Effective date: 2026-07-17
Document version (docVersion): 2026-07-17
Operator and privacy contact: BrainStack Ventures, a sole proprietorship based in Colorado, United States; support@myroofgenius.com
This Privacy Policy explains how BrainStack Ventures (“we,” “us,” or “our”) collects, uses, discloses, and retains personal information when operating MyRoofGenius. BrainStack Ventures is currently a sole proprietorship, not an LLC or corporation.
This Policy applies to myroofgenius.com and MyRoofGenius websites, applications, accounts, trials, subscriptions, tools, analyses, reports, APIs, support, and communications that link to it.
For account, billing, site, product, security, analytics, and direct-support information described here, BrainStack Ventures determines why and how the information is processed. For Customer Content that a business customer submits about its own customers, properties, employees, subcontractors, or other people solely so we can provide the Service, the business customer generally determines the business purpose and is responsible for its notices, permissions, and instructions. Depending on applicable law and context, BrainStack Ventures may act as a service provider or processor for that Customer Content.
This Policy is not a certification of compliance with the GDPR, CCPA/CPRA, Colorado Privacy Act, or any other law. The jurisdiction-specific section below applies only if and to the extent a law applies to a particular person and processing activity.
We collect the following categories from you, your browser or device, service providers, authorized integrations, and the operation of the Service.
Account, trial, and checkout flows may collect whether you accepted the Terms and Privacy Policy; each document’s docVersion and content hash; the action associated with acceptance; time; account, user, or email identifier; request ID; IP address; and user-agent information.
Optional MRG marketing choice is separate. Current signup code can capture whether you opted in, the marketing-disclosure version and hash, the action, time, account or email identifier, request ID, IP address, and user agent. A legal acceptance is not marketing consent.
Depending on the feature you use, this may include:
Customer Content can contain personal information about people other than the account holder. The customer is responsible for having authority to provide it.
Stripe handles full payment-card details. We receive and store limited billing information needed to operate subscriptions, such as billing email, plan, price and interval, trial and subscription status, payment status, timestamps, invoice or receipt metadata, and Stripe customer, checkout, subscription, payment, or charge identifiers. Analytics copies of Stripe identifiers may be masked, but operational billing systems retain identifiers needed to reconcile transactions.
We collect information you submit in contact, support, refund, feedback, waitlist, newsletter-interest, or security forms and emails, including contact details, message content, attachments, routing information, and troubleshooting context.
We use account email for necessary account, security, trial, billing, support, and service messages. We use email for MRG product marketing when you make a separate affirmative choice or otherwise request those communications. You can unsubscribe from marketing without losing necessary service messages.
This may include IP address, user agent, browser and device characteristics, approximate region inferred from network information, request and correlation IDs, timestamps, route and API activity, response status, rate-limit events, authentication events, error and performance information, webhook events, security alerts, and audit logs.
MRG currently uses an opaque first-party analytics identifier named mrg_analytics_session_id, with related browser session storage under mrg.analytics.session_id. It is designed not to contain a name, email address, payment information, or street address. Product and funnel event emitters may create it, place it in session storage and a session cookie, and send it with event name, page path or sanitized URL, time, event properties, and, when authenticated, user or tenant attribution.
Event payloads are filtered to redact common email, phone, address-key, and payment-identifier patterns, but no filter is infallible. Do not place personal information in URLs or fields not intended for it.
If Google Analytics is configured and you select “Accept” in the MRG cookie notice, Google may receive online identifiers, page paths, and event information under Google’s terms. Current code suppresses Google Analytics unless the locally stored choice is accepted and also suppresses it on certain paths such as pricing and subscribe.
We obtain information:
If we obtain business-contact information from another source for a permitted business communication, we may also retain source and suppression information. You may opt out of marketing at any time.
We use information to:
Where a law requires a legal basis, the basis depends on context: performance of a contract or steps you request before a contract; compliance with legal obligations; consent for optional Google Analytics or marketing; and legitimate interests such as security, fraud prevention, support, first-party operational measurement, and service improvement where those interests are not overridden and the law permits that basis. Where consent is legally required, we do not rely on legitimate interests as a substitute.
Requested AI features may send relevant text, images, documents, property information, prompts, and contextual data to Google/Gemini, OpenAI, Anthropic, or a Render-hosted agent or backend service that routes to those providers. Provider selection may depend on the feature, configuration, availability, cost controls, and fallback behavior.
We use provider APIs to produce requested outputs. We do not intentionally direct providers to use private Customer Content to train a public model. However, provider-specific storage, abuse monitoring, human review, and model-training treatment depend on the applicable provider offering, account configuration, contract, and current provider terms. This Policy does not promise zero provider retention or no provider use beyond what the applicable configuration and contract actually provide.
Do not submit specially regulated or highly confidential information to an AI feature unless you have verified that the feature and provider terms are suitable and you are authorized to do so.
We disclose information only as reasonably needed for the purposes above, including to:
Providers may process request metadata and content in locations they operate.
We do not sell personal information for money and do not operate as a data broker. We do not currently use MyRoofGenius personal information to deliver third-party targeted advertisements within the Service.
Optional Google Analytics may receive online identifiers and activity after an accepted choice. Some privacy laws define certain analytics disclosures as “sharing” even when no money changes hands. If that definition applies, you may prevent future optional Google Analytics collection by declining the MRG analytics choice or clearing the accepted choice as described below. First-party operational and funnel records are separate and are not sold.
We may retain an email or identifier on a suppression list after an opt-out so we do not send unwanted marketing again.
Authentication, security, checkout, load-balancing, and preference storage may be necessary for account and payment flows. Supabase and Stripe may use their own cookies or storage when their services are invoked.
When the MRG cookie notice is shown, selecting Accept or Decline stores cookieConsent in local storage and a same-named cookie for up to one year. Closing the notice is treated as Decline in the current interface.
The notice is not currently displayed on every route. It is intentionally suppressed on the home page and many conversion, product, tool, authentication, checkout, support, and signed-in application routes. Its absence does not mean that no essential storage or first-party operational/funnel event is created.
The current Accept/Decline choice controls optional Google Analytics. If no accepted choice exists, Google Analytics does not load through the MRG Google Analytics component.
The current choice does not suppress the first-party mrg_analytics_session_id or first-party product, operational, attribution, conversion, and funnel events described above. The identifier is generally stored for the browser session; corresponding server-side events are retained under the criteria in Section 10.
You can decline when the notice is displayed. To withdraw an existing accepted Google Analytics choice, clear the cookieConsent cookie and local-storage item in your browser’s site-data settings, then choose Decline when the notice is next available. Browser controls can also block or delete cookies, though this may impair account or checkout functions.
The current MRG code does not separately interpret a Global Privacy Control signal. This Policy therefore does not claim automatic GPC handling. Optional Google Analytics remains off unless an accepted local choice exists, but a previously stored accepted choice is not automatically replaced by GPC under the current implementation. Use the withdrawal method above or email a rights request if needed.
Current controls include HTTPS/TLS in transit, provider-managed encryption at rest, authentication and authorization for protected routes, row- and tenant-scoped access patterns, signed Stripe webhook verification, idempotency controls, rate limiting, input and payload limits, and security and operational logging.
These measures reduce risk but do not make the Service perfectly secure. No transmission, account, provider, AI system, or storage system is guaranteed against loss, misuse, or unauthorized access. Use unique credentials, protect your devices, restrict authorized users, avoid submitting unnecessary personal information, and notify us promptly of suspected compromise.
We use the following current periods or criteria:
| Information | Current retention period or criterion |
|---|---|
| Original uploaded analysis images | Up to 30 days after processing, unless needed longer for a requested support matter, security investigation, dispute, legal hold, or legal obligation. |
| Generated reports, PDFs, and saved report artifacts | While the account is active until deleted by the user where a deletion control exists, plus up to 30 days after cancellation for export access. |
| Account, tenant, role, project, and workspace records | While needed to provide the account and until a verified deletion request is completed, subject to exceptions below. |
| Legal-assent records | For as long as reasonably needed to establish the agreement, administer the account or subscription, and establish, exercise, or defend legal claims. |
| Billing, invoice, subscription, refund, fraud, and tax records | For the applicable accounting, tax, payment-network, anti-fraud, chargeback, and legal periods. Stripe may retain its own records under its terms. |
| Consent, unsubscribe, and suppression records | While the choice is active and as long as reasonably needed to prove or honor the choice; suppression records may remain after other marketing data is deleted. |
| First-party analytics and operational events | While reasonably needed for product, reliability, revenue, security, audit, and dispute purposes. We may aggregate or de-identify events for longer-term measurement. Current code does not provide a separate browser control that deletes prior server events. |
| cookieConsent choice | Up to one year in the browser unless cleared sooner. |
| mrg_analytics_session_id browser value | Generally the browser session unless cleared sooner; a server event carrying the identifier follows the event-retention criterion above. |
| Support, lead, refund, feedback, and security communications | While needed to resolve and document the request, maintain the business relationship, prevent abuse, and meet legal or dispute needs. |
| Provider logs, backups, and AI-provider copies | Under provider settings, backup cycles, incident needs, and provider contracts or terms. Deletion from an active database may not immediately remove a rotating backup. |
We may retain a limited record after a deletion request when necessary for security, fraud prevention, tax, accounting, payment disputes, legal claims, consent evidence, suppression, or another legal obligation. We will not use retained exception data for unrelated marketing.
You can:
We may ask you to verify the request through the account, billing email, or other information reasonably necessary to protect the data. An authorized agent may submit a request where applicable, but we may verify both authority and identity. We may deny or limit a request when we cannot verify it, when an exception applies, when disclosure would expose another person’s data or a trade secret, or when the request is abusive or legally exempt. We will explain a denial where required.
Do not send passwords, full card data, API keys, or unrelated identity documents by ordinary email. We will provide a safer method if additional verification is needed.
This section applies only when the identified law applies to BrainStack Ventures, the person, and the processing. Including it does not state that a statutory threshold has been met, that every visitor is covered, or that BrainStack Ventures is certified under that law.
Where applicable, a resident may have rights to confirm processing; access; correct; delete; obtain a portable copy; opt out of sale, targeted advertising, or certain profiling; limit certain sensitive-data uses; appeal a denied request; and receive non-discriminatory treatment. We do not sell personal information for money or currently use it for third-party targeted advertising. Optional Google Analytics disclosures are described in Section 7.
To exercise a right or appeal a decision, email the address in Section 17 with “Privacy Request” or “Privacy Appeal.” We will respond within the period required by the applicable law.
The Colorado Privacy Act generally excludes a Colorado resident acting in a commercial or employment context and applies only when its statutory thresholds and other conditions are met. The California CCPA/CPRA likewise applies only when its statutory definition of a covered business and other conditions are met.
If a law such as the GDPR applies, depending on the processing you may have rights of access, correction, erasure, restriction, objection, portability, consent withdrawal, and complaint to a competent supervisory authority. The purpose and conditional legal bases are described in Section 4.
Data is operated principally from the United States and may be transferred to the United States and other provider locations. Privacy protections may differ. Where an applicable law requires a transfer safeguard, representative, or other mechanism, we will evaluate and use the mechanism required for that processing before relying on it. This is not a representation that a particular transfer certification, standard contractual clause, EEA/UK representative, or data-protection officer is currently in place. Contact us for current transfer or provider information before submitting regulated data.
MyRoofGenius uses AI and rules to generate roofing and business outputs, detect abuse, apply usage limits, route support, and measure events. The Service is designed to require the customer’s human review of roof, business, and customer-facing outputs. BrainStack Ventures does not use a MyRoofGenius roof-analysis output as the sole basis for its own decision that produces a legal or similarly significant effect about an individual.
Do not use the Service as the sole basis for a high-impact decision about a person.
The Service is for adults and business users. We do not knowingly collect personal information directly from a child under 13, and account users must be at least 18. If you believe a child submitted information, contact us so we can investigate and delete it where appropriate. Customers must not upload children’s data unless legally authorized and the Service is appropriate for that use.
The Service may link to or integrate with third-party sites. Their privacy practices are governed by their policies, not this one.
Business customers are responsible for their own privacy notices, rights-request handling, data minimization, retention, and permissions for Customer Content. If a customer receives a request concerning data it placed in MyRoofGenius, it should contact us if it needs reasonable assistance locating or deleting that data.
We may update this Policy to reflect product, provider, legal, or operational changes. Each material replacement will receive a new docVersion and effective date, and the visible text should be bound to a content hash in the legal-document system.
When an account, trial, or checkout flow requires current Privacy Policy assent, a stale docVersion or hash may require you to review and accept the current version. If a change materially affects a consent-based use, we will seek a new choice where required. MRG legal assent and optional marketing consent are separately versioned; the current MRG Google Analytics cookie choice itself is not tied to privacyVersion.
MyRoofGenius is operated by BrainStack Ventures, a sole proprietorship based in Colorado, United States.
Privacy, access, correction, deletion, portability, consent, appeal, and security requests:
Shared BrainStack Ventures support inbox for MyRoofGenius
Suggested subject: “MyRoofGenius Privacy Request,” “MyRoofGenius Privacy Appeal,” or “MyRoofGenius Security Disclosure”
Do not include passwords, payment-card data, API keys, or other secrets in email.