At a glance
BRAVE helps Root communities moderate messages and manage safety. It is operated by WDYM Softworks. A community administrator chooses BRAVE’s settings. Local rules work without Atlas or AI; Atlas sharing and AI analysis are separate, optional settings. BRAVE does not sell app data, use it for advertising, or train AI models on it.
This policy covers BRAVE and this legal website. Root separately operates the Root platform under its Privacy Policy.
Data BRAVE handles
Depending on the permissions granted by a community and the features it enables, BRAVE receives Root user and community identifiers, roles, channel identifiers, messages, attachments and event metadata. It reads this information to apply configured rules, detect spam or harmful content, and show relevant results to authorized people.
When a rule matches or someone files a report, BRAVE may save a message excerpt of up to 240 characters, the relevant identifiers, matched rules, timestamps, a report reason, review status, and moderator actions. It also stores cases, appeals and responses, configuration and revision history, and operational notices. Staff-selected log channels on Root may receive action or report details, visible according to that channel’s permissions.
Member insights are enabled by default but administrators can turn them off. When enabled, BRAVE stores per-member message counts, activity by channel and hour, a recent daily series, and—if the separate word setting remains on—frequent words. It does not need to retain every message to produce these summaries.
Why we use it and your controls
We use app data to enforce the community’s chosen rules, show moderation queues and member-facing notices, investigate reports, process appeals, provide member insights, keep the service secure, and diagnose failures. Community administrators can configure rules, notices, logging, insights, Atlas, AI analysis and automated actions. Moderators can review and reverse decisions where the app permits it; members can view their BRAVE standing and submit appeals.
BRAVE’s decisions can affect a member’s access to a community. Automated matches may be wrong. Community staff should review disputed actions and can use BRAVE’s case and appeal tools. Root’s own permissions and community settings still control what BRAVE can do.
Optional Atlas and AI analysis
Atlas is an optional cross-community safety feature. If enabled, BRAVE sends a Root user identifier to our Atlas service, which derives a secret-keyed pseudonym. Atlas stores that pseudonym, the community identifier, a signal category and severity, and a timestamp. Local-rule signals do not include message text. Atlas may return an aggregated risk result from participating communities. Atlas’s risk engine runs in shadow mode: recommendations do not trigger bans. Report counts and AI alone cannot authorize network punishment.
Separate manual Atlas bans require an explicit human operator decision. Their Root account IDs are encrypted at rest, alongside a keyed pseudonym, decision reason, operator identifier and timestamps. Connected BRAVE servers may receive these IDs and reasons through a private authenticated feed. Communities must separately opt in to enforcement; it is off by default. BRAVE checks changes every five minutes and on member joins, exempts owners, managers and configured trusted roles, and records enforcement receipts in Atlas. These decisions affect participating communities, not Root-wide accounts. An accepted Atlas appeal revokes that manual decision; independent local bans remain.
AI analysis is another separate opt-in setting, available only while the community has 700 members or more. When enabled, message text up to 5,000 characters is sent through our Atlas service to OpenAI’s Moderations API for classification. The Atlas database stores a content hash and classification for caching, not the submitted plaintext. BRAVE does not train LLMs or other AI models with this feature. OpenAI says API data is not used to train its models by default unless the customer opts in; see OpenAI’s API data controls. AI capacity limits or provider failures do not switch off BRAVE’s local rules.
Atlas and AI are off by default. Disconnecting Atlas stops new sharing. Existing signals expire on the schedule below or can be withdrawn individually after review.
Who receives data
Root hosts BRAVE’s per-community app instance and datastore. Authorized community staff see moderation information according to their Root permissions and BRAVE settings; members see their own standing and appeal information. If Atlas is enabled, our Atlas service receives the information described above. If AI analysis is enabled, OpenAI receives submitted text for classification. We may disclose information when required by law or to address security and abuse. We do not sell app data.
This legal website is hosted by Vercel. It does not set first-party cookies or run an analytics script. Vercel may process ordinary request information, such as IP address and browser metadata, to deliver and secure the site; see Vercel’s Privacy Notice.
How long records remain
BRAVE’s scheduled cleanup removes incident records after 30 days. Cases are removed after one year only when their action has expired or has no expiry. Closed appeals are removed after 180 days; open appeals remain until resolved. The daily member-insights series keeps approximately 60 days, while other activity aggregates and the most frequent 200 words per member currently have no automatic expiry. Configuration history keeps the latest 50 revisions.
Atlas removes safety signals and analysis records after 90 days, classification cache entries after one day, and general Atlas audit entries after 30 days. Manual ban decisions, their encrypted account identifiers, operator audit history and community enforcement receipts have no automatic expiry, including after revocation; contact us to request review or deletion. These periods describe the app’s scheduled database cleanup; Root’s hosting, backups and community log channels may have separate retention. A disconnected community’s Atlas connection record is revoked, while prior signals continue to follow their retention schedule unless withdrawn. We may retain information longer when necessary to comply with law or resolve a legitimate dispute.
Access, deletion and questions
Email imbrave@wdym.site to request access, correction or deletion, to contest a BRAVE decision, or to ask a privacy question. Include your Root user ID, the community concerned and enough context to locate the record; do not send passwords or sensitive message content. We may need to verify the request and coordinate with the relevant community administrator or Root. Applicable law may give you additional rights. You can also use BRAVE’s in-app appeal flow for a moderation decision.
Root controls its own account and platform data. For Root-wide requests, use the channels in Root’s Privacy Policy.
Security and updates
We limit access to moderation information, use authenticated connections for Atlas requests, and keep provider credentials out of the client. No security measure is perfect. Processing may occur where Root and our service providers operate. We will update this page when BRAVE’s practices change and show the latest date at the top. Material changes will be communicated through the app or another appropriate channel.
Community showcase and protection totals
Atlas-connected BRAVE installations send a protection heartbeat every five minutes containing their community ID, current member count and whether local protection is enabled. The website publishes aggregate counts for connected installations that reported active protection within the last 30 minutes. These are memberships across communities, which may overlap, rather than unique people. Totals do not include installations that are not connected to Atlas.
Administrators may separately opt in to publish the community's name, small avatar and member count on BRAVE's page. The page shows up to 12 profiles. Names and avatars are not sent for communities that have not opted in. Disabling the showcase clears the stored public name and avatar on the next successful update; cached views can remain briefly. Disconnecting Atlas removes the installation from the public results. Profiles inactive for 30 days are removed. Individual member profiles, IDs, messages and moderation records are never included in this showcase.
Website connection codes and Atlas appeals
At Connect Atlas, the website sends your code to Atlas to approve its specific community request. Codes expire after 15 minutes. Atlas stores a hash of the code; the private community token stays in BRAVE's Root-hosted server.
At Atlas appeals, an appeal code issued for your authenticated Root identity links your explanation to your Atlas case. The code expires after one hour. The website processes the code and explanation through a Vercel function and transmits them to Atlas over HTTPS. Atlas stores the explanation encrypted at rest; senior Atlas reviewers can read it to investigate the appeal. Open explanations remain available until review; closed explanations are removed after 180 days. Your private receipt code can show appeal status for 180 days. Atlas appeals do not automatically reverse local community decisions.
Connection codes confirm requests rather than independently verifying Root community ownership. They do not establish the authenticity of reports. Atlas's evidence engine remains in shadow mode and cannot authorize bans. Separate manual operator bans can be appealed here; accepting an appeal revokes that Atlas decision, and opted-in communities sync the revocation. Independent local decisions remain. Community member reports stay in BRAVE's local Review queue unless separately submitted as Atlas evidence.
Write to imbrave@wdym.site. We’ll point you to the right place.