Privacy

What Brick stores, what it doesn't, and who else sees it.

Last updated 10 September 2026

Brick is a training planner. It holds your season because that is the product — there is nowhere else for a plan to live. It does not hold anything it doesn't need for that, and this page is specific about which is which rather than reserving the right to collect anything.

What Brick stores

Your account

Your training

Everything you'd expect a plan to be made of: your events, the frame you build, its slots and rules, your commitments and availability, the seasons, blocks, weeks and sessions those produce, the steps inside each session, your threshold zones and how they change, and the records of sessions you complete or skip.

Brick also keeps a history of every change to your plan — what changed, what it would take to undo it, and whether it came from the app, the API or an agent over MCP. That history is what makes undo work and what lets you see why a week looks the way it does.

Your sessions and tokens

What Brick does not store

Your IP address is never written to the database. It is held in memory for a few minutes to rate-limit sign-in attempts and form submissions, and it is passed to Cloudflare's bot check when you submit the waitlist form. It is not logged, not retained, and not associated with your account.

Cookies

Brick sets one cookie: the session cookie that keeps you signed in. It is strictly necessary — remove it and the app cannot know who you are — so there is no consent banner, because there is nothing to consent to. There are no analytics or advertising cookies to refuse.

Who else sees your data

Brick uses a small number of services to run, and each sees only what it needs to:

ServiceWhat it doesWhat it sees
RailwayRuns the API and the databaseEverything stored above — it is the database
VercelServes the app and this siteOrdinary web request logs
ResendSends email you asked for: verification, password reset, email changeYour email address and that message
CloudflareBot check on the waitlist form onlyYour IP address and a one-time token, at that moment
GoogleSign-in, only if you choose itThat you signed in to Brick

Your training data is not sold, not shared for advertising, and not used to train anything. Nobody buys it because it is not for sale.

Agents and MCP

Brick has an MCP server, so you can let an AI agent read and change your plan. That only ever happens with an API token you create and can revoke, it reaches only your own data, and every change it makes is recorded in your plan history marked as having come from an agent — so you can always tell what you did from what something else did on your behalf.

What you can do

If you are in the UK or EU, these cover your rights of access, portability, rectification and erasure, and you do not need to ask anyone to exercise them. Brick is the data controller for the data described here.

How long it is kept

Your training data stays until you delete it or your account. Login sessions expire on their own. Email verification and password-reset links expire shortly after they are sent. Deleting your account removes your data from the live database immediately; encrypted backups roll off on their own schedule within 30 days.

Changes to this page

If what Brick stores changes, this page changes with it, and the date at the top moves. If a change is significant — a new category of data, or a new service seeing it — you will be told by email rather than left to notice.

Contact

Questions about any of this: privacy@trybrick.io.