Brainyap Demo Privacy Policy
Last updated: 29/07/2026
Who operates this website?
Brainyap is a demonstration website operated by Shanes Computing and Networking ABN 33554806557. Privacy questions can be sent to info@shanescomputing.com.au.
About this demo
Brainyap v1.73 is a public demonstration undergoing functionality and security testing. Public users receive pseudonymous Asteroid accounts. Please do not enter your real name, email address, confidential information, or sensitive personal information into the demo.
Information we collect
When you create or use an Asteroid account, we store its allocated username, securely hashed password, creation and login information, demo activity, settings, and authentication records. Passwords are not stored in readable form.
We process your IP address to enforce the limit of five Asteroid accounts per internet connection per Australian calendar day, detect abuse, and investigate security incidents. The daily counter uses a protected derived identifier rather than the raw IP address. Raw IP addresses may still appear temporarily in server and security logs.
We use necessary cookies to keep you signed in, protect sessions, and prevent forged requests. We may also record request times, requested pages, browser information, response status, login failures, account-creation attempts, security alerts, and application errors.
When users upload profile photos, album photos, or classified listing photos, Brainyap validates the image and saves a new display copy. This process removes embedded photo metadata such as EXIF, GPS location, camera details, and original timestamp data before the photo is stored. Brainyap still stores the visible image, generated file path, and any caption or profile details the user chooses to add. Users should avoid uploading images that visibly show private information.
End-to-end encrypted private messaging
Brainyap private messages use end-to-end encryption. Message content is encrypted on the sender's device and can be decrypted only by eligible recipient devices included when the message is sent.
Brainyap's server stores and transmits encrypted message content and encrypted device-key envelopes. The website operator cannot read the plaintext contents of end-to-end encrypted private messages.
Brainyap still processes limited metadata required to operate and secure private messaging. This may include participating account and Device IDs, message times, delivery and security events, device approvals, and encrypted message records. This metadata does not provide the website operator with plaintext message content.
End-to-end encryption cannot protect a message after an authorised participant views, copies, screenshots, records, or shares it, or if a participating device is compromised.
Secret-word verification
Brainyap's secret-word feature gives private-chat participants an additional way to confirm that they are communicating with the expected person rather than an impostor, scammer, chatbot, or unauthorised device user.
Participants should agree on a memorable secret word through trusted communication or shared real-world knowledge. Secret-word content is end-to-end encrypted, and the website operator cannot read the plaintext secret word.
A matching secret word records a successful verification for the participating devices. A mismatch creates a security warning so participants can stop and investigate before sharing sensitive information.
Secret words do not replace account passwords, encryption keys, device approval, or normal security precautions. Users must not reuse account passwords, banking passwords, recovery phrases, or other sensitive credentials as secret words.
Secret-word trust is tied to participating devices and browser profiles. It does not automatically transfer to a new Device ID. After changing devices, browsers, or browser profiles, participants must establish and verify a new secret word on their current devices.
Device IDs and device security
Brainyap assigns a Device ID to each browser/device installation that uses private chat. Device IDs allow Brainyap and private-chat participants to distinguish approved devices from newly connected, logged-out, blocked, or revoked devices.
A Device ID is a server record for a browser's private-chat public key, device status, and trust review. The browser-held private key is what decrypts private messages. Brainyap does not receive the browser-held private key.
Brainyap processes limited browser and device information needed to create and manage Device IDs, maintain encryption-key delivery records, deliver encrypted messages to eligible devices, display active devices, display device history, check whether a Device ID is still active, and warn users about unexpected account access.
A Device ID is a security identifier for a browser/device installation. It is not intended to identify a user's real-world identity. Brainyap displays privacy-preserving Device IDs instead of showing another user's browser name, operating system, or detailed device information.
When a new Device ID appears, Brainyap notifies the account owner and private-chat participants. Users can review the device, approve it when recognised, or block it when unexpected.
Brainyap checks Device ID activity when a user logs in, when private chat loads, when a user selects Recheck, and during normal private-chat use. If a Device ID is no longer active, Brainyap marks it as logged out and moves it out of the active device list.
If a user clears browser cache, site data, or private-chat storage, that browser can lose its private-chat encryption key and Device ID record. When the user signs in again from that browser, Brainyap creates or connects a new Device ID. Older Device IDs are not automatically deleted just because a new Device ID appears; they are marked logged out when Brainyap determines they are no longer active.
When a user logs out and chooses to forget the current device, Brainyap deletes that Device ID from the server, removes the server-side browser/device information stored for that Device ID, removes that Device ID from active device lists and device history, removes trust and approval records for that Device ID, and resolves live security alerts linked to that Device ID. The browser also removes its local private-chat device storage where supported by the browser.
Users can delete previous Device IDs from Device ID history. When a user deletes a previous Device ID, Brainyap deletes that Device ID from the server, removes the server-side browser/device information and metadata stored for that Device ID, removes that Device ID from active device lists and device history, removes trust and approval records for that Device ID, and resolves live security alerts linked to that Device ID.
Forgetting or deleting a Device ID does not delete old private conversations. Users can clear private conversations separately with the clear private conversation button. Old encrypted messages remain subject to Brainyap's private-message retention settings. If the forgotten or deleted device was the only device that could open those old messages, those messages can no longer be decrypted on that device.
If a person has no encrypted-chat browser set up, Brainyap cannot encrypt private messages to that person. In that situation, Brainyap tells the sender that the person needs to log in with an encrypted-chat browser before private messages can be sent.
Private messages are encrypted separately for the eligible Device IDs active when each message is sent. A new Device ID cannot decrypt private messages sent before that Device ID existed because it was not provided with the required encrypted message key.
Brainyap retains Device IDs, public encryption keys, approval status, connection status, relevant network-binding information, and device security-event history while they are needed to operate end-to-end encryption and protect accounts. When the account owner forgets or deletes a device, Brainyap deletes the Device ID and its server-side browser/device information as described above.
Private encryption keys remain within the user's browser/device storage and are not provided to the website operator.
Why we collect information
We use collected information to provide demo accounts, authenticate users, enforce account limits, operate and troubleshoot the website, provide encrypted private messaging, manage device security, detect attempted attacks, investigate incidents, and improve application security.
We do not sell Asteroid account information or use it for direct marketing.
Uploads and account recovery
Public Asteroid accounts cannot upload pictures. Asteroid accounts do not currently provide email registration or password recovery.
How we protect information
We use HTTPS, password hashing, end-to-end encryption for private messaging and secret words, protected session cookies, restricted database access, access controls, security monitoring, software updates, and security testing.
No internet-connected system can be guaranteed completely secure.
Who may access information?
Information may be accessed by the website operator, authorised administrators, service providers needed to operate and secure the website, or authorities where disclosure is legally required.
The website operator and administrators cannot read the plaintext contents of end-to-end encrypted private messages or secret words.
How long we keep information
Asteroid accounts and their demo activity are retained for the life of this demo unless removed administratively.
Encrypted private-message records, Device IDs, device approvals, and security-event history may be retained according to Brainyap's operational, security, and message-retention settings.
Access, correction, deletion, and complaints
To ask about information associated with your account, request a correction or deletion, or make a privacy complaint, contact info@shanescomputing.com.au.
Changes to this policy
We may update this policy when the demo or its information-handling practices change. The current version and last-updated date will remain available from the login page.