Privacy Policy

What Brenxa collects, why we collect it, who it reaches, and what you can ask us to do about it.

Last updated 29 July 2026Wikrena Limited

In short

  • We collect what the product needs to work, and nothing for advertising.
  • Your decisions are private to you. We never show them to other users, and we do not sell data to anyone.
  • Newsletter email is opt-in twice: you ask, then you confirm by clicking a link.
  • Access is enforced at the database, not only in the interface.
  • You can ask for a copy of your data, a correction, or its deletion at any time.

This summary is for orientation only. The numbered sections below are the terms that apply.

Who we are

Brenxa is operated by Wikrena Limited, a company incorporated in Nigeria, with its registered office at 12 Achi Street, Independence Layout, Enugu, Nigeria. In this policy, “we” and “us” mean Wikrena Limited.

We are the data controller for the personal data described here. That means we decide what is collected and why, and we are accountable for it. You can reach us about anything on this page at privacy@brenxa.com.

What we collect

We collect four kinds of information, and no more than we need.

Account information

Your email address and, if you provide them, your first and last name. Authentication is handled by Supabase Auth. If you sign in with Google, we receive your email address and name from Google, and we never receive your Google password.

What you tell us during onboarding

Your role, the domains you care about, your goals, and your stated risk tolerance. This exists so recommendations are relevant to you rather than generic.

What you create in the product

The decisions you bring, the context you give, the councils you build, the journal entries you write, and the outcomes you record later. This is the substance of the product and the most sensitive thing we hold.

Technical and usage information

Standard server logs, and on the public blog an anonymous view count. The blog stores a random identifier in a first-party cookie so that one person reading one article twice in a day is counted once. That identifier is never linked to an account, and there is no way for us to connect it back to you.

When a view is recorded we also store the website you arrived from, if your browser sends one. We keep the site name only, never the full address of the page.

We log what people type into the blog’s search box, so we can see what readers are looking for and write about it. Search terms are stored on their own, with no identifier attached at all, so they cannot be linked to each other, to a visit, or to you. If you subscribe to the newsletter we record which page you signed up from.

To stop the signup form being used to send unwanted email to other people, we count recent attempts from each internet address. We do not store the address itself: it is converted into an irreversible code first, and the counter is deleted within a day.

We do not collect special category data, we do not buy information about you from anyone, and we do not run advertising trackers.

Why we collect it, and on what basis

Under the Nigeria Data Protection Act 2023, personal data must be processed on a lawful basis. Ours are:

  • Performance of a contract. Your account, the decisions you create, and the analysis we return. Without this data there is no product to deliver.
  • Consent. Newsletter email. You confirm your address by clicking a link before anything is sent, and you can withdraw at any time from the footer of any email.
  • Legitimate interest. Keeping the service secure and working, preventing abuse of our forms, understanding which articles get read, and seeing what readers search for so we can write about it. In each case the processing is limited to what that purpose actually needs, which is why search terms carry no identifier, referrers keep only the site name, and abuse counters hold no readable address.

Cookies

We set three cookies. None of them are for advertising.

  • Session cookies, set by Supabase Auth, which keep you signed in. Clearing them signs you out.
  • A theme preference, stored in your browser so the site does not flash the wrong colour scheme as it loads.
  • An anonymous blog visitor identifier, a random value used only to avoid counting the same reader twice within twenty four hours.

We use no third-party advertising or cross-site tracking cookies.

Who we share it with

We do not sell your data, and we never show the content of your decisions to other users. We rely on a small number of providers who process data on our instructions:

  • Supabase, for the database, authentication and file storage.
  • Vercel, for hosting and content delivery.
  • Resend, for transactional and newsletter email.
  • AI model providers, for the reasoning itself. Brenxa is deliberately not tied to one provider, and which model runs a given stage of an analysis is a configuration choice. The current list is available on request from privacy@brenxa.com.

We will also disclose data where the law requires it, and we will tell you when we are permitted to.

Where your data is held

Our database and file storage are hosted in the European Union. Hosting and email are delivered over global networks, so your data may be processed outside Nigeria.

Where data leaves Nigeria, we rely on the transfer provisions of the Nigeria Data Protection Act 2023 and on contractual protections with each provider.

How long we keep it

We keep your account and its contents for as long as your account is open. If you ask us to delete it, we will delete or irreversibly anonymise your personal data, except where the law requires us to keep something.

One part of the product works differently and you should know about it. Brenxa’s memory of your decisions is append-only by design. The database physically rejects attempts to edit or delete individual historical records, so the reasoning behind a past recommendation cannot be quietly rewritten. Deleting your account removes the whole record; single entries within it cannot be edited out.

Retention periods for logs and backups have not been finalised, and will be stated here before Brenxa is publicly available.

Your rights

Under the Nigeria Data Protection Act 2023 you can ask us to:

  • confirm whether we hold data about you, and give you a copy;
  • correct anything inaccurate;
  • delete your data, subject to the limits described above;
  • restrict or object to how we process it;
  • provide your data in a portable form;
  • withdraw consent, where consent is the basis we relied on.

Write to privacy@brenxa.com and we will respond within thirty days. If our response does not satisfy you, you can complain to the Nigeria Data Protection Commission.

Security

Access to your data is enforced at the database through row-level security, not only in application code, so a bug in the interface cannot expose one person’s decisions to another. Data is encrypted in transit and at rest by our infrastructure providers.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the Nigeria Data Protection Commission as the Act requires.

Children

Brenxa is not intended for anyone under eighteen, and we do not knowingly collect data from children. If you believe a child has given us personal data, write to privacy@brenxa.com and we will delete it.

Changes to this policy

We will update this page when what we do changes, and the date at the top will always reflect the last substantive change. Where a change materially affects your rights, we will tell you directly rather than rely on you noticing.

Contact

Wikrena Limited
12 Achi Street, Independence Layout, Enugu, Nigeria