data processing agreement, that organiser is the controller of its members' personal data and Zwerm is its processor. Where that split has not been signed off, this notice does not label anyone controller or processor — write to xandersteenbruggex@gmail.com, or ask the organiser who invited you, to find out who is responsible for your community.
For any request or question about this notice, write to xandersteenbruggex@gmail.com.
What Community Brain does
Community Brain is a collective-memory AI agent for place-rooted communities. Members chat or speak with it, and it:
- remembers — a private memory only you see, plus a collective memory the community shares;
- matches — suggests people worth meeting, from facets extracted out of what members have said;
- maps — places members on a community map near others with related interests;
- knows what's on — events and community documents an organiser has connected;
- publishes — a community feed and quote wall built from collective memory, never from raw transcripts.
This community also runs a physical booth where a walk-up visitor can talk to the agent without an account.
You are talking to an AI system, not to a person. Community Brain generates its answers, profile descriptions, skill and expertise labels and connection suggestions automatically. Those outputs can be incomplete, out of date or simply wrong. They are informational and supportive only, and are not an assessment by anyone of a member's professional qualifications, suitability or performance.
What personal data we process
- Identification and contact details — first and last name, email address, phone number where you provide one, profile picture, preferred language.
- Professional and community information — organisation, sector, role, job title, professional background, expertise, skills, interests, projects, collaboration needs, and what you say you are looking for from this community.
- Membership and access — which community you belong to, your role there, how you got access, and your sign-in identities.
- Event and participation information — registrations, attendance, and the sessions, speakers and topics you showed an interest in.
- Conversations — chat messages, voice transcripts, the arguments and results of tools the agent used on your behalf, timestamps, session metadata, and usage and cost data. Community Brain stores transcripts, not audio files.
- Memory and derived material — your private memory, your public bio, matchmaking facets, your position on the community map, extracted facts, community summaries, and the provenance linking each of these back to the conversation it came from. Names and identifying context can stay attached. Every memory item is labelled private or collective, never both; a private item is never shown to other members and never enters the collective memory.
- Privacy and visibility settings — whether you are visible to other members, whether your email address or phone number is shown, and your collective-memory privacy prompt.
- Community sources — what an administrator connects or uploads on behalf of the community: documents, event feeds, recordings, configured web pages.
- Account, technical and operational data — user id, IP address and technical information about your use of the application, security and rate-limit logs, device class, error reports, feedback, and privacy-respecting Vercel Analytics. A profile owner sees how many members opened their profile, never who.
- Anything else you volunteer in the course of using the application.
Most of this you give us directly, by filling in your profile, registering for an event or talking to the agent. Some may reach us indirectly, from other members, from partners, or from public professional sources, where it is relevant to the purposes below.
Community Brain is not meant to process special categories of personal data within the meaning of Article 9 GDPR (health, beliefs, political opinions, sexual orientation and the rest) or data about criminal convictions and offences within the meaning of Article 10 GDPR. Please do not give the agent that kind of information. We take appropriate measures to keep such material out of generated profiles, skills, matchmaking, the community map and the collective memory where processing it is not necessary or permitted.
Why we process it
- Running the service — signing you in, operating, securing, monitoring and debugging the application, enforcing spend and abuse limits, and supporting you when something breaks.
- Your member profile and the member directory — maintaining your profile and, subject to your visibility settings, letting other members find you, search by name and see your profile and event participation.
- Events — registering you, managing attendance, and telling the agent what is on.
- The Community Brain itself — maintaining your private and collective memory; generating and updating your professional profile description; identifying your skills, expertise areas, interests and collaboration needs; suggesting members worth connecting with; and positioning you on the community map so that members with related profiles sit near each other.
- The collective memory — a shared knowledge base combining what was presented and discussed at community events with the material from member conversations that was classified as collective, so the agent can answer other members' questions with real context.
- The community feed — an automatically generated summary of the topics, needs, interests, opportunities and challenges emerging in the community, covering both broad trends and concrete signals from specific members or organisations. The community uses it to shape events, sessions and introductions and to respond to what members actually need.
- Connected tools — carrying out the actions you ask the agent to take, such as creating a calendar entry or sending an email.
- Contacting you about the service.
Community Brain does not sell personal data and does not use it for advertising.
The legal basis, and profiling
We process this personal data on the basis of legitimate interests: facilitating networking, knowledge sharing and collaboration inside the community, and making members' expertise, experience and interests visible and usable to each other. That covers maintaining and displaying member profiles, making expertise searchable, operating the Community Brain, generating profile descriptions and skills, suggesting connections, positioning members on the map, maintaining private and collective memory, generating the community feed, supporting members, and keeping the application secure and working.
When we rely on legitimate interests we weigh them against your rights and freedoms, and we build in safeguards: granular privacy and visibility controls, the privacy prompt, memory management, privacy-by-design defaults, and the ability to change or delete a great deal of this yourself inside the application. Where a purpose rests on your consent instead, you can withdraw it at any time without affecting what was processed before.
Profiling, but no automated decisions with legal effect. Some Community Brain features amount to profiling within the meaning of the GDPR: automated processing is used to analyse your professional interests, expertise, skills and potential connections, drawing on your background, projects, collaboration needs, event participation and conversations, in order to produce a profile description, identify skills, suggest connections and place you on the community map. We do not use Community Brain, or any data it processes, to make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.
Privacy by design: no AI profile until you ask for one. Being a member, or being listed for other members, does not by itself create an AI-generated profile. If you are visible, a limited entry exists based only on what is already shown — name, picture, organisation, role, expertise, contact details where you published them, upcoming events. No further characteristics, skill assessments or generated descriptions are created at that stage. Only when you open the Community Brain yourself, see how it works, and talk to it does it start building a fuller professional profile from your conversations and the material available in the community.
What other members see, and what you control
Your bio, published profile fields, matchmaking facets, map position and collective-memory contributions can be served to other members of the same community, with your name attached. Depending on your settings this can include your email address and phone number.
Who else can see it. A very small number of people — this community's own administrators, plus the platform operator — can open administrative views that include full conversation transcripts with the member's name and email address, the memory items extracted from those conversations (including private ones), and the community's memory store. That access is role-gated, granted manually, and exists for support, moderation, security and debugging only. We would rather state this plainly than let you assume a stronger separation than the system actually enforces.
Four controls are yours:
- Visible to other members. Every membership starts hidden; accepting the Terms makes you findable, and this switch takes you back out of profile reads, matchmaking, the map, the feed and messaging. Hiding is not erasure: your material stays intact and still attributed, and you can switch back at any moment. Anything already delivered to another person cannot be recalled, and summaries built from several members may need a rebuild before they are clean again. If you want deletion rather than invisibility, see below.
- Your collective-memory privacy prompt (Settings → Privacy) — your own words telling the extraction model what should stay private instead of becoming community memory: specific topics, projects, expertise areas, periods, anything you would rather the wider community did not get. It steers a language model, so treat it as a strong preference rather than a deterministic filter.
- Your profile. Your bio, the facets matchmaking searches and whether your contact details are shown are all edited there. You can also lock your profile description, after which later conversations no longer change it automatically. Your raw email address is never part of matchmaking output either way.
- Shared conversation links. You can share a conversation with someone through a link. It is a bearer link: anyone holding the unguessable URL can read that conversation. Links do not expire and cannot yet be revoked in-app, so treat a shared link as permanent.
Where it runs, and who else processes it
- Storage — the database holding accounts, transcripts, messages, profiles and every memory item runs on Neon in Frankfurt, Germany.
- Compute — Modal, pinned to EEA regions for every target that touches personal data, and Vercel in Frankfurt for the web tier.
- Transcribing uploaded recordings — our own speech-to-text model on our own EEA compute: no third-party transcription service, and the audio bytes never leave that path.
Two things are deliberately not EEA-only: Modal's control plane routes short-lived encrypted job metadata via the United States, and Vercel's routing layer runs at edge locations worldwide, so a request made from outside the EEA has its identity resolved there. Where personal data goes outside the EEA, an appropriate transfer mechanism is in place — an adequacy decision (including, where it applies, the EU–US Data Privacy Framework) or another Chapter V safeguard such as the European Commission's standard contractual clauses. Write to xandersteenbruggex@gmail.com for details of the mechanism that applies.
Other processors, by feature, each with its own processing locations: Clerk (sign-in), OpenRouter and the model providers it routes to (text generation, embeddings), ElevenLabs (live voice), Google (connected Workspace features and community-owned Drive sources), Firecrawl (fetching configured web pages), EmailJS (the public access-request form). Each of them receives personal data only so far as it needs to in order to provide its service, under a data processing agreement, and is required to handle it securely and lawfully.
Beyond what is described here, your personal data is not shared with third parties and is never sold.
AI models: no retention, no training. Every model call Community Brain makes itself — the chat agent, memory extraction, matchmaking facets, embeddings, knowledge summaries, the community feed — goes to OpenRouter with data_collection: deny on the request, which drops any provider that would retain your content or train on it from the routing pool for that call. It is set unconditionally on every route and pinned by automated tests so it cannot quietly be dropped. No service provider is permitted to use personal data processed through Community Brain to train AI models.
Live voice is the exception worth knowing. A live voice conversation runs inside ElevenLabs — their speech recognition, their hosted language model, their speech synthesis — so that leg is neither EEA-only nor covered by the rule above. Your voice audio is not kept: recording is switched off on every Community Brain voice agent, ElevenLabs is instructed to delete audio including audio from earlier conversations, and what survives a call is the transcript, stored in Frankfurt. ElevenLabs also sells a stronger contractual Zero Retention Mode; we do not have it, and this notice does not claim it.
Google user data
When a community administrator connects Google Workspace, Community Brain requests only the narrow scopes enabled for that world: reading selected Calendar events, creating/updating/cancelling events, and sending Gmail messages. It does not request inbox-reading or personal Drive scopes; community-owned Drive ingestion is a separate service-account source configured by the community.
Google data is used only to provide the requested feature. Community Brain stores encrypted authorization tokens and may log actions taken, but builds no standing copy of a mailbox. Humans access Google user data only with explicit permission, for security or abuse investigation, where legally required, or in aggregated/anonymised form. Disconnect in the admin configuration, or revoke at Google Account permissions.
Limited Use disclosure. Community Brain's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used for advertising, sold, or used to train generalised or non-personalised AI/ML models.
How long we keep it
Personal data is kept only as long as it is needed for the purpose it was collected for, unless a longer period is required or permitted by law. In practice:
- Login and account data — until the end of your membership of this community, as far as it is needed for authentication, access management and security.
- Private memory — until the end of your membership, unless you delete it earlier through the privacy settings. Deleting something from your private memory does not touch material that was separately classified as collective.
- Collective memory that is still linked to you — until the end of your membership, or until you turn off your visibility in the Community Brain.
- Anonymised collective memory — material that has been aggregated or anonymised so that neither we nor other members can reasonably trace it back to a person is treated as general community knowledge rather than personal data, and can stay in the collective memory for as long as the Community Brain runs, including after you leave.
- AI-generated profile description and skills — for the duration of your membership. When a new description is generated, the previous one is deleted and replaced. Deleting the underlying material, such as your private memory, does not by itself rewrite the current description.
- Community map position and directory profile — for the duration of your membership.
- Conversations and operational records — transcripts, security, cost and acceptance records are kept while they serve those purposes.
When a retention period ends the data is deleted or anonymised. Community Brain does not run a universal automatic purge; removal happens on the schedules above, when you delete it yourself, or when a reviewed request removes or anonymises it. A lapsed membership stops being collectively readable and what it contributed survives un-attributed.
Deleting your data
Two different controls, and it is worth knowing which one you want. Hiding is reversible and deletes nothing. Deleting your data is irreversible and is offered per community, in that community's Login settings.
What deletion does. For the community you run it in, it permanently deletes every conversation you had with that agent, the notes the brain took about you (in every state, including its private notes and your profile documents), your profile and matchmaking facets, your map position, your settings and your membership. It is a real deletion, not an archive: there is no grace period, no restore, and support cannot recover it. Your other Community Brain communities are untouched — you remain a full member of each, with everything of yours intact — and your sign-in account is untouched. Deleting the sign-in account itself, with our sign-in provider, runs the same deletion across every community you were in.
What deletion does not do, and why. General things you told the agent about the community — an event time, a fact about the space — stay in that community's brain, permanently stripped of your name. You do not own collective knowledge you contributed; you own what the brain recorded about you. Three further traces are outside what deletion can reach, and we would rather publish them than have you discover them:
- Other members' notes that mention you by name. Community Brain never works out who a note is about, so it never deletes on someone else's behalf. Deleting by guesswork would misattribute strangers.
- A small number of older notes with no author recorded, from before authorship was stamped. Nothing selects them, so a name can remain in their text.
- A note genuinely about you that the system filed as general community knowledge. It survives with your name removed from its authorship, but possibly still inside its text. This is not programmatically detectable.
Removal from the live system is immediate; encrypted backups are purged on their own retention cycle rather than instantly.
Booth conversations cannot be deleted per person, because they were never linked to one: a booth records no account, no name and no speaker at all. Free text can still identify someone, which is why the booth notice says so before you start.
Your rights
This notice is itself how we inform you about the processing; you can always ask for more at xandersteenbruggex@gmail.com. You also have the right to ask for:
- Access to your data. One copy is free; we may charge a reasonable administrative fee for further copies.
- Rectification of data that is wrong or incomplete.
- Erasure, where the data is no longer needed for the purpose it was processed for; where you withdrew a consent it rested on; where you object and there is no overriding ground; where it was processed unlawfully; where erasure is required by law; or where it was collected in connection with online services offered to children (not applicable here).
- Restriction of processing, where you contest the accuracy of the data; where the processing is unlawful and you prefer restriction to erasure; where we no longer need the data but you need it for a legal claim; or while an objection you made against processing based on legitimate interests is being assessed.
- Objection. Because we rely on legitimate interests, you may object to the processing. If you do, we stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims. You can object to direct marketing at any time, free of charge, by changing your communication preferences in the application, using the unsubscribe link in any message, or writing to xandersteenbruggex@gmail.com.
- Portability — a structured, commonly used, machine-readable copy, where the processing is based on consent and carried out by automated means.
- Withdrawal of consent, where a purpose rests on consent, without affecting processing carried out before.
To exercise any of these, write to xandersteenbruggex@gmail.com. You will need to give us enough information to identify you; where we have reasonable doubts we may ask for more, but only what is necessary and proportionate. Exercising these rights is subject to the conditions the GDPR sets for each of them.
You also have the right to complain to a supervisory authority. In Belgium that is the Data Protection Authority, Drukpersstraat 35, 1000 Brussels — +32 (0)2 274 48 00 — contact@apd-gba.be (dataprotectionauthority.be). You are welcome to come to us first, at xandersteenbruggex@gmail.com.
Security, and who may use this
Data is encrypted in transit, stored Google credentials are encrypted, every member and community read is scoped in application queries, and operational failures are logged. No system is perfectly secure — do not give the agent secrets you would not want stored or surfaced under this notice.
A booth shows a notice before its start control: your voice is processed by ElevenLabs, Community Brain stores the transcript, and parts may enter collective memory. Starting is the visitor's affirmative action after that notice. Booth material is anonymous at the account layer, but free text can identify the speaker or someone else, and Community Brain does not promise deterministic anonymisation.
Community Brain is meant for adults taking part in a community. Children, and others who cannot understand or validly act on this notice, need an arrangement agreed with the community first.
Changes and contact
This notice can be amended at any time; we recommend reading it again now and then. Changes are communicated in the application or by email, and material changes are presented for fresh acknowledgment. Acknowledgment proves notice, not consent to every purpose, and earlier records are kept rather than overwritten.
Questions, or anything else: xandersteenbruggex@gmail.com, or the community organiser who invited you.