Privacy Policy
Effective 11 September 2026 · Versión en español
The short version. The Buril bridge runs on your machine. Your code, scenes, prefabs and assets never leave it unless you deliberately turn on the remote relay. Your prompts go straight from your AI client to the model provider you chose, under your own API key — they pass through nothing of ours and are stored nowhere of ours. We do not train models on your work. Not on any plan, not ever.
1. What this policy covers
This policy applies to buril.ai, the Buril account, the remote relay, and the support and billing services around them (together, the Services). It is operated by Buril (we, us). You can write to hola@buril.ai about anything in it, including a request to delete your account.
The Buril bridge package itself — the software you install into the Unity Editor — is governed by its own licence, which you accept when you install it. That licence, not this policy, decides what you may do with the software. This policy decides what we do with your data, which is very little, because most of the product never touches us.
2. What we collect
2.1 Account data
- Your email address and name, provided by the identity provider you choose (Google, GitHub or Microsoft) when you authorise it. We never receive your password for that provider; we cannot see it and there is nowhere for us to store it.
- Your plan and subscription status, so we know what to enable.
- A billing customer identifier, if you subscribe to a paid plan.
2.2 Billing data
Payments are processed by Stripe. Your card details go directly to Stripe and never pass through, or get stored on, our servers. We keep the identifier Stripe returns, your plan, and your billing period dates. Stripe is an independent processor under its own privacy policy.
2.3 Product use — and what does not reach us
This is the part that matters, and it is the reason Buril is built the way it is:
- The bridge runs locally. The connection between your AI client and your Unity Editor is a connection on your own machine. What the model reads from your project stays between your Editor and your client. We are not in that path.
- Your prompts pass through to your provider — not to us, and not stored. You bring your own API key. Your prompts, your code, and the model's answers travel directly between your AI client and Anthropic, OpenAI, Google, or whichever provider you configured. We do not see them, do not store them, and could not read them if we wanted to.
- With the remote relay enabled — optional, paid separately, available from the Indie plan — messages between your phone or ChatGPT and your Editor pass through our infrastructure in order to arrive. We relay them and delete them once delivered. We do not read them, log their content, or use them for anything else.
- Relay metadata. When the relay is on, we keep connection records (timestamps, your account, the Editor session it was paired with, bytes transferred) for up to 30 days, to operate the service and diagnose outages. Those records contain no message content.
2.4 Diagnostics
If you send us a bug report, what reaches us is what you chose to send. There is no automatic telemetry collection from your project, your Editor, or your machine.
2.5 Website analytics
buril.ai uses no third-party analytics and no advertising trackers. If we ever add privacy-preserving, cookie-less page counting, we will say so here first and it will collect nothing that identifies you.
3. What we never do
- We do not train models on your code, assets, scenes, prompts or the model's outputs — neither on our own account nor on behalf of a third party, and on no plan. This is not an Enterprise-only promise. There is no plan on which it is different.
- We do not sell or share your data with any company, at any price, under any commercial arrangement, and we have not done so.
- We cannot read your project, because we have no access to it: it lives on your machine and the bridge runs there.
- There is no advertising in the product, and no third-party trackers placed for advertising purposes.
4. Where your prompts go, and whose rules apply
Because you bring your own key, the model provider receives your prompts under your account and their terms. That relationship is between you and them. Anthropic, OpenAI and Google each publish how long they retain API inputs and whether they train on them; as of the date of this policy, all three state that API data is not used to train their models by default. We recommend you read the terms of the provider you use. We do not, and cannot, alter what they do with data sent under your key.
If you run a local model (Ollama, LM Studio), nothing leaves your machine at all.
5. Why we process what we do have
- To give you the access your plan includes.
- To bill you, if you are on a paid plan.
- To answer you when you contact support.
- To tell you about changes that affect you — a price change, a change to this policy, a relay outage, a security incident.
- To keep the Services secure and to prevent abuse.
Our legal bases under the GDPR and the UK GDPR are contract (delivering the service you signed up for), legitimate interest (keeping the service working and secure), and legal obligation (tax and accounting records). Where we would need your consent for anything else, we will ask for it separately and you can withdraw it at any time.
6. How long we keep it
| Data | Kept for |
|---|---|
| Account data | While your account exists, then up to 30 days after you delete it |
| Billing records | As long as applicable tax law requires, which can be several years |
| Relay message content | Not retained after delivery |
| Relay connection metadata | Up to 30 days |
| Support conversations | Up to 24 months, so we can follow up on a recurring issue |
7. How we protect it
- All traffic to our Services is encrypted in transit with TLS 1.2 or higher.
- Account and billing data at rest is encrypted with AES-256 or an equivalent standard.
- Internal access to production data is role-based, limited to the people who need it, and logged.
- Credentials for the bridge live in your operating system's keychain (Windows Credential Manager, macOS Keychain, libsecret), not in plain files.
If we suffer a breach that affects your data, we will notify you by email within 72 hours of confirming it, with what happened, what data was involved, what it could mean for you, and what we are doing about it. We will also notify the authorities where the law requires it.
No system is perfectly secure. Keep your identity provider account protected with two-factor authentication; it is the key to your Buril account too.
8. Third parties that touch your data
| Who | What for | What they receive |
|---|---|---|
| Google / GitHub / Microsoft | Identity (SSO) | They confirm who you are and give us your email and name |
| Stripe | Payments | Your payment details, directly, never through us |
| Microsoft Azure | Hosting | Hosts our account services and the remote relay |
| Your model provider | Inference | Your prompts, under your key and their terms — see section 4 |
We do not use any other processor. If that changes, this table changes first.
9. Where your data lives
Our account services and the remote relay are hosted on Microsoft Azure. Because Buril is built and operated from Argentina and serves developers worldwide, your account data may be processed outside the country you live in. Where the GDPR or UK GDPR applies, transfers rely on the European Commission's Standard Contractual Clauses and on the safeguards Azure provides. Your project data is not transferred anywhere by us, because it never leaves your machine.
10. Your rights
Write to hola@buril.ai to request:
- A copy of what we hold about you, in a portable format.
- Correction of anything that is wrong.
- Deletion of your account and everything attached to it.
- That we restrict or stop processing your data.
- An objection to any processing based on legitimate interest.
We answer within 30 days, and we will confirm it is you before acting on a request that could affect your account. If you are in the EU, the UK, California or another jurisdiction with a privacy statute, you have the rights that law grants you and this policy is applied consistently with it. You also have the right to complain to your local data protection authority; we would rather you wrote to us first, but that is your call.
We do not sell personal data and have not done so, so there is no sale to opt out of. We do not profile you or make automated decisions with legal effect on you.
11. Children
Buril is not directed at children under 13, or under the age at which your country requires parental consent if that is higher, and we do not knowingly collect their data. If you believe a child has given us data, write to hola@buril.ai and we will delete it.
12. When this changes
If we change something material we email you before it takes effect and update the date at the top of this page. Minor wording changes are published without notice. The previous version stays available on request.
A note on method. An earlier version of this page asserted things the code did not do. We fixed it, and this document now describes the product's verified behaviour rather than its intended behaviour. If you find a gap between what this says and what Buril does, that is our bug — write to us and we will fix it.