Legal
BakedBrie privacy policy
Beta draft. Approved by the founder on September 19, 2026 for the controlled beta; pending counsel review.
Proposed version: privacy-beta-1
ParagraphAI Inc., operating as BakedBrie, provides business workspaces and a marketplace for expert-built agents and workflows. Contact: bb@paragraphai.com.
1. Roles
For account administration, security, marketplace operations, billing metadata, support, legal compliance, and service analytics, ParagraphAI Inc. determines why and how personal information is handled.
For workspace content submitted by a business buyer, the buyer controls the content and its permitted uses. ParagraphAI Inc. acts as the buyer's processor or service provider and processes the content only to provide, secure, support, recover, and comply with law for the service. A seller receives workspace content only through the buyer's explicit grant and is independently responsible for its seller-side handling.
Final controller/processor terminology and jurisdiction-specific addenda require privacy counsel approval.
2. Information handled
BakedBrie may handle:
- business identity and contact data;
- account, authentication, multifactor, session, recovery, and security-event data;
- workspace, board, card, file, workflow, instruction, output, audit, and support content;
- seller identity, country, address, tax status, classification, onboarding state, listing, support, and dispute data;
- buyer, seller, charge, refund, subscription, application-fee, and reconciliation references received from Stripe, excluding full card details;
- customer-selected AI provider and runtime connection metadata, health, funding attribution, quota state, and revocation state;
- device, browser, network, diagnostic, usage, consent, and acceptance evidence;
- communications, complaints, bounce, suppression, and incident records.
API credentials may be stored only through approved encrypted secret storage. Codex and Claude subscription credentials remain on customer-controlled devices or hosts and are not uploaded to BakedBrie.
3. Purposes
Information is used to provide and secure accounts and workspaces, execute authorized workflows, install and support purchases, route customer-funded AI work, process marketplace records, prevent abuse and fraud, meet tax and legal obligations, recover from failures, communicate about the service, and improve reliability using appropriately limited data.
BakedBrie does not sell workspace content or use it to train a general model. Any materially different use requires a lawful basis, clear notice, and any required consent or contract change.
4. Sharing
Information may be shared with:
- a seller when the buyer explicitly grants access for installation or support;
- infrastructure, authentication, email, database, payment, monitoring, and support providers listed in the subprocessor schedule;
- OpenAI, Anthropic, or a customer-side runtime only when the customer selects that account or runtime for the work;
- professional advisers, auditors, insurers, or authorities where necessary and lawful;
- a successor in a legitimate corporate transaction subject to appropriate safeguards.
Each provider receives only the data needed for its function. Third parties may process data in Canada, the United States, or other disclosed locations, where it can be subject to local law.
5. Retention and deletion
BakedBrie retains information only for documented service, security, recovery, tax, dispute, and legal periods. Workspace deletion follows the product's tombstone, purge, backup-expiry, and subsystem-evidence process. Legal, tax, fraud, charge, refund, dispute, consent, and incident records may be retained longer where required. Final periods require counsel and accountant approval and must match production configuration.
6. Safeguards and incidents
BakedBrie uses tenant isolation, least-privilege roles, multifactor authentication, environment separation, encryption, audit records, bounded execution, revocation, backup, restore, and incident procedures appropriate to the sensitivity and risk. No safeguard eliminates all risk.
Suspected incidents should be reported to bb@paragraphai.com. BakedBrie will investigate, contain, preserve evidence, notify affected customers, and make regulatory reports where required. Final breach thresholds, timelines, and record-retention language require privacy counsel approval.
7. Choices and access
Authorized business contacts may request access, correction, export, deletion, or information about handling by contacting bb@paragraphai.com. Requests are verified and may be limited by another person's rights, confidentiality, security, legal holds, or mandatory retention. A business buyer administers its own authorized users and workspace content.
Users can disconnect provider accounts, revoke customer-side runtimes, change board-agent assignments, and cancel eligible marketplace subscriptions through supported product paths. Revocation stops new authorized use but does not falsify completed audit, payment, tax, or security records.
8. Changes
Material changes receive versioned notice and, where required, renewed acceptance. The final effective date, privacy officer identity, full retention table, and jurisdiction-specific rights must be completed before publication.
