Legal
Privacy Policy
Effective August 19, 2026
This policy explains what personal data Breme collects, how we use it, who we share it with, and the choices and rights you have. The short version: we collect what we need to run the service, we never sell your data, paid-plan content is private and you control whether it helps train our models, and you can reach us anytime at info@breme.ai.
1. Who we are
Breme is operated by Figurative, Inc., a Delaware corporation ("Breme", "we", "us"). We are the controller of the personal data described in this policy.
You can contact us about anything in this policy at info@breme.ai, or by mail at 2810 N Church St STE 90367, Wilmington, DE 19802, United States.
2. What this policy covers
This policy applies to breme.ai, the Breme application, and related services we operate. It covers personal data we collect when you visit our site, create an account, use the product, or communicate with us.
It does not cover third-party sites or services we link to. Those have their own privacy policies.
3. Information we collect
We collect the following categories of data:
- Account information: the email address you sign up with, and the name, profession, and how-you-found-us answer you give during onboarding.
- Google sign-in data: if you sign in with Google, we receive your name and email address from your Google profile.
- Teammate emails: if you invite people to your organization, we collect the email addresses you enter so we can send the invitations.
- Content you upload: images, video, and audio you upload, which may include faces and voices.
- Content you create: prompts, scripts, and other creative content you produce in the product.
- Generation and usage records: the operations you run, the model used, and the cost of each operation.
- Device and usage analytics: information about how you found Breme (such as referring site and campaign tags), pages visited, signup and onboarding milestones, product features used, and general device characteristics. We use this journey data to understand acquisition and improve activation; we do not include your prompts or creative content in these analytics events.
- Payment records: your subscription plan, invoices, and payment status. Your card details are collected and stored by Stripe, our payment processor, and never by Breme.
4. Your content and AI training
We use content created on Breme to train and improve our models. What this means depends on the plan default and your organization preference:
- Every plan: training is enabled or disabled according to the plan default and your organization training preference. A plan may default training off, but an organization admin can turn it on.
- Changing the organization preference affects content created afterward. Content already marked eligible remains eligible for future export even after a later opt-out, downgrade, plan change, or account closure.
- Every plan: our API model providers (OpenAI, Anthropic, and others) are contractually prohibited from training their own models on your content.
Before export, we de-identify the dataset record and deterministically redact identifying prompt text; we do not remove people or other creative subjects from the media. We do not retain a creator mapping in the training dataset, and we do not rebuild completed datasets or models when a preference changes, an account closes, or source content is deleted. Active source systems remain subject to any personal-data rights that apply by law. Those rights are handled through our active-system privacy process; this training pipeline has no creator-linked deletion mechanism for completed exports.
Content you choose to make public may be shown on public pages. On every plan we may use de-identified, aggregated data about how the service is used (usage signals, quality ratings, technical telemetry) to improve it.
5. Where your content lives and who can see it
Content you create is stored privately on every plan; only you and your organization can access it.
Content you choose to make public, and free-plan content we feature on our showcase pages, is publicly viewable where it is displayed.
6. How we use your information
We use the data we collect to:
- Provide and operate the service, including running the AI generations you request.
- Create and manage your account and organization, including sending invitations to teammates.
- Process payments and manage your subscription.
- Send transactional email, such as invitations, receipts, and important service notices.
- Understand how the product is used so we can improve it.
- Keep the service secure, prevent fraud and abuse, and enforce our terms.
- Comply with legal obligations, such as tax and accounting requirements.
7. Legal bases for processing (GDPR)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Contract: processing needed to provide the service you signed up for.
- Legitimate interests: securing the service, analyzing how it is used, and preventing fraud.
- Consent: where required, for example for optional communications. You can withdraw consent at any time.
- Legal obligation: keeping records required by tax and accounting law.
8. Service providers and subprocessors
We share data with a small set of providers who process it on our behalf, only for the purposes listed here:
- Supabase: database, authentication, and file storage.
- Vercel: hosting and product analytics.
- Stripe: payments and billing.
- OpenAI, Anthropic, and Replicate: AI model processing of your prompts and media.
- Unifically: AI model aggregation.
- Cloudflare: AI request routing.
- An email delivery provider: transactional email such as invitations and receipts.
Each provider is bound by contract to handle your data only as needed to provide its service to us.
9. Other times we may disclose data
Beyond the providers above, we may disclose personal data:
- Within your organization: teammates in your organization can see content and activity shared in the shared workspace.
- To comply with law: when required by a valid legal request, such as a subpoena or court order.
- To protect rights and safety: to enforce our terms, or to protect the rights, property, or safety of Breme, our users, or others.
- In a business transfer: if Breme is involved in a merger, acquisition, or sale of assets, in which case this policy will continue to apply to your data.
We do not sell personal data, and we do not share it for targeted advertising.
10. International data transfers
Breme is based in the United States, and your data is processed there. If you are in the EU, UK, or another region with data transfer rules, this means your data is transferred to a country that may have different data protection laws than yours.
For personal data from the EU and UK, we rely on Standard Contractual Clauses with our providers as the transfer mechanism.
11. How long we keep your data
- Account data: for as long as your account exists.
- Content: until you delete it or your account is deleted. When you request account deletion, we remove the account from active access immediately and delete its content from our backend systems within 30 days, subject to legal, security, fraud-prevention, backup-cycle, and de-identification exceptions.
- Billing records: as long as tax law requires, typically 7 years.
- Logs and analytics: for a limited operational period.
12. Your rights (EU and UK)
If you are in the EU or UK, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Have your data erased.
- Receive a copy of your data in a portable format.
- Restrict or object to certain processing.
- Lodge a complaint with your local supervisory authority.
To exercise any of these rights, email info@breme.ai. We will respond within the legally required window.
13. Your rights (US states)
If you live in a US state with a privacy law (such as California, Colorado, Virginia, or Texas), you have the right to:
- Know what personal data we collect and how we use it.
- Delete your personal data.
- Correct inaccurate data.
- Opt out of the sale or sharing of personal data and of targeted advertising. Breme does not sell personal data and does not use it for targeted advertising, so there is nothing to opt out of.
- Not be discriminated against for exercising these rights.
- Appeal if we refuse a request. Reply to our decision and we will have someone else review it.
We honor Global Privacy Control signals from your browser.
To exercise any of these rights, email info@breme.ai. We will respond within the legally required window.
15. Security
We protect your data with encryption in transit, access controls, and row-level security on our database, so each account can only reach its own records.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we learn of a breach affecting your data, we will notify you as required by law.
16. Children
Breme is for users 18 and older. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has given us personal data, contact us at info@breme.ai and we will delete it.
17. Automated decision-making
We do not make automated decisions about you that have legal or similarly significant effects.
Content you submit may be automatically screened for violations of our prohibited-content rules.
18. Changes to this policy
We may update this policy as the service or the law changes. Updates are posted at breme.ai/legal/privacy, and the effective date at the top of this page always shows the current version. For significant changes we will make reasonable efforts to let you know, for example by email or a notice in the service, and where the law requires direct notice of a change, we will provide it. You are responsible for reviewing the current policy periodically.
Questions about this policy can go to info@breme.ai.