Skip to main content

Privacy Policy

Effective September 9, 2026. This explains what the Narrative Modeling App service collects, who else sees it, and how long we keep it. It sits alongside our Terms of Service.

1. Who we are

Noaysk Enterprises, LLC, dba Bria Strategy Group operates the Narrative Modeling App service and is the controller of the personal data described here. Where you upload a dataset containing other people’s personal data, you are the controller of that data and we process it on your behalf.

2. What we collect

  • Account data — the name, email address and profile image your Google or GitHub account releases to us when you sign in, plus the API keys you create.
  • Datasets you upload — the files themselves and everything derived from them: inferred schemas, column statistics, transformations, versions, trained models and prediction results. We do not inspect or restrict what is in them, so whether they contain personal data is your decision.
  • Usage records — the counts we meter for quotas (uploads, training runs, predictions), job status and timestamps, and server logs containing request paths, IP addresses and error details.
  • Billing data — your subscription tier and status. Card details go directly to Stripe; we never see or store them.

3. How we use it, and on what basis

We use account and dataset data to provide the service you asked for — storing your files, running analyses and training the models you request (performance of our contract with you). We use usage records and logs to enforce quotas, keep the service secure and debug failures (our legitimate interest in running a reliable service). We use billing data to take payment and meet our accounting obligations (contract and legal obligation).

We do not sell or share your personal data for advertising, and we do not use your datasets to train our own models. No automated decision producing legal effects about you is made by us; models you train are yours, and how you use them is your responsibility.

4. Sub-processors

Running the service means these third parties process data on our behalf. Each is bound by a data-processing agreement and may only use the data to provide their service to us.

Sub-processorWhat it does with your data
AWS S3Stores your uploaded dataset files and trained model artifacts.
MongoDB AtlasStores your account record, dataset metadata, and job history.
OpenAIGenerates dataset summaries, feature suggestions and result explanations. Receives your column names and up to five sample rows of the dataset being analysed.
StripeProcesses subscription payments and holds your billing details.
GoogleAuthenticates you if you sign in with Google. Receives no dataset content.
GitHubAuthenticates you if you sign in with GitHub. Receives no dataset content.

We will update this list before adding a new sub-processor that receives dataset content.

5. What the AI features send to OpenAI

This is the disclosure most people care about, so it gets its own section. When you use a dataset summary, an AI insight, a feature suggestion or a result explanation, we send OpenAI a description of your dataset: its column names, inferred types, summary statistics, and up to five rows sampled from the file. If those rows contain personal data, that personal data leaves our infrastructure.

These features are optional in the sense that the rest of the product works without them, and the service runs with the AI features disabled when no API key is configured. If you do not want dataset content sent to OpenAI, do not use the AI panels — or tell us at privacy@briaanalytics.com and we will disable them for your account.

6. Retention and deletion

We do not expire your data automatically. Datasets, models and their derived records stay until you remove them or your account is closed.

  • Deleting a dataset removes the uploaded file and the analysis records tied to it. Trained models are separate objects with their own delete action — deleting a dataset does not delete the models you trained from it, so delete those too if you want them gone.
  • Deleting everything — email privacy@briaanalytics.com and we will erase the data we hold for you, including records the self-service delete actions do not reach. We action these within 30 days, and the categories listed below are retained afterwards. Ask us to confirm a specific dataset or model has been removed and we will check it individually.
  • Backups — database snapshots (hourly for two days, daily for a week, weekly for four weeks) and versioned file storage mean a deleted record can survive in backups for up to 35 days after deletion, after which it is purged. We do not use these copies for anything other than disaster recovery.
  • What we keep afterwards — invoices and payment records for as long as tax and accounting law requires, and an append-only erasure log recording that a deletion happened, who asked for it and when. The log records the event, not the data that was deleted.

7. Your rights

Depending on where you live you may have the right to access, correct, export, delete or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. California residents additionally have the right to know what is collected and to not be discriminated against for exercising these rights; we do not sell or share personal information as those terms are defined by the CCPA.

Email privacy@briaanalytics.com to exercise any of these. We respond within 30 days and do not charge for it. If you are in the EU, UK or EEA and are unsatisfied with our response, you may complain to your local supervisory authority.

8. Cookies

We set strictly necessary cookies only: the session cookie that keeps you signed in and the CSRF token that protects the sign-in flow. There are no analytics, advertising or cross-site tracking cookies, which is why you see no consent banner.

If we ever add analytics, we will add a consent mechanism before turning it on and update this section.

9. Security

Data is encrypted in transit and at rest in our storage providers. Access is scoped per account: dataset, model and version records are keyed to their owner and checked on every request. Model artifacts are signed and verified before being loaded. Internal access to production is limited to the people who operate the service.

No service is immune to breach. If one occurs affecting your personal data, we will notify affected account holders and any regulator we are required to notify, without undue delay.

10. International transfers

Our infrastructure and our sub-processors are primarily in the United States. If you are in the EU, UK or EEA, using the service transfers your data there, relying on the Standard Contractual Clauses (and the UK Addendum where relevant) in our agreements with those providers.

11. Children

The service is not intended for anyone under 16, and we do not knowingly collect their personal data. Tell us if you believe a child has created an account and we will remove it.

12. Changes and contact

We will notify account holders before a change that materially affects how we handle personal data takes effect. For anything in this policy, including a data request, contact privacy@briaanalytics.com.