Cerebro-V

Privacy Policy

Last updated 6 August 2026

Cerebro-V is a content platform operated by [LEGAL ENTITY — set before launch]. This policy explains what we collect, why, and what we do with it. It covers app.cerebro-v.com.

What we collect

  • ·Account details — your name, email address and a hashed password. We never store your password in a readable form.
  • ·Workspace content — the brands, briefs, posts and images you create in Cerebro-V.
  • ·Connected account credentials — access tokens for the services you connect, such as Google Search Console and WordPress. These are encrypted at rest.
  • ·Usage records — which features were used and when, for billing and for the audit trail.

Google user data

When you connect Google Search Console, we request the webmasters.readonly scope. That is read-only: we can see your search performance data and cannot modify anything in your Search Console account.

  • ·We use it only to show you search performance and to identify content opportunities inside Cerebro-V.
  • ·We do not sell it, share it with third parties, or use it for advertising.
  • ·We do not use it to train any machine learning model.
  • ·You can disconnect at any time from Settings, or revoke access from your Google account permissions page. We delete the stored tokens when you do.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

WordPress

Connecting WordPress issues Cerebro-V an application password through WordPress's own authorisation screen. We never see or store your WordPress account password. The application password is encrypted at rest and used only to publish and manage the content you ask us to. You can revoke it at any time from your WordPress profile.

AI processing

Briefs and brand information are sent to Google's Gemini models to generate content. We do not use your content to train models, and we do not permit our providers to do so.

Where your data lives

Data is stored in the United Kingdom and the European Economic Area. Content is isolated per workspace at the database level, so one customer's data cannot be read by another.

How long we keep it

  • ·Account and workspace content — for as long as your account is open.
  • ·Connected account tokens — until you disconnect the service or close your account.
  • ·Audit logs — 12 months.
  • ·After you close your account, we delete your data within 30 days, except where we are legally required to retain it.

Your rights

Under UK GDPR you can ask for a copy of your data, ask us to correct or delete it, object to processing, or ask us to restrict it. Email [email protected] and we will respond within one month.

Security

  • ·All traffic is encrypted in transit with TLS.
  • ·Connected account credentials are encrypted at rest with AES-256-GCM, bound to your workspace so they cannot be read outside it.
  • ·Workspace isolation is enforced by the database, not only by application code.
  • ·Two-factor authentication is available and required for accounts with publishing rights.

Contact

[email protected]