WikiBrainPrivacy PolicySign in← Home
WikiBrain · Last updated 2026-09-08

Privacy Policy

Terms of Service·Back to help

Effective 2026-09-08 · version 1.1 · The Traditional Chinese text is the binding version; this English text is a faithful summary.

In one sentence: your notes are yours. We send content to the AI model you chose only when you press a button, do nothing else with it, do not track you, do not sell data, and deleting your account cascades through everything. The questions below spell out the details and double as the notice required by Taiwan's Personal Data Protection Act.

The service is operated by Daniel Huang at wikibrain.app; contact hello@wikibrain.app.

Are my notes used to train AI?

No. We train no models and use your content for nothing beyond the product. When you press ingest, chat or lint, the relevant notes go to the model provider you picked in Settings (Anthropic, OpenAI or OpenRouter) with your own API key; that leg is governed by the provider's terms. Most providers do not train on API traffic by default, but check the one you chose.

Who can see my notes?

You, and the clients you authorise (Cursor, Claude Code, Claude.ai, ChatGPT, through MCP tokens or OAuth grants you create). Every query is scoped to your workspace. The operator does not read your content, except the minimum needed when you report a problem and agree, or to handle a security incident or a lawful request.

Do you track me?

No. No Google Analytics, no ad pixels, no third-party trackers. The site uses one essential login-session cookie, so there is no cookie banner. Server logs record IP, time and path for rate limiting and security investigation, kept at most 90 days.

Where is my data?

Singapore. Servers and PostgreSQL run in Railway's Singapore region; daily backups stay in the same region. Legally this is an international transfer, controlled by contract and encryption.

When does content leave your servers?

Only when you trigger a feature, and only what that feature needs: the AI provider you configured (your key); during the trial, the first 10 runs without a key go through our OpenRouter account (OpenRouter privacy); Crossref, arXiv and PubMed public APIs receive only an identifier when you import a source with a DOI; URL imports are fetched by our server; Zotero is read with your key once you link it; Resend delivers transactional e-mails; Paddle handles checkout and card data, sending us only subscription status and ids; lawful requests, with notice to you where the law allows. Nothing else is sold, rented or shared.

What exactly do you store?

Account data (e-mail, hashed password, username, Google account id if used); your knowledge base (notes in the raw / wiki / schema layers, version snapshots, image attachments, Markdown converted from imported pages, PDFs and Word files); chat and job logs (tool calls, tokens, estimated cost, errors); API keys you choose to save (AES-256-GCM, only the last four characters shown); MCP tokens (hashed), OAuth grants and sessions; subscription state from Paddle; usage counters; server logs. Purposes: providing the service, account security and abuse prevention, running AI jobs on your instruction, billing, account e-mails, legal compliance.

How long do you keep it?

The latest version of every note while your account exists; older snapshots 90 days on Pro and trial, 7 days on Free. Chats, job logs, imported sources and attachments until you delete or archive them. Keys until you remove them. Server logs at most 90 days.

What happens when I delete my account?

Settings → Delete account removes all notes, versions, chats, job logs, attachments, keys and tokens from the primary database immediately; copies in backups expire within 30 days. Paddle keeps transaction records as its legal obligations require. Export a zip first if you want to keep your notes.

What are my rights?

Access, copy (Settings → Export zip, Obsidian-compatible), correct, restrict, and delete (Settings → Delete account, or e-mail hello@wikibrain.app). We respond within 15 days, extendable by 15. An e-mail address is required to have an account.

How is it protected?

HTTPS throughout; hashed passwords; API and Zotero keys encrypted with AES-256-GCM using a key kept separate from the login signing secret; hashed MCP tokens; workspace isolation on every query; per-IP, per-token and per-user rate limits; SSRF protection on outbound fetches. If a breach affects you, we notify you by e-mail within 72 hours of learning about it.

Under 18?

The service is not directed at people under 18; use it with a legal guardian's consent. We delete data collected without such consent once we learn of it.

Does this apply to self-hosted copies?

No. The core is open source under AGPL-3.0 at https://github.com/wikibrain-app/wikibrain; self-hosters are responsible for their own data. This policy covers only wikibrain.app as operated by us.

Will this change?

Material changes are announced by e-mail and on the site 14 days before they take effect. Governing law: Taiwan (R.O.C.). Questions: hello@wikibrain.app.