Privacy Policy
IMPORTANT LEGAL NOTICE: This document constitutes a legally binding agreement between you and Brushfire Research, a product of Mighty Group, LLC. Please read it carefully before using the Brushfire mobile application. This document has been prepared as a comprehensive draft and must be reviewed and approved by qualified legal counsel before publication or app store submission. This Privacy Policy describes how Brushfire Research, a product of Mighty Group, LLC ("Brushfire," "we," "us," or "our") collects, uses, stores, protects, and handles your personal information when you use the Brushfire mobile application (the "App") on Android or iOS devices. It also describes your rights with respect to your personal information under applicable federal and state privacy laws. This Privacy Policy applies specifically to the Brushfire mobile application and supplements the existing Brushfire Research web platform Privacy Policy. In the event of any conflict between this document and the web platform policy, this mobile-specific policy governs with respect to your use of the App.
1. Who We Are and How to Contact Us
Brushfire Research is a two-sided AI-powered market research platform operated by Mighty Group, LLC. The App enables two types of users: (1) Signal Providers — individuals who participate in research surveys in exchange for rewards, and (2) Sensemakers — organizations and researchers who create and distribute research instruments.
2. Information We Collect
2.1 Account Registration Information When you register for a Brushfire account through the App, we collect: First name and last name Email address Mobile phone number (used for account verification via OTP and account communications only) Password (stored in encrypted, hashed format — never in plaintext) Date of birth (used to verify you are 18 years of age or older — we do not accept registrations from minors) 2.2 Demographic Profile Information As a Signal Provider (survey respondent), you are asked to complete a demographic profile. This information is used exclusively to match you to relevant research instruments and to power the analytical dashboards available to research clients (Sensemakers). We do not sell, share, or transfer your demographic information to any third party for any purpose. The demographic fields we collect are: Demographic Field Data Type Purpose Age Continuous numeric value (min–max range) Audience targeting and analytical segmentation Gender Categorical (Female, Male, Non-binary, Prefer not to say) Audience targeting and analytical segmentation Location — State US state of residence Audience targeting and analytical segmentation Location — City City of residence Audience targeting and analytical segmentation Education Level Categorical (7 options including Prefer not to say) Audience targeting and analytical segmentation Employment Status Categorical (7 options including Prefer not to say) Audience targeting and analytical segmentation Household Size Ordered categorical (1 to 7+ people, Prefer not to say) Audience targeting and analytical segmentation Number of Children Ordered categorical (None to 5+, Prefer not to say) Audience targeting and analytical segmentation Industry / Field of Work Categorical (34 industry options) Audience targeting and analytical segmentation Marital Status Categorical (6 options including Prefer not to say) Audience targeting and analytical segmentation Housing Status Categorical (Rent, Own, Other, Prefer not to say) Audience targeting and analytical segmentation Device Type Categorical (Mobile, Web, Both) Platform analytics and instrument distribution 2.3 Survey Response Data When you participate in a research instrument (survey) through the App, we collect your responses to the questions presented. Survey responses are associated with your demographic profile for analytical purposes and are shared in aggregated, de-identified form with the Sensemaker (research client) who created the instrument. Individual responses may be linked to your account for reward calculation and platform integrity purposes. 2.5 Identity Verification Data (eKYC) To maintain the integrity of our research platform and ensure that survey responses come from real, unique individuals, we conduct identity verification for certain Signal Provider accounts through a third-party electronic Know Your Customer (eKYC) process. During eKYC verification, we collect and process through our eKYC provider: Full legal name (verified against a government-issued photo ID) Date of birth (verified against a government-issued photo ID) Government-issued photo ID (document image captured and processed by our eKYC provider) Liveness check / biometric facial scan (a selfie or video used to confirm you are physically present and match the photo ID) BIOMETRIC DATA NOTICE: The liveness check component of eKYC involves the collection and processing of biometric identifiers or biometric information as defined under the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), the Washington My Health MY Data Act, and similar state biometric privacy laws. Biometric data is processed exclusively by our third-party eKYC verification provider and is not stored by Brushfire beyond what is necessary to complete the verification process. Brushfire does not sell, lease, trade, or profit from biometric data. Our eKYC provider's data retention and destruction schedule applies to all biometric data collected during verification. By proceeding with eKYC verification, you consent to the collection and processing of your biometric data as described in this section. eKYC verification is conducted by a qualified third-party identity verification provider. Brushfire is not responsible for the data practices of that provider beyond what is governed by our data processing agreement with them. The current eKYC provider can be identified by contacting us at info@brushfireresearch.com. Identity verification is not a prerequisite for using the Brushfire App. Unverified Signal Providers retain full access to the App, including wallet and reward redemption. Verification status is used solely to determine eligibility for certain survey distribution targeting. 2.6 Financial and Reward Information When you redeem rewards from your in-app wallet, we process your redemption request through a third-party gift card fulfillment provider. We do not collect or store credit card numbers, bank account details, or other payment card information directly. Financial transaction processing is governed by our third-party fulfillment partner's privacy policy and security practices. 2.7 Technical and Usage Data We automatically collect certain technical information when you use the App, including: Device type, operating system, and version App version and session data Crash logs and error reports (for platform stability purposes) Survey completion times (used for analytical dashboard features) Login and session timestamps
3. How We Use Your Information
We use the information we collect for the following purposes: Purpose Data Used Legal Basis Account creation and authentication Registration information, device data Contractual necessity Matching you to relevant research surveys Demographic profile data Contractual necessity / Legitimate interest Powering analytical dashboards for research clients Demographic data + survey responses (aggregated) Contractual necessity / Legitimate interest Calculating and crediting survey rewards Account data, survey completion records Contractual necessity Processing reward redemptions Account data, redemption requests Contractual necessity Identity verification (eKYC) Legal name, DOB, government ID, biometric liveness data Contractual necessity / Legal obligation Platform integrity and fraud prevention Account data, device data, eKYC results Legitimate interest / Legal obligation Sending in-app notifications about surveys, rewards, and account updates Account data, notification preferences Contractual necessity / Consent Improving platform performance and features Aggregated usage data, crash reports Legitimate interest Complying with legal obligations As required by applicable law Legal obligation We do not use your demographic information, survey responses, or personal information for advertising targeting, for sale to third parties, or for any purpose not explicitly stated in this Privacy Policy. Demographic information is used exclusively to match Signal Providers to relevant research instruments and to generate aggregated analytical insights for Sensemakers.
4. How We Share Your Information
4.1 With Research Clients (Sensemakers) Research clients who create surveys on the Brushfire platform have access to aggregated, de-identified analytical data from survey responses. Sensemakers see demographic breakdowns and response distributions at a group level — they do not have access to individual respondent identities, names, email addresses, or any information that would allow them to identify a specific survey participant. 4.2 With Third-Party Service Providers We share limited personal information with trusted third-party service providers who assist us in operating the platform. These providers are contractually bound to use your information only to perform services on our behalf and in accordance with this Privacy Policy: eKYC / Identity Verification Provider — receives legal name, DOB, government ID image, and biometric liveness data for identity verification purposes only Gift Card / Reward Fulfillment Provider — receives redemption request data to process and deliver rewards Cloud Infrastructure Provider — hosts encrypted platform data in secure data centers Analytics and Crash Reporting Tools — receives aggregated, de-identified usage and error data We do not share your personal information with any third party for advertising, marketing, or commercial data sale purposes. 4.3 Legal Disclosures We may disclose your personal information if required to do so by law, regulation, subpoena, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to protect our legal rights, protect the safety of any person, or investigate fraud or security issues. 4.4 Business Transfers In the event of a merger, acquisition, asset sale, or other business transfer, your personal information may be transferred as part of the transaction. We will notify you via email or in-app notification before your information is transferred and becomes subject to a different privacy policy. 4.5 Cross-Border Transfers of Information Bushfire may transfer or process your Information in countries outside your country of residence where required to provide the Services or support our operations. Bushfire will ensure that any cross-border transfer of Information is carried out in accordance with applicable data protection laws and that appropriate safeguards are implemented to protect your Personal Data.
5. Your Privacy Rights — State-Specific Disclosures
Depending on the state in which you reside, you may have specific rights regarding your personal information. We honor these rights for all users regardless of which state's law technically applies. The following is a summary of rights under major US state privacy laws: State Law Applies To Key Rights California CCPA/CPRA California residents Right to know, right to delete, right to correct, right to opt out of sale/sharing, right to limit use of sensitive personal information, right of no retaliation Virginia CDPA Virginia residents Right to access, right to delete, right to correct, right to data portability, right to opt out of processing for targeted advertising or profiling Colorado CPA Colorado residents Right to opt out, right to access, right to correct, right to delete, right to data portability, right to appeal a controller's decision Connecticut CTDPA Connecticut residents Right to access, correct, delete, and port data; right to opt out of targeted advertising, sale, and certain profiling Texas TDPSA Texas residents Right to access, correct, delete, and port data; right to opt out of sale and targeted advertising; sensitive data requires consent Illinois BIPA Illinois residents Specific rights regarding biometric data including the right to be informed about collection, the right to consent, and the right to data destruction timelines Washington My Health MY Data Act Washington residents Specific rights regarding health and biometric data — liveness check data collected during eKYC is subject to this Act All other US states All users We apply the principles of transparency, data minimization, and user control to all users regardless of state residence 5.1 How to Exercise Your Rights To exercise any of the rights listed above, please submit a request to: Email: info@brushfireresearch.com with subject line: 'Privacy Rights Request' Include your full name, email address registered with Brushfire, and a description of the right you wish to exercise We will respond to all verifiable requests within 45 days. We may need to verify your identity before processing your request. We will not discriminate against you for exercising your privacy rights — your access to the App and survey participation eligibility will not be affected by submitting a privacy rights request. 5.2 Sensitive Personal Information — Opt-Out and Limitation Rights The following categories of information we collect are considered Sensitive Personal Information under one or more applicable state laws: Biometric data collected during eKYC verification — subject to the biometric data notice in Section 2.5 Precise geolocation — we collect State and City level location only; we do not collect GPS-level precise geolocation data We do not use Sensitive Personal Information for any purpose beyond what is necessary to provide the services described in this Privacy Policy. We do not sell Sensitive Personal Information. 5.3 Bushfire will process your Information only in accordance with your documented instructions and solely for the purpose of providing the Services requested by you. Bushfire will not sell your Information and will not retain, use, or disclose your Personal Data except as necessary to provide the Services, as permitted under this Privacy Policy, or as required or permitted by applicable law. If Bushfire reasonably believes that any instruction provided by you would violate applicable law, Bushfire will, to the extent legally permitted, notify you before acting on such instruction.
6. Data Retention
Data Category Retention Period Notes Account registration information Duration of active account + 60 days after deletion request Permanently removed within 60 days of deletion confirmation Demographic profile data Duration of active account + 60 days after deletion request Retained while account is active to support ongoing survey matching Survey responses Duration of active account; individual responses may be deleted 60 days after receipt if over account response limits Aggregated and de-identified response data may be retained longer for analytical purposes eKYC verification records As required by applicable law and our eKYC provider's data destruction schedule Biometric data is subject to provider's retention and destruction timeline Wallet and reward transaction records 7 years (financial record-keeping obligations) Subject to applicable financial regulations In-app notification history 6 months from delivery Automatically deleted after 6 months per platform notification retention rules Technical and usage logs 90 days rolling Used for platform stability and security monitoring only Backup media Residual copies may persist on backup media for up to 90 days after deletion Overwritten and destroyed at next backup cycle after the 60-day deletion window
7. Data Security
We implement and maintain reasonable and appropriate technical, administrative, and physical safeguards designed to protect your personal information from unauthorized access, disclosure, alteration, or destruction. These measures include: Encryption of data in transit using TLS/HTTPS Encryption of sensitive data at rest Password hashing using industry-standard one-way hashing algorithms OTP-based verification for account changes and email updates Access controls limiting internal access to personal data on a need-to-know basis Regular security monitoring and incident response procedures 7.1 Encryption at Rest Encryption at rest is enabled by default on all storage and snapshot volumes used by the Brushfire platform. All personal data stored on our infrastructure is protected using the Advanced Encryption Standard (AES)-256, the industry benchmark for symmetric encryption and a standard mandated under GDPR Article 32 technical and organisational measures. AES-256 ensures that your personal information, demographic data, and survey responses remain protected against unauthorised access at the storage layer, including in the event of physical media theft or unauthorised infrastructure access. 7.2 Encryption in Transit Encryption in transit is enforced across all data communications on the Brushfire platform. All client-to-database and intra-cluster network traffic is secured using mandatory Transport Layer Security (TLS). This means that all personal information transmitted between your device and the Brushfire platform, between our application servers and our database infrastructure, and between internal platform services, is encrypted in transit and protected against interception. Unencrypted connections are not accepted. TLS enforcement applies to all API calls, authentication flows, data submissions, and administrative operations within the platform. No method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. In the event of a security breach that is likely to result in a risk to your rights and freedoms, we will notify you and applicable regulatory authorities as required by law.
8. Protection of Minors
The Brushfire App is not intended for and may not be used by individuals under the age of 18 ("Minors"). We do not knowingly collect personal information from Minors. During the registration process, we require users to confirm their date of birth and verify that they are 18 years of age or older. If we become aware that we have inadvertently collected personal information from a Minor, we will take immediate steps to delete that information from our systems. If you have reason to believe a Minor has registered for a Brushfire account, please contact us immediately at info@brushfireresearch.com. This App is not directed at children under the age of 13 and we do not knowingly collect personal information from children under 13. Our practices are consistent with the Children's Online Privacy Protection Act (COPPA).
9. Push Notifications and In-App Communications
The Brushfire App sends in-app push notifications to notify you of new survey availability, reward credits, account updates, and platform announcements. Push notifications are delivered only through in-app channels — we do not send unsolicited SMS or email marketing messages. You may manage your notification preferences through your device's notification settings at any time. Disabling notifications will not affect your ability to use the App, participate in surveys, or redeem rewards, but may result in you missing time-sensitive survey availability notices.
10. Cookies and Mobile Tracking Technologies
The Brushfire mobile application does not use browser cookies. The App may use local device storage (such as device tokens) for authentication session management. We do not use cross-app tracking, advertising identifiers (IDFA/GAID), or third-party tracking SDKs for advertising purposes within the App.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes — particularly changes that affect how we collect, use, or share your personal information or sensitive data — we will notify you through a prominent in-app notice and, where required by applicable law, obtain your consent before the changes take effect. The 'Last Updated' date at the top of this document reflects the most recent revision. Your continued use of the App after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
Legal Review Notice
This document is a comprehensive draft prepared for internal review purposes. It is not a substitute for legal advice. Before publishing this Privacy Policy and Terms of Service on the Apple App Store, Google Play Store, or within the Brushfire App, this document must be reviewed and approved by a qualified attorney licensed in the relevant jurisdiction(s). Key areas requiring specific legal review before publication include: (1) Biometric data disclosures and consent mechanisms for BIPA, Washington My Health MY Data Act, and Texas CUBI compliance; (2) California CCPA/CPRA 'Do Not Sell or Share My Personal Information' disclosure and link requirements; (3) State-specific biometric data destruction schedule requirements; (4) Apple App Store and Google Play Store privacy label (Data Safety/Nutrition Label) accuracy; (5) Arbitration clause enforceability under applicable state law; (6) eKYC provider-specific data processing agreement alignment.
