Brix36 Privacy Notice
Effective date: 25 August 2026
Who we are
Brix36 is operated by SOCIALISER APP LTD (company number 17243028), registered at Unit 82a James Carter Road, Bury St. Edmunds, United Kingdom, IP28 7DE. SOCIALISER APP LTD is the controller of personal data described in this notice.
Privacy questions and data-rights requests can be sent to simeon@brix36.com.
What Brix36 does
Brix36 helps artists and their teams create artist profiles, collect authorised Artist DNA material, organise releases or standalone music videos, analyse songs, develop creative direction, review storyboards and, where enabled, produce AI-assisted promotional clips and music videos.
Information we collect
We collect information that you provide or create in Brix36, including:
- account information such as your name, email address, internal user ID, verification state and connected Google or Apple login method;
- artist and project information such as artist profiles, inferred and confirmed sound/scene labels, releases, songs, non-lyrical song themes, music-video briefs, prompts, creative direction, storyboards, approvals, feedback and change requests;
- files and references such as audio, photographs, video, artwork, previous-work links, generated material and completed deliverables;
- purchase and credit information such as the store product, transaction identifier, purchase/refund environment, Brix Credit grant or spend, resulting balance and the production order funded by it; Brix36 does not receive your payment-card or bank-account details;
- rights and consent records such as who authorised likeness material, the scope of that permission, evidence supplied, withdrawal and deletion status;
- optional social-connection information such as the platform, provider account and artist-profile identifiers, username, display name, profile URL, connection state, posts, captions, links, import status and the pictures or video that the feature is permitted to read;
- facial information processed for optional likeness verification, including live facial images or video collected on BytePlus's hosted page, authorised photographs compared with the successful capture, facial-recognition features used for that comparison, the comparison result, and Brix36's consent, session, status and provider-reference records;
- support and safety information such as messages to us, in-app content reports and our response; and
- technical and security information such as device/platform type, IP and network metadata, request timestamps, security events and service errors where our systems or providers retain them; and
- optional Meta measurement and SDK-diagnostic information sent only after you opt in, such as app opens, completed registration, checkout starts, completed Brix Credit purchases, product and currency information, a device or advertising identifier where the operating system makes one available, and limited Meta SDK reliability diagnostics such as an SDK crash, error or unresponsiveness report with its stack or cause, operating-system version, device model, app version and report time. Brix36 does not intentionally add your music, photographs, video, Artist DNA, project names, prompts, storyboards or face-verification information to these events or reports.
If you connect Google or Apple, we receive the provider's stable account identifier, verified email address and any display name the provider supplies. We use the identity token and, for Apple, the one-use authorisation code only to verify the sign-in. Apple refresh-token material needed for account-deletion revocation is encrypted at rest and is never exposed to the app.
Optional social connections are available now for Brand Scan and are explained under Connected social accounts and Brand Scan below.
How we use information and our lawful bases
We use personal data:
- to create and secure your account, provide the features you request, save your work and deliver outputs — necessary to perform our contract with you;
- to validate Brix Credit purchases, maintain your balance, fund the production you approve, handle refunds or reversals and provide purchase support — necessary to perform our contract with you and comply with financial obligations;
- to measure song structure, transiently transcribe uploaded songs, reduce the transcript to non-lyrical themes, infer an artist-specific sound profile for your review, and prepare storyboards when you request AI-assisted work — necessary to perform our contract with you;
- to connect supported social accounts, import and classify permitted account history for Brand Scan, record its source and preserve removal decisions so material is not silently re-imported — necessary to provide the optional feature you choose to use;
- to protect accounts, prevent abuse, investigate faults, respond to support requests and improve reliability — our legitimate interests in operating a safe and dependable service;
- to review reported generated content, enforce rights restrictions and protect artists and other people — our legitimate interests and, where applicable, legal obligations;
- to keep narrowly required rights, consent, financial and audit records — compliance with legal obligations and our legitimate interest in establishing or defending legal claims; and
- to process an artist's likeness or other sensitive reference material only where the required explicit permission has been recorded, and to stop new use when that permission is withdrawn; and
- where you choose to opt in, to use limited Meta app events to measure which Brix36 advertisements lead to app use, registration, checkout and completed credit purchases, improve app-ad delivery, and receive limited Meta SDK reliability diagnostics to maintain and analyse the integration — your consent, which you can withdraw at any time.
Brix36 does not make solely automated decisions that have legal or similarly significant effects on you. Automated analysis and generation can recommend or create material, but the user reviews and approves creative choices.
AI processing and service providers
We use suppliers to run Brix36. Depending on which feature you use, personal data may be processed by:
- Fly.io for application hosting;
- Supabase for the production database;
- Cloudflare, including R2, for DNS, security and private file storage;
- Resend for account and security email;
- Apple and Google when you choose their sign-in service or buy Brix Credits through their store;
- RevenueCat for store-purchase validation, product availability and Brix Credit grants, spends, balances and refund/reversal reconciliation;
- OpenAI for transient transcription of an uploaded song when song-theme understanding is enabled;
- Anthropic for reducing that transient transcript to non-lyrical themes, classifying permitted connected-account material, learning evidence-backed Artist DNA and directing storyboards;
- Zernio for optional hosted connection of supported social accounts and import of permitted account history for Brand Scan; and
- Meta Platforms for optional, consent-gated app-ad measurement, attribution, analytics and optimisation through Meta App Events, and limited reliability diagnostics from that SDK; and
- fal.ai and BytePlus ModelArk for selected media-generation requests, with BytePlus also providing the real-person verification, facial comparison and private identity-asset library described below.
Payment-card and bank-account information stays with the App Store or Play billing service and is not sent to Brix36. RevenueCat and Brix36 receive the customer, product and transaction information needed to fulfil and support the purchase. Brix Credits are non-cash units used only inside Brix36 and do not expire.
We send an AI provider only the information and references needed for the requested task. A provider does not receive your whole Artist DNA library by default. Provider availability, model capability and rights rules determine which route can be used, and a request is refused when Brix36 cannot identify a permitted route.
Song tempo, sections, beats and energy are measured locally on Brix36's server. When song-theme understanding is enabled, the uploaded song is also sent to OpenAI's audio-transcription API. The resulting transcript is held only long enough to ask Anthropic for a short set of meanings and situations; Brix36 does not write the verbatim transcript to its database or pass it to the storyboard planner. Brix36 stores only the non-lyrical themes, an analysis status and the model provenance. Those themes may state explicit adult subject matter plainly where it is central to the song. Sound, scene and subgenre suggestions are shown for approval, denial or editing before they become the artist's confirmed profile.
When Brix36 uses fal.ai, source photographs and other private files remain in Brix36 storage. fal.ai receives a signed link that normally expires after 15 minutes and fetches the referenced material to carry out the request; Brix36 does not upload that source file into fal.ai's CDN. fal.ai's public documentation currently explains deletion of stored request payloads and generated output files, but does not state whether it keeps a separate processing copy of a file fetched from a customer's external link or, if so, for how long. Brix36 is seeking written clarification. Until the answer and our automated request-deletion path are verified, Brix36 cannot promise that fal.ai immediately removes every transient processing copy.
Brix36 does not offer a likeness route that avoids fal.ai. Where an artist's likeness is used, both fal.ai and BytePlus ModelArk may be involved in producing it, and there is no single-provider option to choose between them. If you do not accept the fal.ai limitation described above, do not authorise likeness processing for that artist: Brix36 will still produce the video, using invented likenesses instead of that artist's own. If you have already authorised it and want to stop, withdraw the permission on the artist's likeness screen and email simeon@brix36.com. Withdrawal stops new use immediately; where a provider has not confirmed deletion of a copy it holds, Brix36 will not describe that copy as deleted.
BytePlus separately states that ModelArk inputs and outputs which trigger its content-safety filter may be retained for up to 180 days in Malaysia. That is a content-filter rule, not the normal retention period for face verification, and it does not answer when a liveness capture, retained benchmark image, comparison result, failed-session data, backup or log is erased.
We may also disclose information where the law requires it, to protect someone's vital interests, to establish or defend legal claims, or as part of a properly controlled company sale or reorganisation.
We do not sell personal data and Brix36 does not show third-party advertising inside the app. A Meta-enabled version contains Meta's App Events SDK solely for the optional advertising measurement and related SDK diagnostics described below.
Optional Meta advertising measurement
A Meta-enabled version of Brix36 asks before activating Meta advertising measurement. Until you choose Allow Meta measurement, Brix36 does not activate Meta App Events or enable advertising-identifier collection. On iPhone and iPad, Brix36 also asks for Apple's App Tracking Transparency permission; Meta measurement remains off unless both your Brix36 choice and Apple's permission allow it.
If you opt in, Brix36 may send Meta app opens, a completed registration, the start of a Brix Credit checkout and a completed store purchase. Those events may include the store product, price, currency and number of credits, along with an app-instance, device or advertising identifier made available by the operating system. Meta uses the information for app-ad attribution, measurement, analytics and optimisation, including working out whether a Meta advertisement led to an install, registration, checkout or purchase.
After the SDK is activated, it may also send Meta limited reliability diagnostics about the integration. Depending on the platform, remote SDK settings and failure, this can include an SDK crash, error or unresponsiveness report with its stack or cause, operating-system version, device model, app version and report time. Brix36 and Meta use this information for app functionality and analytics: to diagnose the integration, understand its reliability and fix faults. Brix36 does not intentionally add your music, photographs, video, Artist DNA, project names, prompts, storyboards, generated content, facial images, face-verification results or likeness-permission records to Meta events or diagnostic reports.
You can turn this sharing off under Account → Meta ad measurement. On iPhone or iPad you can also deny or revoke tracking in the device's privacy settings. Turning it off disables new Brix36 App Events and advertising-identifier transmission. Because the installed SDK does not expose a cross-platform control that removes every active diagnostic handler, close and reopen Brix36 after turning measurement off to stop new SDK reliability diagnostics in that app process. A diagnostic already created while measurement was enabled may remain queued and could be sent if measurement is later enabled again. Turning measurement off does not erase information Meta already received. Meta's published privacy policy explains that retention depends on the information and why it is used rather than giving a fixed App Events retention period. You can read it at https://www.facebook.com/privacy/policy/ and use Meta's own privacy controls for information held by Meta.
Connected social accounts and Brand Scan
Social connections are optional and are currently available for Instagram, TikTok and YouTube. Brix36 uses Zernio to open the platform's hosted authorisation flow and creates an artist-specific Zernio profile only when you start a connection. Brix36 does not ask for your social-media password and does not publish or post to a connected account.
After connection, Brix36 records the platform and account identifiers, username, display name, profile URL, connection state and import timestamps, and uses Zernio to read the account history available through that connection. For Instagram, eligible pictures and video may be downloaded into private Brix36 storage, screened and visually classified. For TikTok and YouTube, Brix36 stores permitted links and metadata and does not download or cache the audiovisual content. Anthropic may process the permitted picture, video still, caption, link or metadata to separate useful Artist DNA material from irrelevant or unusable material.
Material kept by the scan appears in Brand Scan without a separate approval step for every item, subject to the permitted uses for its source. You can remove an item afterwards. Brix36 records the source account and the outcome and reason for each item it checked; filtered media is not stored as a Brix36 asset.
Disconnecting asks Zernio to detach that platform account and stops it being included in later scans. It does not remove Brand Scan material already imported or the associated local provenance and decision history. Remove or withdraw those items separately, or delete the artist or account.
Deleting the artist or account removes the corresponding local Zernio identifiers and imported Brix36 data through the ordinary deletion process. As at this notice's effective date, however, the current integration does not automatically disconnect every remaining Zernio account or delete the artist-specific profile held by Zernio. Brix36 does not promise a fixed Zernio-side erasure period and will not describe a supplier-side profile or connection record as deleted without confirmation.
Face verification and facial information
Likeness verification is optional. When it is chosen, the artist is sent to a real-person verification page hosted by BytePlus ModelArk. BytePlus collects facial images or video to check that a live person is present, extracts facial-recognition features and compares the person's face with authorised photographs added to that artist's verified provider library. Brix36 uses the provider result to decide whether those photographs may be used for real-person video. The check begins only after the required separate likeness permission has been recorded.
The live capture is submitted directly through BytePlus's hosted page. Brix36 stores the consent record, verification-session status, expiry or failure information, provider result code and group or asset references, together with the authorised photographs already stored for the artist.
If the artist passes the live check, BytePlus states that it retains the successful capture as a benchmark or reference image for later authentication. BytePlus also states that facial-recognition features extracted for a comparison are deleted immediately after the comparison, while the same-person or different-person result remains. BytePlus does not publish a fixed retention period for the retained benchmark image or comparison result.
BytePlus states that facial information for this service is stored in Singapore. Its published material does not state how long it retains facial images, video, results or related copies where a check fails, is abandoned, expires, or succeeds but its provider group is not reconciled to Brix36. Expiry of the verification link or exchange token is not evidence that the supplier data has been erased.
BytePlus says facial information is deleted or anonymised within an unspecified reasonable period after its customer instructs deletion, permission is withdrawn or ends, the relevant portrait is deleted, or the customer account is closed. It also publishes asset and asset-group deletion operations, but does not publish a maximum time for removal from primary storage, replicas, backups, safety or security records, logs, the benchmark image or the retained comparison result.
Within Brix36, withdrawing likeness permission stops new likeness use immediately. Withdrawal, permission expiry and artist or account deletion record provider asset and group deletion obligations where Brix36 has a provider identifier. As at this notice's effective date, ModelArk remote-deletion calls are built but are not enabled in production pending controlled verification of the deletion contract. Recording an obligation is therefore not proof that BytePlus has received or completed a deletion instruction, and the obligation remains open.
A failed, abandoned or expired verification may expose no provider asset or group identifier that the current integration can address through the published deletion operations. Brix36 cannot promise a fixed completion period for that case or for any supplier copy, backup, log, benchmark image or retained result. Brix36 will not describe provider-side facial information as deleted without evidence.
International transfers
Some suppliers may process data outside the United Kingdom. Where required, we rely on an applicable adequacy regulation or contractual and organisational safeguards designed to protect the transferred data. You may ask us for more information about the safeguard used for a particular transfer.
BytePlus states that facial information used for real-person verification is processed and stored in Singapore. We are confirming the contractual safeguard that applies to that transfer and will not claim that a particular safeguard is in place without evidence.
Retention
We keep account and project information while your account is active and for as long as needed to provide the service. When you delete your account, Brix36 removes or irreversibly de-identifies the account and workspace data, revokes sessions and connected login methods, and records deletion work for external files or provider copies so failed deletions can be retried.
Some information may be kept for longer when necessary:
- encrypted backups may remain until the relevant provider's normal backup cycle expires;
- security, support and operational records are retained only for as long as reasonably needed to investigate incidents and operate the service;
- moderation reports may survive deletion as a minimised forensic record so abuse can be reviewed and legal claims handled; and
- consent, purchase, credit-ledger, production-order and other audit evidence may be retained for the period required by law or reasonably needed to establish or defend a claim, which may be up to six years in the United Kingdom.
Pending deletion or token-revocation records remain until the relevant external deletion is confirmed, or until an unresolved provider limitation has been explained and handled consistently with applicable law and your rights. The operational record is then minimised when it is safe to do so.
The additional retention and deletion limits for connected social accounts and facial information are set out in those sections above. The normal one-month period for responding to a data-rights request is a response period, not a promise that every supplier copy will be erased within one month.
Your choices and rights
Depending on the circumstances, UK data-protection law gives you rights to:
- access your personal data;
- correct inaccurate data;
- ask for deletion;
- restrict or object to processing;
- receive portable data you provided;
- withdraw consent without affecting earlier lawful processing; and
- complain to the UK Information Commissioner's Office.
You can update ordinary account and project information in the app. Account deletion is available under Account → Delete account. If you cannot access the app, email simeon@brix36.com from the address connected to your account. We may need to verify that the account is yours before acting.
To exercise another right, email simeon@brix36.com. We normally respond within one month, subject to the limits and extensions allowed by law.
You can contact the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/ or by calling 0303 123 1113.
Other people's information and artist likenesses
Only upload or connect music, images, video, names and likenesses that you are authorised to use. If you provide information about another person, you are responsible for having authority to do so and for making this notice available to them where required.
Artist DNA is creative reference material, not automatic permission. Brix36 records likeness permission separately and may require proof from the artist or their authorised representative. Withdrawing permission stops new use. Deletion from an external provider may complete later if that provider is temporarily unavailable; where a provider has not documented deletion of a particular processing copy, Brix36 will not describe that copy as deleted without evidence.
Children
Brix36 is intended for professional artists and their teams and is not directed to children. You must be at least 18 years old, or the age of legal majority where you live, to create an account.
Security
We use measures including encrypted transport, hashed passwords and session tokens, private signed file access, restricted service credentials, encrypted Apple token storage and access controls scoped to each workspace. No service can guarantee absolute security. Contact simeon@brix36.com immediately if you believe an account or file has been accessed improperly.
Changes to this notice
We may update this notice as Brix36 changes. We will publish the new effective date and bring material changes to users' attention before a new use of personal data begins where required.