brickster.ai collects only what we need to run the service. This page describes exactly what — written in plain English instead of legalese.
What we collect
Email address (digest subscribers)
When you subscribe to the brickster.ai digest, we store your email address in our database and use it for one purpose: to send you the weekly digest. We do not share your email with third parties or use it for advertising or remarketing. We don't sell email lists. We don't enrich your email against any third-party database.
Along with your email we record the source of the signup (hero or footerform), the timestamp, and a salted hash of your IP address, which rate-limits the verification-code step so the form can't be used to send mail to a stranger. That's it.
Anonymous server logs
Our hosting provider (Vercel) collects standard server-access logs (IP address, user-agent, request path, timestamp, response status) for traffic analysis and abuse prevention. These logs are not linked to your email and are not used for advertising.
Web analytics (Google Analytics 4)
We use Google Analytics 4 to understand which pages get traffic and how visitors find the site. GA4 sets a small set of analytics cookies (_ga, _ga_*) to count unique visitors, and uses your IP address (truncated before storage) to infer rough geography at the country level. It does not collect your name, email, or any identifier we provide. We do not connect GA data to the subscriber list. The two are separate, unrelated datasets.
GA only runs on the production site. It does not fire on local development builds or Vercel preview deployments.
Contact form submissions
If you submit the contact form, we store your name, email address, the message body, a salted hash of your IP address (used for rate-limiting and abuse detection, not reversible to the IP itself), and the timestamp. We use these only to read and reply to your message. We do not add contact-form addresses to the digest subscriber list — those are separate flows. We do not market to you or share the data with third parties.
Clicks on contributor profile links
The contributors pagelinks out to each contributor's LinkedIn profile. When you click one of those links we record three things: which profile you clicked, that it was clicked from the contributors page, and the timestamp. Alongside them we store a salted hash of your IP address (the same one-way form as the contact form, not reversible to the IP itself), used only to keep one person from skewing the count and to tell clicks apart from visitors.
That is the whole record: no user agent, no cookie, no account link, and no name. The IP hash is not anonymous, though, and we won't pretend otherwise: we hold the salt, so given an IP we could recompute the hash and find the rows it made. Nobody has ever asked us to, and the section on retention below says what to do if you want yours gone.
The links carry rel="noreferrer", so LinkedIn is not told you arrived from this site. The counts stay with us, are never shown on the site, are never shared, and are used for one thing: knowing whether the contributors page is worth maintaining.
What we do NOT collect
- Cross-site behavioural advertising pixels (no Meta pixel, no LinkedIn Insight, no programmatic remarketing)
- Behavioral advertising profiles
- Cross-site identifiers tied to your email
- Anything this page does not describe
How we use the AI assistant
The AI assistant on the home page sends your question to Google's Gemini API to embed it and to generate the answer. Google may retain the question according to Google's own data-handling terms — see Gemini API data governance.
We also keep the question text in our own database, stored against a salted hash of your IP address (used for rate-limiting and abuse detection, not reversible to the IP). We use it to spot topic gaps (questions the archive can't answer well yet) and to improve retrieval. We never link the question to an email address or any other identifier. We do not share assistant questions with third parties beyond Google (the model provider).
Sharing answers.If you click “Share answer” on a result, we save a snapshot of that question, the assistant's reply, and the cited sources to our database and return a public link (e.g. brickster.ai/a/xxxxxxxxxx). Anyone with the link can open it — they aren't indexed by search engines, and the 10-character id is not guessable, but treat the link as you would any pasted URL. We'll delete a shared snapshot on request from the contact form — include the share id or the full URL.
Data processors
The companies we rely on to operate the site:
- Vercel, Inc. — hosting and edge logs. vercel.com/legal/privacy-policy
- Supabase, Inc. — Postgres database holding subscriber emails, contact messages, assistant questions, and the contributor-link click counts. supabase.com/privacy
- Google LLC — Gemini API for assistant queries and content summaries; Google Analytics 4 for traffic measurement. policies.google.com/privacy
- Resend, Inc. — transactional email delivery (subscribe-verification codes, admin notifications). resend.com/legal/privacy-policy
- MailerLite Limited — delivery of the weekly digest to subscribers, including aggregate open- and click-tracking shown in the publisher dashboard. mailerlite.com/legal/privacy-policy
How long we keep your data
Subscriber email: until you unsubscribe or ask us to delete it, whichever comes first.
Contact form messages: until you ask us to delete them. We periodically prune old threads (older than 24 months) during routine database maintenance.
Server access logs: 30 days, as per Vercel's default retention policy.
Contributor profile-link clicks: kept as long as the contributors page exists, since the whole point is a running total. If you want yours deleted, send us the IP address you browsed from via the contact form and we can find and remove those rows. The IP hash is the only handle they have, so without it there is nothing for us to match on.
Your rights
Regardless of where you are based, you can:
- Get a copy of your data — reach out via the contact formand we'll send you everything we have on file across the categories described above, within 30 days.
- Delete your data — use the same contact form. Ask us to delete and we will.
- Unsubscribe — every digest email has a one-click unsubscribe link.
If you are based in the EU/EEA you have additional rights under the GDPR (right to rectification, right to data portability, right to object, right to lodge a complaint with your supervisory authority). All of these are honored — reach out via the contact form to exercise them.
Cookies
We do not set first-party tracking cookies. The only third-party script we embed is Google Analytics 4 (described above), which sets a small set of analytics cookies (e.g. _ga, _ga_*) to count unique visitors. The site uses localStorage only for persisting your light/dark theme preference; this never leaves your browser.
Children
brickster.ai is not directed to children under 13 (or under 16 in the EU/EEA). We do not knowingly collect personal information from children. If you believe we have, please reach out via the contact form and we will delete it.
Changes to this policy
If we change anything material, we'll update the "Last updated" date at the top of this page. For substantive changes affecting subscribers, we'll send a notice email before the change takes effect.
Contact
Privacy questions, data-subject requests, or concerns — please get in touch via the contact form.
