Privacy policy

Privacy policy.

Last updated: 24 September 2026

Learning Brain is an evidence-grounded learning-design tool that connects to your AI assistant via the Model Context Protocol. This policy describes what data is collected, how it's used, how long it's kept, and who it's shared with.

Questions about this policy or your data: info@learningbrain.ai.

The short version.

  • Only what's needed to give you access and keep Learning Brain running is collected.
  • Your prompts, tool inputs and tool outputs are not stored. They're processed in memory and returned to your AI client. They are not written to the database or to our logs.
  • For each tool call we record which tool was called, when, and from which account — never what was in the call.
  • Your data is never sold or shared for marketing. We use a small number of service providers to run Learning Brain, listed in section 4.
  • You can ask us to delete your account and its data at any time by email.

1. Data collected

At signup

When you request access via the signup form at learningbrain.ai:

  • Email address
  • Name
  • Your role, as you describe it
  • Whether you ticked the box to receive occasional emails about Learning Brain
  • Timestamp of signup

When you connect an AI client

When your AI client (Claude, Codex, ChatGPT, etc.) connects via OAuth:

  • OAuth client ID and registration details (the app's name and the addresses it returns to)
  • Access and refresh tokens issued to your AI client (stored only as hashes)
  • A record linking the connected client to your signup email

To confirm it's you, we email a single-use link to your signup address. The link expires after 15 minutes and is stored only as a hash.

If you use an API key

If you use the API-key route (for environments that block OAuth):

  • A hash of your lb_* API key, linked to your email (the key itself is never stored)
  • Timestamps for creation and last use

If you ask for a new key, we email you a single-use link, as above.

Account administration

  • Which parts of Learning Brain your account can use
  • If access is withdrawn, a record of that with a short reason

During tool use

For each tool call, the following is recorded:

  • Tool name (e.g., arch_design_module)
  • Timestamp
  • Release tier and knowledge-base version
  • The IDs and evidence ratings of the research notes the tool returned
  • Rubric name used (if any)
  • A random call ID
  • The OAuth client identifier and your account email (so calls can be attributed to your account for support and access control)
  • The User-Agent header sent by your AI client (e.g., Claude/0.13.2 (Macintosh)), so we know which AI apps Learning Brain is used from. This is the same string every website you visit receives; nothing is added to it.
  • Whether your AI client says it can show interactive forms, recorded with its User-Agent when it connects, so Learning Brain can show you a form where your app supports one and ask in text where it doesn't. It's deleted with your account.

The following is not recorded or logged:

  • The content of your prompts
  • The inputs you pass to the tool (learner context, course briefs, design drafts, etc.)
  • The outputs the tool returns (the scaffolded prompts and research notes your AI sees)
  • The final content your AI produces

If a tool declines a request, only the tool name, the type of refusal and (where details are missing) the names of the missing fields are logged, never the text you sent. This is a deliberate design choice: your design work stays between you and your AI client.

Operational logs and rate limiting

Our hosting provider keeps application logs. They contain your email address (and, at signup, your name) when you sign up, connect or ask for a key, and your email and User-Agent for each tool call. They never contain tool inputs or outputs. These logs are held by the hosting provider under its own retention settings, and are not copied anywhere else.

To limit abuse, your IP address is used in the server's memory to count requests. It is never written to disk, and it is cleared whenever the server restarts.

2. How the data is used

DataPurpose
Email, nameGive you access; send sign-in confirmation links; contact you about service updates or outages
RoleUnderstand who Learning Brain is serving
OAuth tokens, API keysAuthenticate your requests to the MCP server
Account access settingsDecide which tools your account can use
Tool-call recordsMonitor reliability; find gaps in the research the tools draw on; detect abuse
User-Agent stringIdentify which AI clients (Claude Desktop, ChatGPT, Codex, Cursor, etc.) Learning Brain is used from, so compatibility fixes can be prioritised
Whether your AI client can show formsShow the learner-profile form only where it can appear, and ask in text elsewhere
Email (only if you ticked the box)Send occasional news about Learning Brain

None of this data is used for advertising, profiling, or resale.

Occasional emails. If you tick the box when you sign up, we may send you occasional news about Learning Brain. The box is not ticked unless you tick it. To stop these emails, reply to any of them or write to info@learningbrain.ai.

3. Legal basis

Under UK GDPR, the lawful basis is:

  • Contract performance for processing necessary to provide the tool you signed up for (access, sign-in emails, tool use).
  • Legitimate interest for minimal operational records and logs (service reliability and abuse prevention).
  • Consent for occasional news emails, which you can withdraw at any time.

4. Third parties

The following sub-processors are used:

ProviderPurposeLocation
Fly.ioApplication hosting, HTTPS and application logsLondon (LHR)
ResendSends sign-in confirmation and key-recovery emails (receives your email address and the link)EU (Ireland)
Google FontsServes the fonts on this website (receives your IP address and browser details when a page loads)United States
GitHubPublic hosting of the Claude Code plugin repository (no user data)United States

Your data is never shared with any third party for marketing. Your AI client (Anthropic, OpenAI, etc.) sees the tool outputs Learning Brain returns, but your data is not transmitted to Anthropic or OpenAI independently — that communication is between you and the AI provider you chose.

5. Retention

  • Signup records — kept while your account is active. Deleted within 30 days of a deletion request.
  • OAuth tokens — access tokens expire after 1 hour; refresh tokens after 90 days. Expired tokens are deleted automatically.
  • Confirmation links — expire after 15 minutes and are deleted once used or expired.
  • API keys — a revoked key stops working immediately. Its record (a hash, never the key) stays with your account until the account is deleted.
  • Tool-call records — kept while your account is active and deleted with your account.
  • Operational logs — held by our hosting provider under its own retention settings (see section 1).

6. Your rights

Under UK GDPR you have the right to:

  • Access the personal data held about you
  • Correct inaccurate data
  • Delete your data (right to erasure)
  • Restrict or object to processing
  • Export your data (portability)
  • Withdraw consent at any time

To exercise any of these, email info@learningbrain.ai. A response will be provided within 30 days. Deletion is carried out by us on request; there is no self-service delete button. Deleting your account removes your data from our database, including your tool-call records.

If you believe your data has been mishandled, you can complain to the UK Information Commissioner's Office (ico.org.uk) or your local EU supervisory authority.

7. Security

  • All traffic to the Learning Brain MCP server is encrypted in transit (HTTPS).
  • API keys are stored only as keyed hashes (HMAC-SHA-256). Access tokens, refresh tokens and confirmation links are stored only as SHA-256 hashes. None of them can be read back from the database.
  • The database is on a private volume with access restricted to the service owner.
  • There are no passwords. You confirm your email address through a single-use link that expires after 15 minutes.
  • Reasonable efforts are made to protect your data, but absolute security cannot be guaranteed.

To report a security issue responsibly, email info@learningbrain.ai with "Security" in the subject line.

8. International transfers

The servers are located in the UK (London region via Fly.io). If you access Learning Brain from outside the UK/EU, your data will be transferred to and processed in the UK under UK GDPR. Sign-in emails are sent through Resend in the EU (Ireland). Google Fonts, which serves the website's fonts, may process your IP address in the United States.

9. Cookies

The learningbrain.ai website sets no cookies and uses no analytics or third-party trackers. The website's fonts are loaded from Google Fonts (see section 4).

10. Children

Learning Brain is a professional tool and not directed at children under 16. Data is not knowingly collected from children.

11. Changes to this policy

Any material changes will be posted to this page with a revised "Last updated" date, and affected users notified by email where possible. Continued use after a change constitutes acceptance.

12. Contact

Email: info@learningbrain.ai
Website: learningbrain.ai