Privacy notice.
Effective 23 August 2026 · version 2026-08-23
This notice explains how ALL SURE LTD, trading as Brain of Record, handles personal information in connection with brainofrecord.com and the BoR service.
Your data remains yours. We do not sell Customer Content, advertise against it, or use it to train AI models.
1. Who is responsible
ALL SURE LTD is the controller for website, account, security, support and business-administration information. Contact us at info@logsure.io.
An organisation or other Customer subject to data-protection law is normally the controller for personal information it puts in its brain, and ALL SURE LTD is its processor. An individual using a brain only for personal or household activities may fall outside the UK GDPR's personal and household activity rules; ALL SURE LTD remains responsible for complying with our own obligations when we handle that information. If another person or organisation gave you access, contact them first about information inside their brain. We will assist where required.
2. Information we handle
Website and network information
Our infrastructure receives ordinary request information such as IP address, requested URL, time, browser or client type, response status and security signals. The public site currently uses no advertising pixels or optional analytics cookies.
Account and security information
We may process your name, email address, brain name, role, area permissions, authentication and OAuth records, API-key hashes, session records, access history and support communications. Secret login and API tokens are stored only in hashed form where the architecture permits.
Customer Content
BoR stores the documents, frontmatter, files and version history submitted by or for a Customer. This may contain personal information about Authorised Users, family and household members, employees, contractors, customers, suppliers or other people. The Customer decides what is included and who may access each area.
MCP requests
We process the MCP requests required to authenticate a caller and retrieve, search or file authorised content. We do not receive the wider conversation you have with your chosen AI provider, its model credentials or its token usage.
3. Why we use information
- Provide the Service: create and administer accounts, authenticate callers, enforce permissions, store and return content, support exports and respond to support requests. Where our contract is with the individual whose information we need, we rely on performance of that contract. We also rely where appropriate on our legitimate interests and those of the Customer in delivering the Service to Authorised Users. Where we act only as a processor, the Customer determines the applicable lawful basis and instructs us.
- Security and reliability: prevent abuse, investigate errors, protect customers and maintain service availability. We rely on our legitimate interests and those of our Customers.
- Billing and business administration: manage orders, payments, tax, accounting and legal claims. We rely on contract, legitimate interests and legal obligations as applicable.
- Communications: send requested login links and essential service messages, and answer enquiries. We rely on contract and legitimate interests.
- Legal compliance: respond to lawful requests and protect legal rights. We rely on legal obligation and legitimate interests as applicable.
Where we rely on legitimate interests, you may object by contacting us. We do not carry out solely automated decision-making that has legal or similarly significant effects on you.
4. What we do not do
- We do not sell or rent personal information or Customer Content.
- We do not use Customer Content for advertising or behavioural profiling.
- We do not use Customer Content to train AI models.
- We do not send Customer Content to a model provider for our own purposes.
If a Customer directs BoR to return information to its chosen AI tool, that tool receives the information on the Customer's instruction and its own privacy terms apply.
5. Who receives information
Information is available to authorised members of the relevant Customer according to its permissions. We also use carefully selected infrastructure and email providers to operate BoR. Our Subprocessor Register names them, explains their functions and identifies processing locations.
We may disclose information to professional advisers bound by confidentiality; to courts, regulators or law enforcement where lawfully required; or as part of a corporate transaction where the recipient is bound to protect it. We do not treat a corporate transaction as permission to change the uses promised in this notice.
6. International transfers
Our primary database is hosted in London. Cloudflare operates a global network and Resend stores email account data and delivery records in the United States. Where UK personal information is transferred to a country without applicable UK adequacy regulations, we use approved contractual safeguards and any required transfer assessment. Contact us to request more information about those safeguards.
7. Retention and deletion
- Customer Content: retained while the Customer uses the Service. After termination it is available for export for 30 days, then deleted from active systems within 30 days. Restricted backup copies age out through provider backup cycles and are not restored except for disaster recovery.
- Account and permission records: retained while the account is active and normally deleted or anonymised within 30 days after the Customer's deletion period, unless needed for security, disputes or law.
- Login and session secrets: login links expire after 10 minutes; browser sessions expire after 30 days. Expired records may be retained for a limited period for fraud prevention and security before deletion.
- Security and network records: retained according to provider and operational schedules, normally no longer than 90 days unless required to investigate an incident.
- Transaction and legal records: retained for the period required by tax, accounting and limitation laws, normally up to seven years.
8. Security
We use encryption in transit, provider encryption at rest, hashed credentials, least-privilege database roles, tenant and area access controls, short-lived OAuth access tokens, restricted sessions and security testing. No system can guarantee absolute security. If you suspect a problem, contact us promptly.
9. Cookies and local storage
The public website currently sets no optional analytics or advertising cookies. When authenticated web access is made available, it uses a strictly necessary, secure, HTTP-only session cookie to keep a user signed in. We will ask for consent before setting any non-essential cookie or similar technology.
10. Your rights
Depending on the circumstances, UK data-protection law gives you rights to access, correct, erase, restrict or receive personal information, and to object to processing. Where processing relies on consent, you may withdraw it. These rights may be limited by law and depend on whether ALL SURE LTD or the Customer is the controller.
Send requests concerning our controller data to info@logsure.io. We may need to verify your identity. For information inside a brain controlled by another person or organisation, contact that Customer first.
You may complain to the Information Commissioner's Office. We would appreciate the opportunity to address your concern first.
11. Children
BoR accounts are for people aged 18 or over and the Service is not directed to children. An adult may include information about a child in a personal or family brain only where they have the right to do so and use appropriate access controls.
12. Changes
We will keep this notice accurate as the Service changes. We will update the version and effective date and give Customers advance notice of a material change to how we use or disclose personal information. A new unrelated use of Customer Content would require a compatible lawful basis and, where appropriate, the Customer's explicit agreement.
13. Contact
Email info@logsure.io. ALL SURE LTD is registered in England and Wales under company number 16710999. Registered office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ. ICO registration: C1904601.