Brainyap Demo Privacy Policy
Last updated: 27/08/2026
Who operates this website?
Brainyap is a demonstration website operated by Shanes Computing and Networking ABN 33554806557. Privacy questions can be sent to info@shanescomputing.com.au.
About this demo
Brainyap v1.88 is a public demonstration undergoing functionality and security testing. Public users receive pseudonymous Asteroid accounts. Please do not enter your real name, email address, confidential information, or sensitive personal information into the demo.
Information we collect
When you create or use an Asteroid account, we store its allocated username, securely hashed password, creation and login information, demo activity, settings, and authentication records. Passwords are not stored in readable form.
We process your IP address to enforce the limit of five Asteroid accounts per internet connection per Australian calendar day, detect abuse, and investigate security incidents. For the daily Asteroid counter, Brainyap uses HMAC-SHA256 hashing to save a protected code made from the IP address instead of saving the readable IP address in the counter. Raw IP addresses may still appear temporarily in server and security logs.
We use necessary cookies to keep you signed in, protect sessions, and prevent forged requests. We may also record request times, requested pages, browser information, response status, login failures, account-creation attempts, security alerts, and application errors.
When users upload profile photos, album photos, or classified listing photos, Brainyap validates the image and saves a new display copy. This process removes embedded photo metadata such as EXIF, GPS location, camera details, and original timestamp data before the photo is stored. Brainyap still stores the visible image, generated file path, and any caption or profile details the user chooses to add. Users should avoid uploading images that visibly show private information.
Soapbox proposal voting
Brainyap records that you have voted to prevent duplicate voting. The selected option updates the combined results but is not stored against your account. Results update after every confirmed vote.
Vote preferences are not intentionally included in application or Splunk logs.
Soapbox proposal votes are final. Before submitting, Brainyap asks you to confirm that the vote cannot be changed or cancelled after it is counted.
End-to-end encrypted private messaging
Brainyap private messages use end-to-end encryption. Message content is encrypted on the sender's device and can be decrypted only by eligible recipient devices included when the message is sent.
Brainyap's server stores and transmits encrypted message content and encrypted device-key envelopes. The website operator cannot read the plaintext contents of end-to-end encrypted private messages.
Brainyap still processes limited metadata required to operate and secure private messaging. This may include participating account and Device IDs, message times, delivery and security events, device approvals, and encrypted message records. This metadata does not provide the website operator with plaintext message content.
End-to-end encryption cannot protect a message after an authorised participant views, copies, screenshots, records, or shares it, or if a participating device is compromised.
Secret-word verification
Brainyap's secret-word feature gives private-chat participants an additional way to confirm that they are communicating with the expected person rather than an impostor, scammer, chatbot, or unauthorised device user.
Participants should agree on a memorable secret word through trusted communication or shared real-world knowledge. Secret words are encrypted at rest on Brainyap's server with a separate server-side key. They are not end-to-end encrypted. Brainyap can decrypt a secret word only when the feature needs to show it to the intended participant or check a typed confirmation.
A matching secret word records a successful verification for the participating devices. A mismatch creates a security warning so participants can stop and investigate before sharing sensitive information.
Secret words do not replace account passwords, encryption keys, device approval, or normal security precautions. Users must not reuse account passwords, banking passwords, recovery phrases, or other sensitive credentials as secret words.
Secret-word trust is tied to the private-chat relationship between the participating accounts and their current device trust state. After a device warning, participants can use the saved secret word to confirm they are speaking with the expected person.
Device IDs and device security
Brainyap assigns a Device ID to each browser/device installation that uses private chat. A Device ID is a server record for that browser's public chat key, connection status, approval status, and device-security history. The private key that opens encrypted private messages stays in the user's browser/device storage and is not provided to Brainyap.
Device IDs help users spot unexpected access and possible impersonation. If a new browser/key appears for an account, Brainyap can show a warning so the account owner and private-chat participants can review the device, approve it when recognised, or block it when unexpected.
Brainyap displays privacy-preserving Device ID codes instead of detailed browser or operating-system labels. Brainyap also checks whether Device IDs are active, logged out, blocked, or eligible to receive encrypted private-message keys.
Forgetting or deleting a Device ID removes that server-side device record, related approval records, and live alerts for that device. It does not delete old private conversations. If that browser was the only place with the private key for older encrypted messages, those messages cannot be opened from that browser after the device storage is removed.
Why we collect information
We use collected information to provide demo accounts, authenticate users, enforce account limits, operate and troubleshoot the website, provide encrypted private messaging, manage device security, detect attempted attacks, investigate incidents, and improve application security.
We do not sell Asteroid account information or use it for direct marketing.
Uploads and account recovery
Public Asteroid accounts cannot upload pictures. Asteroid accounts do not currently provide email registration or password recovery.
How we protect information
We use HTTPS, password hashing, end-to-end encryption for private messages, server-side encryption at rest for secret words, protected session cookies, restricted database access, access controls, security monitoring, software updates, and security testing.
No internet-connected system can be guaranteed completely secure.
Who may access information?
Information may be accessed by the website operator, authorised administrators, service providers needed to operate and secure the website, or authorities where disclosure is legally required.
The website operator and administrators cannot read the plaintext contents of end-to-end encrypted private messages. Secret words are protected with server-side encryption at rest and can be decrypted by Brainyap when the secret-word feature needs to display or verify them.
How long we keep information
Asteroid accounts and their demo activity are retained for the life of this demo unless removed administratively.
Encrypted private-message records, Device IDs, device approvals, and security-event history may be retained according to Brainyap's operational, security, and message-retention settings.
Access, correction, deletion, and complaints
To ask about information associated with your account, request a correction or deletion, or make a privacy complaint, contact info@shanescomputing.com.au.
Changes to this policy
We may update this policy when the demo or its information-handling practices change. The current version and last-updated date will remain available from the login page.