Privacy Policy
Last updated: August 26, 2026
BRNR turns a short story about your situationship into a playlist-style CD cover. This page explains what I collect, why, and which services help run the site.
Who I am
BRNR is a solo project I made for fun. I’m not a company — just one person shipping a small web toy. For privacy questions, email lulubattelli@gmail.com.
What I process
- Your situation text — what you type to burn a CD. I use it to score the vibe and match songs. It may be sent to an AI provider when live analysis is on.
- Technical data — IP address, basic request metadata, and a long-lived anonymous cookie (
brnr_aid) so free daily burn limits work and abuse is harder. - Optional Spotify connection — if you save a playlist, Spotify provides tokens so a playlist (and sometimes a cover) can be created. I never get your Spotify password.
- Pro / payments (when enabled) — Pro isn’t for sale yet. If I add paid plans later, this page will name the payment provider and what entitlement data I store.
- Ads (when enabled) — if advertising is turned on (e.g. Google AdSense), the ad partner may set cookies or collect device / approximate location data to serve and measure ads. I’ll update this page and, where required, ask for cookie consent before non-essential ads.
Cookies
brnr_aid— essential anonymous ID for rate limits (HttpOnly, long-lived).- Test-mode cookie — only if owner test tools are unlocked; not for normal use.
- Spotify-related storage in your browser — so a connected session can continue.
- Advertising cookies — only if/when ads are turned on and allowed.
- Cloudflare Turnstile — short-lived check after an off-topic prompt (when captcha is enabled), to limit spam.
Who gets data
I don’t sell your situationship stories. These processors help run BRNR:
- Hosting / edge — Vercel
- Rate limits / short-lived counters — Upstash Redis
- AI analysis (when not offline) — OpenAI
- Playlists — Spotify (only if you connect)
- Advertising — Google AdSense or similar (when ads are live)
Each provider has its own privacy policy. Your text and technical data are processed as needed to provide the feature you asked for.
How long data is kept
- Burn limits / anonymous IDs — on the order of days to months (cookie up to ~13 months; daily counters reset on a rolling window).
- Server logs — short operational retention, then discarded or aggregated.
- Spotify tokens — until you disconnect, they expire, or you clear site data.
There’s no public archive of your stories. Don’t paste anything you wouldn’t want processed by those providers.
Legal bases (EEA / UK)
Where GDPR applies, processing is based on:
- Contract / service delivery — burning a CD from your prompt, Spotify save when you ask.
- Legitimate interests — security, abuse prevention, keeping free burns fair.
- Consent — non-essential cookies / ads when asked for.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or restrict personal data, or to object to certain processing. Email lulubattelli@gmail.com and I may need to verify the request. You can also clear site cookies and storage in your browser anytime (that also resets the anonymous burn identity).
Children
BRNR isn’t directed at children under 16. If you think a child submitted personal data, clear site data on that device; I delete what I reasonably can when I’m made aware.
Changes
I may update this policy as the product changes (ads, Pro, new providers). The “Last updated” date at the top will change when I do.