B36Brix36

Brix36 Privacy Notice

Effective date: 25 August 2026

Who we are

Brix36 is operated by SOCIALISER APP LTD (company number 17243028), registered at Unit 82a James Carter Road, Bury St. Edmunds, United Kingdom, IP28 7DE. SOCIALISER APP LTD is the controller of personal data described in this notice.

Privacy questions and data-rights requests can be sent to simeon@brix36.com.

What Brix36 does

Brix36 helps artists and their teams create artist profiles, collect authorised Artist DNA material, organise releases or standalone music videos, analyse songs, develop creative direction, review storyboards and, where enabled, produce AI-assisted promotional clips and music videos.

Information we collect

We collect information that you provide or create in Brix36, including:

If you connect Google or Apple, we receive the provider's stable account identifier, verified email address and any display name the provider supplies. We use the identity token and, for Apple, the one-use authorisation code only to verify the sign-in. Apple refresh-token material needed for account-deletion revocation is encrypted at rest and is never exposed to the app.

Optional social connections are available now for Brand Scan and are explained under Connected social accounts and Brand Scan below.

How we use information and our lawful bases

We use personal data:

Brix36 does not make solely automated decisions that have legal or similarly significant effects on you. Automated analysis and generation can recommend or create material, but the user reviews and approves creative choices.

AI processing and service providers

We use suppliers to run Brix36. Depending on which feature you use, personal data may be processed by:

Payment-card and bank-account information stays with the App Store or Play billing service and is not sent to Brix36. RevenueCat and Brix36 receive the customer, product and transaction information needed to fulfil and support the purchase. Brix Credits are non-cash units used only inside Brix36 and do not expire.

We send an AI provider only the information and references needed for the requested task. A provider does not receive your whole Artist DNA library by default. Provider availability, model capability and rights rules determine which route can be used, and a request is refused when Brix36 cannot identify a permitted route.

Song tempo, sections, beats and energy are measured locally on Brix36's server. When song-theme understanding is enabled, the uploaded song is also sent to OpenAI's audio-transcription API. The resulting transcript is held only long enough to ask Anthropic for a short set of meanings and situations; Brix36 does not write the verbatim transcript to its database or pass it to the storyboard planner. Brix36 stores only the non-lyrical themes, an analysis status and the model provenance. Those themes may state explicit adult subject matter plainly where it is central to the song. Sound, scene and subgenre suggestions are shown for approval, denial or editing before they become the artist's confirmed profile.

When Brix36 uses fal.ai, source photographs and other private files remain in Brix36 storage. fal.ai receives a signed link that normally expires after 15 minutes and fetches the referenced material to carry out the request; Brix36 does not upload that source file into fal.ai's CDN. fal.ai's public documentation currently explains deletion of stored request payloads and generated output files, but does not state whether it keeps a separate processing copy of a file fetched from a customer's external link or, if so, for how long. Brix36 is seeking written clarification. Until the answer and our automated request-deletion path are verified, Brix36 cannot promise that fal.ai immediately removes every transient processing copy.

Brix36 does not offer a likeness route that avoids fal.ai. Where an artist's likeness is used, both fal.ai and BytePlus ModelArk may be involved in producing it, and there is no single-provider option to choose between them. If you do not accept the fal.ai limitation described above, do not authorise likeness processing for that artist: Brix36 will still produce the video, using invented likenesses instead of that artist's own. If you have already authorised it and want to stop, withdraw the permission on the artist's likeness screen and email simeon@brix36.com. Withdrawal stops new use immediately; where a provider has not confirmed deletion of a copy it holds, Brix36 will not describe that copy as deleted.

BytePlus separately states that ModelArk inputs and outputs which trigger its content-safety filter may be retained for up to 180 days in Malaysia. That is a content-filter rule, not the normal retention period for face verification, and it does not answer when a liveness capture, retained benchmark image, comparison result, failed-session data, backup or log is erased.

We may also disclose information where the law requires it, to protect someone's vital interests, to establish or defend legal claims, or as part of a properly controlled company sale or reorganisation.

We do not sell personal data and Brix36 does not show third-party advertising inside the app. A Meta-enabled version contains Meta's App Events SDK solely for the optional advertising measurement and related SDK diagnostics described below.

Optional Meta advertising measurement

A Meta-enabled version of Brix36 asks before activating Meta advertising measurement. Until you choose Allow Meta measurement, Brix36 does not activate Meta App Events or enable advertising-identifier collection. On iPhone and iPad, Brix36 also asks for Apple's App Tracking Transparency permission; Meta measurement remains off unless both your Brix36 choice and Apple's permission allow it.

If you opt in, Brix36 may send Meta app opens, a completed registration, the start of a Brix Credit checkout and a completed store purchase. Those events may include the store product, price, currency and number of credits, along with an app-instance, device or advertising identifier made available by the operating system. Meta uses the information for app-ad attribution, measurement, analytics and optimisation, including working out whether a Meta advertisement led to an install, registration, checkout or purchase.

After the SDK is activated, it may also send Meta limited reliability diagnostics about the integration. Depending on the platform, remote SDK settings and failure, this can include an SDK crash, error or unresponsiveness report with its stack or cause, operating-system version, device model, app version and report time. Brix36 and Meta use this information for app functionality and analytics: to diagnose the integration, understand its reliability and fix faults. Brix36 does not intentionally add your music, photographs, video, Artist DNA, project names, prompts, storyboards, generated content, facial images, face-verification results or likeness-permission records to Meta events or diagnostic reports.

You can turn this sharing off under Account → Meta ad measurement. On iPhone or iPad you can also deny or revoke tracking in the device's privacy settings. Turning it off disables new Brix36 App Events and advertising-identifier transmission. Because the installed SDK does not expose a cross-platform control that removes every active diagnostic handler, close and reopen Brix36 after turning measurement off to stop new SDK reliability diagnostics in that app process. A diagnostic already created while measurement was enabled may remain queued and could be sent if measurement is later enabled again. Turning measurement off does not erase information Meta already received. Meta's published privacy policy explains that retention depends on the information and why it is used rather than giving a fixed App Events retention period. You can read it at https://www.facebook.com/privacy/policy/ and use Meta's own privacy controls for information held by Meta.

Connected social accounts and Brand Scan

Social connections are optional and are currently available for Instagram, TikTok and YouTube. Brix36 uses Zernio to open the platform's hosted authorisation flow and creates an artist-specific Zernio profile only when you start a connection. Brix36 does not ask for your social-media password and does not publish or post to a connected account.

After connection, Brix36 records the platform and account identifiers, username, display name, profile URL, connection state and import timestamps, and uses Zernio to read the account history available through that connection. For Instagram, eligible pictures and video may be downloaded into private Brix36 storage, screened and visually classified. For TikTok and YouTube, Brix36 stores permitted links and metadata and does not download or cache the audiovisual content. Anthropic may process the permitted picture, video still, caption, link or metadata to separate useful Artist DNA material from irrelevant or unusable material.

Material kept by the scan appears in Brand Scan without a separate approval step for every item, subject to the permitted uses for its source. You can remove an item afterwards. Brix36 records the source account and the outcome and reason for each item it checked; filtered media is not stored as a Brix36 asset.

Disconnecting asks Zernio to detach that platform account and stops it being included in later scans. It does not remove Brand Scan material already imported or the associated local provenance and decision history. Remove or withdraw those items separately, or delete the artist or account.

Deleting the artist or account removes the corresponding local Zernio identifiers and imported Brix36 data through the ordinary deletion process. As at this notice's effective date, however, the current integration does not automatically disconnect every remaining Zernio account or delete the artist-specific profile held by Zernio. Brix36 does not promise a fixed Zernio-side erasure period and will not describe a supplier-side profile or connection record as deleted without confirmation.

Face verification and facial information

Likeness verification is optional. When it is chosen, the artist is sent to a real-person verification page hosted by BytePlus ModelArk. BytePlus collects facial images or video to check that a live person is present, extracts facial-recognition features and compares the person's face with authorised photographs added to that artist's verified provider library. Brix36 uses the provider result to decide whether those photographs may be used for real-person video. The check begins only after the required separate likeness permission has been recorded.

The live capture is submitted directly through BytePlus's hosted page. Brix36 stores the consent record, verification-session status, expiry or failure information, provider result code and group or asset references, together with the authorised photographs already stored for the artist.

If the artist passes the live check, BytePlus states that it retains the successful capture as a benchmark or reference image for later authentication. BytePlus also states that facial-recognition features extracted for a comparison are deleted immediately after the comparison, while the same-person or different-person result remains. BytePlus does not publish a fixed retention period for the retained benchmark image or comparison result.

BytePlus states that facial information for this service is stored in Singapore. Its published material does not state how long it retains facial images, video, results or related copies where a check fails, is abandoned, expires, or succeeds but its provider group is not reconciled to Brix36. Expiry of the verification link or exchange token is not evidence that the supplier data has been erased.

BytePlus says facial information is deleted or anonymised within an unspecified reasonable period after its customer instructs deletion, permission is withdrawn or ends, the relevant portrait is deleted, or the customer account is closed. It also publishes asset and asset-group deletion operations, but does not publish a maximum time for removal from primary storage, replicas, backups, safety or security records, logs, the benchmark image or the retained comparison result.

Within Brix36, withdrawing likeness permission stops new likeness use immediately. Withdrawal, permission expiry and artist or account deletion record provider asset and group deletion obligations where Brix36 has a provider identifier. As at this notice's effective date, ModelArk remote-deletion calls are built but are not enabled in production pending controlled verification of the deletion contract. Recording an obligation is therefore not proof that BytePlus has received or completed a deletion instruction, and the obligation remains open.

A failed, abandoned or expired verification may expose no provider asset or group identifier that the current integration can address through the published deletion operations. Brix36 cannot promise a fixed completion period for that case or for any supplier copy, backup, log, benchmark image or retained result. Brix36 will not describe provider-side facial information as deleted without evidence.

International transfers

Some suppliers may process data outside the United Kingdom. Where required, we rely on an applicable adequacy regulation or contractual and organisational safeguards designed to protect the transferred data. You may ask us for more information about the safeguard used for a particular transfer.

BytePlus states that facial information used for real-person verification is processed and stored in Singapore. We are confirming the contractual safeguard that applies to that transfer and will not claim that a particular safeguard is in place without evidence.

Retention

We keep account and project information while your account is active and for as long as needed to provide the service. When you delete your account, Brix36 removes or irreversibly de-identifies the account and workspace data, revokes sessions and connected login methods, and records deletion work for external files or provider copies so failed deletions can be retried.

Some information may be kept for longer when necessary:

Pending deletion or token-revocation records remain until the relevant external deletion is confirmed, or until an unresolved provider limitation has been explained and handled consistently with applicable law and your rights. The operational record is then minimised when it is safe to do so.

The additional retention and deletion limits for connected social accounts and facial information are set out in those sections above. The normal one-month period for responding to a data-rights request is a response period, not a promise that every supplier copy will be erased within one month.

Your choices and rights

Depending on the circumstances, UK data-protection law gives you rights to:

You can update ordinary account and project information in the app. Account deletion is available under Account → Delete account. If you cannot access the app, email simeon@brix36.com from the address connected to your account. We may need to verify that the account is yours before acting.

To exercise another right, email simeon@brix36.com. We normally respond within one month, subject to the limits and extensions allowed by law.

You can contact the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/ or by calling 0303 123 1113.

Other people's information and artist likenesses

Only upload or connect music, images, video, names and likenesses that you are authorised to use. If you provide information about another person, you are responsible for having authority to do so and for making this notice available to them where required.

Artist DNA is creative reference material, not automatic permission. Brix36 records likeness permission separately and may require proof from the artist or their authorised representative. Withdrawing permission stops new use. Deletion from an external provider may complete later if that provider is temporarily unavailable; where a provider has not documented deletion of a particular processing copy, Brix36 will not describe that copy as deleted without evidence.

Children

Brix36 is intended for professional artists and their teams and is not directed to children. You must be at least 18 years old, or the age of legal majority where you live, to create an account.

Security

We use measures including encrypted transport, hashed passwords and session tokens, private signed file access, restricted service credentials, encrypted Apple token storage and access controls scoped to each workspace. No service can guarantee absolute security. Contact simeon@brix36.com immediately if you believe an account or file has been accessed improperly.

Changes to this notice

We may update this notice as Brix36 changes. We will publish the new effective date and bring material changes to users' attention before a new use of personal data begins where required.