←  GreenBrain home

Privacy Policy

Effective: · Clarified October 4, 2026 · Free public beta

Who is responsible for your data. GreenBrain LLC, a Connecticut limited liability company (“GreenBrain”, “we”, “us”), Connecticut, USA.

Privacy questions, access, correction, export, or deletion requests: support@greenbrain.io. This policy is governed by the laws of the State of Connecticut, with venue in Connecticut courts, as set out in our Terms of Service.

GreenBrain ("we", "us", "our") runs the GreenBrain app and the public website at greenbrain.io. This policy explains what we collect, why, which outside companies touch it, how long we keep it, and how to get it back or get rid of it. It is written for the landscapers who use GreenBrain and for their customers whose details end up in it.

1. Information we collect

2. Where customer information comes from

Most customer information is typed in or imported by the landscaping business that uses GreenBrain. Some arrives through public surfaces that business chooses to turn on:

If you are a customer of a landscaping company that uses GreenBrain, that company is the business you have the relationship with; we process your information on their behalf. Ask them first about your records, and contact us if you need help reaching them.

3. How we use it

We do not sell, rent, or trade personal information, we do not use it for cross-site targeted advertising, and we do not use your customer list to market to your customers.

4. Service providers who handle data for us

AI is optional. Before using external AI features, you can review the providers and information involved and choose whether to allow AI processing. Accepting our Terms is not permission to share with AI. You can continue using manual CRM tools without allowing AI, and review or revoke your choice in Settings → AI sharing. Your choice is tied to your own login, not granted to everyone in your workspace. Revoking stops future processing through these AI features; it cannot recall information already sent or stop a provider request already in progress. If the disclosed providers or processing scope change, a previous permission does not automatically authorize the new scope.

We use outside companies and public services only as needed to run the features you use. Each one receives only what its job requires. As of the effective date they are:

We may also disclose information at your direction, to the recipients you choose, in a business transfer (we would tell you first), or when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or enforce our Terms.

5. AI models and training

We do not use your data, or your customers' data, to train AI models. The AI providers we send data to through their business APIs — Anthropic and Groq — do not use API inputs or outputs to train their models by default under their commercial terms. The founder's own workspace also uses OpenAI through the founder's ChatGPT account; whether OpenAI may use that workspace's data to improve its models is governed by that account's data-control setting, not by an API agreement. No other workspace's data goes to OpenAI.

6. Cookies, session storage, and Google Analytics

GreenBrain uses one essential, secure session cookie to keep you signed in. The anonymous public-page visit identifier described above lives in sessionStorage, not a cookie, and ends with the browser session.

Google Analytics runs on our home page (greenbrain.io), our comparison pages, our free tools and calculators, and our pricing guides. It sets first-party measurement cookies with a random identifier and tells Google which pages you viewed, the page that referred you, campaign tags in the link, how long you stayed, your browser, device type, screen size, and language, and an approximate location that Google derives from your IP address. We have turned off Google signals and ad-personalization features in our code, so this data is not used for Google advertising or linked to your Google account by us. We do not send Google your name, email, or anything you type into a form. Google Analytics is not loaded inside the app, on this page, on the Terms, or on any customer-facing invoice, quote, or portal page. You can block it with your browser's privacy settings or an extension.

We do not use advertising pixels, session recording, or third-party chat widgets, and we do not build cross-site advertising profiles.

7. Text messages and email

GreenBrain sends a text or email to your customers only when you initiate a send or explicitly turn on a scheduled review request or quote follow-up. Confirmation and send-password controls apply where shown in the product. We never message your customers on our own. GreenBrain may text or email you, the business, about your own account, for example a new website lead, an accepted quote, or a password reset.

8. How long we keep data, and how to delete it

While your account is active, we keep your workspace so the app works. Some operational logs are trimmed automatically: raw request metadata, landing-page funnel events, outbound message logs, and AI usage counts are kept for up to 90 days; internal AI routing telemetry for 30 days. The action ledger, which records which actions GreenBrain carried out in a workspace, their outcome, and the approvals given (never conversation text or message content), is kept for 365 days. The audit log, which records security events and who did what to an account (including every action GreenBrain's operator takes on your workspace), is kept for one year: entries about the operator's actions are removed only when they are a year old, while entries created by accounts' own activity are also capped at the most recent 50,000 in total and 5,000 per workspace. Location history is kept while your account is active and deleted when your account is deleted. It is not trimmed on a timer, because mileage and time on site are calculated from it.

Deleting your account. Go to Settings → Account & payments → Delete account, confirm your password, and type DELETE. For a workspace owner, this is one database transaction that removes the workspace, team logins, sessions, customer and financial records, saved snapshots, integrations, public and portal links, leads, sent-message records, support data, receipts, uploaded images, brand assets, email and text suppression lists and ledgers, follow-up logs, GPS and location history, AI usage telemetry, quotas, and account tokens. A team member deleting their own login removes that login and its personal location history without deleting the company workspace. You can also email support@greenbrain.io from your account email and we will do it for you. Either way, audit log entries about the deleted account are kept for the rest of their year, but the account's identifier in them is replaced with a random alias and the network addresses recorded for the account's own actions are removed, so they no longer identify you.

Backups. For recovery, we keep backup copies of the database. They contain everything in it, including location history and the data of accounts deleted after the copy was made, so deleted data leaves backups only when those copies age out or are deleted. Where the copies are kept, and for how long:

Copies of your data that leave the hosting environment are encrypted. All backup copies are access-restricted and are used only to recover the service, never to recreate an individual deleted account.

Records we may keep longer. Opt-out lists (so STOP keeps working), payment records tied to Stripe transactions, and security or abuse records may be retained when needed to honor opt-outs, resolve disputes, meet provider or legal obligations, or maintain financial records.

9. Your data, your choices

How to make a request. Email support@greenbrain.io to access, correct, export, or delete your personal data, or to opt out of any processing you are entitled to opt out of. Tell us what you want and which account or business it concerns; we may need to confirm your identity, usually by a reply from your account email. We aim to answer every privacy request within 30 days, and always within 45 days, or tell you why we need more time as the law allows.

Appeals. If we decline your request, you can appeal: reply to our answer, or email support@greenbrain.io with "Privacy appeal" in the subject. We will review it and tell you the outcome in writing within 60 days. If you disagree with the outcome, you can contact the Connecticut Attorney General at portal.ct.gov/ag, or your own state's attorney general.

10. Security

Data moves between your browser and our servers over TLS/HTTPS. Passwords are salted and hashed, and active session tokens are stored as hashes. Password-reset links are single-use and expire after 60 minutes. Integration credentials are encrypted before storage. Each workspace is isolated from every other workspace. Sends, money actions, and deletions ask for confirmation before they run, except scheduled review requests and quote follow-ups you turn on, and required automatic replies such as HELP. Off-site backups are encrypted with authenticated encryption and GreenBrain will not email a plaintext backup if the encryption key is missing. No system is perfectly secure, and we cannot promise absolute security; if we learn of a breach affecting your data, we will tell you.

11. Children

GreenBrain is a business tool for people 18 and older. We do not knowingly collect personal information from children.

12. Contact

Questions about this policy or your data: support@greenbrain.io

13. Changes to this policy

We may update this policy. For material changes we will notify active users by email or in the app before the change takes effect, and every revision is listed here. When a material change takes effect, the app asks you to review the updated policy before you continue, and we record which version you accepted. For changes that are not material, such as clarifications and corrections, continued use after the change takes effect means you accept the updated policy.