Privacy
Who we are, what we collect, why we are allowed to, who handles it, where it is, how we protect it, how long we keep it, and what you can make us do about it.
The short version
You can complete the Snapshot and read your full Brain Profile without giving us an email address, creating an account, or sending your answers anywhere. Scoring runs in your browser.
You can play every game on the public bench the same way, without an account. Nothing about those runs reaches us.
We ask for an email address only if you want something sent to you, or when you create an account. We count visits only if you say yes when asked, and we never sell or share your personal information.
Who is responsible
Brainmaxing is operated by Ana Ultimate Group Ltd, a company registered in England and Wales under company number 17407324, whose registered office is 27 Old Gloucester Street, London, United Kingdom, WC1N 3AX.
Ana Ultimate Group Ltd decides how and why the personal data described here is used, which makes it the controller for it under the UK General Data Protection Regulation and, where it applies, the EU General Data Protection Regulation.
For anything about your data — a question, a request, a complaint, or telling us something here is wrong — write to support@brainmaxing.net or use the contact form. Both reach the same place, and we reply to the address you give us.
We have not appointed a data protection officer. We do not think we have to: one is required where a company's main work is monitoring people at scale, or handling health or similar data at scale, and neither describes what we do. If that changes we will appoint one and say so here. Saying we had one when we do not would be a worse answer than this one.
We have also not appointed a representative inside the European Union — neither the data protection representative that the EU General Data Protection Regulation asks a company outside the EU to have, nor the legal representative that the EU Digital Services Act asks for. We have chosen to go without both for now and to decide again once a real number of the people using Brainmaxing are in the EU. We would rather write that down here than have you assume otherwise.
What we collect, and why
Your six Snapshot answers and the resulting Brain Profile, only if you choose to save a result or to have it sent to you. Otherwise they stay in your browser for the length of your visit and never reach us.
Your email address, only if you ask us to send you something. Before we add an address to any mailing list we send one confirmation message to it and wait for you to open the link inside; if you never do, nothing is stored.
Your email address again if you create an account, because it is how you sign in — there are no passwords here, only a link we send you.
If you press Continue with Google, Google sends us your name, your email address, your Google account identifier and a link to your profile picture. We keep the email address, because it is how you sign in. We never open the other three: your name and your picture arrive and are never read by anything here, and your Google account identifier is neither stored nor written to a log. Your Google account is governed by Google's own privacy policy rather than by this one, and your Brainmaxing account is deleted the same way as any other.
If you have an account: your username, the results you saved, the games you ran and what they scored, your progress through the seven-day plan, your reading and learning state, your preferences and your sign-in sessions.
With each game you run while signed in: the conditions it ran under — whether you used a touch screen or a keyboard, whether animation was reduced, whether the device is a phone, tablet, laptop or desktop, which browser family it was, and the timing calibration the page measured. It is kept because a reading means nothing without it, and none of it names your device or follows you anywhere.
If you take part in the community: what you post, the groups you join, your check-ins, and any report you make or that is made about a post.
If you buy a plan: an order reference, the amount, the currency, the plan, the billing period, and the record that a payment succeeded or failed. So that your plan page can show you which card is about to be charged, we also keep the card's brand, its last four digits and its expiry month and year — never the number itself, never the security code. Your card details never reach our servers — see the payments paragraph below.
Your IP address, briefly, to limit how many requests one address can make to our servers. It is held in memory or in a short-lived table, cleared about an hour later, and it is not joined to your answers or your account.
Optional usage counts, if you agree to be counted — that the assessment was started, that a result was shown, whether the 3D model loaded. With each count we store the page's address without anything after the question mark, the website you arrived from as a name like 'example.com' and never the full address, any campaign tags in the link you followed, whether the screen was phone-sized or larger, and a random number that ties together the counts of one page view and is thrown away when you leave. No cookie, no account number, no email address, no IP address and nothing about your browser. These are counts of events, not profiles of people, and nothing in them can be traced back to your answers or to you.
Why we are allowed to use it
To give you the product you asked for — your account, your saved results, your runs, your plan, the community — we rely on performance of a contract with you. Without this data there is no account to give you.
To send you a sign-in link, a receipt, or a message you asked for, we rely on performance of a contract. To send you a marketing email we rely on your consent, which you give by confirming your address and can withdraw from any message.
To count visits we rely on your consent, asked for plainly and refused as easily as it is given. Decline, and nothing is recorded at all — not on our side either.
To keep the service standing up — rate limiting, abuse prevention, moderation, security logging — we rely on our legitimate interests in running a service that works and is not abused, balanced against your interests. You can object, and we will look at it.
To keep the records a company is required to keep, and to answer a lawful request from an authority, we rely on our legal obligations.
Who handles it for us
Our database is Neon, which runs the Postgres database holding your account and everything in it. It is hosted in Amazon Web Services' London region, in the United Kingdom.
Our hosting is Hostinger, which serves the site and runs the mailbox we answer support from.
Email is delivered by Resend. Resend receives the address a message is sent to and the message itself — a sign-in link, a confirmation, a result you asked for. It never receives your Snapshot answers or your scores.
Payments are taken by Stripe. Stripe receives your email address, the amount, the currency, the plan, an order reference and — from your own browser, never from our servers — your card or wallet details and whatever billing information it needs. Stripe never receives your answers, your scores, your runs or your progress. We never see or store your card number.
Nobody handles the optional usage counts for us. If you agree to be counted, the counts go to our own database — the Neon one named above, in London — and to no other company. There is no analytics service, no tracking script from anyone else, and nothing about your visit is sent off our own site.
If your browser sends the Global Privacy Control signal, we treat it as a no and do not ask, unless you later choose to be counted yourself on the privacy page.
Each of these handles your data on our instructions, under a contract, and for nobody else. We do not sell your personal information and we do not share it for advertising.
Where your data is
Your account data sits in a database in London, in the United Kingdom. It does not leave the United Kingdom at rest.
Some of the companies above are established outside the United Kingdom, or have group companies that are, so some of what they do on our behalf may involve data reaching the United States or the European Economic Area. Where that happens we rely on the transfer mechanisms in the contract we have with each of them — the UK International Data Transfer Addendum to the European Commission's standard contractual clauses, or an adequacy decision where one covers the country.
We name this honestly rather than precisely because the precise position for each company is one of the questions we have put to a qualified adviser before this notice is treated as final. If you want to know where a particular piece of your data has been, ask us and we will tell you what we know.
How we protect it
The site is served only over HTTPS: a request for the unencrypted address is answered with a redirect, not with a page, and we tell your browser to refuse an unencrypted connection.
There are no passwords to steal. You sign in with a link we email you, or with Google. Your sign-in cookie is scoped so that a script on the page cannot read it and it is only ever sent back to this site.
The confirmation link we send before adding an address to the mailing list carries an encrypted token rather than your address, so a copy of that link tells nobody who it was for.
We limit how many times one address or one connection can ask us to send an email or create something, so an automated attempt runs out of road quickly.
No system is perfectly secure and we do not claim ours is. If we ever lose control of personal data in a way that puts you at risk, we will tell the Information Commissioner's Office within 72 hours of finding out, and we will tell you as well where the law requires it.
How long we keep it
Account data — your address, username, saved results, runs, progress, reading state, community posts and preferences: for as long as the account exists, and removed when you delete it.
Sign-in sessions: a session lasts 30 days, and the expired record is removed 90 days after it stops being usable.
Results that are not linked to any account: 24 months from the day they were produced, then deleted.
Community notifications: 90 days. Moderation records — a report, a moderator action — are stripped of who made them after 24 months and kept as counts.
IP addresses used for request limiting: about an hour, and a little longer if a clean-up run fails. The row is removed by a sweep that runs at most once a minute and is retried on the next one, so it outlives the limiting window it was written for and then goes.
Usage counts, if you agreed to be counted: each individual count is deleted 90 days after it was recorded. Before that happens we add it into a daily total — how many visits a page had on a day, and how many arrived from a given site — and those totals are kept. A total names nobody and cannot be taken apart again: there is no visit, no session and no person in it, only a number per day.
Emails you send to support, and any request you make about your own data, live in our support mailbox. There is no database here that holds them: the contact form sends a message and stores nothing. They are kept while the case is open, then for 12 months, then deleted — long enough to answer a follow-up and to show that we replied and when.
Records of a payment are kept by Stripe under its own obligations as well as ours, and Stripe keeps them on its own terms for its own legal and tax purposes. Deleting your Brainmaxing account removes our copy; it does not and cannot reach into Stripe's records.
Cookies and what is stored in your browser
This site sets one cookie, and only one. It is first-party — set by Brainmaxing, sent only back to Brainmaxing, and shared with no one else. There are no advertising, no analytics and no cross-site tracking cookies: nothing we set follows you to another site, and the optional visit counts, on the visits you allow us to count, set no cookie at all. Two further cookies are described below and are not set at all today, because the parts of the product they belong to are switched off.
A sign-in cookie, set only once you have created an account and opened a sign-in link. It is what keeps you signed in, so the member area knows a request is yours. It carries a session identifier and nothing else, a script in your browser cannot read it, and it is removed the moment you sign out. Most visitors never make an account and so never receive it. Sign-in sessions last 30 days.
A Google sign-in cookie, set only if you press Continue with Google, and only for the ten minutes that trip takes. It holds the one-time values that prove the return from Google belongs to the same browser that left — encrypted, so nothing in it can be read even by us without the key, and a script in your browser cannot reach it at all. It is deleted the moment you land back here, whether the sign-in worked or not. Never press the button and you never receive it. Today this cookie is not set at all: Continue with Google is not configured on this deployment, so the button is not shown, the address that would begin the trip answers 404, and nothing can create the cookie.
A referral cookie, set only if you arrive through an invite link that someone shared with you. It records the invite code, so that — if you later choose to sign up — the person who invited you can be credited. It holds that code and a short signature that proves the cookie came from us; it names no one, a script cannot read it, and it is never sent to another site. It is discarded after 30 days, or as soon as it has done its one job. Decline it, or arrive without one, and nothing changes for you: you still get the whole product, and the visit is simply credited to nobody. Today this cookie is not set at all: that part of the product is switched off, so an invite link takes you to the site and nothing is stored in your browser.
Eight things are stored in your browser: your answer to the question about counting visits, so we do not ask again; whether you muted the sound in a game; your recent runs and your best in each game you have played; your Snapshot result, so a refresh does not lose it; a copy of a Snapshot result you asked to save to an account, held while you open the sign-in link; the page you were on when you asked to sign in, so you land back on it; a marker that the sign-in you just finished began at a Snapshot result; and how many times this device has started each test, so you are given a different form next time. None of these is a cookie, and clearing your browser data removes them; two of them are gone the moment you close the tab. Five of them never leave this device at all. The other three do, and only on something you do: a run you finish while signed in is also saved to your account, so your history follows you between devices; and your Snapshot answers are sent to us only if you ask us to save the result to an account.
What we do not collect
We do not send your individual answers to any analytics provider, and we no longer use one at all. The usage counts go to our own database and nowhere else. What you said about your sleep or your routines is not something a third party needs, and now there is no third party.
We do not use cross-site tracking cookies or advertising trackers. The one first-party cookie described above is the only one we set, and it does not follow you across the web.
We do not collect health records, and we do not ask for information about diagnoses or medication.
We do not ask for and do not want special-category data — anything about your health, your race or ethnicity, your religion, your politics, your sex life or sexual orientation, your trade-union membership, or your genetics or biometrics. The Snapshot asks about sleep, routines and working conditions, and nothing in it is built to reveal any of those. If you write something like that to us in an email, we use it only to answer you.
We never see your card number, your card's security code, or your bank credentials. They go from your browser to Stripe and never pass through our servers.
Decisions made about you by a computer
Your Snapshot result and your game scores are produced by fixed, published arithmetic. The same inputs always give the same output, there is no hidden model, and the weights are on the method page for you to read.
Nothing here makes a decision that has a legal effect on you or anything similarly significant. Nothing decides whether you get a job, credit, insurance, a place on a course, or care. If a number here is ever used to decide something about you, it will be because you chose to show it to somebody.
Your rights
Wherever you live, you can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to stop or limit what we do with it, object to processing we base on our legitimate interests, and ask for your data in a portable form. Where we rely on your consent you can withdraw it at any time, and withdrawing it does not undo what was lawful before.
If you have an account you do not have to ask us for two of those. Settings has a control that downloads a complete copy of your data as a machine-readable file, and a control that deletes the account. Deleting removes your saved results, your history, your runs, your progress, your community content, your billing records on our side and your sessions. It cannot be undone.
You can unsubscribe from any email using the link in that email, and you can change your answer about being counted at any time on the privacy page.
If you are in the United Kingdom or the European Economic Area, those rights are the ones in the UK GDPR and the GDPR, and you can complain to a supervisory authority. In the United Kingdom that is the Information Commissioner's Office; in the EEA it is the authority for the country you live in.
We answer a rights request within one month. If a request is genuinely complicated we may take up to two months more, and we will tell you inside the first month if that happens. We do not charge for it.
If you live in California or another US state with a privacy law
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the past twelve months, and there is nothing on this site that could — there are no advertising trackers and no advertising cookies here.
In the vocabulary California uses, the categories we collect are: identifiers — your email address, your username, an order reference, and a short-lived record of your IP address; internet or network activity — the event counts described under What we collect, and why, and only if you agree to be counted; commercial information — which plan you bought, when, and whether the payment worked; and your own content — your Snapshot answers, your runs and your progress. We collect them for the purposes set out under Why we are allowed to use it, we disclose them only to the service providers named under Who handles it for us, and we keep them for the periods under How long we keep it. We do not collect what California calls sensitive personal information.
Because we do not sell or share, there is nothing for a do-not-sell request to switch off. We honour the Global Privacy Control anyway: if your browser sends it, we do not ask to count your visit.
You can ask us what we have collected about you, ask for a copy of it, ask us to correct it, and ask us to delete it. Use the controls in Settings or write to us. We will not treat you differently for exercising any of these rights.
We do not process sensitive personal information for the purpose of inferring characteristics about you, and we do not use your information for automated decisions producing legal or similarly significant effects.
Children
Brainmaxing is for adults. You must be 18 or over to create an account or to buy a plan.
We do not knowingly collect personal data from anyone under 18. If you believe a child has given us data, write to support@brainmaxing.net and we will delete it.
Changes to this notice
When this notice changes in substance we update the date at the top of it, and if the change matters to you we tell you by email before it takes effect.
The date at the top is the only signal a returning reader gets, so it is only moved when something real has changed — never for a typo.