Privacy Policy

How Brilly collects, uses, stores and shares information.

Effective date: October 6, 2026

This policy explains what Brilly (brillybot.online) does with your information. Brilly is operated by Ahmed Ayman Ahmed Fouad Hamam ("Brilly", "we", "us"). It should be read together with our Terms of Service. Questions about this policy or your data: support@brillybot.online.

1. Your account

You can create a Brilly account in one of two ways:

  • Email and password. We receive the email address you provide. Your password is sent from your browser directly to our authentication provider (Supabase Auth), which stores it in hashed form. Brilly's servers never receive or store your password. We send the emails this requires, such as account confirmation and password reset.
  • Google sign-in. See section 2.

For either method we hold an account identifier, your email address, and account timestamps, and — where available — a display name and profile picture URL, so we can identify your account and show it in the interface.

2. Google sign-in

If you choose to sign in with Google, Google provides the authentication information needed to sign you in and create your Brilly account: your Google account identifier, email address, name and profile picture URL.

That is all Brilly requests from Google. Signing in with Google does not give Brilly access to your Gmail, Google Drive, Calendar, contacts or any other Google service. (Brilly has a feature for saving email addresses you want to share files with; those are addresses you type in yourself, not contacts read from your Google account.)

3. Your content

"Your content" means anything you provide to Brilly, including prompts, messages, uploaded files, datasets, drafts, scheduled posts, profile details, configuration and preferences, and other inputs.

You retain ownership of your content. We process, store and transmit it only as necessary to provide the features you use, as described in this policy and in our Terms of Service.

4. Your AI provider keys (BYOK)

Brilly's AI features use an AI provider account that you connect with your own API key. Here is exactly what happens to that key:

  • It is stored in your browser's local storage (and in session storage if you choose a provider for a single tab). It is not stored in our database.
  • When you make a request that needs AI, your browser reads the key and sends it to Brilly's server with that request.
  • Our server forwards the request, with your key, to the provider you selected and returns the response. We only forward to a fixed list of approved provider addresses.
  • The key is used in memory for that request only. It is not written to our database, not stored durably on our servers, and not logged by us.

Removing a key in Brilly deletes it from your browser. You can also revoke it with the provider at any time.

5. AI providers you choose

When you use an AI feature, the content needed to answer your request is sent to the AI provider you selected. Depending on the feature, that can include your message and recent conversation history, text and images from files you upload, a screenshot you choose to share, your custom tutor instructions and skills, your Fitness profile and saved training plan (section 7), details of a dataset you are analysing, including sample rows (section 6), and, for the Brilly X content planner, your content ideas, goals, niche and style summary and any of your own posts you choose as voice examples, abstract patterns from the benchmark profiles you watch and any results you enter for your own experiments when you generate today’s ideas or a draft, the conversation you ask for reply suggestions on, and a short summary of your day when you plan it (section 8).

That provider processes your content under its own terms and privacy policy, not ours, and any usage charges are billed to you by the provider. We do not control how a provider uses, retains, logs or trains on the data you send it, so please read the policy of the provider you choose. Supported providers include OpenAI, Google Gemini, Anthropic (via OpenRouter), xAI, DeepSeek, Mistral, Groq, Perplexity, OpenRouter and Together AI.

AI model training. Brilly does not use your content to train its own foundation models. The third-party AI providers you connect may process the data you send them under their own terms and privacy policies, which may differ.

6. Brilly Data

When you use Brilly Data to analyse a dataset, we store:

  • your projects and their names;
  • the dataset files you upload (CSV or Excel), in private storage tied to your account;
  • information about each dataset, such as its file name, size and structure, and the results of Brilly's inspection of it;
  • your analysis history, including the steps you apply, generated code, and results such as charts.

To inspect a dataset, Brilly runs its own inspection program on the file in an isolated server environment provided by our hosting provider. When you ask Brilly's AI about a dataset, the request sent to your AI provider includes the file name, the structure of the data, summary information, and up to 20 sample rows of the actual data. Please take this into account before uploading data containing personal, financial or other sensitive information.

You can delete a Data project, together with its dataset, from within Brilly.

7. Brilly Fitness

To personalise training assistance, Brilly Fitness stores the information you enter in your fitness profile:

  • age, sex, height and weight;
  • training experience, primary and secondary goals, and activity level;
  • training days per week, session length and preferred days;
  • training environment and available equipment;
  • any training limitations or exercises you prefer to avoid;
  • training plans you choose to save.

This is information you provide to shape your training. It is not a medical record, and Brilly does not diagnose or assess anyone's health. Training limitations are your own description of what you prefer to avoid; Brilly does not interpret them as a diagnosis.

When you ask Brilly Fitness a question or ask it to build a plan, your profile and current saved plan are sent to your chosen AI provider (section 5) along with your message. Your Fitness conversation itself is kept only in your browser tab while you use it and is not saved to our database.

You can edit your fitness profile at any time. There is not yet a button to delete your fitness profile or saved plans; to have them deleted, contact us (section 16).

8. X (Twitter)

Public X data

Brilly's X intelligence features retrieve public X posts and account information using Brilly's own server-side access to the X API, based on the niche, keywords and handle you enter. This does not require connecting your X account and gives Brilly no access to your private X data. Your settings for this feature are stored in your browser, and search results are not saved to our database, apart from the content labels described under “Content analysis (Jev)” and the benchmark profiles described below.

Benchmark profiles

You can add public X profiles to a benchmark watchlist. For each watched profile, Brilly reads through its own X API access the public profile details (name, username, profile picture, follower and post counts, verification, and whether the account is protected) and the account’s recent public original posts: their text and time, their public engagement counts (likes, replies, reposts, quotes and, where X provides them, impressions), and whether they include media or quote another post. Replies and reposts are not collected, and protected accounts are not read.

This public data is kept in a shared cache so each profile is read from X at most once a day, however many Brilly users watch it. The posts’ text is sent to Jev (TypeSafe AI) to label hook, structure and tone, as described under “Content analysis (Jev)”. Brilly uses the data only to compare each post with that creator’s own typical performance and to find patterns; the people you watch are not Brilly users and are not contacted. Brilly stores which profiles you watch, and removing a profile removes it from your watchlist. It is public X data, and Brilly never presents it as private or as belonging to you.

Each time Brilly reads a benchmark post’s public counts it keeps a dated record of them, so performance can be compared at the same age later. When you choose “Fetch missing data” for selected posts, Brilly also reads from X each post’s full text, language, edit history and media details (type, size, video length and any alt text the author wrote) and keeps them with the post. Brilly does not download images or videos. If X reports a post as deleted when Brilly reads it, Brilly removes its copy and everything derived from it.

Content analysis (Jev)

To label X posts — their opening style, structure, tone and topic, and whether they are about your niche — Brilly sends the text of those posts, together with your niche, categories and keywords, to Jev, a classification model provided by TypeSafe AI, a third-party provider. This covers public posts found by a Top Posts search, posts from benchmark profiles you watch and, when you refresh analytics, your own posts. When you plan your week, Brilly may send your new ideas and your recent ideas so Jev can flag near-duplicates, and when you generate a draft it may send that draft so Jev can flag claims worth checking. When you choose “Analyze with Jev” for selected posts, Brilly sends the text of those posts — public benchmark posts, or the text of your own posts that you fetched from X or pasted — so Jev can label their content, opening, structure, tone, stated claims and ending; engagement figures are not sent. Only what the feature needs is sent. Jev returns labels and probabilities; it does not write content, and Brilly’s metrics (likes, engagement, best times, follower counts) are never produced by it.

Brilly’s access key for Jev stays on Brilly’s servers. TypeSafe AI processes the content it receives under its own terms and privacy policy. Brilly stores the labels Jev returns — with the post ID, a fingerprint of the text (not the text itself), the model that answered and its confidence — so the same post is not sent again. When Jev is unavailable, Brilly uses its own rules instead and says so.

Connecting your X account

You can choose to connect your X account so Brilly can publish content for you. You authorise this on X's own authorisation page, where you can see what access you are granting. If you connect, Brilly stores:

  • your X account ID and username, and the permissions you granted;
  • the X access token and, where X issues one, a refresh token. These are encrypted with AES-256-GCM before they are stored on our servers, kept in a table that cannot be read from your browser session, and used only by Brilly's server;
  • the status of the connection;
  • during authorisation only, short-lived security values used to complete the sign-in with X, which are deleted once used and otherwise expire after 15 minutes.

To provide scheduling, Brilly also stores:

  • drafts and scheduled posts, threads and X Articles you write;
  • your queue time slots and timezone;
  • publishing status, attempts and error information;
  • the IDs of posts and Articles Brilly publishes for you, and for an Article the draft ID X assigns before it is published.

Posting-time analytics. To analyse when your content has historically performed best, Brilly reads your own recent original posts from X and stores, for each one: its X post ID, when it was posted, its character count, and its public engagement counts — likes, replies, reposts, quotes, and impressions where X provides them. It also stores your follower count at the time of reading. Brilly does not store the text of these posts. It reads them only when you open the analytics or refresh them, not continuously.

Content planner. When Brilly reads your posts for analytics, it also stores short structural labels for each one — the kind of opening hook, the post structure, the tone and a short topic label — and a summary of your writing style made of numbers such as typical length, line count and how often you use questions, lists, emoji or links. It does not store the text. When you plan content, Brilly stores the ideas it suggests (topic, angle, format, the evidence behind the suggestion and a suggested posting window), whether you marked an idea “More like this” or “Not interested”, and, if you save a generated draft, which idea it came from and its labels, so Brilly can later show how posts it helped create have performed. Your content goals and formats are kept in your browser.

Planning and draft generation use the AI provider you connect (section 5). Brilly sends it the idea, its evidence, your niche and goals, and your style summary. If you choose “Use my style”, Brilly fetches up to five of your own posts that you select from X and includes their text in that one request; they are not stored. To check a draft is not a near-copy of someone else's post, the opening lines of posts from your latest Top Posts search are sent to Brilly's server; they are compared there, never sent to your AI provider, and never stored. Brilly never publishes a generated draft on its own — it becomes a draft or a scheduled post only when you save or schedule it.

X Articles. Articles you write or generate are stored like your other drafts: title, optional subtitle and body. A scheduled Article is sent to X through X's Articles API when it is due — first as a draft on your X account, then published. If you generate an Article, Brilly sends your AI provider the idea, its evidence, your goals, the objective you chose and your style summary.

Daily activities. When you plan your day, Brilly stores the plan: each activity's type, title, reason, time, estimated minutes and whether you marked it done or skipped, and a link to the scheduled item or idea it relates to. For a suggested engagement session it stores references to the conversations it suggested — the X post ID, the author's username and Brilly's reasons — but not the text of those posts. If you use an AI provider to plan your day, Brilly sends it a short summary: how many items are scheduled and when, how many ideas, conversations and mentions there are, your goals and your chosen effort level.

Conversations and mentions. To suggest conversations, Brilly searches recent public X posts in your niche, or reuses your latest Top Posts search. To show mentions, Brilly reads posts that mention you through your X connection, together with the post each one replies to and the first post of that conversation, so you can see what is being answered. It does this only when you ask, and shows the results without storing their text. When you click “Suggest replies”, that conversation — the message, the post it replies to and the conversation’s first post — and your style summary are sent to your AI provider; the suggestions are placed in your reply editor and are not stored. To enforce a daily limit on reply suggestions, Brilly stores how many you generated on the current day (UTC).

Replies you send. You can write a reply, or edit a suggestion, and send it from Brilly. A reply is sent only when you click “Send reply”, to the post shown, through your X connection; just before sending, Brilly reads that post from X to check it is still the one you saw. For each reply you send, Brilly stores a record without the reply’s text: the ID of the post you replied to, the ID of your reply on X, whether it was sent, and when. Brilly uses these records to stop the same reply being sent twice and to apply a daily safety limit on replies sent from Brilly.

Growth insights. To show what has worked for your account, Brilly analyses the post metrics and labels described above; the insights are calculated when you open them and are not stored. To show a follower trend, each analytics refresh also stores your follower count for that day. Brilly records whether a scheduled item was placed with “Schedule at best time”, and the content goals you had selected when an idea was planned. If you create or skip a growth experiment, Brilly stores it: the idea it tests (topic, hook, structure, format and suggested time), Brilly's reasons, its status, and a link to the idea and post it relates to. Its result is read from that post's existing metrics, not copied. If you ask for an AI-written weekly summary, the week's calculated figures — counts, multiples of your baseline, topic and hook labels, activity completion and follower change — are sent to your AI provider; no post text is included.

Post feature analysis. When you refresh analytics, Brilly also keeps a dated record of each of your posts’ public counts at that moment, and text measurements calculated from the post while it is read — such as character, word, line, link and emoji counts — together with a fingerprint of the text, not the text. When you choose “Fetch missing data”, Brilly reads selected posts from X through your connection; their text is shown to you and used for the analysis you ask for, and is not stored. Text you paste is labelled as yours and is not stored either. Labels Jev returns for your posts are stored privately with the model that answered and its probabilities. If you annotate a post’s media (for example, “side-by-side layout”), the annotation and any note are stored privately for you. For each paid analysis you start, Brilly stores a usage record — how many posts, requests and tokens it used — to prevent duplicate runs and apply daily limits.

Pattern discovery. When you choose “Calculate from saved data”, Brilly analyses post features and measurements it has already stored — your own posts, or the public posts of benchmark profiles you watch — without any new request to X, Jev or an AI provider. It saves each analysis privately for you: the settings you chose, the IDs of the posts and measurements used (not their text), and the calculated results. Brilly keeps your 20 most recent analyses; reopening one re-checks that its posts still exist and removes links to any that don’t. Your private annotations are only ever used in your own analyses.

Creator playbooks and today’s ideas. Opening a creator playbook, the lessons from your watchlist or the Today page uses only data Brilly has already stored, without any request to X, Jev or an AI provider. When you press “Generate ideas” or “Draft this”, Brilly sends one request to the AI provider you connect (section 5) with abstract patterns — labels such as the kind of opening or structure and how many posts and creators showed them, not the text of anyone’s posts — together with your niche, goals, style summary, recent idea titles and, for a draft, the results you entered yourself. Each saved idea keeps its brief, the evidence level behind it, the IDs (not the text) of the benchmark posts and creators it drew on, the model that wrote it, any results you enter, and the feedback you give. To check that an idea or draft is not a near-copy, it is compared on Brilly’s server with the cached posts of the profiles you watch; those posts are not sent to your AI provider. Nothing is scheduled or published from these ideas unless you save or schedule it yourself.

Performance predictions. When you choose “Predict performance”, Brilly estimates how a draft may perform using your own posts’ historical results and the draft’s content features — a statistical model, not an AI guess about virality. If you train the predictor, Brilly stores the model it builds from your stored results (the features it uses, their weights and how well it did on your later posts). Each prediction is stored privately for you with the estimate, the model version and the derived features of the draft — not its text. Predictions use no AI provider and make no request to X. Only if you choose “Analyze + predict” is the draft’s text sent once to TypeSafe’s Jev, as described above, to label its content features. Estimates are of ordinary public X impressions, not verified or monetization metrics.

Growth goals and daily plans. If you set up a growth goal, Brilly stores the campaign you configure (targets, dates, starting values, timezone, Focus Mode and any X usage budget) and your campaign progress: the official eligibility or qualifying-impression counter and verified follower count you enter manually from X Creator Studio, when you read them, and an optional note. Brilly cannot see verified or qualifying impressions itself; it only stores what you enter, and it keeps earlier versions when you correct an entry. These values are kept separate from the ordinary public impression counts Brilly reads for your posts, and Brilly never attributes them to individual posts. From your entries and the data Brilly already stores, it derives pacing, activity associations (statistical associations between your activity and your counter, not causes) and daily and weekly recommendations, and it stores what it recommended and any feedback you give. These calculations use no AI provider and make no request to X. Only if you choose “Explain my plan” or a written weekly summary is the plan’s summary (never your posts’ text) sent once to the AI provider you configured with your own key. This information is private to your account.

Connecting Claude Code or other MCP clients. You can create a Brilly MCP access token in Brilly X (Claude / MCP) to connect an external MCP client, such as Claude Code, that you run. A connected client can read the Brilly X data covered by the scopes you grant (analytics and patterns, goal and plans, benchmark playbooks, predictor status, ideas and drafts) and can save drafts for you to review. It cannot publish, schedule or reply, and Brilly never publishes content an MCP client created on its own: you review it and publish it yourself. Brilly stores only a hash of the token (never the token itself), its scopes, when it was created, last used, expires or was revoked, and a log of each call (the tool, time, outcome and ids such as a saved draft’s id — not your content). Data the client reads goes to that client, and if it is an AI assistant, to its provider under that provider’s terms; this only happens after you create a token and connect the client. You can revoke a token at any time. MCP access covers Brilly X only, not other Brilly products.

Brilly uses the connection only for actions you authorise. At the time you schedule, the content you wrote is sent to X and published to your account, and a reply is sent when you click “Send reply”. Brilly does not automatically like, follow, reply to or repost anything on your behalf.

Disconnecting. You can disconnect your X account in Brilly at any time. Disconnecting deletes the stored access and refresh tokens, attempts to revoke Brilly's access with X, and marks the connection as disconnected. Your drafts, scheduled items and publishing history are kept so you don't lose your work, and your X username and account ID remain on the disconnected connection record. You can also revoke Brilly's access from your X account settings. Content already published to X stays on X until you delete it there.

Information sent to X, and posts published there, are also subject to X's own terms and privacy policy.

10. Email

We send email through our email delivery provider (Resend) for:

  • account emails, such as confirming your email address and resetting a password;
  • share emails that you trigger yourself, sending a file to a recipient you choose;
  • support conversations when you write to support@brillybot.online.

For share emails we store the files you share (see section 11), the email addresses you choose to save, delivery records such as the recipient, template and status, and an unsubscribe and suppression list so that unsubscribes and bounces are respected. We do not send marketing or promotional email.

11. Files, screen sharing and voice input

When you upload a document, Brilly extracts its text to answer your questions about it, and keeps a record of the file (name, size and date) to track your storage use. When you share a file by email, it is stored in private storage tied to your account and a signed link valid for seven days is sent to the recipient; anyone holding that link can download the file until it expires.

Screen sharing uses your browser's standard screen-capture permission. A frame is captured only when you ask Brilly to look at your screen, is sent to your chosen AI provider for that request, and is not stored on our servers. Avoid sharing screens that show passwords, keys or other sensitive information.

Voice input uses your browser's built-in speech recognition. In some browsers, notably Chrome, your audio is processed by the browser vendor under its own privacy policy. Brilly does not receive or store the audio.

12. Browser storage and cookies

Brilly stores some things in your browser rather than on our servers.

Local storage and session storage hold your sign-in session so you stay logged in, your AI provider keys and settings (section 4), your tutor sessions, custom tutors, saved chats, screen library and skills, your Brilly X intelligence settings, Brilly Data workspace layout, and preferences such as theme. These are not uploaded to our database, are removed if you clear your browser storage, and do not sync between browsers or devices.

Cookies. Brilly itself keeps your sign-in session in local storage rather than in a cookie. Cookies are set by Google Analytics (section 13). We do not use advertising cookies.

13. Analytics and operational data

Brilly uses Google Analytics, which sets cookies and collects standard usage information such as pages viewed, approximate location derived from your IP address, and device and browser details. We use it to understand how the site is used.

Our hosting, database and other infrastructure providers also process technical information such as IP addresses, request details, timestamps, and diagnostic and security logs, as needed to host, secure and operate the service. Brilly's own diagnostic logs may occasionally include limited request details, such as a web address that failed to load, but never your API keys or X tokens. We do not use this information to build advertising profiles.

14. How we use information

We use information to:

  • authenticate you and keep your account secure;
  • provide the features you use and save your content and settings;
  • send your AI requests to the provider you selected;
  • inspect and analyse datasets you upload;
  • personalise Brilly Fitness answers and plans;
  • connect your X account and schedule and publish the content you choose;
  • retrieve web search results you ask for;
  • send account, share and support email;
  • understand usage, and secure, troubleshoot and maintain the service;
  • comply with legal obligations where they apply.

15. Service providers and sharing

Brilly uses third-party infrastructure and service providers to operate, which may include Supabase (authentication, database and file storage), Vercel (hosting and the isolated environment used to inspect datasets), Google (sign-in and analytics), Resend (email), Firecrawl (web search), X, TypeSafe AI (Jev content classification), and the AI provider you choose. Each processes information under its own terms and privacy policy.

Information is shared with these providers only as needed for what you ask Brilly to do:

  • your prompts and the context they need go to the AI provider you selected;
  • posts and threads you schedule go to X when they are published;
  • search queries and web addresses go to our search provider;
  • the text of posts, ideas or drafts being classified, with your niche terms, goes to TypeSafe AI (Jev);
  • the recipient and content of an email go to our email provider.

Brilly does not sell your personal data.

Brilly and these providers may process information in countries other than the one you live in.

16. Retention, deletion and your rights

We keep information for as long as needed to provide the service to you — generally for as long as your account exists — and as needed to keep the service secure, to preserve history you have chosen to keep, and to meet legal obligations.

What you can do yourself in Brilly:

  • remove your AI keys and clear content stored in your browser;
  • delete uploaded files and saved email contacts;
  • delete a Brilly Data project and its dataset;
  • edit your fitness profile;
  • disconnect your X account and cancel scheduled posts.

There is not yet a self-service button to delete your whole account. To have your account and associated data deleted — including your fitness profile and saved plans — email support@brillybot.online from the address you signed up with, and we will action it manually. Data already sent to an AI provider, posts already published to X, and emails already delivered are outside our control and cannot be recalled by us.

Depending on where you live, you may have rights under applicable law to access, correct, delete or receive a copy of your personal information, to restrict or object to certain processing, and to withdraw consent where processing is based on it. To make a request, contact support@brillybot.online.

17. Security

We use reasonable technical and organisational safeguards to protect your information. These include HTTPS for all traffic; authentication before your data can be accessed; database row-level security so each account can reach only its own rows; private file storage accessed through time-limited signed links; keeping secrets on the server rather than in the app you download; encrypting X access and refresh tokens before storing them; and requesting only the permissions each integration needs.

Brilly is a small, independently run service, and no method of transmission or storage is completely secure. Please don't upload information you could not afford to have exposed.

18. Children

Brilly is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us with personal information, contact us and we will remove it.

19. Payments

Brilly does not sell plans or take payments, and does not collect card numbers, billing addresses or tax details. Our database contains a dormant table left over from an earlier version of the product; it holds no payment information.

20. Changes to this policy

We may update this policy as Brilly changes. When we make a material change we will update the effective date above and, where appropriate, let you know in the app or by email.

21. Contact

Questions, requests about your data, or privacy concerns: support@brillybot.online.

See also our Terms of Service and Refund Policy.