Privacy
Last updated 9 August 2026
This policy explains what Brace collects, why, and what you can ask us to do with it. It describes how the product works today. If something here is unclear, write to accounts@brace.chat and we will answer.
Two kinds of people, two different roles
If you use Brace to run support, you are our customer. We hold your account details and act on your instructions.
If you contacted a company that uses Brace, that company decides what happens to your conversation. We store and process it for them. Ask them first, and they can ask us.
What we collect
- Account details. Name, email address and password for each agent, and the workspace name.
- Conversations. Messages, attachments, private notes and the contact records they belong to, for as long as the workspace keeps them.
- Contact details a visitor gives. Email address, phone number and any custom fields the workspace has configured.
- Technical data. IP address at the point a contact record is created, browser and page URL where a chat started, and ordinary server logs.
- A contact record when a chat widget loads. Opening a page that carries a chat widget, including our own support page, creates an anonymous contact record before you type anything. It holds a generated name and the technical data above, and it is how the conversation is attached to you if you do write.
- Billing data. Plan, seat count and subscription status. Card details go directly to Stripe and never reach our servers.
Who else processes it
We use a small number of subprocessors. Each one only receives what its job needs.
- OpenAI processes conversation content for the AI features: answering from your help center, drafting agent replies, summarising, labelling and translating. If those features are switched on for a workspace, the message text involved is sent to OpenAI to produce the answer. Workspaces that supply their own provider key send that content to the provider they chose instead.
- Microsoft Azure hosts the servers and the database.
- Stripe processes payments.
- Backblaze stores encrypted database backups.
- Amazon Web Services delivers transactional email.
How long we keep it
Conversations and contacts stay until the workspace deletes them or closes the account. Backups are kept on a rolling schedule and age out. Server logs are short lived.
Deleting your data
Write to accounts@brace.chatto request deletion of a workspace or of a particular person's data, and we will action it. Tell us which workspace and which records you mean. If you are an end customer of a business that uses Brace, contact that business first, because the data is theirs to direct.
Deletion is handled by hand rather than by a self-service button, and some copies persist for a period afterwards: backups age out on their own schedule, and some derived records are removed on a separate pass. We will tell you what has been removed and when.
Security
Traffic is encrypted in transit. Passwords are stored hashed. Provider keys a workspace supplies are stored encrypted and are never shown again after they are saved. Access to production is limited to people who need it.
Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, and to object to some processing. Write to accounts@brace.chat and we will respond.
Changes
If this policy changes materially we will update the date at the top of this page and, for changes that affect customers, send an email.