Legal
Privacy policy
Last updated: 28 July 2026
This policy explains what Brevard Creek Labs collects when you use brevardcreek.com and the platform behind it, why we collect it, and what you can ask us to do with it. It is written to be read.
Who we are
Brevard Creek Labs is the controller of the personal data described here. You can reach us at the contact form.
What we collect
If you only visit the website
Our web server keeps a standard access log: the requesting IP address, the time, the page requested, the response status, the referring page and the browser's user-agent string. We use it to keep the site running and to see abuse. There are no analytics scripts, no advertising tags, no third-party trackers and no cookies on the public pages of this site.
If you have an account
- Your email address and display name, because an account needs both.
- A password, stored only as a PBKDF2 hash. We cannot read it.
- The content you create: messages, documents, files, notes and boards.
- Records of when you signed in, and from which IP address.
- Call records — who called whom, when, and for how long. Not the audio or video, which never passes through our servers when a direct connection between the two browsers is possible.
Cookies
We set one cookie, and only after you sign in: a session cookie that keeps you signed in. It is HTTP-only, Secure, and scoped to brevardcreek.com. It is strictly necessary for the service to function, so no consent banner is shown for it. We do not use cookies for analytics or advertising.
Why we are allowed to hold it
For account data and content: to perform the contract we have with you. For access logs and security records: our legitimate interest in keeping the service available and unabused. Where a legal obligation requires us to keep something, that obligation.
Who else sees it
We do not sell personal data and we do not share it for advertising. It is disclosed only to the providers that run the service beneath us, to anyone you deliberately share it with inside the platform, and where the law compels us.
Those providers are DigitalOcean, who host the servers, and Brevo, who carry outbound email. Everything else — the application, the databases, the file storage and the servers that set up calls — we run ourselves.
Where it is held, and for how long
Data is held on servers in the United States. Account data and content are kept for as long as the account exists; when an account is deleted, its content goes with it. We keep the fourteen most recent daily backups, after which the oldest is overwritten.
What you can ask for
You can ask us for a copy of your personal data, ask us to correct it, ask us to delete it, or object to how we are using it. Write to the contact form and we will respond within 30 days. Depending on where you live you may also have the right to complain to a data protection authority.
Security
Traffic is encrypted in transit. Passwords are hashed, never stored in a form we can read. Access to production systems is limited to the people who operate them. No system is perfect; if you find a problem, please tell us through the contact form and we will treat it seriously.
Children
The platform is a business product and is not directed at children under 16. We do not knowingly collect their data.
Changes
If this policy changes materially we will say so on this page and update the date at the top. Continuing to use the service after a change means the updated policy applies.