Legal
Privacy Policy
What we collect, why we collect it, who we share it with, and what you can ask us to do about it.
Last updated
3 August 2026
Draft
This policy is a working draft pending legal review. It describes our actual practices, but it is not yet final.
1. Who we are
Brackits is operated by Course Scale Up Ltd, a company registered in England and Wales (company number 15327661), registered office Arundel House, Foxhole Road, Chorley, England, PR7 1NY ("Brackits", "we", "us").
We are the data controller for the personal data described in this policy, except where we act as a processor on your behalf — see section 7.
Questions about this policy or your data: [email protected].
2. The short version
- We collect the minimum we need to run your account and generate your designs.
- We do not sell your data, and we do not run advertising or analytics trackers on this website.
- Your design prompts and brand guidelines are sent to third-party AI providers so they can be processed. We do not permit them to train on your data.
- We never receive your Thinkific password. We hold an OAuth token, encrypted, which you can revoke at any time.
- Learner data from your school reaches us only if you explicitly switch on a personalization option. It is off by default.
3. What we collect
Account and team data
Authentication is handled by WorkOS AuthKit. We store your name, email address, and the identifier WorkOS assigns you. We also store the teams you belong to, your role in them, and the email addresses of people you invite.
Waitlist
If you request a private-beta invite we store the email address you submit, so we can contact you when a place opens up.
Content you create
Projects, design guidelines, generated designs and their version history, and any images you upload. This content is yours; we process it to provide the service.
Integration credentials
When you connect a Thinkific school we store the OAuth access token, encrypted at rest. When you connect a WordPress site we store a hash of the site key, not the key itself. We never ask for or receive your password on any connected platform.
AI prompts and usage records
The instructions you give the design agent, any reference images you attach, and the resulting conversation. We also record per-request metadata — model used, token counts, duration, and cost — so we can operate and bill the service accurately.
Technical data
Server logs including IP address, user agent, and request paths, retained for security and debugging. Contact-form submissions record your IP address and user agent to help us deal with spam.
Cookies
We use a session cookie to keep you signed in, a CSRF cookie to protect form submissions, and a local preference for light or dark appearance. That is all. There are no analytics, advertising, or third-party tracking cookies on this site, so we do not show a cookie banner.
4. Why we use it, and our lawful basis
| Purpose | Data | Lawful basis |
|---|---|---|
| Provide your account and workspace | Account, team, content | Performance of a contract |
| Generate and publish designs | Prompts, guidelines, assets | Performance of a contract |
| Publish to connected platforms | Integration credentials | Performance of a contract |
| Operate, secure, and debug the service | Technical and usage data | Legitimate interests |
| Manage the private beta waitlist | Email address | Consent |
| Reply to your enquiries | Contact-form data | Legitimate interests |
| Meet legal and accounting obligations | Account and transaction records | Legal obligation |
5. AI processing
Brackits generates designs using large language models operated by third parties. To do that, we send them your design instructions, your brand guideline, any reference images, and the current contents of the design being edited.
- Requests are routed through OpenRouter by default, with Anthropic and OpenAI as direct fallbacks.
- We use these providers under terms that prohibit training on data submitted through their APIs.
- Providers may retain request data briefly for abuse monitoring, per their own policies.
- Do not put personal data of your learners, or any confidential information, into a design prompt. There is no reason to, and we cannot recall it once sent.
If you connect an external MCP server of your own, prompts and tool results also travel to whatever endpoint you configure. That connection is yours to vet.
6. Learner data from your Thinkific school
Some Brackits designs can personalise themselves — greeting a signed-in student by name, or listing the courses they are enrolled in. This is the one place where your learners' data touches our systems, so we want to be precise about it.
- The personalization tiers are off by default. You switch them on per section, in your Thinkific theme.
- When enabled, we read the signed-in learner's profile and enrollment records from Thinkific's API to render the design. Requests are authenticated with a signed handle, not with an identity supplied by the browser.
- The standalone shareable embed page mints an anonymous handle and accepts no visitor identity from the URL, so it cannot be used to look someone up.
- We do not use learner data for any purpose other than rendering the design you asked for, and we do not send it to AI providers.
For this data you are the controller and we are your processor. If you need a data processing agreement for your own compliance, email [email protected] and we will provide one.
7. Who we share data with
We do not sell personal data. We share it only with the service providers below, each of which processes it on our instructions.
| Provider | What it does | Data involved |
|---|---|---|
| WorkOS | Authentication | Name, email, session |
| Laravel Cloud | Application hosting and database | All stored data |
| Cloudflare | Object storage, CDN, design compilation, screenshots | Uploaded assets, published designs |
| OpenRouter | AI request routing (default provider) | Prompts, guidelines, design content |
| Anthropic | AI model provider | Prompts, guidelines, design content |
| OpenAI | AI model provider (fallback) | Prompts, guidelines, design content |
| Firecrawl | Website scraping for brand import | The URL you ask us to import |
| ScreenshotOne | Screenshot capture for brand import | The URL you ask us to import |
| Bunny Fonts | Webfont delivery on this website | IP address (no cookies, no tracking) |
We may also disclose data where we are legally required to, or to establish or defend legal claims. If Brackits is acquired, data would transfer to the acquirer under this policy.
8. International transfers
Several providers above are based outside the UK, primarily in the United States. Where personal data is transferred outside the UK we rely on the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with appropriate technical safeguards.
9. How long we keep it
- Account and content: for as long as your account is open. Delete your team and we remove its projects, designs, guidelines, and assets.
- Waitlist entries: until you are invited, or you ask us to remove you.
- Contact enquiries: up to 24 months.
- AI usage records: retained for accounting and capacity planning; they contain token counts and costs, not prompt text.
- Server logs: typically 30 days.
- Integration credentials: deleted when you disconnect the integration.
10. Security
All traffic is encrypted in transit. Integration credentials are encrypted at rest. Access to
production systems is restricted to people who need it. Published embeds render inside a Shadow DOM
and strip script tags and javascript: URLs before rendering.
No system is perfectly secure. If you believe you have found a vulnerability, please report it to [email protected] rather than disclosing it publicly.
11. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Have your data erased.
- Restrict or object to how we process it.
- Receive your data in a portable format.
- Withdraw consent where consent is the basis we rely on.
Email [email protected] and we will respond within one month. If you are unhappy with our response you can complain to the Information Commissioner's Office at ico.org.uk.
12. Children
Brackits is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. Note that learner data flowing through personalised embeds is your responsibility as the school operator.
13. Changes to this policy
We will update the date at the top of this page whenever this policy changes. For material changes we will email account holders.
Questions
Ask us anything about your data.
If something here is unclear, or you need a data processing agreement for your own compliance, we'll help.
Or email [email protected] directly.