Privacy Notice

Last updated: 3 September 2026

How Community Brain handles personal data. Community Brain is a collective-memory AI service that communities run for their members, built and operated by Zwerm.

Every community running a Community Brain world also has an organiser. Where a community has signed a data processing agreement, that organiser is the controller of its members' personal data and Zwerm is its processor. Where that split has not been signed off, this notice does not label anyone controller or processor — write to xandersteenbruggex@gmail.com, or ask the organiser who invited you, to find out who is responsible for your community.

For any request or question about this notice, write to xandersteenbruggex@gmail.com.

What Community Brain does

Community Brain is a collective-memory AI agent for place-rooted communities. Members chat or speak with it, and it:

This community also runs a physical booth where a walk-up visitor can talk to the agent without an account.

You are talking to an AI system, not to a person. Community Brain generates its answers, profile descriptions, skill and expertise labels and connection suggestions automatically. Those outputs can be incomplete, out of date or simply wrong. They are informational and supportive only, and are not an assessment by anyone of a member's professional qualifications, suitability or performance.

What personal data we process

Most of this you give us directly, by filling in your profile, registering for an event or talking to the agent. Some may reach us indirectly, from other members, from partners, or from public professional sources, where it is relevant to the purposes below.

Community Brain is not meant to process special categories of personal data within the meaning of Article 9 GDPR (health, beliefs, political opinions, sexual orientation and the rest) or data about criminal convictions and offences within the meaning of Article 10 GDPR. Please do not give the agent that kind of information. We take appropriate measures to keep such material out of generated profiles, skills, matchmaking, the community map and the collective memory where processing it is not necessary or permitted.

Why we process it

Community Brain does not sell personal data and does not use it for advertising.

We process this personal data on the basis of legitimate interests: facilitating networking, knowledge sharing and collaboration inside the community, and making members' expertise, experience and interests visible and usable to each other. That covers maintaining and displaying member profiles, making expertise searchable, operating the Community Brain, generating profile descriptions and skills, suggesting connections, positioning members on the map, maintaining private and collective memory, generating the community feed, supporting members, and keeping the application secure and working.

When we rely on legitimate interests we weigh them against your rights and freedoms, and we build in safeguards: granular privacy and visibility controls, the privacy prompt, memory management, privacy-by-design defaults, and the ability to change or delete a great deal of this yourself inside the application. Where a purpose rests on your consent instead, you can withdraw it at any time without affecting what was processed before.

Profiling, but no automated decisions with legal effect. Some Community Brain features amount to profiling within the meaning of the GDPR: automated processing is used to analyse your professional interests, expertise, skills and potential connections, drawing on your background, projects, collaboration needs, event participation and conversations, in order to produce a profile description, identify skills, suggest connections and place you on the community map. We do not use Community Brain, or any data it processes, to make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.

Privacy by design: no AI profile until you ask for one. Being a member, or being listed for other members, does not by itself create an AI-generated profile. If you are visible, a limited entry exists based only on what is already shown — name, picture, organisation, role, expertise, contact details where you published them, upcoming events. No further characteristics, skill assessments or generated descriptions are created at that stage. Only when you open the Community Brain yourself, see how it works, and talk to it does it start building a fuller professional profile from your conversations and the material available in the community.

What other members see, and what you control

Your bio, published profile fields, matchmaking facets, map position and collective-memory contributions can be served to other members of the same community, with your name attached. Depending on your settings this can include your email address and phone number.

Who else can see it. A very small number of people — this community's own administrators, plus the platform operator — can open administrative views that include full conversation transcripts with the member's name and email address, the memory items extracted from those conversations (including private ones), and the community's memory store. That access is role-gated, granted manually, and exists for support, moderation, security and debugging only. We would rather state this plainly than let you assume a stronger separation than the system actually enforces.

Four controls are yours:

Where it runs, and who else processes it

Two things are deliberately not EEA-only: Modal's control plane routes short-lived encrypted job metadata via the United States, and Vercel's routing layer runs at edge locations worldwide, so a request made from outside the EEA has its identity resolved there. Where personal data goes outside the EEA, an appropriate transfer mechanism is in place — an adequacy decision (including, where it applies, the EU–US Data Privacy Framework) or another Chapter V safeguard such as the European Commission's standard contractual clauses. Write to xandersteenbruggex@gmail.com for details of the mechanism that applies.

Other processors, by feature, each with its own processing locations: Clerk (sign-in), OpenRouter and the model providers it routes to (text generation, embeddings), ElevenLabs (live voice), Google (connected Workspace features and community-owned Drive sources), Firecrawl (fetching configured web pages), EmailJS (the public access-request form). Each of them receives personal data only so far as it needs to in order to provide its service, under a data processing agreement, and is required to handle it securely and lawfully.

Beyond what is described here, your personal data is not shared with third parties and is never sold.

AI models: no retention, no training. Every model call Community Brain makes itself — the chat agent, memory extraction, matchmaking facets, embeddings, knowledge summaries, the community feed — goes to OpenRouter with data_collection: deny on the request, which drops any provider that would retain your content or train on it from the routing pool for that call. It is set unconditionally on every route and pinned by automated tests so it cannot quietly be dropped. No service provider is permitted to use personal data processed through Community Brain to train AI models.

Live voice is the exception worth knowing. A live voice conversation runs inside ElevenLabs — their speech recognition, their hosted language model, their speech synthesis — so that leg is neither EEA-only nor covered by the rule above. Your voice audio is not kept: recording is switched off on every Community Brain voice agent, ElevenLabs is instructed to delete audio including audio from earlier conversations, and what survives a call is the transcript, stored in Frankfurt. ElevenLabs also sells a stronger contractual Zero Retention Mode; we do not have it, and this notice does not claim it.

Google user data

When a community administrator connects Google Workspace, Community Brain requests only the narrow scopes enabled for that world: reading selected Calendar events, creating/updating/cancelling events, and sending Gmail messages. It does not request inbox-reading or personal Drive scopes; community-owned Drive ingestion is a separate service-account source configured by the community.

Google data is used only to provide the requested feature. Community Brain stores encrypted authorization tokens and may log actions taken, but builds no standing copy of a mailbox. Humans access Google user data only with explicit permission, for security or abuse investigation, where legally required, or in aggregated/anonymised form. Disconnect in the admin configuration, or revoke at Google Account permissions.

Limited Use disclosure. Community Brain's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used for advertising, sold, or used to train generalised or non-personalised AI/ML models.

How long we keep it

Personal data is kept only as long as it is needed for the purpose it was collected for, unless a longer period is required or permitted by law. In practice:

When a retention period ends the data is deleted or anonymised. Community Brain does not run a universal automatic purge; removal happens on the schedules above, when you delete it yourself, or when a reviewed request removes or anonymises it. A lapsed membership stops being collectively readable and what it contributed survives un-attributed.

Deleting your data

Two different controls, and it is worth knowing which one you want. Hiding is reversible and deletes nothing. Deleting your data is irreversible and is offered per community, in that community's Login settings.

What deletion does. For the community you run it in, it permanently deletes every conversation you had with that agent, the notes the brain took about you (in every state, including its private notes and your profile documents), your profile and matchmaking facets, your map position, your settings and your membership. It is a real deletion, not an archive: there is no grace period, no restore, and support cannot recover it. Your other Community Brain communities are untouched — you remain a full member of each, with everything of yours intact — and your sign-in account is untouched. Deleting the sign-in account itself, with our sign-in provider, runs the same deletion across every community you were in.

What deletion does not do, and why. General things you told the agent about the community — an event time, a fact about the space — stay in that community's brain, permanently stripped of your name. You do not own collective knowledge you contributed; you own what the brain recorded about you. Three further traces are outside what deletion can reach, and we would rather publish them than have you discover them:

Removal from the live system is immediate; encrypted backups are purged on their own retention cycle rather than instantly.

Booth conversations cannot be deleted per person, because they were never linked to one: a booth records no account, no name and no speaker at all. Free text can still identify someone, which is why the booth notice says so before you start.

Your rights

This notice is itself how we inform you about the processing; you can always ask for more at xandersteenbruggex@gmail.com. You also have the right to ask for:

To exercise any of these, write to xandersteenbruggex@gmail.com. You will need to give us enough information to identify you; where we have reasonable doubts we may ask for more, but only what is necessary and proportionate. Exercising these rights is subject to the conditions the GDPR sets for each of them.

You also have the right to complain to a supervisory authority. In Belgium that is the Data Protection Authority, Drukpersstraat 35, 1000 Brussels — +32 (0)2 274 48 00 — contact@apd-gba.be (dataprotectionauthority.be). You are welcome to come to us first, at xandersteenbruggex@gmail.com.

Security, and who may use this

Data is encrypted in transit, stored Google credentials are encrypted, every member and community read is scoped in application queries, and operational failures are logged. No system is perfectly secure — do not give the agent secrets you would not want stored or surfaced under this notice.

A booth shows a notice before its start control: your voice is processed by ElevenLabs, Community Brain stores the transcript, and parts may enter collective memory. Starting is the visitor's affirmative action after that notice. Booth material is anonymous at the account layer, but free text can identify the speaker or someone else, and Community Brain does not promise deterministic anonymisation.

Community Brain is meant for adults taking part in a community. Children, and others who cannot understand or validly act on this notice, need an arrangement agreed with the community first.

Changes and contact

This notice can be amended at any time; we recommend reading it again now and then. Changes are communicated in the application or by email, and material changes are presented for fresh acknowledgment. Acknowledgment proves notice, not consent to every purpose, and earlier records are kept rather than overwritten.

Questions, or anything else: xandersteenbruggex@gmail.com, or the community organiser who invited you.