Privacy Policy
This policy reflects how Britemet Home and the public website are designed to handle data, based on current product and infrastructure practices. It is written for transparency (including GDPR-style notice content). Have a solicitor finalize controller identity, legal entity details, and any jurisdiction-specific notices before public launch.
1. Who we are
Britemet Software (“Britemet,” “we,” “us”) provides operational software products, including Britemet Home (home.britemet.com) and this marketing website (britemet.com).
For personal data processed in Britemet Home, Britemet is the data controller (or equivalent under applicable law), unless a written agreement for Britemet Estate says otherwise.
Privacy contact: privacy@britemet.com · General: hello@britemet.com
2. Scope
This policy covers:
- The public website and contact forms;
- Britemet Home accounts, household data, billing, support, and AI features;
- Related transactional email and security logging.
Britemet Estate may add contractual privacy terms for Private Office deployments.
3. Data we collect
3.1 Account and authentication
Name, email address, authentication identifiers (for example via AWS Cognito), password or federated sign-in data as configured, session tokens, and security events. Used to create and secure your account. Legal basis where GDPR applies: contract performance; security logging may also rely on legitimate interests.
3.2 Household operational data
Information you and authorized members enter into Britemet Home, which may include home profile and address details, rooms, maintenance tasks and service history, inventory and warranties, documents and files, vendors and contacts, vehicles, finances and bills, insurance and claims context, family and pet information, calendars, chores and tasks, travel and sitter guides, emergency card content, and similar household records. Legal basis: contract performance.
3.3 Sensitive and special-category data (optional)
If you use optional features, you may store highly sensitive values such as Wi-Fi passwords, safe or alarm codes, and medical notes (for example allergies or medications). Medical information is treated as special-category health data where GDPR applies and is stored with stronger controls (field-level encryption, restricted roles). Legal basis for health data: explicit consent where required (you choose to use the feature). Do not store data you are not allowed to process about others.
3.4 Usage and security data
IP address and related metadata in audit or security logs, user agent, approximate timestamps of sensitive actions (for example secret reveals, exports, membership changes), and operational diagnostics. Legal basis: legitimate interests in securing the service and investigating abuse; legal obligations where applicable.
3.5 Billing
When paid plans are enabled, subscription status and customer identifiers needed for Stripe (or similar). Full card numbers are handled by the payment processor, not stored as raw PAN in Britemet application databases. Legal basis: contract performance and legal obligations for tax/accounting where applicable.
3.6 Website and contact forms
When you contact us, we collect the details you submit (name, email, company or household, product interest, message). Forms post over HTTPS to Britemet-owned endpoints and email delivery (for example AWS SES), not a public form-relay service. Legal basis: legitimate interests in responding to inquiries, or pre-contract steps at your request.
3.7 What we do not collect by design
We do not use advertising cookies or sell personal data to advertisers. Marketing site cookies, if any beyond strictly necessary preferences, will be disclosed and controlled as required by law.
4. How we value your privacy
Britemet is built for sensitive household and operational information. Our design goals are:
- Your data is for running your home (or organization), not for ad targeting. We do not sell personal data to advertisers or use household records to build advertising profiles.
- Least privilege by default. Roles limit who can see finances, documents, vault fields, and other areas.
- Sensitive fields get stronger protection. Vault secrets and optional medical notes are designed for field-level encryption, hidden display, and audited reveal where implemented.
- AI is optional and separated. Britemet Home works without using Brit. Highly sensitive vault and medical vault values are designed never to be included in AI model context. You may opt out of AI integration as described in the AI Policy and section 7 below.
- Clear retention and exit. You can export and delete on defined schedules; we keep some security and legal logs longer only where needed.
5. How we use data
- Provide, maintain, and improve Britemet Home and related services;
- Authenticate users and enforce household roles and permissions;
- Send transactional email (password reset, invitations, operational notices);
- Process subscriptions and prevent fraud;
- Provide optional AI assistance when you use Brit and have not opted out (see AI Policy);
- Secure the platform, audit sensitive actions, and meet legal obligations;
- Respond to website and product inquiries.
6. Role-based access inside a household
Household owners invite members with roles (for example partner/admin, member, child, sitter). Visibility is limited by role: children and sitters do not receive full finance, vault, or document access. Adults with appropriate roles may see broader household data. Owners and admins manage membership. You should only invite people you trust and choose roles carefully.
7. Encryption and security measures
Highly sensitive fields are designed to be encrypted at rest with AES-256-GCM (envelope encryption patterns in production), hidden by default, and decrypted only for authorized roles on explicit reveal, with audited access where implemented. Production architecture targets private networking, managed keys (for example AWS KMS), encrypted databases and object storage, TLS in transit, and secrets kept outside application images. See our public Security overview for a non-exhaustive summary. No system is perfectly secure.
8. Optional AI (Brit) and separation from sensitive details
Britemet Home may offer optional AI features, including the assistant (“Brit”) and related helpers (for example consented document extraction or capture OCR). Important points:
- Optional. You can use Home without AI. Core household features do not require a model.
- Household opt-out. Owners and admins can disable AI for the whole household in Settings → AI & privacy. You may also request household-level AI opt-out via privacy@britemet.com. Opting out stops optional model assistance (assistant, extraction, vision OCR, AI weather checklists, and similar); it does not by itself erase your household records.
- Data classes. (1) Vault / medical: Wi‑Fi passwords, access codes, and medical vault fields stay in your encrypted database and are designed never to be sent to a model (enforced in application code). (2) Operational records such as maintenance, vendors, and inventory may be included in model context only when household AI is on and your role may see them. (3) Free-text you type in chat or AI-assisted forms may go to the model when AI is on; the product warns you not to paste secrets. Full detail: AI Policy: data classes.
- Transmission to Claude. In production, if AI is enabled and you use an AI feature, our servers send the permitted prompt and context to Claude on Amazon Bedrock under our AWS account (IAM task role), over TLS. Development environments may use the Anthropic API when configured. Your browser talks to Britemet over HTTPS; it does not expose vault keys to the model. Details are in the AI Policy.
- No ad sale of AI traffic. We do not sell AI prompts or household context to advertisers.
9. Who we share data with (sub-processors)
We share data with service providers who process it on our instructions to run the product:
- Amazon Web Services (AWS): infrastructure such as compute, databases, object storage, authentication (Cognito), email (SES), logging, key management, and, in production, Amazon Bedrock to run Claude for optional AI features;
- Stripe: payment processing when billing is enabled;
- Anthropic: Claude model provider for environments that call the Anthropic API directly (for example local development); production Home is designed to invoke Claude via AWS Bedrock under our account (see AI Policy).
We do not sell your personal data. We may disclose information if required by law, to protect rights and safety, or in connection with a corporate transaction with appropriate safeguards.
10. International transfers
Data may be stored in AWS regions used for your deployment (for example US regions such as us-east-1, or EU regions such as eu-west-1 when offered). AI provider processing may also occur in the provider’s supported regions. Where personal data is transferred outside the UK/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses through provider DPAs where applicable.
11. Data retention standards
We keep data only as long as needed for the purpose, then delete or anonymize it subject to legal holds and security requirements.
11.1 Household and account data
- Active accounts: account profile and household operational data (maintenance, inventory, documents metadata, family context, and similar) for the life of the account while needed to provide the service;
- Account deletion: when you delete your account, sessions end and primary application data is removed after a short grace period (target: hard deletion of application household data within about 7 days), subject to job completion;
- Vault and medical vault fields: retained with the household while the account is active; deleted with the household on the same deletion path (ciphertext and associated material as designed in the product);
- Files in object storage: removed with account/household deletion subject to storage lifecycle rules;
- Backups: encrypted backups may lag primary deletion for a limited period (on the order of days to about a month for automated database backups) until they expire.
11.2 Sessions, email, and operations
- Sessions: limited lifetime (on the order of weeks) or until logout / password reset;
- Password reset tokens: short-lived (on the order of hours);
- Transactional email delivery logs: short periods as retained by the email provider (on the order of days);
- Application and infrastructure logs: typically weeks to a few years depending on class (operations vs security evidence).
11.3 Security, audit, and consent evidence
- Audit and security logs (for example sensitive reveals, membership changes, security events): longer retention where required for security, fraud prevention, or legal duties (targets can extend to multi-year periods, for example on the order of 6 years for certain audit evidence classes);
- Consent records: may be retained as evidence even after account closure where the law requires;
- Legal holds: when required, we may pause deletion of covered records until the hold ends.
11.4 AI-related retention
- Chat turns and consented extractions: processed to produce a response; we do not keep your household as a permanent training set inside Britemet for general models;
- Limited AI operational metadata: may be kept for rate limiting, abuse prevention, reliability, and cost control;
- Provider retention: AWS Bedrock and/or Anthropic may process model traffic under their own terms for abuse monitoring and legal compliance; opting out of AI reduces new transmissions;
- Opt-out: Settings → AI & privacy disables new model processing for the household once applied; does not shorten retention of ordinary household records unless you also delete the account or specific data.
For AI detail, see the AI Policy.
12. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or port personal data, to object to certain processing, and to withdraw consent where processing is consent-based. For Britemet Home:
- Access / portability: export household data from in-product settings where available (typically machine-readable JSON; vault fields may remain encrypted ciphertext in export depending on product design);
- Rectification: update profile and household records in the product;
- Erasure: delete your account in settings where available, or contact us;
- AI opt-out: disable AI for the household in Settings → AI & privacy, or contact privacy@britemet.com;
- Complaints: you may contact us first; you may also lodge a complaint with a supervisory authority (for example the ICO in the UK or your EU member state DPA).
Contact privacy@britemet.com to exercise rights. We may need to verify your identity.
13. Children
Britemet Home may include child roles for household participation under an adult owner’s account. We do not market Britemet Home as a service directed at children acting alone. Owners are responsible for invitations and for information they store about minors. If you believe we have collected a child’s data inappropriately, contact privacy@britemet.com.
14. Cookies
Britemet Home uses strictly necessary cookies or similar storage for authentication/session and essential preferences (for example household context). We do not use advertising or cross-site tracking cookies for the core product. The marketing site uses only what is needed for basic operation unless you later enable optional analytics with notice and choice where required.
15. Automated decision-making
We do not use automated decision-making that produces legal or similarly significant effects without human involvement. Optional AI assistance is described in the AI Policy.
16. Changes
We may update this policy. The effective date will change when we do. For material changes affecting Home users, we will provide notice by email or in-product notice where reasonably practicable.
17. Contact
privacy@britemet.com · hello@britemet.com · Contact form
Related: Terms of Service · AI Policy · Security