Privacy Policy
This Privacy Policy describes how Brontara LLC ("Brontara," "we," "us," or "our") collects, uses, stores, and shares information when you access or use brontara.co and any software, platforms, applications, dynamic tools, or SaaS products operated under the Brontara umbrella, including but not limited to Cahori, Sualei, Kompara, Taalcip, Stemali, Karsabou, Boujaya, Sorotster, Suaralei, Lokstraat, Periplus (and related legal intake tools), AI Trucking (aitrucking.brontara.co), and any other current or future Brontara products (collectively, the "Services"). By using the Services, you agree to the practices described in this Policy. This Policy works together with the Master Terms of Use.
Roles Under Data Protection Law
- Brontara as a Data Controller: We act as a Data Controller for account details, billing records, direct user settings, and general website interaction data.
- Brontara as a Data Processor: When providing SaaS applications to business accounts who upload Customer Content, legal intake data, or health records, Brontara acts as a Data Processor on behalf of the customer. A separate Data Processing Addendum (DPA) or Business Associate Agreement (BAA) governs those business processing activities and prevails over conflicting terms in this Policy.
1. What We Collect
We collect only the information necessary to operate, secure, and deliver the Services:
- Account Information: Name, email address, job title (optional), and company details provided during account setup.
- User Content / Inputs: Text, media, prompts, conversation histories, tasks, voice recordings, uploaded documents, logistics parameters, or other materials you submit to any Brontara product to render outputs and maintain session states.
- Usage & System Diagnostics: Feature interactions, session durations, system performance metrics, and error logs used for security and operational monitoring.
- Billing Information: Payments are processed directly by third-party payment gateways (e.g., Stripe). Brontara stores tokenized payment references and invoice history; we do not store raw payment card numbers.
- Device & Technical Data: IP addresses, browser types, operating system details, and technical headers collected automatically for security monitoring and fraud prevention.
- Product-Specific Inputs (only when using relevant tools): Suaralei & voice tools — uploaded audio files, voice samples, and generated synthetic audio scripts. AI Trucking — Hours-of-Service (HOS), routing parameters, fleet metrics, payroll/tax inputs, or logistics data. Lokstraat — target website domain configurations and user-approved content modifications. Periplus & legal tools — case intake questionnaires, client communications, and legal documentation. Healthcare products — any Protected Health Information (PHI) processed under an executed BAA.
Biometric Disclaimer: We do not extract biometric voiceprints, facial geometry, or unique biometric identifiers from uploaded content. Voice samples submitted to Suaralei are processed strictly as operational audio inputs to render requested synthetic outputs.
2. How We Use Information & AI Model Boundaries
We use collected data solely to operate the Services, satisfy contractual duties, and maintain system integrity:
Service Delivery & Local Runtime Inference
Executing AI responses, rendering voice audio (Suaralei), calculating logistics routes (AI Trucking), delivering client-side web changes (Lokstraat), and running legal intake workflows (Periplus). Core AI prompts and runtime model inferences are executed on Brontara's self-hosted infrastructure.
GDPR Legal Bases for Processing
- Contract Performance (Art. 6(1)(b)): Delivering core product features, processing billing, and fulfilling platform requests.
- Legitimate Interests (Art. 6(1)(f)): Securing our infrastructure, detecting fraud, fixing system bugs, and improving overall service performance.
- Consent (Art. 6(1)(a)): Processing optional analytics cookies or voluntary marketing opt-ins.
- Legal Obligation (Art. 6(1)(c)): Retaining financial records and responding to lawful legal requests.
AI Model Training Boundaries (Master Terms Alignment)
- We do not use Customer Content (prompts, logs, voice samples, legal intake data, or health records) to train, fine-tune, or improve public or shared AI models, except in aggregated and fully de-identified form.
- Absolute Bar: Protected Health Information (PHI) and attorney-client privileged intake data (e.g., Periplus) are strictly prohibited from being used for AI model training or fine-tuning under any circumstances.
Transactional Communications
Sending receipts, password reset links, security notices, maintenance alerts, and annual renewal reminders. We do not send unsolicited commercial marketing without your explicit opt-in.
3. Data Infrastructure, Security & Retention Schedule
Infrastructure & Hosting
Brontara Services are hosted on self-hosted, private server infrastructure located in Denver, Colorado, USA. Customer data and AI prompts remain within Brontara's controlled infrastructure environments during runtime processing.
Data Security Controls
- Data in Transit: All network communication is encrypted using industry-standard TLS 1.2+ protocols.
- Data at Rest & Backups: Live operational databases on disk are isolated via system role-based access controls (RBAC) and strict file permissions (660). Database backups are encrypted using gpg-AES256 before offsite storage. Sensitive fields (such as PHI under an executed BAA) utilize per-organization payload encryption.
Retention Schedule
- Conversational Content: Retained while needed to provide the Service. For the Cahori assistant, conversational rows (messages and conversation memory) are purged after eighteen (18) months (548 days) by an automated retention task; reference and profile data are kept until you delete your account. Other Brontara products retain operational logs only as long as necessary to deliver and secure the Service.
- Voice Samples: Audio submitted to Suaralei is automatically deleted thirty (30) days after generation by a scheduled cleanup task, or sooner if you configure a shorter window in account settings.
- Account Records: Core account and billing metadata are retained while your account is active and for the period required by law for accounting and tax compliance.
- Post-Termination Export Window: Upon account cancellation, Customer has a thirty (30) day window to export Customer Content via platform controls. After 30 days, remaining Customer data will be purged or de-identified, subject to legal holds or BAA requirements.
- Web Server Logs: Our web servers keep standard access logs of requests — including the network address a request came from, what was requested, and when — for fourteen (14) days. These are used only to operate and secure the Services, diagnose faults, and detect abuse.
4. Subprocessors & External Integrations
Brontara engages a limited group of third-party service providers to support specific platform functions under strict data protection agreements:
- Infrastructure & Security: Cloudflare (CDN, edge routing, web application firewall, and secure tunnel infrastructure).
- Payment Processing: Stripe (secure subscription billing and card handling).
- Transactional Messaging: Transactional SMTP email gateways; Telegram infrastructure (specifically to route incoming voice messages for Cahori voice-capture features).
- Audit & Data Enrichment APIs (Lokstraat): Google Places, Firecrawl, and DataForSEO (queried strictly during live audit tasks to fetch third-party web metric data).
No Sale or Brokerage: We do not sell, rent, trade, or share personal data with third-party data brokers or advertisers. We do not run third-party advertising on any Brontara platform.
Customers may request the current list of subprocessors and a Data Processing Addendum (including Standard Contractual Clauses where applicable) by emailing [email protected]. We will provide notice of material changes to subprocessors that process personal data.
5. Web Snippets & Lokstraat (lok.js)
When you deploy the Lokstraat snippet or any Brontara script on a target website:
- Zero Visitor Tracking: The script sends a basic, non-identifying site-ID ping to our servers solely to confirm active installation status.
- No Visitor Personal Data: The snippet does not collect, track, or store personal information or browsing history regarding your website visitors.
- No Tracking Cookies: The snippet sets no cookies and uses no local storage mechanisms to track end users.
6. The Brontara Assistant
Brontara.co includes an assistant that answers questions about our products using our published user guides and About page. It requires no account and sets no cookies.
Questions You Ask
- What We Keep: The text of your question, which guide sections were used to answer it, and the date. We use this only to find gaps in our documentation — the questions our guides fail to answer are the ones we most want to see.
- What We Do Not Keep With It: We do not record your browser, session, account, or any cookie alongside your question, and we do not store your network address with it. We cannot tell which questions came from the same person.
- Scrubbing Before Storage: Question text is automatically stripped of anything that looks like personal information — email addresses, phone numbers, long numeric strings, and web addresses containing tracking parameters — and replaced with placeholders before it is written.
- Retention: Question records are deleted automatically after ninety (90) days by a scheduled retention task.
Keeping the Assistant Available
The assistant is open to everyone and needs no account, so to stop any one visitor overwhelming it — or misusing the message form — we count how many recent requests have come from each visitor. We do this using a scrambled token derived from your network address rather than storing the address itself, we never keep it alongside your questions, and it is deleted within twenty-four (24) hours.
If You Leave a Message
When the assistant cannot answer your question, you can choose to send a message to a human. The name, email address, and message you enter are emailed to us so that we can reply, and are not added to the question records described above. We use them only to answer you.
Voice Input
If you use the microphone, your audio is sent to speech-recognition software running on Brontara's own hardware in Colorado. It is transcribed and immediately discarded — never written to storage, never sent to any third-party speech service, and never used to train any model.
No Cookies
The assistant sets no cookies and uses no local storage. Your conversation exists only in your browser and disappears when you close the tab.
7. Special Categories of Data
- Protected Health Information (PHI): Governed exclusively by HIPAA and a fully executed Business Associate Agreement (BAA). PHI is never used for model training.
- Attorney-Client Privileged Intake (Periplus): Handled under strict confidentiality parameters and restricted strictly to rendering legal intake operations; never used for model training.
- Voice Samples (Suaralei): Uploaded solely to generate requested audio outputs. Users represent under Section 3 of the Master Terms that they hold explicit, verifiable legal consent for all submitted audio recordings.
8. Your Privacy Rights
Depending on your jurisdiction, you may exercise the following rights regarding your personal data:
- Access & Portability: Request details regarding personal data we hold about you or export your User Content.
- Correction & Deletion: Request correction of inaccurate account data or complete deletion of your account and personal records (fulfilled within 30 days, subject to legal retention duties or BAA requirements).
- Restriction & Objection: Object to processing based on legitimate interests or restrict specific data processing activities.
California Residents (CCPA/CPRA)
- You have the right to know what personal data is collected, request deletion, request correction, and receive non-discriminatory treatment for exercising your rights.
- Sensitive Personal Information: You have the right to limit the use of Sensitive Personal Information to that which is necessary to perform the Services.
- No Sale/Sharing: Brontara does not sell or share personal information for cross-context behavioral advertising purposes.
EU / UK Residents (GDPR / UK GDPR)
In addition to the rights above, you have the right to lodge a complaint with your local Data Protection Supervisory Authority.
To exercise any privacy right, contact us at [email protected] or [email protected].
9. Cookies & First-Party Analytics
We use essential technical cookies to keep you authenticated and secure active user sessions.
Our cookie management layer (brontara_consent.js) offers optional, privacy-friendly first-party analytics when you select "Accept All." These first-party analytics collect basic feature-interaction metrics to help us fix system bugs, do not use cross-site tracking cookies, and are enabled only with your consent. You can clear or manage cookies via your browser settings at any time; disabling essential cookies will prevent active login sessions.
10. International Data Transfers
Brontara LLC operates its self-hosted infrastructure within the United States. If you access the Services from outside the U.S., your information will be processed in the United States. Where required for international business transfers, Brontara relies on standard contractual safeguards (such as EU Standard Contractual Clauses).
11. Children's Privacy
Our Services are intended strictly for commercial and adult users aged 18 or older. We do not knowingly collect personal data from children under 18. If we discover personal data collected from a minor, we will delete it promptly.
12. Policy Amendments
Brontara LLC reserves the right to update this Privacy Policy. Material changes will be communicated via email or in-app notice at least 14 days before taking effect. Continued use of the Services after the effective date constitutes acceptance.
13. Privacy Contact & Registered Office
For privacy inquiries, DPA requests, or legal notices, contact Brontara LLC at:
Privacy Support: [email protected]
Legal & DPA Requests: [email protected]
Registered Office Address:
Brontara LLC
1500 N Grant St, Ste N
Denver, CO 80203, USA