Last updated 2 October 2026
Privacy Policy
Cerebrus is a private knowledge base: you upload your documents and ask questions in plain words. This page explains what we keep, who sees it and how you stay in control.
Who we are
Cerebrus is run by Bruno Falcão (“we”), and is available at admin.cerebrus.cloud. Accounts are created by an administrator; there is no public sign-up. For any privacy question write to [email protected].
What Cerebrus does
Cerebrus reads the documents you give it, breaks them into passages and facts, and lets you chat with them. Every answer cites the documents it comes from. Your projects are private to your account.
What we store
- Your account: name, email address and a hashed password (we never keep the password itself).
- Your content: the documents you upload or link, the passages and facts read from them, your chats and your feedback on answers.
- AI usage records: for every AI call, its cost, duration, outcome and what caused it (user, project, document, chat, task). These records never contain your prompts, the answers or document text.
- Your AI keys: the provider keys you add on the AI keys page, stored encrypted and shown only by their last four characters.
- Connected accounts: if you connect Google Drive or Microsoft OneDrive, the sign-in tokens that let Cerebrus read the folders you link, stored encrypted.
How your data is protected
Documents, passages, facts, chats, stored files and connected-account tokens are encrypted at rest with a separate key for each project. Those project keys are themselves protected by a master key that is kept outside the database, so a copy of the database alone cannot be read.
AI processing and your own AI keys
To read documents and answer questions, Cerebrus sends document text and your questions to an AI provider. Cerebrus has no AI keys of its own: you add your own keys, and everything the AI does for your projects runs on, and is billed to, your keys. The providers you can choose are Google (Gemini API), OpenAI, Anthropic (Claude), OpenRouter and Voyage AI.
Once content reaches the provider you chose, it is handled under that provider’s own terms and privacy policy. Read them before you upload sensitive material.
Google Drive and Microsoft OneDrive
You can link a folder from your Google Drive or Microsoft OneDrive so that new and changed files are picked up automatically.
- Read-only. Cerebrus asks Google for the read-only Drive permission (
drive.readonly) and Microsoft for read access to your files (Files.Read.All, plus basic sign-in and profile permissions andoffline_accessso syncing keeps working). Cerebrus never changes or deletes anything in your Drive or OneDrive. - Only the folders you link are read. Cerebrus does not index the rest of your Drive or OneDrive.
- Tokens are encrypted and belong only to the person who connected.
- Disconnect any time from the connections page. For Google, Cerebrus asks Google to revoke its access and deletes its copy of the tokens. For Microsoft, Cerebrus deletes its copy of the tokens and pauses your linked folders; Microsoft offers no revoke call for this sign-in, so you can also remove the app’s access in your Microsoft account settings. Documents already imported stay in your project until you delete them.
Google API Services User Data Policy
Cerebrus’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms, for data we receive from your Google Drive:
- We use it only to provide the feature you asked for: indexing the folders you link, for your own projects, so you can search and chat with them.
- We do not use it for advertising, and we do not sell it.
- People do not read it, except with your consent, to protect security or to comply with the law.
- We do not use it to develop, improve or train generalized AI or machine-learning models. Content is sent to the AI provider you configured with your own keys only to answer your own questions.
Deleting your data
- A document: deleting it removes its stored file, pages, passages, summaries and facts.
- A project: deleting it permanently removes its documents, passages, facts, chats, feedback and stored files, any operator benchmark samples taken from it, and destroys its encryption key, so any leftover copy, a backup included, can no longer be read.
- Your account: email [email protected] and we will delete it.
No selling, no ads, no tracking
We do not sell or share your data, and Cerebrus shows no ads. We use no analytics or tracking cookies. The only cookies are the ones needed to run the site: your sign-in session, a security token that protects forms, and, only if you tick “Keep me signed in”, a cookie that keeps you signed in.
Changes and contact
If we change this policy we will update the date above. Questions, or requests to see or delete your data: [email protected].