Brix36

Brix36 Privacy Notice

Effective date: 30 September 2026

Who we are

Brix36 is operated by SOCIALISER APP LTD (company number 17243028), registered at Unit 82a James Carter Road, Bury St. Edmunds, United Kingdom, IP28 7DE. SOCIALISER APP LTD is the controller of personal data described in this notice.

Privacy questions and data-rights requests can be sent to simeon@brix36.com.

What Brix36 does

Brix36 helps artists and their teams build Artist DNA for their artists, plan and direct music videos from their own songs and short films up to five minutes from an idea or a script, and produce them with AI.

Information we collect

We collect information that you provide or create in Brix36, including:

If you connect Google or Apple, we receive the provider's stable account identifier, verified email address and any display name the provider supplies. We use the identity token and, for Apple, the one-use authorisation code only to verify the sign-in. Apple refresh-token material needed for account-deletion revocation is encrypted at rest and is never exposed to the app.

Artist DNA links and social media scans are optional and are explained under Artist DNA links and social media scans below.

How we use information and our lawful bases

We use personal data:

Brix36 does not make solely automated decisions that have legal or similarly significant effects on you. Automated analysis and generation can recommend or create material, but you decide what to generate, keep and share.

AI processing and service providers

We use suppliers to run Brix36. Depending on which feature you use, personal data may be processed by:

Payment-card and bank-account information stays with the App Store or Play billing service and is not sent to Brix36. RevenueCat and Brix36 receive the customer, product and transaction information needed to fulfil and support the purchase. Brix Credits are non-cash units used only inside Brix36 and do not expire.

Brix36 asks for AI-processing permission separately from advertising measurement. The requested task may send your chosen photos, song audio, voice recordings, scripts and other text to the providers described here. You can decline the request or withdraw permission under Account → AI processing. Withdrawal prevents new requests covered by that permission; it does not recall information already sent, cancel all work already in progress or delete existing results. Remove results or request deletion separately. Permission is associated with your signed-in account on that device. Connecting Brix36 to an AI assistant such as Claude or ChatGPT is a separate choice with its own permissions, described below.

We send an AI provider only the information and references needed for the requested task. A provider does not receive your whole Artist DNA library by default. Provider availability, model capability and rights rules determine which route can be used, and a request is refused when Brix36 cannot identify a permitted route.

Song tempo, sections, beats and energy are measured on Brix36's own server. The uploaded song is also sent to OpenAI's audio-transcription service, which returns the words it hears with their timings. Brix36 stores those timed lyric lines with the song's analysis. It uses them to show on the storyboard which lines your artist lip-syncs, and it includes them when it asks Anthropic to plan the storyboard and to find the song's themes. Those themes may state explicit adult subject matter plainly where it is central to the song. When a shot is made, short clips of the song are sent to the video or lip-sync model making that shot, so the artist's mouth moves in time with the lines.

When you choose your own recorded or uploaded voice, ElevenLabs receives the recording to create a speaking voice. A voice description goes to ElevenLabs for voice design; selecting a ready-made library voice does not itself record you. Film dialogue is sent for speech generation. The resulting speech may then be sent to the selected video or lip-sync provider and used in the completed film. Use only your own voice or a voice you have permission to use.

Prepared samples, uploaded recordings, cloned/designed voices and generated speech are different records. Brix36 retains the data needed for the selected feature and records provider cleanup when a Brix36-owned voice is retired or its artist/account is deleted. Cleanup can be pending or fail and require retry. A shared library copy may remain while another artist uses it. A voice held in your own connected ElevenLabs account is not owned by Brix36 and is not deleted by Brix36. Removing it from a Brix36 artist does not erase it from your supplier account.

We have not verified a single maximum retention period covering provider recordings, voice objects, speech, processing copies, backups and logs, or deletion completion for every copy. A local cleanup timer or successful voice-object deletion is not proof that every supplier copy is erased. Ask simeon@brix36.com about a particular voice or deletion request. We do not promise that all providers use the same training or retention settings.

Most AI providers receive a signed link to a private file rather than the file itself. The link normally expires after six hours, and the provider fetches the file from Brix36 storage. OpenAI, Anthropic and fal.ai's face swap receive the file itself.

When Brix36 uses fal.ai, source photographs and other private files remain in Brix36 storage. fal.ai receives a signed link that normally expires after six hours and fetches the referenced material to carry out the request; Brix36 does not upload that source file into fal.ai's CDN. fal.ai's public documentation currently explains deletion of stored request payloads and generated output files, but does not state whether it keeps a separate processing copy of a file fetched from a customer's external link or, if so, for how long. Brix36 is seeking written clarification. Until the answer and our automated request-deletion path are verified, Brix36 cannot promise that fal.ai immediately removes every transient processing copy.

When an artist's photos are in their Artist DNA, the image and video providers above may receive them to show that artist: OpenAI, fal.ai, Alibaba Cloud, MiniMax and, after the one-time face check, BytePlus ModelArk. You cannot limit this to one provider. If you do not want an artist's likeness used this way, do not add their photos, or delete the artist. You can also email simeon@brix36.com to ask us to request deletion of copies that providers hold. Deleting the artist stops new use immediately; where a provider has not confirmed deletion of a copy it holds, Brix36 will not describe that copy as deleted.

BytePlus separately states that ModelArk inputs and outputs which trigger its content-safety filter may be retained for up to 180 days in Malaysia. That is a content-filter rule, not the normal retention period for face verification, and it does not answer when a liveness capture, retained benchmark image, comparison result, failed-session data, backup or log is erased.

We may also disclose information where the law requires it, to protect someone's vital interests, to establish or defend legal claims, or as part of a properly controlled company sale or reorganisation.

Brix36 does not show third-party advertisements inside the app. Optional advertising attribution involves disclosure to other companies as described below; it is not anonymous merely because an identifier replaces your name.

Optional advertising measurement

Measurement is optional. The launch flow asks for a separate choice after sign-up, with a control under Account → Ad measurement. On iPhone and iPad, Apple's App Tracking Transparency permission must also allow tracking. Declining measurement does not remove ordinary creative functionality. Analytics and advertising collection are disabled by default, and Google advertising personalisation remains off.

After consent, AppsFlyer receives the Brix36 account/customer user ID for permitted install, app-open and purchase attribution. AppsFlyer's installation identifier is also associated with the RevenueCat customer. RevenueCat is the sender of configured credit-purchase events to AppsFlyer; Brix36 does not use the AppsFlyer Purchase Connector or a second client purchase event for that same attribution. When the Meta and Google Analytics for Firebase SDKs are enabled, the app also sends registration and checkout events to them, and a separate credit-purchase analytics event to Firebase. These app event calls do not send registration or checkout events to AppsFlyer. Required store validation and credit accounting operate independently of this optional attribution.

Permitted events may include product, amount, currency, account/customer user ID, AppsFlyer ID, device or advertising identifiers, IP-derived approximate location, campaign information and app/device/network details. AppsFlyer and enabled partners use these for attribution, analytics and advertising measurement or optimisation. Configured partners may include Meta, Google Ads, Apple Ads, TikTok, Snap and OpenAI. Advanced Matching and Advanced data sharing are not part of the launch configuration. We do not intentionally send creative uploads, recordings, dialogue, project names, prompts or face information as advertising-event content.

The enabled SDKs may also process technical/performance information. Meta, if activated, may send limited crash, error or unresponsiveness reports containing a stack or cause, operating-system version, device model, app version and time. Brix36's service also processes operational errors and security/request metadata independently of optional advertising measurement. Supplier technical categories and retention vary; we do not claim that no diagnostics are collected merely because we do not create a custom event.

Turn measurement off under Account → Ad measurement. On Apple devices you can also revoke tracking in system privacy settings. Withdrawal stops new permitted Brix36 measurement and requests removal of the AppsFlyer/RevenueCat attribution linkage; it does not reverse store accounting or erase previously sent events or partner records. Already-created or in-flight records may remain. If Meta diagnostics were active, close and reopen the app after withdrawal because its SDK does not expose a cross-platform control that removes every active diagnostic handler. A diagnostic created while enabled may remain queued and be sent after a later opt-in.

We have not verified a uniform retention period or immediate erasure guarantee across AppsFlyer, RevenueCat and every advertising partner. Contact simeon@brix36.com for access or deletion requests, including partner copies. See [AppsFlyer privacy](https://www.appsflyer.com/legal/privacy-policy/), [RevenueCat privacy](https://www.revenuecat.com/privacy/), [Meta privacy](https://www.facebook.com/privacy/policy/) and [Google privacy](https://policies.google.com/privacy).

Brix36 in your AI assistant (the connector)

You can connect Brix36 to an AI assistant you already use, such as Claude, ChatGPT, Gemini, Microsoft Copilot, Perplexity, Cursor or VS Code. The connector uses the Model Context Protocol (MCP) at `https://api.brix36.com/mcp`. It is off until you connect it, and setup steps are at [brix36.com/connect](https://brix36.com/connect).

How you connect. Your AI app sends you to a Brix36 page. You sign in to Brix36 there, never inside the AI chat, and Brix36 does not give your password to the AI app. The page shows the app's name, the web address you will be sent back to, and the permissions it is asking for. Nothing is connected unless you choose Allow.

The permissions, in plain English.

What the AI service receives. When you use the connector, the AI service receives the requests it makes to Brix36 and the answers Brix36 sends back, for example project names, storyboard and script text, lyric lines on your board, artist names, progress and video links. The company that runs your AI assistant (for example Anthropic for Claude, OpenAI for ChatGPT or Google for Gemini) processes your prompts, conversations and those answers under its own terms and privacy policy. It is not Brix36's service provider, and Brix36 cannot control or delete what it keeps. Check its settings and policy before you connect.

What Brix36 keeps. Brix36 does not receive your AI conversation, only the requests your AI sends to Brix36. We keep the name and return address the AI app registered, the permissions you allowed, secure hashes of the sign-in tokens (never the tokens themselves), and a record of each connector request that changed or started something, so we can control access, prevent duplicate charges, recover from errors and help you if something goes wrong. We rely on performing our contract with you as the lawful basis for this.

How long access lasts and how to disconnect. Each access token lasts 15 minutes and is renewed in the background while the connection is in use. To disconnect, remove or disconnect Brix36 in your AI app's connector or app settings. If you want every connection to your account cut off straight away, email simeon@brix36.com and we will revoke them. Deleting your Brix36 account also ends every connection. Deleting a Brix36 project or account does not erase conversation copies held by your AI service; ask that service to delete them.

Artist DNA links and social media scans

When you paste a link to a website or a social profile in Artist DNA, Brix36's own server reads that public page to find usable photos and details. It does not log in to the account. For some platforms a public page can only be used as a style reference, and connecting the account imports more.

Social connections are optional and are currently available for Instagram, TikTok and YouTube. Brix36 uses Zernio to open the platform's hosted authorisation flow and creates an artist-specific Zernio profile only when you start a connection. Brix36 does not ask for your social-media password and does not publish or post to a connected account.

After connection, Brix36 records the platform and account identifiers, username, display name, profile URL, connection state and import timestamps, and uses Zernio to read the account history available through that connection. For Instagram, eligible pictures and video may be downloaded into private Brix36 storage, screened and visually classified. For TikTok and YouTube, Brix36 stores permitted links and metadata and does not download or cache the audiovisual content. Anthropic may process the permitted picture, video still, caption, link or metadata to separate useful Artist DNA material from irrelevant or unusable material.

A scan imports eligible Artist DNA material and shows its results. Material kept by the scan is subject to the permitted uses for its source. You can remove an item afterwards. Brix36 records the source account and the outcome and reason for each item it checked; filtered media is not stored as a Brix36 asset.

The scan uses temporary access and asks Zernio to disconnect it after scanning. Cleanup may fail and require retry; a pending request is not confirmed removal. Disconnecting stops future use of that connection once completed. It does not remove Artist DNA material already imported or the associated local provenance and decision history. Remove or withdraw those items separately, or delete the artist or account.

Deleting the artist or account removes the corresponding local Zernio identifiers and imported Brix36 data through the ordinary deletion process. Temporary connection cleanup does not establish deletion of every profile, connection record or other copy held by Zernio. Brix36 does not promise a fixed Zernio-side erasure period and will not describe a supplier-side profile or connection record as deleted without confirmation.

Face verification and facial information

A face check is needed only when a video is made with the Seedance video model and a real person appears in it. The artist is then sent once to a real-person verification page hosted by BytePlus ModelArk. BytePlus collects facial images or video to check that a live person is present, extracts facial-recognition features and compares the person's face with authorised photographs added to that artist's verified provider library. Brix36 uses the provider result to decide whether those photographs may be used for real-person video. The check begins only after the artist's permission for that model has been recorded.

The live capture is submitted directly through BytePlus's hosted page. Brix36 stores the consent record, verification-session status, expiry or failure information, provider result code and group or asset references, together with the authorised photographs already stored for the artist.

If the artist passes the live check, BytePlus states that it retains the successful capture as a benchmark or reference image for later authentication. BytePlus also states that facial-recognition features extracted for a comparison are deleted immediately after the comparison, while the same-person or different-person result remains. BytePlus does not publish a fixed retention period for the retained benchmark image or comparison result.

BytePlus states that facial information for this service is stored in Singapore. Its published material does not state how long it retains facial images, video, results or related copies where a check fails, is abandoned, expires, or succeeds but its provider group is not reconciled to Brix36. Expiry of the verification link or exchange token is not evidence that the supplier data has been erased.

BytePlus says facial information is deleted or anonymised within an unspecified reasonable period after its customer instructs deletion, permission is withdrawn or ends, the relevant portrait is deleted, or the customer account is closed. It also publishes asset and asset-group deletion operations, but does not publish a maximum time for removal from primary storage, replicas, backups, safety or security records, logs, the benchmark image or the retained comparison result.

Within Brix36, withdrawing that permission stops new Seedance use of the likeness immediately. Withdrawal, permission expiry and artist or account deletion record provider asset and group deletion obligations where Brix36 has a provider identifier. As at this notice's effective date, ModelArk remote-deletion calls are built but are not enabled in production pending controlled verification of the deletion contract. Recording an obligation is therefore not proof that BytePlus has received or completed a deletion instruction, and the obligation remains open.

A failed, abandoned or expired verification may expose no provider asset or group identifier that the current integration can address through the published deletion operations. Brix36 cannot promise a fixed completion period for that case or for any supplier copy, backup, log, benchmark image or retained result. Brix36 will not describe provider-side facial information as deleted without evidence.

International transfers

Some suppliers may process data outside the United Kingdom. Where required, we rely on an applicable adequacy regulation or contractual and organisational safeguards designed to protect the transferred data. You may ask us for more information about the safeguard used for a particular transfer.

Brix36 does not choose a processing region for OpenAI, Anthropic, fal.ai, the model makers fal.ai passes requests to, or ElevenLabs. Alibaba Cloud Model Studio processes Wan video requests in Singapore. MiniMax is used through its international service. Seedance video generation is provided by BytePlus Pte. Ltd. (Singapore), part of ByteDance, and runs in BytePlus's Johor, Malaysia region. BytePlus may store data in Singapore, Malaysia, the United States, Hong Kong, Indonesia and Japan.

BytePlus states that facial information used for real-person verification is processed and stored in Singapore. We are confirming the contractual safeguard that applies to that transfer and will not claim that a particular safeguard is in place without evidence.

Retention

We keep account and project information while your account is active and for as long as needed to provide the service. When you delete your account, Brix36 removes or irreversibly de-identifies the account and workspace data, including film projects, recordings and generated speech, revokes sessions and connected access, and records deletion work for external files or provider copies so failed deletions can be retried.

Alibaba Wan task records created for a video request are kept for 24 hours. That period covers the task record, not the video kept with the project.

Some information may be kept for longer when necessary:

Pending deletion or token-revocation records remain until the relevant external deletion is confirmed, or until an unresolved provider limitation has been explained and handled consistently with applicable law and your rights. The operational record is then minimised when it is safe to do so.

The additional retention and deletion limits for voices, connected social accounts, assistants, advertising measurement and facial information are set out in those sections above. The normal one-month period for responding to a data-rights request is a response period, not a promise that every supplier copy will be erased within one month.

Your choices and rights

Depending on the circumstances, UK data-protection law gives you rights to:

You can update ordinary account and project information in the app. Account deletion is available under Account → Delete account. If you cannot access the app, email simeon@brix36.com from the address connected to your account. We may need to verify that the account is yours before acting.

To exercise another right, email simeon@brix36.com. We normally respond within one month, subject to the limits and extensions allowed by law.

You can contact the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/ or by calling 0303 123 1113.

Other people's information and artist likenesses

Only upload or connect music, images, video, names and likenesses that you are authorised to use. If you provide information about another person, you are responsible for having authority to do so and for making this notice available to them where required.

Artist DNA is creative reference material. By adding a real person's photos, you confirm that you are authorised to use their likeness in AI-generated video. Brix36 asks for that person's recorded permission and a one-time face check only before the Seedance video model shows them, and may require proof from the artist or their authorised representative. Deleting the artist stops new use. Deletion from an external provider may complete later if that provider is temporarily unavailable; where a provider has not documented deletion of a particular processing copy, Brix36 will not describe that copy as deleted without evidence.

Children

Brix36 is available to users aged 13 and over and is not directed to children under 13. Users under 18 may use Brix36 only with a parent or legal guardian's permission and supervision, as explained in our Terms of Service. Optional real-person face verification is restricted to adults.

If you believe a child under 13 has created an account or supplied personal information to Brix36, contact simeon@brix36.com so we can investigate and remove the account and information where appropriate.

Security

We use measures including encrypted transport, hashed passwords and session tokens, private signed file access, restricted service credentials, encrypted Apple token storage and access controls scoped to each workspace. No service can guarantee absolute security. Contact simeon@brix36.com immediately if you believe an account or file has been accessed improperly.

Changes to this notice

We may update this notice as Brix36 changes. We will publish the new effective date and bring material changes to users' attention before a new use of personal data begins where required.