Last updated 7 August 2026

Privacy Policy

This Privacy Policy explains how Monsef Holdings Pty Ltd (ABN 58 694 849 735) ("OzBrain", "we", "us", or "our") collects, uses, discloses, and safeguards personal information when you use OzBrain at ozbrain.co and related services, including the MCP connector (the "Service").

We design these practices to align with the Australian Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs), and with the EU General Data Protection Regulation (GDPR) where it applies. Your use of the Service is also governed by our Terms of Service.

1. Information we collect

Information you provide

  • Account information. Email address and related authentication details when you create or sign in to an account (magic link sign-in).
  • Brain content. Articles, descriptions, routing indexes, staged writes, tasks, comments, links, and other knowledge you or your connected agents write into the Service.
  • Connections. OAuth client details for AI platforms you connect (for example Claude, ChatGPT, Cursor), including client identity used for attribution and revoke.
  • Support and contact. Name, email, and message content you send through contact forms or email.

Information collected automatically

  • Usage and audit events. Product events needed to operate the Service, including Chronicle activity, onboarding milestones, and account logs that record which client or agent performed a read or write.
  • Technical logs. Standard request metadata such as IP address, timestamps, user agent, and error diagnostics from our hosting providers, used for security, reliability, and abuse prevention.

2. How we use your information

We use personal information to:

  • Provide, maintain, and improve the Service
  • Authenticate you and manage connected AI clients
  • Run the staged write protocol, tasks, search, and related features
  • Send service communications (sign-in links, security notices, product email you have a relationship basis for)
  • Monitor and prevent abuse, fraud, and security threats
  • Respond to support requests and privacy rights requests
  • Comply with law

We do not sell your personal information. We do not use brain content for advertising. We do not train foundation models on customer brain content.

3. Customer content and agents

You (or your organisation) own the content you store in OzBrain. We process that content only to provide the Service under our Terms of Service.

When you connect an AI client through OAuth, that client can call OzBrain tools on your behalf. Content returned to that client leaves OzBrain under your instruction and is then handled under your agreement with that AI provider (for example Anthropic or OpenAI). Those providers are recipients you choose, not OzBrain marketing partners.

4. Storage and security

Account and brain data are stored in Postgres and Auth systems operated by Supabase. The application is hosted on Vercel. Data in transit uses TLS. Access to production systems is limited to authorised operators of Monsef Holdings Pty Ltd.

No method of electronic storage is perfectly secure. Report suspected security issues to security@monsef.com.

5. Sharing and subprocessors

We share personal information only as needed to run the Service:

  • Supabase. Authentication and database hosting.
  • Vercel. Application hosting and related edge/network infrastructure.
  • NitroSend. Transactional and lifecycle email delivery (for example magic links and product email).
  • Legal and safety. When required by law, regulation, legal process, or to protect rights, safety, and the integrity of the Service.
  • Business transfers. In connection with a merger, acquisition, or asset sale, with notice where required.

6. Cookies

We use essential cookies and similar storage required for authentication and session continuity. We do not run third-party advertising trackers on the Service.

7. Retention

We retain account and brain data while your account is active. If you ask us to close an account, contact privacy@monsef.com. We will confirm what we can export, what we delete, and any limited records we must keep for legal, security, or billing reasons. Self-serve hard delete and full export are on the product roadmap; until those flows ship, we handle requests manually.

8. International transfers

Monsef Holdings Pty Ltd is based in Australia. Infrastructure providers may process data in other countries, including the United States. Where required, we rely on appropriate contractual and organisational safeguards with those providers.

9. Your rights

Depending on your location, you may have rights to access, correct, delete, or export personal information, to restrict or object to certain processing, and to withdraw consent where processing is based on consent. To exercise these rights, email privacy@monsef.com.

10. Children's privacy

The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If we learn that we have, we will take steps to delete it.

11. Changes

We may update this Privacy Policy from time to time. For material changes we will provide notice by email or in-product notice when practical, and update the "Last updated" date above. Continued use after the effective date means you accept the updated policy.

12. Complaints

If you believe we have breached the Australian Privacy Principles or your privacy rights, contact privacy@monsef.com. We aim to respond within 30 days. If you are not satisfied, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

13. Contact

For questions about this Privacy Policy or our data practices:

Monsef Holdings Pty Ltd

ABN 58 694 849 735

Suite 122, 283 Glen Huntly Road

Elsternwick VIC 3185

Australia

Email: privacy@monsef.com