← bravely.dev

Privacy Policy — Bravely Websites

Last updated: July 26, 2026 · Effective: July 26, 2026

Bravely Studios LLC (“we,” “our,” or “us”) operates Bravely Websites, our website design, build, and hosting service. This policy covers the quote form at bravely.dev/websites and the client portal at websites.bravely.dev. It describes how we handle your information as a prospective or active client, and how we handle information your site collects from your visitors.

Two Different Roles, and Why It Matters

There are two separate sets of data here, and we treat them differently. Your data as our client — your contact details, your account, your change requests, your billing. We decide how that is handled, so we are the controller of it, and this policy explains it. Your visitors’ data — anything your website collects from the people who visit it, such as a contact form or a booking. That is your data about your customers. You decide what your site collects and why, which makes you the controller; we host and process it for you. You are responsible for your site’s own privacy policy and cookie notice, and for having a lawful basis for what your site collects. Be aware of one thing we do with it, because it is not obvious: when your site receives an enquiry, we also copy it into our own systems so it appears in your portal inbox. That copy includes the visitor’s name, email address, message, and IP address, and it lives in a database we operate for our client portal generally rather than one dedicated to you. We do not use it for our own purposes and we do not share it, but you should know it exists, and your own privacy notice should account for it. We do not currently have a signed data-processing agreement with you covering this. If you need one, and you should if your site is directed at people in the EEA or UK, email privacy@bravely.dev and we will put one in place.

Information We Collect About You

• Quote enquiries — your name, email address, and whatever you write in the message. If you tick the marketing box on that form, we also add you to our marketing list; leaving it unticked keeps you off it. • Account details — the email address you sign in to the portal with, your name, your business, and the sign-in records needed to keep your account secure. • Project information — the brief, content, images, and business details you give us to build your site. • Change requests — the full text of each request, any files you attach, and a detailed log of what the AI agent did to your site in response, including the files it read and changed and the commands it ran. • Billing records — what you were invoiced, what you paid, and when. We invoice you directly and do not run card payments through this service. • Portal analytics — aggregate usage of the portal itself, so we can see what is being used and what breaks. • Support correspondence — the emails you send us and our replies.

How Change Requests Are Processed

When you submit a change request, the text and any attachments are passed to an AI coding agent that makes the change and builds a preview for you to approve. We want to be straight with you about two things here. First, where the processing happens. Your request content is processed by Anthropic’s Claude. That processing currently runs on a subscription account rather than under a negotiated enterprise data-processing agreement, which means it is governed by Anthropic’s own published terms for that account rather than by a contract we have signed on your behalf. We are working to change that. If you need AI processing of your content to sit under a written data-processing agreement before you use the change portal, tell us at privacy@bravely.dev and we will handle your changes manually instead. Second, no Bravely employee reviews the change before you see it. There is no human approval step and no automated content screening between the agent and your preview. You are the reviewer. We can take any request over manually if you ask, or if the automated run fails. Because of both of those, do not put passwords, card numbers, health information, passport or national-identity numbers, or other people’s personal data into a change request. We do not filter or scan requests for that, so nothing catches it if you do.

Attachments and Site History

Files you attach to a change request are stored in our object storage and are also committed into your site’s private source-control history alongside the change they belong to. Source control keeps history permanently by design, which means an attachment stays in the repository history even after the file is removed from the live site. If you need something purged from history, tell us and we will rewrite it out, but ask us rather than assuming a deletion has removed it everywhere. This matters most for photographs of identifiable people, so send those deliberately.

Your Site and Its Files

We store your site’s code, content, and assets in private source control and on the hosting platform that serves it. We keep operational logs and uptime-monitoring records for the sites we host so we can tell when something breaks. Our uptime monitoring checks that your contact form still works end to end, which means it submits a test entry through your form on a schedule; if you see periodic test submissions in your inbox, that is us. Where we run analytics for your site, we configure it and can turn it off at your request; what it collects about your visitors is data you control, as described above.

Backups

We do not currently operate a separate backup service for the sites we host. Your site’s code and content live in source control, which lets us roll back a change or restore a previous version, and that covers the most common problem. It does not cover data your site collects from your visitors after it goes live, such as contact-form submissions held in your site’s database. If you need those backed up or exported on a schedule, ask us and we will scope it. We would rather tell you this plainly than let you assume a safety net that is not there.

How We Use Your Information

We use your information only to run the service: • answer your quote enquiry and scope the work • design, build, host, and maintain your site • process the changes you ask for and show you previews • invoice you and keep the records the law requires • monitor uptime and investigate faults • understand aggregate portal usage so we can improve it • answer your support requests and tell you about things that affect your site We do not sell your information, use it for advertising, or use your project content to market to anyone else. We will not feature your site as recent work without telling you first, and we will remove it on request.

Data Retention

Quote enquiries are kept for as long as we might reasonably follow up, then deleted or anonymized; ask us and we will delete one sooner. Client account, project, and change-request records — including the agent activity log for each request — are kept for the life of the engagement and a reasonable period afterwards so we can support and re-deliver your site. Uploaded attachments expire from our object storage after 90 days but, as described above, remain in your site’s source-control history indefinitely unless you ask us to purge them. Site content lives in source control for as long as we host you and through the wind-down period in your terms. Invoicing and tax records are kept for as long as the law requires, typically seven years. Operational logs are kept for a short period and then discarded.

Deleting Your Data

The client portal does not have a self-service delete button. To close your portal account and remove the data attached to it, email privacy@bravely.dev from the address you sign in with and we will confirm and process it. Tell us at the same time if you want your site’s source-control history purged of attachments, or an export of the enquiries your site has collected, since those are separate steps.

Children's Privacy

Bravely Websites is a business service intended for adults, and we do not knowingly collect personal information from children. If your site is directed at children, that brings obligations under laws such as COPPA that are yours to meet as the site owner, and you should tell us so we can configure hosting and analytics appropriately.

Your Privacy Rights

Depending on where you live, you have rights over the personal data we hold about you. We honor these rights for everyone who asks, regardless of where you live. • Access — ask what personal data we hold about you and get a copy. • Correction — ask us to fix data that is wrong or incomplete. • Deletion — ask us to delete your personal data by emailing privacy@bravely.dev from the address on your account. Where a product has a built-in Delete Account control you can use that instead; bravely.dev/delete-account explains what applies to each product. • Portability — ask for your data in a portable, machine-readable format. • Objection and restriction — ask us to stop or limit certain processing. • Withdraw consent — where we rely on consent (marketing email, optional analytics), you can withdraw it at any time without affecting processing that already happened. • Non-discrimination — we will not degrade your service or charge you more for exercising any of these rights. EEA and UK residents also have the right to lodge a complaint with your local supervisory authority. California residents may use an authorized agent; we may verify the agent's authority and confirm the request with you first. Other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect) have equivalent rights, including a right to appeal a denied request — reply to our decision email with "Appeal" and we will respond in writing within the period the law requires. Canadian residents have access, correction, and consent-withdrawal rights under PIPEDA; Australian residents have access and correction rights under the Australian Privacy Principles. To exercise any right, email privacy@bravely.dev. We respond within the timeframe the applicable law requires — generally 30 days under GDPR and 45 days under the CCPA, with an extension where the law permits one. We may need to verify your identity before acting, usually by confirming control of the email address on the account.

Legal Basis for Processing

If you are in the EEA or UK, we rely on these lawful bases under the GDPR and UK GDPR: • Performance of a contract — creating and securing your account, delivering the features you paid for, syncing your content, processing purchases, and providing support. • Legitimate interests — keeping the service secure and reliable, preventing fraud and abuse, understanding aggregate product usage, and improving the product. We balance these against your rights and do not use them to justify intrusive tracking. • Consent — marketing email, and optional analytics where a client offers a toggle. You can withdraw consent at any time. • Legal obligation — keeping tax, accounting, and consent records, and responding to lawful requests.

International Data Transfers

Bravely Studios LLC is a US company. We and our sub-processors process data in the United States and in other countries where they operate. For personal data originating in the EEA, UK, or Switzerland, we rely on appropriate transfer safeguards in our processor agreements — such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum — where those safeguards are required. Email privacy@bravely.dev if you want more detail about the safeguards that apply to you.

California Notice at Collection

For California residents, the categories of personal information we collect for this product are: • Identifiers — your name, email address, business name, and the account identifier used to sign you in to the portal. • Commercial information — what we invoiced you and what you paid, held in our own records. • Internet or other electronic network activity — portal usage analytics, and the IP addresses and user-agent strings attached to enquiries your site receives. • Your content — the brief, copy, images, and files you give us; the text of your change requests; and your site’s code and content. • Personal information about other people — whatever your site collects from your visitors, which we hold as your processor and not for our own purposes. We collect this from you, your device, and our own systems, and we use it to run the product, honor what you have bought, keep the service secure, and support you. We disclose it to the service providers listed under "Sub-processors," each for a business purpose under a written contract. We do not sell your personal information and we do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA and CPRA, and we have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for any purpose that would trigger the right to limit. If that ever changes we will update this policy and provide the required opt-out before the practice begins. Retention is described under "Data Retention" above and, for account-level data, in the Bravely Account privacy policy.

Sub-processors

We use the following service providers to run this product. They receive only what they need to perform their service for us, and each is bound by the data-processing terms that apply to our use of their service. Where a provider is not yet covered by a written data-processing agreement with us, its entry below says so. If you need a data-processing agreement in place before you use this product, email privacy@bravely.dev: • Cloudflare, Inc. — hosting, the Workers runtime, object storage for your uploads and previews, and the database your site uses. See cloudflare.com/privacypolicy. • Google LLC — Firebase Authentication for portal sign-in, and Firestore, which stores your client record, your change requests, and the enquiries your site receives. See policies.google.com/privacy. • Anthropic PBC — processes the text and attachments of your change requests to make the change, and powers the AI drafting tools where we enable them. See the "How Change Requests Are Processed" section below, which explains the current legal posture of this processing honestly. See anthropic.com/legal/privacy. • GitHub, Inc. (Microsoft) — private source control for your site’s code, content, and any files you attach to a change request. See docs.github.com/site-policy. • Resend Inc. — delivers email your site sends, such as forwarding a contact-form message to you, and our own operational alerts. See resend.com/legal/privacy-policy. • PostHog Inc. — product analytics on the client portal. See posthog.com/privacy. • Prodject.ly — our own project-tracking product, on separate infrastructure, which is the system of record for every change request: its full text, your name and email, and the log of what the AI agent did. It is operated by Bravely Studios LLC. If we add or change a sub-processor in a way that materially changes how your data is processed, we will update this policy and give additional notice where the law or our data-processing commitments require it.

Security

We protect your data with authenticated accounts, encryption in transit, access controls on our backend systems, and a deliberately small number of people who can reach production. No system is perfectly secure, and we do not claim guarantees we have not built and verified. Where a product makes a specific security claim, that claim appears in the app-specific sections above and is limited to what we have actually shipped. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulators as required by law.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make a material change — a new category of data, a new sub-processor, a new purpose, or a new legal basis — we will update the "Last updated" and "Effective" dates and give additional notice where the law requires it. Where a change requires fresh consent under the GDPR, UK GDPR, CASL, or a similar regime, we will ask for it before relying on the new purpose. Non-material changes (typos, clarifications, link fixes) are reflected by updating the "Last updated" date.

How to Contact Us

Bravely Studios LLC Privacy and data rights: privacy@bravely.dev Product support: support@bravely.dev Website: https://bravely.dev Postal address: available on request to privacy@bravely.dev.