Privacy policy
BrainLLM is software you run yourself. The project operates no service that receives your data.
Effective 4 October 2026. This policy covers the BrainLLM software, published by miisodev, and this website.
Who holds your data
Whoever runs a BrainLLM server, which is normally you. BrainLLM connects your AI client to a TriliumNext instance you choose. The project has no account system, no hosted service and no access to any server you deploy.
What the software stores
- Your notes, in your own Trilium: what you and your AI client write through BrainLLM, including session logs, diary entries and revisions. They stay there until you delete them in Trilium.
- Sign-in records, in a file on your BrainLLM server when OAuth is enabled: registered client applications, single-use authorization codes (ten minutes), and refresh tokens (up to 90 days, rotated on every use and stored only as SHA-256 hashes). Access tokens last one hour and are not stored.
- Configuration on your server: the ids of your brain's structural notes, size baselines for maintenance, and the names and dates of named backups.
- Backups on your Trilium server, made by Trilium when BrainLLM asks for one.
What it collects and shares
Nothing. BrainLLM has no analytics, telemetry or usage reporting. A BrainLLM server talks to three parties only: your AI client, your Trilium instance, and, during sign-in, the client's public OAuth metadata document (for Claude, on claude.ai). It reads only what your client asks it to read, and does not access your conversations beyond the content your client sends to its tools.
Your AI client sends tool calls and receives their results. How that client handles your conversations is set by its own provider's policy; for Claude, see Anthropic's privacy policy.
Logs
A BrainLLM server writes start-up and error messages to its own console. They contain no note content, passwords or tokens. Where those logs go is decided by whoever runs the server and their host.
This website
This site is hosted on GitHub Pages and loads its fonts from Google Fonts, so GitHub and Google receive your IP address and browser details when you visit, under their own privacy policies. The site sets no cookies and runs no analytics.
Your control
- Read, correct or delete any note in Trilium directly.
- Revoke a client by removing its connector, or every client at once by changing
BRAINLLM_OAUTH_SECRET. - Delete everything by deleting your Trilium data and your BrainLLM server's volume.
Changes and contact
Changes to this policy are published on this page and in the project's repository history. Questions: miisodev@gmail.com or a GitHub issue.