Information BrillSync processes
BrillSync may process the Tesla model and model year you choose; customer confirmations about software, PWS/Boombox availability, powered hardware, and motion safety; selected products and options; project and order identifiers; prices and currency; processing and delivery status; and the information you submit through Support.
Stripe may provide BrillSync with payment-session identifiers, payment-intent identifiers, payment status, transaction amount, and customer details made available for the transaction, such as an email address. BrillSync does not receive or store your full payment-card number.
Hosting, security, and rate-limiting systems may process technical request information such as IP address, browser or device information, timestamps, request identifiers, and security signals as needed to operate and protect the service.
How customer audio is handled
When supported by your browser, your selected source audio is decoded and normalized on your device before private upload. BrillSync converts the working copy to a standardized 44.1 kHz, 16-bit, mono PCM WAV for server validation and fulfillment. The original large source file does not need to be uploaded to BrillSync as part of this flow.
BrillSync processes the normalized audio, source and working file names, file sizes, duration and validation information, and generated package data needed to create and deliver the selected product. BrillSync does not sell uploaded audio and does not use customer audio to train general-purpose artificial-intelligence models.
How information is used
BrillSync uses information to create and validate guest projects; enforce Tesla compatibility and safety rules; calculate server-authoritative pricing; provide secure checkout; verify signed payment events; generate and package purchased files; provide private downloads; prevent duplicate charges and abuse; troubleshoot failures; answer Support or privacy requests; and meet security, accounting, dispute, and legal obligations.
Service providers
BrillSync currently relies on Supabase for database and private file storage, Stripe for embedded checkout and payment processing, and Netlify for hosting and server functions. These providers process information on BrillSync’s behalf or under their own applicable service terms only as needed for their roles.
When information may be shared
BrillSync may disclose information to service providers needed to operate the service; to investigate fraud, security incidents, chargebacks, or abuse; to comply with law, legal process, or valid government requests; to protect rights, safety, and property; or as part of a lawful business reorganization or transfer subject to appropriate protections. BrillSync does not sell personal information for money and does not use personal information for third-party behavioral advertising.
Retention
Guest project, normalized-audio, preflight, fulfillment, and delivery records are designed to be temporary and are retained only as needed to validate, fulfill, deliver, support, secure, and troubleshoot the applicable order. Private download links are short-lived and are created only after the backend confirms access to the paid delivery.
Payment, order, legal-acceptance, fraud-prevention, support, and dispute records may be retained longer when reasonably necessary for accounting, security, tax, chargeback, contractual, or legal obligations. Retention periods may vary by record type and applicable law.
Cookies and browser storage
BrillSync uses essential browser mechanisms to operate the guest Studio. A secure guest capability cookie helps prove that the same browser is authorized to use a private guest project. Session storage may preserve an order reference so an existing checkout or paid order can be restored after refresh without creating another charge. BrillSync does not require advertising cookies for the clean Studio flow.
Your choices and privacy requests
Depending on where you live and applicable law, you may have rights to request access, correction, deletion, portability, restriction, or other action concerning personal information. Submit a request through Support and choose “Privacy request.” BrillSync may need to verify the request and may retain information that law, security, payment, tax, fraud-prevention, or dispute obligations require.
Security
BrillSync uses private storage, restricted database access, guest-capability controls, server-side validation, short-lived signed delivery URLs, exact-origin checks, encrypted transport, Stripe webhook-signature verification, idempotent payment processing, and rate limits designed to reduce unauthorized access and abuse. No online service can guarantee absolute security.
Children
BrillSync is not directed to children under 13 and does not knowingly seek personal information from children under 13. A parent or guardian who believes a child submitted information may contact Support.
Changes to this policy
BrillSync may update this policy when the service, providers, security practices, or legal requirements change. The effective date will be revised for an updated policy. The policy version acknowledged for an order may be recorded with the order for transaction and compliance purposes.
Contact
For privacy questions or requests, use the BrillSync Support form and choose “Privacy request,” or email support@brillsync.com.