Accounts and sign-in
BrainHalf uses account information to sign you in and associate projects with your account. The email/password flow hashes passwords on the server. New email accounts verify ownership before signing in. Resend delivers verification, password-reset, and contact emails; it receives the recipient address and message content. Reset links expire after 30 minutes and verification links after 24 hours. Resetting a password revokes existing sessions. The Google flow requests basic profile and email information to identify your account; it does not request access to your Gmail messages or Drive files.
The browser stores session information so the app can make authenticated requests. Sign-out revokes the session and removes the active browser session. Theme preferences and local project caches also use browser storage.
Website analytics
BrainHalf uses Google Analytics on public pages to understand visits and improve the website. Google Analytics may use cookies and process browser, device, and usage information.
The integration sends public page addresses without query strings or fragments and includes only the referring website’s origin. It does not start for signed-in sessions or project and sign-in callback URLs, and collection is disabled when a visitor signs in. Advertising personalization and Google signals are disabled in the site configuration.
Advertising
BrainHalf shows ads from Google AdSense on public pages to support the free tier. Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this website or other websites.
Google’s use of advertising cookies enables it and its partners to serve ads to you based on your visit to this site and other sites on the internet. You can opt out of personalized advertising in Google Ads Settings (adssettings.google.com) and opt out of other third-party vendors’ cookies at aboutads.info/choices.
Ads do not appear inside signed-in workspaces, project previews, or published apps you build. Advertising cookies are separate from the session cookies required to sign in.
App reliability measurements
BrainHalf records first-party generation, app-verification and publishing outcomes with account and project IDs, revision hashes and timestamps. These records help measure verified apps per generation, successful publishing and time to a first live app. They do not include prompts, source code, passwords or customer records.
We also record the first observed workspace activity and whether the account is active again between days 7 and 14. Outcome records are separate from Google Analytics and remain after project deletion for reliability reporting. Account reports are private; aggregate reports require operator access.
Prompts, code, and AI providers
The building workflow sends your prompts and relevant project context to the configured AI provider for the model you select. Provider availability and processing depend on the platform configuration and the provider’s own terms.
Do not include passwords, private API keys, or information you are not authorized to share in a prompt. Generated apps should read secrets from their own server environment rather than embedding them in frontend files.
Project storage and removal
The platform uses Cloudflare infrastructure for accounts and project services, with browser caches to support the workspace. Project files may also be backed up to object storage.
Deleting a project immediately revokes access and removes local files and conversation history after the request is accepted. An automatically retried cleanup job removes app deployments, databases, server source, attachments, stored project credentials, and backups. The dashboard shows pending and completed cleanup. Minimal project-ID ownership tombstones remain to prevent another account from reclaiming a deleted project; cleanup status is retained for 30 days.
Previews and external services
Generated previews run in a restricted frame. A generated app may load images, packages, or external services specified in its source, and those services can receive requests from your browser. Inspect the app and its integrations before using sensitive information.
Private project URLs are excluded from search indexing by the platform’s crawl controls. Search controls complement authentication; they do not replace it.