Legal

Privacy Policy

What we collect, why we collect it, who we share it with, and what you can ask us to do about it.

Last updated

3 August 2026

Draft

This policy is a working draft pending legal review. It describes our actual practices, but it is not yet final.

1. Who we are

Brackits is operated by Course Scale Up Ltd, a company registered in England and Wales (company number 15327661), registered office Arundel House, Foxhole Road, Chorley, England, PR7 1NY ("Brackits", "we", "us").

We are the data controller for the personal data described in this policy, except where we act as a processor on your behalf — see section 7.

Questions about this policy or your data: [email protected].

2. The short version

  • We collect the minimum we need to run your account and generate your designs.
  • We do not sell your data, and we do not run advertising or analytics trackers on this website.
  • Your design prompts and brand guidelines are sent to third-party AI providers so they can be processed. We do not permit them to train on your data.
  • We never receive your Thinkific password. We hold an OAuth token, encrypted, which you can revoke at any time.
  • Learner data from your school reaches us only if you explicitly switch on a personalization option. It is off by default.

3. What we collect

Account and team data

Authentication is handled by WorkOS AuthKit. We store your name, email address, and the identifier WorkOS assigns you. We also store the teams you belong to, your role in them, and the email addresses of people you invite.

Waitlist

If you request a private-beta invite we store the email address you submit, so we can contact you when a place opens up.

Content you create

Projects, design guidelines, generated designs and their version history, and any images you upload. This content is yours; we process it to provide the service.

Integration credentials

When you connect a Thinkific school we store the OAuth access token, encrypted at rest. When you connect a WordPress site we store a hash of the site key, not the key itself. We never ask for or receive your password on any connected platform.

AI prompts and usage records

The instructions you give the design agent, any reference images you attach, and the resulting conversation. We also record per-request metadata — model used, token counts, duration, and cost — so we can operate and bill the service accurately.

Technical data

Server logs including IP address, user agent, and request paths, retained for security and debugging. Contact-form submissions record your IP address and user agent to help us deal with spam.

Cookies

We use a session cookie to keep you signed in, a CSRF cookie to protect form submissions, and a local preference for light or dark appearance. That is all. There are no analytics, advertising, or third-party tracking cookies on this site, so we do not show a cookie banner.

4. Why we use it, and our lawful basis

Purpose Data Lawful basis
Provide your account and workspace Account, team, content Performance of a contract
Generate and publish designs Prompts, guidelines, assets Performance of a contract
Publish to connected platforms Integration credentials Performance of a contract
Operate, secure, and debug the service Technical and usage data Legitimate interests
Manage the private beta waitlist Email address Consent
Reply to your enquiries Contact-form data Legitimate interests
Meet legal and accounting obligations Account and transaction records Legal obligation

5. AI processing

Brackits generates designs using large language models operated by third parties. To do that, we send them your design instructions, your brand guideline, any reference images, and the current contents of the design being edited.

  • Requests are routed through OpenRouter by default, with Anthropic and OpenAI as direct fallbacks.
  • We use these providers under terms that prohibit training on data submitted through their APIs.
  • Providers may retain request data briefly for abuse monitoring, per their own policies.
  • Do not put personal data of your learners, or any confidential information, into a design prompt. There is no reason to, and we cannot recall it once sent.

If you connect an external MCP server of your own, prompts and tool results also travel to whatever endpoint you configure. That connection is yours to vet.

6. Learner data from your Thinkific school

Some Brackits designs can personalise themselves — greeting a signed-in student by name, or listing the courses they are enrolled in. This is the one place where your learners' data touches our systems, so we want to be precise about it.

  • The personalization tiers are off by default. You switch them on per section, in your Thinkific theme.
  • When enabled, we read the signed-in learner's profile and enrollment records from Thinkific's API to render the design. Requests are authenticated with a signed handle, not with an identity supplied by the browser.
  • The standalone shareable embed page mints an anonymous handle and accepts no visitor identity from the URL, so it cannot be used to look someone up.
  • We do not use learner data for any purpose other than rendering the design you asked for, and we do not send it to AI providers.

For this data you are the controller and we are your processor. If you need a data processing agreement for your own compliance, email [email protected] and we will provide one.

7. Who we share data with

We do not sell personal data. We share it only with the service providers below, each of which processes it on our instructions.

Provider What it does Data involved
WorkOS Authentication Name, email, session
Laravel Cloud Application hosting and database All stored data
Cloudflare Object storage, CDN, design compilation, screenshots Uploaded assets, published designs
OpenRouter AI request routing (default provider) Prompts, guidelines, design content
Anthropic AI model provider Prompts, guidelines, design content
OpenAI AI model provider (fallback) Prompts, guidelines, design content
Firecrawl Website scraping for brand import The URL you ask us to import
ScreenshotOne Screenshot capture for brand import The URL you ask us to import
Bunny Fonts Webfont delivery on this website IP address (no cookies, no tracking)

We may also disclose data where we are legally required to, or to establish or defend legal claims. If Brackits is acquired, data would transfer to the acquirer under this policy.

8. International transfers

Several providers above are based outside the UK, primarily in the United States. Where personal data is transferred outside the UK we rely on the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with appropriate technical safeguards.

9. How long we keep it

  • Account and content: for as long as your account is open. Delete your team and we remove its projects, designs, guidelines, and assets.
  • Waitlist entries: until you are invited, or you ask us to remove you.
  • Contact enquiries: up to 24 months.
  • AI usage records: retained for accounting and capacity planning; they contain token counts and costs, not prompt text.
  • Server logs: typically 30 days.
  • Integration credentials: deleted when you disconnect the integration.

10. Security

All traffic is encrypted in transit. Integration credentials are encrypted at rest. Access to production systems is restricted to people who need it. Published embeds render inside a Shadow DOM and strip script tags and javascript: URLs before rendering.

No system is perfectly secure. If you believe you have found a vulnerability, please report it to [email protected] rather than disclosing it publicly.

11. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Have inaccurate data corrected.
  • Have your data erased.
  • Restrict or object to how we process it.
  • Receive your data in a portable format.
  • Withdraw consent where consent is the basis we rely on.

Email [email protected] and we will respond within one month. If you are unhappy with our response you can complain to the Information Commissioner's Office at ico.org.uk.

12. Children

Brackits is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. Note that learner data flowing through personalised embeds is your responsibility as the school operator.

13. Changes to this policy

We will update the date at the top of this page whenever this policy changes. For material changes we will email account holders.

Questions

Ask us anything about your data.

If something here is unclear, or you need a data processing agreement for your own compliance, we'll help.

Contact us

Or email [email protected] directly.