Legal
Security and data
How your content, your learners' data and your credentials move through Brackits, in plain terms. The privacy policy and terms remain the binding documents; each section below links to the one it summarises.
Last updated
23 September 2026
Found a problem?
If you think you have found a vulnerability, email [email protected] rather than disclosing it publicly.
The short version
- Your instructions, brand guideline and designs go to AI providers so they can generate designs. Your learners' data does not.
- Learner data from Thinkific is read when a learner views a page, and only while the Brackits section's personalization box is ticked. What we pass to your designs never includes a learner's name or email address.
- We never see your passwords: sign-in happens on WorkOS, Thinkific connects over OAuth, and cards are entered on Stripe's pages.
- Integration credentials are encrypted at rest.
- Everything in Brackits belongs to a team, and people see only what their role in it allows.
AI processing
To generate a design we send the model your instructions, the project's name and description, its design guideline, any reference images, and the current design being edited. Requests go through OpenRouter by default, with direct providers as fallbacks.
Learner data is no part of it. Designs are generated in Brackits ahead of time; a learner's details are only fetched later, when they view the page, and never go to a model.
Which providers we use, and what they may keep, is in section 5 of our privacy policy.
Learner data from Thinkific
The Brackits section on your Thinkific site has one switch, Allow Brackits to fetch personalization data, and it is ticked when you add the section. While it is ticked and a learner is signed in, the page hands us a handle for that learner, signed on Thinkific's side and valid for five minutes, so the browser cannot change whose data it asks for. Untick the box and the section sends us nothing about your learners.
With the handle we read the learner's profile and enrollments from Thinkific's API, along with your course catalog, and keep the learner's slice in a cache for about a minute. Before the result reaches your design we blank the learner's first name, last name and email address, so what a design gets from us can show their courses and progress but never their name or email.
What the profile holds, how form entries record a learner, and why we act as your processor for this data are in section 6 of the privacy policy.
Connected platforms
We never ask for your password on Thinkific or WordPress. Thinkific connects over OAuth, and WordPress with a site key. Both are stored encrypted at rest, and disconnecting an integration deletes them.
What connecting authorises us to do is in section 7 of our terms.
Sign-in and access
Sign-in happens on a page hosted by WorkOS, so your password never reaches Brackits.
Inside Brackits everything belongs to a team. Teams have Owner, Admin and Member roles, and only owners and admins can invite people or manage billing. Each project also has its own Owner, Editor and Viewer roles, so a client or contractor can see one project without the rest.
Claude and other MCP clients, and the Chrome extension, sign in through your browser and receive a token rather than your password. MCP tools act as you, in your current team, under the same roles as the app. The extension's token can only list your designs and fetch them.
The public endpoints your published designs call from a visitor's browser are rate limited by IP address.
Keeping your own sign-in safe is covered in section 3 of our terms.
Designs on your site
A published design renders inside a Shadow DOM, which keeps your site's styles and the design's
apart. Before it renders, script tags and javascript: links in its HTML are removed. A
design's own behaviour runs as a separate script on your page, as any embed's does, which is one more
reason to review a design before you publish it.
Two placements write the design into the page itself instead: the Thinkific SEO snapshot and the WordPress plugin's SEO mode.
Reviewing what the AI produces is your call; section 5 of our terms explains why.
Forms and data tables
When a design collects entries, a sign-up form for example, they are saved to a data table in your project. Each table has a row limit and stops accepting entries when it is full. A design can read entries back only if you allow it, and then only the fields you name. You can search, export as CSV and delete entries in Brackits.
How long we keep what you store is in section 9 of the privacy policy.
Payments
Plans are paid through Stripe. You enter your card, billing address and any VAT number on Stripe's checkout and manage them in Stripe's billing portal, so card details never reach our servers. We keep the Stripe references that tie your team to its subscription and invoices.
How plans, credit and cancelling work is on the billing and cancellation page.
Where your data lives
Brackits is hosted on Laravel Cloud, with published designs and uploads stored on Cloudflare. WorkOS handles sign-in. OpenRouter, Anthropic and OpenAI run the AI models. Firecrawl and ScreenshotOne read a website you ask us to import, and Bunny Fonts serves this website's fonts. Payments go through Stripe.
What each provider receives, and how data leaves the UK, is in sections 7 and 8 of the privacy policy.
Agreements and questions
If you need a data processing agreement for your own compliance, email [email protected] and we will provide one. For anything this page doesn't answer, use our contact form.
Questions
Ask us how your data is handled.
If you are reviewing Brackits for your school or a client and need more detail than this page gives, we'll answer.
Or email [email protected] directly.