Brilliani Labs
Security & Privacy FAQ
Last updated July 2026
How we keep your account, your payments and your data safe, in plain language. For the full legal detail, see our Privacy Policy.
We don't store your passwords
We use Google Sign-In for authentication, so we never see, store or handle your password. When you log in you authenticate directly with Google, the same security that protects Gmail, Google Drive and billions of accounts worldwide. If our site were ever compromised, there are no passwords to steal, because we don't have them.
We don't handle your card details
All payments are processed by Stripe, one of the world's most trusted payment platforms. Your card details go straight to Stripe's secure servers. We never see or store them. Stripe is certified to PCI DSS Level 1, the highest security standard in the payments industry.
Your connection is encrypted
Every page on Brilliani Labs is served over modern TLS encryption (versions 1.2 and 1.3); older, weaker protocols are refused. Look for the padlock in your browser's address bar. It means everything you send to us, and everything we send back, is scrambled so no one can read it in transit. Connections are additionally protected by HSTS, so browsers will only ever reach us over a secure connection.
We run on Cloudflare
Our entire platform is built on Cloudflare's global edge network, which gives us:
- DDoS protection against traffic floods
- A Web Application Firewall (WAF) that filters malicious requests
- Automatic threat detection and bot filtering
- A strict Content Security Policy and modern security headers on every response
What we collect
When you're signed in, we log which tools you use and when. This helps us:
- Keep the platform secure (detecting unusual activity)
- Improve the tools (understanding which features matter most)
- Manage your subscription (billing status, via Stripe)
We do not:
- Sell your data
- Track you across other websites
- Use your data for advertising
- Share your information with third parties beyond our essential processors (Google, Stripe, Cloudflare)
How to delete your account
Email [email protected] and we'll delete your account and all associated activity logs within 30 days. Subscription and tax records are retained for 7 years, as required by Dutch law.
Found a security issue?
We welcome responsible disclosure. Contact us at [email protected], or review our security.txt. We respond to every report, and we won't take legal action against researchers who act in good faith.
Please report privately, avoid accessing or modifying other people's data, and allow us reasonable time to remediate before any public disclosure. Thank you for helping keep our members safe.