Back

Privacy Policy

Effective 11 September 2026 · Versión en español

The short version. The Buril bridge runs on your machine. Your code, scenes, prefabs and assets never leave it unless you deliberately turn on the remote relay. Your prompts go straight from your AI client to the model provider you chose, under your own API key — they pass through nothing of ours and are stored nowhere of ours. We do not train models on your work. Not on any plan, not ever.

1. What this policy covers

This policy applies to buril.ai, the Buril account, the remote relay, and the support and billing services around them (together, the Services). It is operated by Buril (we, us). You can write to hola@buril.ai about anything in it, including a request to delete your account.

The Buril bridge package itself — the software you install into the Unity Editor — is governed by its own licence, which you accept when you install it. That licence, not this policy, decides what you may do with the software. This policy decides what we do with your data, which is very little, because most of the product never touches us.

2. What we collect

2.1 Account data

2.2 Billing data

Payments are processed by Stripe. Your card details go directly to Stripe and never pass through, or get stored on, our servers. We keep the identifier Stripe returns, your plan, and your billing period dates. Stripe is an independent processor under its own privacy policy.

2.3 Product use — and what does not reach us

This is the part that matters, and it is the reason Buril is built the way it is:

2.4 Diagnostics

If you send us a bug report, what reaches us is what you chose to send. There is no automatic telemetry collection from your project, your Editor, or your machine.

2.5 Website analytics

buril.ai uses no third-party analytics and no advertising trackers. If we ever add privacy-preserving, cookie-less page counting, we will say so here first and it will collect nothing that identifies you.

3. What we never do

4. Where your prompts go, and whose rules apply

Because you bring your own key, the model provider receives your prompts under your account and their terms. That relationship is between you and them. Anthropic, OpenAI and Google each publish how long they retain API inputs and whether they train on them; as of the date of this policy, all three state that API data is not used to train their models by default. We recommend you read the terms of the provider you use. We do not, and cannot, alter what they do with data sent under your key.

If you run a local model (Ollama, LM Studio), nothing leaves your machine at all.

5. Why we process what we do have

Our legal bases under the GDPR and the UK GDPR are contract (delivering the service you signed up for), legitimate interest (keeping the service working and secure), and legal obligation (tax and accounting records). Where we would need your consent for anything else, we will ask for it separately and you can withdraw it at any time.

6. How long we keep it

DataKept for
Account dataWhile your account exists, then up to 30 days after you delete it
Billing recordsAs long as applicable tax law requires, which can be several years
Relay message contentNot retained after delivery
Relay connection metadataUp to 30 days
Support conversationsUp to 24 months, so we can follow up on a recurring issue

7. How we protect it

If we suffer a breach that affects your data, we will notify you by email within 72 hours of confirming it, with what happened, what data was involved, what it could mean for you, and what we are doing about it. We will also notify the authorities where the law requires it.

No system is perfectly secure. Keep your identity provider account protected with two-factor authentication; it is the key to your Buril account too.

8. Third parties that touch your data

WhoWhat forWhat they receive
Google / GitHub / MicrosoftIdentity (SSO)They confirm who you are and give us your email and name
StripePaymentsYour payment details, directly, never through us
Microsoft AzureHostingHosts our account services and the remote relay
Your model providerInferenceYour prompts, under your key and their terms — see section 4

We do not use any other processor. If that changes, this table changes first.

9. Where your data lives

Our account services and the remote relay are hosted on Microsoft Azure. Because Buril is built and operated from Argentina and serves developers worldwide, your account data may be processed outside the country you live in. Where the GDPR or UK GDPR applies, transfers rely on the European Commission's Standard Contractual Clauses and on the safeguards Azure provides. Your project data is not transferred anywhere by us, because it never leaves your machine.

10. Your rights

Write to hola@buril.ai to request:

We answer within 30 days, and we will confirm it is you before acting on a request that could affect your account. If you are in the EU, the UK, California or another jurisdiction with a privacy statute, you have the rights that law grants you and this policy is applied consistently with it. You also have the right to complain to your local data protection authority; we would rather you wrote to us first, but that is your call.

We do not sell personal data and have not done so, so there is no sale to opt out of. We do not profile you or make automated decisions with legal effect on you.

11. Children

Buril is not directed at children under 13, or under the age at which your country requires parental consent if that is higher, and we do not knowingly collect their data. If you believe a child has given us data, write to hola@buril.ai and we will delete it.

12. When this changes

If we change something material we email you before it takes effect and update the date at the top of this page. Minor wording changes are published without notice. The previous version stays available on request.

A note on method. An earlier version of this page asserted things the code did not do. We fixed it, and this document now describes the product's verified behaviour rather than its intended behaviour. If you find a gap between what this says and what Buril does, that is our bug — write to us and we will fix it.