Privacy

Local work stays local.
The waitlist stays minimal.

The native app and the public release waitlist are separate systems with different data paths.

1. The macOS app

Cerebro stores projects, agents, settings, working state, run history, receipts, and connected knowledge in the selected application data root on your Mac. We do not receive that local state merely because you run the app.

Claude Code, Codex, and any connected service use the network paths and accounts you configure for them. Their handling of prompts, files, and usage is governed by their own terms and your setup.

The site does not run behavioral measurement scripts, advertising pixels, or session replay.

2. The release waitlist

When you join, Cloudflare D1 is the canonical subscriber database. We store the normalized email address, the page source, consent time and copy version, subscription status, a consent generation, opaque identifiers, and delivery state needed to send and reconcile the promised messages.

Cloudflare Turnstile protects the form from bots. It processes browser and security signals to decide whether a submission is legitimate; Cerebro receives only the verification result needed to accept or reject the signup.

We do not store raw IP addresses or browser user-agent values for new signups. Legacy values are cleared during migration. We do not sell waitlist data or use it for unrelated advertising.

The waitlist promise is limited to important release notes and the public-beta launch once email delivery is enabled.

3. Email delivery

Email delivery is currently paused. D1 remains the source of truth for consent and subscription status. No provider request is made while delivery is paused. When delivery is enabled, Resend will deliver the waitlist messages. Delivery records keep the template version, subject, sender, payload integrity data, provider message identifier, attempt state, and bounded error classification needed for safe retries and support.

No email open or click measurement is enabled for launch.

Each message includes an unsubscribe link signed for its environment. The token contains an opaque signup identifier, consent generation, nonce, and signature; it does not contain the email address.

4. Retention and deletion

  • A subscribed address is kept until the launch notice is sent, then for no more than 90 days for delivery support. If no launch occurs, consent expires after 24 months unless you explicitly confirm it again.
  • An unsubscribe prevents further sends immediately. Plaintext subscriber detail and detailed delivery rows are deleted or anonymized within 30 days.
  • A one-way suppression digest may remain only to prevent accidental re-import, until 90 days after public launch and never longer than 24 months from unsubscribe. A deliberate new signup replaces it with fresh consent.
  • Delivery records are kept for no more than 90 days after their terminal state. Unknown outcomes must be reconciled within that window.
  • Rows requiring review are exported for operator review and removed within their 30-day bound.

These limits are enforced through a dry-run-first maintenance tool with guarded, explicit apply steps. There is no automatic background deletion process, so an operator must run the due-row maintenance procedure.

You may also request deletion. A verified request is completed within 30 days and removes the signup, provider identifiers, stored payload data, matching suppression record, and reconciliation tombstones. The operator verifies the request without putting the address in command-line history.

5. Preview and production separation

Preview and production use separate D1 databases, signing keys, origins, and delivery modes. Preview can send only to an explicitly allowlisted recipient. Production currently uses an empty allowlist, so signups are stored without outbound provider requests while email delivery is paused. Production data is not used to test preview deployments.

6. Your choices

You can request access, correction, removal, or deletion at hello@trycerebro.com. When email delivery is enabled, each waitlist message will also include an unsubscribe link.

This notice will be updated when the public app or its data flows materially change. The effective version will remain visible on this page.

Effective: July 18, 2026