Brewed AI — Intelligent Agents & Configuration
How it works Agents Pricing Security FAQ
Book a 20-min call

Legal

Privacy Policy

Last updated: 20 August 2026 Entity: Brewed Security Consulting LLC Applies to: brewed-ai.com and the Brewed AI service

Contents

  1. The short version
  2. Two different things
  3. Data we collect on this site
  4. Data our agents process
  5. AI providers & sub-processors
  6. How long we keep things
  7. How we protect it
  8. Who we share with
  9. Your rights
  10. If something goes wrong
  11. Children
  12. Changes
  13. Contact

The short version

If you're just browsing, we collect analytics about how the site is used, and whatever you type into the contact form. Nothing else.

If you're a client, our agents touch your business data — including personal information about your customers — to do the work you hired them for. That data is sent to a commercial AI provider for processing under terms that forbid using it to train their models. We will tell you exactly which systems each agent can reach. We don't sell anything to anyone, ever.

Two different things this covers

Most privacy policies describe one relationship. This one has to describe two, and they work differently.

  • You visiting brewed-ai.com. Here we are the ones deciding what gets collected. That's covered in "Data we collect on this site".
  • Our agents working inside your business. Here you decide what data exists and why; we handle it on your instructions. In data-protection language you are the controller and we are the processor. That's covered in "Data our agents process".

If you're a client, the signed agreement between us governs the second relationship, and it takes precedence over anything on this page.

Data we collect on this site

Analytics

We use Google Analytics 4 to understand how people find and use the site — pages viewed, roughly where in the world you are, which buttons get clicked, what device you're on. This sets cookies in your browser. We use it to work out which parts of the site are doing their job, not to identify you personally.

You can opt out with Google's browser add-on, or by blocking analytics in your browser or an extension. The site works normally either way.

The contact form

If you fill in the contact form we collect your name, email address, phone number if you give one, and whatever you write in the message. We use it to reply to you and to prepare for a conversation. We don't add you to a marketing list.

Form submissions are delivered to us through Web3Forms, which processes the data in transit under its own privacy policy.

The Front Desk chat

If you use the chat on this site, what you type is sent to OpenRouter, which routes it to an AI model to generate a reply. We restrict that routing to providers with zero data retention, so your message is not stored or used for training. We don't ask for your name or email in the chat, and we'd rather you didn't type anything confidential into it — it's a demo, not a support desk.

Fonts

Typefaces load from Google Fonts, which means Google's servers see your IP address when the page loads. No cookies are set by the font request.

Server logs

Our web host keeps standard request logs — IP address, timestamp, page requested, browser string. Ordinary infrastructure housekeeping, not something we mine.

Data our agents process for clients

This is the part that matters most, and the part a generic privacy policy would miss.

A Brewed AI agent does its job by reading and acting on data inside your business. Depending on the workflow you've asked us to automate, that can include:

  • Email in a mailbox you've connected — including messages from your customers
  • Calendar entries, availability and appointment details
  • Customer names, contact details, addresses and job history
  • Documents, invoices, quotes and forms you route to the agent
  • Records in whatever systems you've explicitly connected

Much of that is personal information about your customers, not about you. We handle it only to carry out the workflow you've defined, and for no other purpose. We do not use it to build products, benchmark other clients, or market anything.

Scoped access, written down. Each agent is granted access to exactly the systems its job needs and nothing more. We document that scope with you before the agent goes live, and you can revoke it at any time. Ask us for the current scope of any agent and we'll send it.

Your responsibilities

You're the one who decides what data the agent sees. If your customers' data is subject to rules beyond ordinary business confidentiality — health information, payment card data, anything covered by a regulation specific to your industry — tell us before we build, so we can scope the agent correctly or tell you honestly that we're not the right fit.

AI providers and other sub-processors

Agents reason using commercial AI models that we do not operate ourselves. This means your data is transmitted to a third-party provider to be processed. We are not going to pretend otherwise — it's the single most important thing to understand about handing work to an AI agent.

What we can tell you about how that provider handles it:

  • We use commercial API tiers under business terms that prohibit the provider from training its models on your data. This is not the same as a consumer chatbot, where the default is often the opposite.
  • Retention at the provider is limited to a short operational window for abuse monitoring, after which the data is deleted. It is not kept indefinitely.
  • We will name the provider and share the applicable terms on request. We'd rather you check than take our word for it.
  • If we change providers in a way that materially affects how your data is handled, we'll tell you before it happens.

Other services involved in running the business: our web host, Google Analytics, Web3Forms for contact form delivery, and standard email and calendar infrastructure. We'll provide a current sub-processor list to any client who asks.

How long we keep things

  • Contact enquiries: kept while we're talking and for a reasonable period afterwards. Ask us to delete them and we will, within five business days.
  • Client business data: kept only as long as needed to run your agents. The specific retention window is agreed with you in writing and set out in your agreement.
  • Agent activity logs: retained through the engagement so you have an audit trail, then deleted or handed over at your choice when we finish.
  • Analytics: retained per Google Analytics' configured retention period.

When an engagement ends, we delete or return your data on your instruction. Say the word and we'll confirm in writing when it's done.

How we protect it

Brewed AI is part of a network security practice, so we'd be embarrassed to get this wrong.

  • Least-privilege access for every agent and every person — nobody and nothing gets reach it doesn't need
  • Credentials and API keys stored in a secrets manager, never in code or documents
  • Encryption in transit for everything, and at rest wherever the underlying service supports it
  • Multi-factor authentication on every account that touches a client system
  • A readable log of what each agent did and when

No one can promise a system will never be breached, and we won't. What we can promise is that we designed for the possibility rather than assuming it away.

Who we share data with

We do not sell your data. We do not share it with advertisers. We do not trade it, rent it, or hand it to data brokers.

We share it only with the sub-processors listed above, strictly to deliver the service, and if the law requires us to. If we ever receive a legal demand for a client's data, we'll tell you unless we're legally prohibited from doing so.

Your rights

Whoever you are, you can ask us to:

  • Tell you what information we hold about you
  • Correct anything inaccurate
  • Delete it
  • Stop contacting you

Email sales@brewedsecurity.com and we'll respond within five business days.

If you are a customer of one of our clients and your data reached us through their agent, please contact that business directly — they decide what happens to their records, and we act on their instructions. Tell us anyway if you can't reach them and we'll help make the connection.

If something goes wrong

If we become aware of a security incident affecting your data, we will tell you promptly and in plain English: what happened, what data was involved, what we've done about it, and what you should do. We won't wait for certainty before flagging something that looks serious, and we won't bury it in a status page.

Children

Brewed AI is sold to businesses. We do not knowingly collect information from anyone under 18 through this website. If you believe a child has submitted information to us, tell us and we'll delete it.

Changes to this policy

If we change it, we'll update the date at the top. If a change materially affects how client data is handled, we'll email clients rather than rely on you noticing.

Contact

Brewed Security Consulting LLC — trading as Brewed AI

Email: sales@brewedsecurity.com

Phone: (513) 285-6631

Cincinnati, Ohio · serving Cincinnati, Dayton and Northern Kentucky

© 2026 Brewed Security Consulting LLC. Brewed AI is a Brewed Security company. Home · Terms of Service · Brewed Security