Privacy Policy
What Brenxa collects, why we collect it, who it reaches, and what you can ask us to do about it.
In short
- We collect what the product needs to work, and nothing for advertising.
- Your decisions are private to you. We never show them to other users, and we do not sell data to anyone.
- Newsletter email is opt-in twice: you ask, then you confirm by clicking a link.
- Access is enforced at the database, not only in the interface.
- You can ask for a copy of your data, a correction, or its deletion at any time.
This summary is for orientation only. The numbered sections below are the terms that apply.
Who we are
Brenxa is operated by Wikrena Limited, a company incorporated in Nigeria, with its registered office at 12 Achi Street, Independence Layout, Enugu, Nigeria. In this policy, “we” and “us” mean Wikrena Limited.
We are the data controller for the personal data described here. That means we decide what is collected and why, and we are accountable for it. You can reach us about anything on this page at privacy@brenxa.com.
What we collect
We collect four kinds of information, and no more than we need.
Account information
Your email address and, if you provide them, your first and last name. Authentication is handled by Supabase Auth. If you sign in with Google, we receive your email address and name from Google, and we never receive your Google password.
What you tell us during onboarding
Your role, the domains you care about, your goals, and your stated risk tolerance. This exists so recommendations are relevant to you rather than generic.
What you create in the product
The decisions you bring, the context you give, the councils you build, the journal entries you write, and the outcomes you record later. This is the substance of the product and the most sensitive thing we hold.
Technical and usage information
Standard server logs, and on the public blog an anonymous view count. The blog stores a random identifier in a first-party cookie so that one person reading one article twice in a day is counted once. That identifier is never linked to an account, and there is no way for us to connect it back to you.
When a view is recorded we also store the website you arrived from, if your browser sends one. We keep the site name only, never the full address of the page.
Alongside it we store your country and whether you are on a phone, a tablet or a desktop. The country comes from our content network, which works it out at the edge, so your IP address never reaches us and we could not store it if we wanted to. Country only, never a town or a city.
On an article we also record how far down the page you reached, in quarters, and how many seconds the tab was actually visible. This is how we tell an article that was opened from one that was read. It is tied to the same anonymous browser identifier as the view count and to nothing else, so it cannot be connected to you, and a visit shorter than a few seconds is not recorded at all.
We log what people type into the blog’s search box, so we can see what readers are looking for and write about it. Search terms are stored on their own, with no identifier attached at all, so they cannot be linked to each other, to a visit, or to you. If you subscribe to the newsletter we record which page you signed up from.
To stop the signup form being used to send unwanted email to other people, we count recent attempts from each internet address. We do not store the address itself: it is converted into an irreversible code first, and the counter is deleted within a day.
Newsletter email
If you subscribe, we record whether each issue was delivered, whether it was opened, and which links in it were followed. This is how we know whether the writing is worth continuing and whether our email is reaching inboxes at all.
Two things worth being plain about. Opens are measured by a small image loaded when the message is displayed, and many mail apps now load that image automatically, so our open figures are an over-count rather than a record of who read something. Links in our emails pass through our email provider so the click can be counted, then send you straight on to the page you asked for.
None of this is used to build a profile, and it is never combined with what you do on the site. You can stop all of it by unsubscribing, from the link at the bottom of every issue.
We do not collect special category data, we do not buy information about you from anyone, and we do not run advertising trackers.
Why we collect it, and on what basis
Under the Nigeria Data Protection Act 2023, personal data must be processed on a lawful basis. Ours are:
- Performance of a contract. Your account, the decisions you create, and the analysis we return. Without this data there is no product to deliver.
- Consent. Newsletter email, including the delivery, open and click records described above. You confirm your address by clicking a link before anything is sent, and you can withdraw at any time from the footer of any email.
- Legitimate interest. Keeping the service secure and working, preventing abuse of our forms, understanding which articles get read, and seeing what readers search for so we can write about it. In each case the processing is limited to what that purpose actually needs, which is why search terms carry no identifier, referrers keep only the site name, and abuse counters hold no readable address.
Where your data is held
Our database and file storage are hosted in the European Union. Hosting and email are delivered over global networks, so your data may be processed outside Nigeria.
Where data leaves Nigeria, we rely on the transfer provisions of the Nigeria Data Protection Act 2023 and on contractual protections with each provider.
How long we keep it
We keep your account and its contents for as long as your account is open. If you ask us to delete it, we will delete or irreversibly anonymise your personal data, except where the law requires us to keep something.
One part of the product works differently and you should know about it. Brenxa’s memory of your decisions is append-only by design. The database physically rejects attempts to edit or delete individual historical records, so the reasoning behind a past recommendation cannot be quietly rewritten. Deleting your account removes the whole record; single entries within it cannot be edited out.
Retention periods for logs and backups have not been finalised, and will be stated here before Brenxa is publicly available.
Your rights
Under the Nigeria Data Protection Act 2023 you can ask us to:
- confirm whether we hold data about you, and give you a copy;
- correct anything inaccurate;
- delete your data, subject to the limits described above;
- restrict or object to how we process it;
- provide your data in a portable form;
- withdraw consent, where consent is the basis we relied on.
Write to privacy@brenxa.com and we will respond within thirty days. If our response does not satisfy you, you can complain to the Nigeria Data Protection Commission.
Security
Access to your data is enforced at the database through row-level security, not only in application code, so a bug in the interface cannot expose one person’s decisions to another. Data is encrypted in transit and at rest by our infrastructure providers.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the Nigeria Data Protection Commission as the Act requires.
Children
Brenxa is not intended for anyone under eighteen, and we do not knowingly collect data from children. If you believe a child has given us personal data, write to privacy@brenxa.com and we will delete it.
Changes to this policy
We will update this page when what we do changes, and the date at the top will always reflect the last substantive change. Where a change materially affects your rights, we will tell you directly rather than rely on you noticing.