Privacy Policy
Last updated: October 5, 2026
1. Introduction
Copy and Funnel Accelerator LLC ("we," "us," or "our"), located at 1180 N Town Center Drive, Suite 100, Las Vegas, Nevada 89144, United States, operates StefanBrain, an AI-powered marketing assistant. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our Service.
2. Information We Collect
Account Information
- Email address (for authentication and communication)
- Account preferences and settings
- Trial invitation, trial status, membership, and business/team access information
Usage Data
- Chat messages and conversations with the AI assistant
- Uploaded files and attachments (images, documents, URLs)
- Generated content and AI outputs
- Feature usage patterns and interaction history
Connected Account Data
- Connector account identity and workspace metadata
- Encrypted OAuth access and refresh tokens for connected services
- Messages, calendar data, files, documents, spreadsheets, presentations, property metadata, and report results returned from connected services when you request them
- Shopify store data from stores you connect through the StefanBrain app, as described in Section 5
Technical Data
- IP address and approximate location
- Browser type and version
- Device information and operating system
- Pages visited and features used
- Session duration and interaction timestamps
Cookies and Tracking
- Session cookies for authentication
- Analytics cookies (PostHog) for product improvement
- Functional cookies for user preferences
3. How We Use Your Information
- To provide, maintain, and improve the Service
- To authenticate your identity and manage your account
- To process your requests and generate AI-powered responses
- To analyze usage patterns and improve the user experience
- To send service-related communications
- To send onboarding, product education, lifecycle, and marketing communications where permitted
- To detect and prevent fraud, abuse, or unauthorized access
- To comply with legal obligations
Marketing, onboarding, and product education emails include unsubscribe controls. Transactional or product-critical emails, such as login codes, trial invite links, team invitations, and account notices, may still be sent as needed to provide the Service.
4. Google User Data and Connected Google Services
If you choose to connect a Google account to StefanBrain, we access and use Google user data only to provide the Google connector features you request inside the Service.
Google scopes we may request
openid, https://www.googleapis.com/auth/userinfo.email, and https://www.googleapis.com/auth/userinfo.profile to identify your Google account and complete account linkinghttps://www.googleapis.com/auth/gmail.readonly, https://www.googleapis.com/auth/gmail.labels, https://www.googleapis.com/auth/gmail.compose, and https://www.googleapis.com/auth/gmail.send for Gmail connector features you triggerhttps://www.googleapis.com/auth/drive, https://www.googleapis.com/auth/documents, https://www.googleapis.com/auth/spreadsheets, and https://www.googleapis.com/auth/presentations for Google Drive, Docs, Sheets, and Slides features you triggerhttps://www.googleapis.com/auth/calendar for Google Calendar listing, event lookup, and user-requested calendar event changeshttps://www.googleapis.com/auth/analytics.readonly for Google Analytics 4 property discovery, metadata lookups, compatibility checks, and read-only reporting
How we use Google user data
- To authenticate and maintain your Google connection
- To execute user-requested Gmail, Drive, Docs, Sheets, Slides, Calendar, and Google Analytics actions inside StefanBrain
- To return the requested emails, calendar events, files, metadata, and analytics results in your chat history and generated outputs
- To secure the Service, investigate abuse, and comply with applicable law
Storage and sharing of Google user data
- We store encrypted OAuth tokens and connector metadata needed to keep your connection active
- We may store Google-derived content or metadata when it becomes part of your chat history, generated outputs, connector state, or security and audit records needed to provide the feature you requested
- We do not sell Google user data
- We do not use Google user data for advertising or marketing personalization
- We do not use Google user data to train generalized artificial intelligence or machine learning models
- We only use and transfer Google user data as needed to provide the user-facing features you requested, keep the Service secure, comply with law, or with your consent
5. Shopify Store Data
You can install the StefanBrain app on a Shopify store and connect the store to your StefanBrain account. In this section, "you" means the merchant or a person the merchant authorizes to connect the store. We use the store's data only for the purposes below.
Store data we access
- Store details such as name, contact email, domains, currency, time zone, and plan
- Products, inventory, discounts, files, themes, and online store content such as pages
- Orders, including the full order history, with details such as totals, discounts, status, line items, tags, survey answers, UTM tags, and ad ids
- Customer records such as Shopify customer ids, order counts, total spent, and tags
The app cannot access customer names, emails, phone numbers, or addresses.
How we use Shopify store data
- To answer your questions about the store in chat
- To make the store changes you approve, such as updating a product, creating a discount code, or publishing a page
- To match post-purchase survey answers to your products
- If you link the store to a Meta ad account, to match store sales to your ads and calculate store metrics such as revenue and new-customer rate
- To keep the Service secure and comply with the law
Who controls store data
- You control the store's data, including your customers' data. We process it on your behalf and only on your instructions, unless the law requires otherwise.
- Your instructions are the requests you make and the settings you choose in the Service.
- We do not sell store data.
- We do not use your customers' data to target ads or to market to them.
- We do not use store data to train generalized artificial intelligence or machine learning models.
- We send store data to our service providers, such as our AI model providers, only to run the Service.
- If you shop at a store that uses StefanBrain, contact that store about your data. We help the store answer your request.
How long we keep store data
- We keep the store's access tokens, encrypted, only while the app is installed. We delete them as soon as Shopify tells us the app was uninstalled.
- If you link the store to a Meta ad account, we copy its orders and keep the copy up to date. We keep copied orders while the app is installed, even if you unlink the store.
- Copied orders hold the order id, totals, dates, UTM tags, ad ids, the order's place in the customer's history, and a one-way hash of the customer's Shopify id. They hold no names or contact details.
- Store data that StefanBrain shows you in chat becomes part of your chat history. It stays there until you delete the chat or ask us to delete your account, except for the customer ids we remove below.
- We log each store request StefanBrain runs for you in chat, with its result, to secure the Service and fix problems. The log stays until you ask us to delete your account, except for the customer ids we remove below.
- When a customer asks the store to delete their data, Shopify forwards the request to us. We then remove that customer's Shopify id and order ids from your chat history and the log at once, and the customer's hash from copied orders.
- Shopify asks us to erase the store's data 48 hours after the app is uninstalled. Within 30 days of that request, we erase the orders we copied. We also remove every customer id and order id of the store from your chat history and the log. We skip both if the store reinstalls the app first.
- When a customer asks the store for their data, Shopify forwards the request to us. Our support team sends the store what we hold about that customer within 30 days.
6. Third-Party Services
We share data with third-party service providers to operate the Service. They include:
- Anthropic — AI model provider. Chat messages are sent to Anthropic's API for processing. Subject to Anthropic's usage policies.
- OpenRouter — AI model routing. Chat messages pass through OpenRouter on their way to Google's Gemini models.
- Google Gemini — AI model provider. Google's Gemini models process chat messages and the videos you ask StefanBrain to analyze.
- OpenAI — AI model provider for image generation, ad copy, and creative analysis. It also drafts follow-up emails to members who cancel.
- AssemblyAI — Audio/video transcription. Video URLs may be sent for transcript generation, and voice recordings captured during composer dictation are streamed for live transcription.
- Amazon Web Services (AWS) — Cloud infrastructure and file storage (S3).
- ActiveCampaign — Onboarding, product education, lifecycle, and marketing communications.
- Google — Connected account provider for Gmail, Google Drive, Docs, Sheets, Slides, Calendar, and Google Analytics when you enable those connectors.
- Shopify — Connected store platform when you install the StefanBrain app on a Shopify store and connect it to your account (Section 5).
- PostHog — Product analytics for understanding usage patterns.
- Browserless — Headless browser service for web page rendering and screenshot capture.
Our Sub-processors page lists the providers that process your data on our behalf, what each one does, and the data it handles.
We do not sell your personal information to third parties.
7. Data Retention
We retain your account information and chat history for as long as your account is active or as needed to provide the Service. You may request deletion of your data by contacting us. We may retain certain information as required by law or for legitimate business purposes. Section 5 explains how long we keep Shopify store data and what we erase after a store uninstalls the app.
When an app calls StefanBrain through the Developer API, over MCP or REST, we log each tool call, including calls refused for rate limits, budgets, or invalid input. A log entry is tied to your account and holds the tool name and the arguments sent, such as a message or prompt. It also holds any note the app adds to explain the call, the outcome, timing, and the app's name and version. Before we store an entry, we replace credentials we can detect, such as API keys, tokens, and passwords in links, with a placeholder. We keep these entries permanently, and only in that scrubbed form. They stay after you delete a chat. We delete them when you ask us to delete your account.
8. Data Security
We implement reasonable technical and organizational measures to protect your information, including encryption in transit (TLS/SSL), secure database access controls, and authentication safeguards. We encrypt our database and file storage at rest, and we encrypt connected-service access tokens before we store them. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your personal information
- Object to or restrict certain processing activities
- Request a copy of your data in a portable format
To exercise these rights, contact us at support@stefanbrain.com.
10. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will delete it promptly.
11. International Data Transfers
Your information may be transferred to and processed in the United States and other countries where our service providers operate. By using the Service, you consent to the transfer of your information to these jurisdictions.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact Us
For questions about this Privacy Policy or your personal data, contact us at:
Copy and Funnel Accelerator LLC
1180 N Town Center Drive, Suite 100
Las Vegas, Nevada 89144
United States
Email: support@stefanbrain.com