Brimley

Legal · Privacy Policy

Privacy Policy

Last updated: 30 April 2026

This Privacy Policy describes how FluxAI US LLC, trading as Brimley ("Brimley", "we", "us"), collects, uses, shares, and protects personal data in connection with the Brimley platform and website (collectively, the "Service").

Brimley operates as a data controller in respect of personal data it collects directly (e.g. account holders and visitors to our website), and as a data processor in respect of personal data our customers upload or generate through the Service. When we act as a processor, the Data Processing Addendum applies in addition to this policy.

1. Personal data we collect

1.1 From account holders

  • Account information — name, work email address, organisation, password hash, time zone, and similar identifiers.
  • OAuth tokens — when you connect Google Workspace, we store the OAuth refresh token issued to us under the gmail.send and gmail.modify scopes.
  • Billing — billing contact, plan, invoice history. Card data is held by our payment processor; we never see the full card number.
  • Usage data — pages viewed, features used, request logs, error reports, and session metadata, used for security and product improvement.

1.2 From customers (about their prospects)

When customers use the Service, they provide or generate personal data about the business contacts they wish to reach ("Contact Data"). Contact Data typically includes a business email address, name, employer, job title, professional social profile, and publicly available business information. Customers may also upload their own lists.

Brimley supplements Contact Data with information licensed from third-party B2B data providers. Where Brimley acts as a controller of Contact Data — for example, when we maintain a suppression list to honour opt-out requests across the platform — this Privacy Policy applies.

2. Lawful basis

Where the EU/UK GDPR applies, we rely on the following lawful bases:

  • Performance of a contract — to provide the Service to you and your organisation.
  • Legitimate interests — to operate, secure, and improve the Service; to communicate with you about your account; and to maintain a B2B contact-data product where the data subject's role-based interest is reasonably balanced against our processing.
  • Consent — for any optional analytics, marketing cookies, or product communications you opt into.
  • Legal obligation — to comply with applicable laws, including responding to lawful data-subject requests.

3. How we use personal data

  • To deliver, secure, and improve the Service;
  • To authenticate users and manage their organisations;
  • To generate and send outbound messages on your instruction;
  • To honour suppression, do-not-contact, and unsubscribe requests across our platform;
  • To bill you and prevent payment fraud;
  • To respond to your support requests and legal-rights requests;
  • To comply with legal obligations and to enforce our Terms.

We do not train AI models on your Customer Data, and we do not sell personal data.

4. Sharing & subprocessors

We share personal data only with the following categories of recipients:

  • Hosting and infrastructure providers that host the Service or store backups;
  • Email-delivery providers — specifically, Google Workspace, which sends messages on your behalf using credentials you have authorised;
  • AI inference providers that generate message drafts from your prompts; these providers process input on a transient basis and are contractually prohibited from training on your data;
  • B2B data providers from whom we license Contact Data;
  • Payment processors that handle billing;
  • Professional advisors (auditors, lawyers, accountants);
  • Authorities, where required by law.

An up-to-date list of named subprocessors is available on request from [email protected]. Where required by the GDPR, our written agreements with subprocessors impose data-protection obligations equivalent to those in our DPA with you.

5. International transfers

Brimley and several of its subprocessors operate outside the European Economic Area or the United Kingdom. Where we transfer personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) or another lawful transfer mechanism.

6. Retention

We retain personal data for as long as it is necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Customer Data is deleted or returned within 30 days of account closure, except where retention is required by law (for example, financial records). Suppression-list entries are retained indefinitely so that an opt-out can be honoured even after the underlying record is deleted.

7. Your rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you;
  • Correct or update inaccurate personal data;
  • Request deletion ("right to be forgotten");
  • Object to or restrict certain processing;
  • Receive your personal data in a portable format;
  • Withdraw consent where processing relies on consent;
  • Lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office).

California residents have additional rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of the sale or sharing of personal information. Brimley does not sell personal data.

To exercise any of these rights — including to remove your business contact details from our suppression-aware database — email [email protected]. We will verify your identity before acting on a request and will respond within the timeframe required by your local law (typically 30 days).

8. Cookies

The Service uses a small number of strictly necessary cookies to authenticate sessions and protect against cross-site request forgery. We do not use third-party advertising or behavioural-tracking cookies.

9. Security

We maintain administrative, technical, and physical safeguards designed to protect personal data, including TLS in transit, at-rest encryption for sensitive credentials, scoped access controls, and audited logs. No system is perfectly secure; you are responsible for using strong, unique credentials and for the security of any device that has access to your account.

10. Children

The Service is not directed to children under 16, and we do not knowingly collect personal data from them.

11. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be notified by email or in-product notice.

12. Contact

For privacy questions, contact [email protected].

Confirm

Connect a sending mailbox?

Brimley sends from your Gmail — your reputation, your sender, your rules. You can keep building this campaign without it, but it won't be able to launch until a mailbox is connected.

Takes about 30 seconds. Brimley only asks for permission to send emails on your behalf and track replies on those threads — we never read the rest of your inbox.

Connect Gmail →