Home/Privacy Policy

Privacy Policy

Effective Date: April 28, 2026  ·  Last Updated: April 28, 2026

Brightcone.ai (“Company,” “we,” “us,” or “our”) is committed to protecting your privacy and providing a secure online experience. This Privacy Policy describes how we collect, use, disclose, and protect personal information in connection with your use of https://www.brightcone.ai and the Brightcone Platform, the Brightcone Product Suite (including Bright Bot, Bright Insights, Bright Connect, Bright Predict, Bright Schedule, and Bright Notes), and all related features, pages, applications, and infrastructure operated by the Company (collectively, the “Service”).

By accessing or using the Service, you accept and agree to this Privacy Policy. Do not use the Service if you do not agree to this Privacy Policy.

This Privacy Policy is incorporated by reference into our Terms of Use. To the extent you have entered into any other agreements with the Company relating to the Service or any of the Company’s products or offerings that contain specific privacy or data handling policies, those specific policies will take precedence over any conflicting provisions in this Privacy Policy.

1. Scope

This Privacy Policy applies to all information collected through the Service, including through the Website and any related web or mobile applications; in email, text, or other electronic communications between you and us; through connected third-party integrations you authorize; and when you interact with our advertising or applications on third-party platforms that link to this Privacy Policy.

This Privacy Policy does not apply to information collected offline or through means not described above, or to third-party websites, services, or applications that may be linked from the Service.

2. Definitions

“User”
means any individual who creates an account or otherwise accesses or uses the Service.
“User Content”
means any documents, files, data, prompts, queries, voice inputs, or other information uploaded, submitted, or generated by a User through the Service.
“AI Systems”
means the artificial intelligence, machine learning, large language models, agentic frameworks, and automated technologies used to power or support the Service, including models provided by third-party AI providers.
“AI-Generated Output”
means any response, summary, recommendation, prediction, note, report, or other content generated by AI Systems in connection with the Service.
“Training Data”
means Personal Data or User Content used to train, fine-tune, validate, or otherwise improve AI Systems.
“Third-Party AI Providers”
means external AI model providers whose large language models or related technologies are integrated into or used to power the Service, including but not limited to OpenAI, Anthropic, Google, Mistral, and Microsoft Azure OpenAI.
“Connected Accounts”
means third-party enterprise systems, platforms, and collaboration tools voluntarily connected by a User or their organization, including but not limited to ServiceNow, Salesforce, Jira, Confluence, Microsoft Outlook, Microsoft Teams, and Slack. Access is initiated and controlled by the User or their organization and may be revoked at any time.
“Processing”
means any operation performed on Personal Data or User Content, including collection, storage, use, modification, and deletion.
“Security Incident”
means any confirmed unauthorized access, disclosure, alteration, or destruction of Personal Data or User Content.
“Separate Agreement”
means a separate written agreement with the Company governing your use of Company products or services (including, without limitation, a Master Services Agreement, Software License Agreement, Subscription Agreement, Data Processing Agreement, or Business Associate Agreement).

3. Information We Collect

We collect information that identifies, relates to, describes, or could reasonably be linked to you (“Personal Data”). This includes information you provide directly to us, such as your name, email address, phone number, mailing address, account credentials, billing and payment information, and any communications you send to us. Depending on the nature of the services you use, we may also collect professional or employment-related information such as job title, organizational role, work history, or similar details.

We also collect User Content, including documents, prompts, queries, voice inputs, and other information you submit through the Service, as well as your interactions with AI Systems, feedback you provide on AI-Generated Outputs, and any corrections or modifications you make to those outputs. This information is used to provide the Service and, where applicable and in accordance with this Privacy Policy, to improve our AI Systems.

We collect certain information automatically when you use the Service, including your IP address, device identifiers, browser type, general location data, and usage information such as pages visited, time spent, and referring URLs.

Where you connect third-party enterprise systems or collaboration tools through Connected Accounts, we collect the data and metadata necessary to facilitate those integrations, limited to what is explicitly authorized by you or your organization.

In connection with certain products, particularly those serving healthcare, clinical, HR, and financial use cases, we may collect sensitive information such as clinical documentation, government-issued identification, financial data, or workforce-related data. Protected health information (PHI), as defined under the Health Insurance Portability and Accountability Act (HIPAA), is processed only where a separately executed Business Associate Agreement (BAA) is in place with the Company and the applicable product is configured to operate under that BAA. Sensitive information is collected only to the extent required for the applicable service and is handled in accordance with applicable law and any applicable Separate Agreement. The Service includes automatic PII and PHI detection and redaction capabilities to help limit unnecessary exposure of sensitive data.

We collect Personal Data directly from you, automatically through your use of the Service, and in some cases from Connected Accounts or third parties such as business partners or service providers where permitted by law. We collect only what is reasonably necessary to fulfill the purposes described in this Privacy Policy and do not collect Personal Data for purposes incompatible with those disclosed at the time of collection.

4. How We Use Your Information

We use Personal Data and User Content to:

  • Provide, operate, maintain, and improve the Service and all products within the Brightcone Product Suite;
  • Process transactions and fulfill service requests;
  • Respond to inquiries and communicate with you regarding your account;
  • Personalize and optimize your experience with the Service, including tailoring AI-Generated Outputs to your role, organization, and use case;
  • Send administrative or service-related communications;
  • Send marketing communications where permitted by law and subject to your opt-out rights;
  • Monitor, analyze, and improve usage, performance, and AI System accuracy;
  • Enforce our Terms of Use;
  • Comply with legal obligations and respond to lawful requests; and
  • Detect, prevent, and address fraud, security issues, or technical problems.

5. Automated Processing and Artificial Intelligence

5.1 How We Use AI

The Service is powered by artificial intelligence, machine learning, large language models, agentic frameworks, and related automated technologies. AI Systems are central to the functionality of the Brightcone Platform and all products in the Brightcone Product Suite, including AI-powered help desk automation, document intelligence and summarization, clinical documentation, workforce forecasting, omnichannel contact center capabilities, and predictive scheduling. We use AI Systems to analyze and process User Content; generate recommendations, summaries, predictions, notes, and other outputs; optimize Service performance and functionality; route inputs to the most appropriate model for the task; personalize responses based on your role, organization, and data; and detect fraud, security threats, and other harmful activity.

5.2 Multi-Model AI and Model Routing

The Service supports multiple large language models and may route your inputs and User Content to different Third-Party AI Providers depending on the task, configuration, and deployment model. Third-Party AI Providers whose models may process your data include OpenAI (GPT), Anthropic (Claude), Google (Gemini), Mistral, and Microsoft Azure OpenAI, among others. The specific models used in connection with your account may vary based on your organization’s configuration and any bring-your-own-model arrangements. All Third-Party AI Providers are contractually required to protect your Personal Data in accordance with applicable law and to process it only as directed by us. We do not permit Third-Party AI Providers to use your Personal Data for their own independent training or commercial purposes without your consent.

5.3 Use of Data to Train and Improve AI Systems

We will not use Personal Data or User Content to train, fine-tune, validate, or improve our AI Systems, including custom or department-specific language models developed as part of the Service, unless you (or, where applicable, your organization) expressly opt in to such use. Where opt-in is offered, we will provide clear notice and an easy mechanism to withdraw consent at any time by contacting us at hello@brightcone.ai. We may use Personal Data and User Content in aggregated or de-identified form to operate, secure, debug, and improve the Service, provided that such use does not re-identify you or your organization.

5.4 AI-Generated Outputs

AI-Generated Outputs are produced by automated systems and may be inaccurate, incomplete, or not suitable for your specific circumstances. You are responsible for reviewing any AI-Generated Output before relying on or acting upon it. This is particularly important in connection with clinical documentation, financial analysis, workforce decisions, and other high-stakes use cases. The Company makes no representations or warranties regarding the accuracy, reliability, or fitness for a particular purpose of any AI-Generated Output.

5.5 Human Review and Oversight

Certain AI-driven processes may be reviewed or overseen by authorized Company personnel for quality assurance, safety, accuracy, and compliance purposes. All such access is subject to appropriate confidentiality obligations and access controls. Where automated processing may produce decisions that have a legal or similarly significant effect on you, you may have the right to request human review of such decisions, object to the outcome, or obtain an explanation of the basis for the decision, subject to applicable law. Our products are designed to support, augment, and inform human decision-making, not to replace it. By using our Service, you agree to comply with all applicable laws, regulations, or guidelines governing your use of our Service, including any requirements relating to human review of AI-Generated Outputs.

5.6 Feedback and Continuous Learning

The Service may incorporate feedback you provide, including corrections, ratings, or modifications to AI-Generated Outputs, to improve AI System performance on an ongoing basis. By providing feedback through the Service, you acknowledge that such feedback may be used to refine and improve our AI Systems in accordance with this Privacy Policy. You may opt out of having your feedback used for this purpose by contacting us at hello@brightcone.ai.

5.7 AI Ethics and Bias

We are committed to the responsible development and deployment of AI. We take reasonable steps to monitor AI Systems for bias, discriminatory outputs, and unintended behavior, and to implement safeguards around high-stakes automated decisions. The Service incorporates AI governance and observability tools designed to ensure responsible, compliant AI adoption. Users who have concerns about the behavior or outputs of our AI Systems are encouraged to contact us at hello@brightcone.ai.

7. Sharing of Your Information

We do not sell your Personal Data. We may share Personal Data in the following circumstances:

  • With Third-Party AI Providers whose large language models power or support the Service, including OpenAI, Anthropic, Google, Mistral, and Microsoft Azure OpenAI, solely as necessary to provide AI-powered functionality and subject to contractual data protection obligations;
  • With cloud infrastructure providers on whose platforms the Service is deployed, including Amazon Web Services, Microsoft Azure, and Google Cloud, as applicable based on your deployment configuration;
  • With identity and access management providers such as Okta, Azure Active Directory, and Ping Identity, as necessary to authenticate and authorize users;
  • With AI governance and observability partners, as necessary to ensure responsible and compliant AI operation;
  • With Connected Account providers and enterprise application platforms you authorize, including ServiceNow, Salesforce, Jira, Confluence, Microsoft Outlook, Microsoft Teams, and Slack, limited to what is necessary to provide the requested integration;
  • With other service providers and vendors who perform services on our behalf;
  • To comply with legal obligations or respond to lawful requests;
  • To protect the rights, property, or safety of the Company, Users, or others; and
  • In connection with a merger, acquisition, restructuring, or sale of assets, in which case the acquiring entity will be required to honor this Privacy Policy or provide comparable protections.

All third-party service providers and AI providers are contractually required to protect Personal Data in accordance with applicable law and to process it only as directed by us. We do not use or disclose sensitive Personal Data for purposes other than those permitted by applicable law. You may exercise your opt-out rights through any “Do Not Sell or Share My Personal Information” link or similar mechanism made available on our Services, where applicable.

8. Deployment and Data Residency

The Service is available in multiple deployment configurations, including fully managed SaaS, isolated virtual private cloud (VPC), on-premises deployment within your own data center, and hybrid configurations. The configuration selected by your organization determines where your Personal Data and User Content are stored and processed.

In certain deployment configurations, including VPC and on-premises deployments, your data is stored and processed entirely within your organization’s own environment and does not leave that environment unless you choose to enable integrations that require data transfer. In SaaS deployments, data is stored on secure cloud infrastructure operated by or on behalf of the Company. Regardless of deployment model, the Company implements the security and access controls described in this Privacy Policy.

Where your organization has specific data residency requirements, including requirements that data remain within a particular geographic region or jurisdiction, those requirements should be addressed in your agreement with the Company.

9. Security Measures

We implement enterprise-grade administrative, technical, and physical safeguards to protect Personal Data and User Content. Our security measures include:

  • Role-based access control (RBAC) with granular permissions and multi-tenant isolation;
  • Single sign-on (SSO) integration with enterprise identity providers including Okta, Azure Active Directory, and Ping Identity;
  • SCIM provisioning for automated user lifecycle management;
  • Automatic PII and PHI detection and redaction;
  • End-to-end encryption for data in transit and at rest;
  • Memory encryption to protect sensitive context;
  • Data residency controls that can be configured to prevent data from leaving your environment;
  • Comprehensive audit logging and observability aligned with HIPAA and SOC 2 Type II frameworks;
  • Zero Trust architecture principles;
  • AI-specific safeguards including protections against prompt injection, unauthorized model access, and adversarial inputs; and
  • Incident response procedures with defined escalation and notification timelines.

No system is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for ensuring appropriate access controls are configured within your organization’s deployment.

10. Data Breach Notification

In the event of a Security Incident affecting your Personal Data, we will notify affected Users and, where applicable, the relevant supervisory authority, in accordance with applicable law and the timelines required thereunder.

11. Data Retention and Deletion

We retain Personal Data and User Content only as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, regulatory, contractual, and operational requirements. In determining appropriate retention periods, we consider the nature and sensitivity of the Personal Data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the data, and applicable legal requirements. When Personal Data is no longer needed, we will delete or anonymize it in accordance with our internal policies. In deployment configurations where data resides within your organization’s own environment, retention and deletion of that data is subject to your organization’s own policies and controls.

12. Sensitive Personal Data

Given the industries we serve, the Service may process sensitive Personal Data including protected health information, clinical documentation, financial account data, government-issued identification numbers, biometric information, neural data, precise geolocation, and workforce-related information. We process such data only as necessary to provide the Service, comply with legal obligations, or for other purposes permitted by applicable law. We do not use or disclose sensitive Personal Data beyond those purposes unless we obtain your consent where required. California residents have the right to limit the use and disclosure of sensitive Personal Data under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and we honor such requests in accordance with applicable law. The Service is not directed to consumers under the age of 18, and where Personal Data of a consumer known to be under 18 is processed, we obtain affirmative opt-in consent before any sale or sharing as required by California law. The Service includes automatic PII and PHI detection and redaction capabilities; however, the Service is not designed for the processing of Protected Health Information under HIPAA unless a separate Business Associate Agreement has been executed with the Company.

13. No Financial Incentives

We do not offer financial incentives, price differences, or service differences in exchange for the retention, sale, or sharing of Personal Data.

14. Cookies and Tracking

The Service uses essential cookies necessary for operation and performance monitoring, and may use optional cookies to support analytics and marketing. Users may manage cookie preferences through their browser settings or any cookie consent tools we make available. Disabling certain cookies may affect the functionality of the Service. Where required by law, we obtain your consent before placing non-essential cookies.

Required Cookies

These cookies are necessary for the operation of the Service and cannot be disabled. They may be set to recognize you when you return to the Service after providing your identification.

Functional Cookies

These cookies improve the performance, functionality, and offerings of the Service, including usage analytics and improvement of user experience. We may use our own technology or third-party tools to track and analyze usage data.

Advertising Cookies

These cookies monitor user behavior across websites for direct marketing purposes. You may refuse advertising cookies through your browser settings or available consent tools.

15. Your Privacy Rights

Depending on your location, you may have the right to access, correct, delete, restrict, or object to the processing of your Personal Data, and to request data portability. Where automated processing, including AI-driven decision-making, produces decisions with a legal or similarly significant effect on you, you may have the right to request human review of such decisions, object to the outcome, or obtain an explanation of the basis for the decision. We may take reasonable steps to verify your identity before fulfilling a request. To submit a request, contact us at hello@brightcone.ai.

16. Transfer of Information Across Borders

Your information may be processed in the United States or other countries where we or our service providers operate. Where required by applicable law, we implement appropriate safeguards for cross-border transfers, including Standard Contractual Clauses (SCCs) or other legally recognized transfer mechanisms. Organizations with specific data residency requirements should address those requirements in their agreement with the Company.

17. California Resident Rights (CCPA/CPRA)

17.1 Right to Know

You have the right to request information about our collection and use of your Personal Data over the past 12 months, including the categories of Personal Data collected and their sources; the business or commercial purpose for collecting or sharing your Personal Data; the categories of third parties with whom we have shared your Personal Data; and the specific pieces of Personal Data we have collected about you.

17.2 Right to Delete

You have the right to request deletion of your Personal Data, subject to certain legal exceptions, such as where retention is necessary to complete a transaction or fulfill a legal obligation.

17.3 Right to Correct

You have the right to request correction of inaccurate Personal Data we maintain about you.

17.4 Right to Opt Out of Sharing

To the extent we engage in activities considered “sharing” of Personal Data under California law, you have the right to opt out. We do not sell Personal Data. You may exercise your right to opt out by contacting us at hello@brightcone.ai or using any available cookie preference tools. We recognize and honor opt-out preference signals sent by your browser or device, including the Global Privacy Control (GPC) signal, as a valid request to opt out of the sale or sharing of your Personal Data in accordance with California Code of Regulations title 11, Section 7025. Where we have processed an opt-out request, we will display visual confirmation that the request has been honored.

17.5 Exercising Your California Rights

To submit a valid request, please contact us at hello@brightcone.ai. We will respond within forty-five (45) days of receipt. You may also authorize an agent to exercise your rights on your behalf by providing written authorization.

17.6 No Discrimination

We will not discriminate against you for exercising your rights under the CCPA/CPRA.

17.7 Shine the Light

California residents may request information about our disclosure of Personal Data to third parties for their direct marketing purposes by contacting us at hello@brightcone.ai.

18. Nevada Resident Rights

Nevada residents may opt out of the sale of certain Personal Data by contacting us at hello@brightcone.ai with the subject line “Nevada Do Not Sell Request.” We do not currently sell Personal Data as defined under Nevada Revised Statutes Chapter 603A.

19. European, United Kingdom, and Swiss Residents

If you are located in the European Union, United Kingdom, or Switzerland, you have the right to access, rectify, or erase your Personal Data; restrict or object to processing; request data portability; and, where processing is based on consent, withdraw that consent at any time. You also have the right to object to solely automated decision-making, including AI-driven processing, that produces legal or similarly significant effects, and to request human review of such decisions. You have the right to lodge a complaint with the supervisory authority in your country of residence. We require only the information reasonably necessary to provide the Service and retain Personal Data only as long as necessary to fulfill the purposes described in this Privacy Policy or to comply with legal obligations.

20. Children's Privacy

The Service is not directed to children under the age of 13, and we do not knowingly collect Personal Data from children under 13. If we become aware that we have collected such data, we will take prompt steps to delete it. If you believe we may have inadvertently collected information from a child under 13, please contact us immediately at hello@brightcone.ai.

21. Linked Websites

The Service may contain links to third-party websites. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal information.

22. How to Opt Out of Marketing Communications

You may opt out of marketing communications at any time by clicking the “unsubscribe” link in any marketing email or by contacting us at hello@brightcone.ai. Opting out of marketing communications does not affect our ability to send transactional or account-related communications.

23. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Updates will be posted with a revised “Last Updated” date. Your continued use of the Service after such posting constitutes your acceptance of the updated Privacy Policy.

24. Enforcement

If you believe the Company has not adhered to this Privacy Policy, please notify us at hello@brightcone.ai and we will investigate and address the matter in accordance with applicable law.

Contact Us

Questions or concerns about this Privacy Policy? Reach out to us:

Brightcone.ai

hello@brightcone.ai

Effective Date: April 28, 2026  ·  Last Updated: April 28, 2026