The Brainworks Foundry
Privacy Policy
The short version: we measure which campaigns bring people here, and we do it without following you around the internet. This site sets no cookies, runs no third-party advertising pixels, and never sells personal information. What follows describes exactly what we collect and why — written to match what the code actually does.
Last updated 29 July 2026
1. Who we are
This site is operated by Brainworks Ventures Foundry, Inc., a Delaware C-corporation (the “Issuer”), all of whose issued and outstanding capital stock is held by its founder, Dr. Phillip Alvelda, in his individual capacity. Brainworks Ventures, LLC is an affiliate under common control (Dr. Alvelda is its sole member) and holds no equity interest in the Issuer. References to “we”, “us” and “the Foundry” mean those entities. For any privacy question, correction or deletion request, write to alvelda@brainworks.ai. A human reads that inbox.
This policy covers foundry.brainworks.ai. It does not cover third-party sites we link to, nor the separate confidential data room, which is governed by the subscription documents and the Private Placement Memorandum.
2. Analytics — cookieless by choice
We use Plausible Analytics and nothing else. It is loaded once in the site's root layout and runs on every page. We chose it deliberately over the more common alternatives because it sets no cookies, writes nothing to local storage, and assigns no persistent identifier to you. It cannot follow you to another website, because it holds nothing that would let it recognise you there.
What it records is aggregate and non-identifying: the page visited, referrer, campaign parameters, approximate country, and coarse device and browser type. It does not record your IP address in the analytics dataset — your IP is used transiently to derive country and a per-day counting hash, then discarded. Plausible processes this data in the EU as our processor, and is contractually barred from using it for its own purposes.
One first-party custom event exists: EOI, fired when someone completes the express-interest form. It records that a submission happened, the check-size bracket selected, and which campaign it came from. It carries no name, no email address and no free-text.
This is why you are not being asked to click a cookie banner. Consent theatre exists mostly to license third-party tracking. We would rather not do the tracking.
3. Advertising and campaign attribution
We advertise and publish, and we need to know what works — otherwise we waste money that belongs to our investors. We do this with first-party campaign attribution only.
When you arrive from an advertisement, a social post or a newsletter, the link may carry campaign parameters in the URL — utm_source, utm_medium, utm_campaign, utm_term, utm_content and ref. We read those from your own click and, if you later submit the express-interest form, store them alongside that submission so we can tell that (for example) a LinkedIn post produced a given enquiry. That is the entire mechanism. It is a label on the door you came through, not a tag on you.
Where an advertising platform reports results back to us — impressions, clicks, cost per enquiry — we use it in aggregate, campaign-level form. We do not upload your email address or any other identifier to an advertising platform for matching, custom-audience building or retargeting.
If this ever changes, this page changes first. Should we later adopt a conversion pixel or any advertising technology that stores an identifier on your device, we will (a) update this section to name it before it goes live, and (b) gate it behind an explicit opt-in consent banner as described in §5. We will not quietly switch one on.
4. Information you give us deliberately
Express interest. The form collects your email address, the investment-size band you select, and your self-certification that you are an accredited investor. We use it to send you the materials you asked for and to continue the conversation. Selecting a size band is an indication of interest, not a commitment, and not an investment.
Accreditation verification. Rule 506(c) obliges us to take reasonable steps to verify accredited status before any SAFE is executed. That verification happens later, through the subscription process governed by the Private Placement Memorandum, and may involve a third-party verification provider or a letter from your accountant, attorney or registered investment adviser. Sensitive financial evidence supplied for that purpose is handled under the offering documents, is used only to establish eligibility, and is not used for marketing. See the legal and offering disclosures for the surrounding terms.
Email correspondence. If you write to us, we keep the thread, as any business does. Every marketing email we send carries a working unsubscribe; honouring it is a legal obligation under CAN-SPAM and we treat it as one. Opting out of marketing does not delete records we must retain for securities-compliance purposes.
5. Cookies and device storage
This site currently sets no cookies at all. Not analytics cookies, not advertising cookies, not “functional” cookies.
The only thing we place on your device on a public page is a single session-storage flag remembering whether you un-muted the audio on the hero video, so it does not surprise you twice. It is erased when you close the tab and it identifies nothing. The authenticated investor dashboard uses local storage to remember interface preferences such as whether a help panel is collapsed.
Our commitment on this point is procedural rather than merely descriptive: before this site sets any non-essential cookie or similar identifier, it will present a consent interface that works — with a genuine reject option given equal prominence — and the identifier will not be set unless you opt in. Strictly necessary cookies, if ever required for security or session integrity, are the sole exception, and would be listed here.
6. Talking to Hallie — the voice and chat assistant
Hallie is the AI that operates the Foundry, and you can speak with her or type to her on this site. She will tell you she is an AI, because she is instructed to and because pretending otherwise would be indefensible.
Voice. Speaking with Hallie streams your audio to our speech-and-language provider in order to transcribe it and generate a spoken reply. For each conversation we keep an operational audit record containing a random session identifier, your IP address, your browser user-agent string, and the start, end and duration of the session. We keep it to detect abuse, diagnose faults and evidence what the assistant was asked — a reasonable expectation for a regulated offering. Your IP is also held briefly in memory for rate limiting.
Chat. Typed conversations are processed to generate a reply and may be retained in operational logs for the same abuse-prevention and quality-assurance reasons.
Grounding, and its privacy consequence. Hallie answers only from a curated public corpus about the Foundry. If a question falls outside it she declines and refers you to the offering documents rather than improvising. A practical side effect: do not put confidential information into the assistant. It is not the right channel for your financial details. Use email for anything sensitive.
7. Why we are allowed to do this, and who else sees it
Where the UK or EU GDPR applies, our lawful bases are: legitimate interests for cookieless aggregate analytics, first-party campaign attribution, and security and abuse prevention — each being low-impact and reasonably expected; performance of a contract or steps prior to one for handling your express-interest submission and any subsequent subscription; consent for marketing email where consent is required, and for any future non-essential cookie; and legal obligation for securities and financial-services recordkeeping.
We share personal information only with service providers who process it on our instructions, under contract, and for no purpose of their own — analytics hosting, email delivery, speech and language processing, e-signature and document custody, and accreditation verification. We also share with our placement agent and its broker-dealer where you have engaged with the offering through them, and with professional advisers, auditors and regulators where we are required to.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. Under the CCPA as amended by the CPRA, we have never done either. There is accordingly no “Do Not Sell or Share My Personal Information” mechanism to offer you, because there is no such activity to opt out of.
8. How long we keep things
Aggregate analytics: retained in aggregate form and not tied to an identifiable person, so it is not deleted on an individual basis — there is no individual record in it to delete.
Express-interest submissions and correspondence: for as long as the enquiry is live, and thereafter for the period required by securities and tax recordkeeping rules. FINRA Rule 2210 requires retail communications relating to this offering to be retained for not less than three years, as noted in our disclosures.
Assistant session audit records: retained on a short operational cycle for abuse prevention and diagnostics, and not used to build a profile of you.
Investor and subscription records: retained for the statutory periods applicable to a securities issuer, which outlast the offering itself.
9. Your rights, and how to actually use them
Depending on where you live you may have rights to access, correct, delete, port or restrict your personal information, to object to processing based on legitimate interests, to withdraw consent, and not to be discriminated against for exercising any of them. California residents additionally have the rights to know, delete, correct and to limit the use of sensitive personal information; we do not use sensitive personal information for inferring characteristics.
To exercise any right, email alvelda@brainworks.ai with what you want. We will verify that the request comes from you or an authorised agent, and respond within the timeframe the applicable law sets — thirty days under GDPR, forty-five under the CCPA, extendable where the law permits and we tell you why. No fee, no dark patterns, no requirement to create an account.
Some records we may be legally unable to delete on request, notably securities-compliance and anti-money-laundering records. Where that applies we will say so plainly and identify what is being retained and under what obligation, rather than refusing without explanation.
If we handle a request badly, you may complain to your supervisory authority — in the UK, the Information Commissioner's Office. We would prefer you told us first, and we will treat it as a defect to fix.
10. What we do not do
Stated plainly, so it can be held against us:
- We do not sell or rent your personal information. Ever.
- We do not run third-party advertising or social-media pixels on this site, and do not participate in cross-site behavioural advertising networks.
- We do not fingerprint devices, and do not attempt to identify you across sites or sessions.
- We do not buy personal data from data brokers to enrich our records.
- We do not set non-essential cookies without opt-in consent — see §5, which is a commitment and not merely a description.
- We do not use your conversations with Hallie, or your correspondence with us, as training data for third-party AI models.
- We do not knowingly collect information from children. This site is for accredited investors and is not directed to anyone under 18.
11. International transfers, security, and changes
Transfers. We are a US issuer and our providers operate in the United States and the European Union, so personal information may be transferred internationally. Where UK or EU data is transferred to the United States, we rely on the appropriate safeguards available to us, including the UK and EU standard contractual clauses with our processors.
Security. The site is served over TLS; access to investor records is restricted to those who need it; and confidential offering material sits behind the data room rather than on public pages. No system is perfect and we will not pretend ours is. If we discover a breach affecting your personal information, we will notify you and the relevant regulator as the law requires.
Changes. When we change this policy we will move the “last updated” date and, for any change that materially expands what we collect or how we use it, say so prominently rather than burying it in a diff. This version is dated 29 July 2026.
This policy describes our practices in good faith and is not legal advice. Nothing in it is an offer to sell or a solicitation of an offer to buy any security; see the legal and offering disclosures for the terms that govern the offering itself.
Questions about your privacy
Write to alvelda@brainworks.ai. If you think something on this page misdescribes what the site actually does, tell us — that is a bug, and we will fix the behaviour or the wording, whichever is wrong.