Skip to content
Bryllyant
  • AI
  • Services
  • Industries
  • Integrations
  • Use cases
  • About
Let's talk
Legal

Privacy policy

Effective October 8, 2026

Bryllyant, Inc. ("Bryllyant", "we", "us"), a Delaware corporation, builds software for businesses. This policy explains what personal information we collect, how we use it, who else handles it, and the choices you have. It covers our website, bryllyant.com, and its contact form; email to us; our dealings with the people we work with; and XipID Verification Messages, a text messaging program we operate. Bryllyant Console, the internal tool we use with our own QuickBooks company, has its own privacy policy.

Questions about this policy, and requests about your information, go to privacy@bryllyant.com.

The short version

  • We collect what you tell us, and basic information about how our site is used.
  • We use it to reply to you, to do our work, and to run our business.
  • We don't sell personal information for money. Through Google, Meta, and LinkedIn, we show our ads to people who've visited our site.
  • If your browser sends Global Privacy Control or Do Not Track, our site loads no analytics or advertising tags at all.
  • We never share mobile numbers or text-message consent for marketing.
  • You can ask what we hold about you, and ask us to correct or delete it.

Work we do for clients

When we build or run software for a client, the personal information in that work belongs to the client. We handle it only on the client's instructions, under our agreement with the client, and the client's own privacy policy explains how it's used. This policy doesn't cover it, so if your information is in a client's systems, please ask that client; we'll help them answer you. The exception is our text messaging program: the SMS and Text Messaging section below covers what we collect to run it.

What we collect

What you give us

  • When you write to us, through our contact form or by email: your name, your work email, your company if you give it, the topic, and what you tell us.
  • When we work together, as a client, a vendor, a partner, or a business considering us: names, roles, and contact details; our correspondence and meetings; and what our proposals, agreements, and invoices need.

What our site collects

  • On every visit, our hosting provider receives what every web request carries, such as your IP address, your browser, and the page you asked for. It uses them to deliver the site and keep it secure.
  • Through Google's tags, unless your browser asks not to be tracked: the pages you view, the page that sent you, your device and browser, your approximate location, a cookie identifier, whether you went on to write to us after clicking one of our ads, and that you visited, so we can show you our ads elsewhere. If you're signed in to a Google account that allows personalized ads, Google also links this to your account, so we can show you our ads on your other devices and see our visitors' age ranges, genders, and interests, only in aggregate.
  • Through Meta's pixel, unless your browser asks not to be tracked, and never in the European Economic Area, the United Kingdom, or Switzerland: the pages you view, the page that sent you, your device and browser, your approximate location, a cookie identifier, whether you went on to write to us, with the topic you chose, and that you visited, so we can show you our ads on Facebook and Instagram. It doesn't receive your name, your email, or your message.
  • Through LinkedIn's Insight Tag, unless your browser asks not to be tracked, and never in the European Economic Area, the United Kingdom, or Switzerland: the pages you view, the page that sent you, your IP address, your device and browser, the buttons and links you click, identifiers kept in your browser, whether you went on to write to us after seeing or clicking one of our LinkedIn ads, and that you visited, so we can show you our ads on LinkedIn and elsewhere. It doesn't receive your name, your email, or your message.
  • On our contact form, Google reCAPTCHA, which keeps out spam: it collects information about your device and browser and how you use the page, and Google processes it for us to tell people from bots, not for advertising.
  • When you send our contact form, we also record the page you sent it from, the IP address it came from, the kind of device, operating system, and browser you used, and reCAPTCHA's score of how likely it is that a person sent it.
  • How you came to our site, unless your browser asks not to be tracked: the site that sent you, the page you first opened, the campaign tags on that link, and whether you came from an ad, but not the ad's click identifier. Our site keeps this in your browser's session storage, which your browser clears when you close the tab, and sends it to us only with the contact form. We don't record it for visitors in the European Economic Area, the United Kingdom, or Switzerland.

What others give us

Someone may introduce you to us, such as a client, a partner, or a reseller. We may also read what a business publishes about itself and its people, such as its website or a professional profile.

How we use it

  • To reply to you, and to prepare proposals and agreements.
  • To do the work we've agreed to do, and to bill for it.
  • To send you the business email you'd expect from us. If we send you marketing email, every message has a way to unsubscribe.
  • To learn how our site is used, and by what kinds of businesses and professionals, and improve it, to see which of our ads, and which other sites and links, lead people to write to us, and to show our ads to people who've visited our site.
  • To keep our site and systems secure, and to prevent fraud and abuse.
  • To meet our legal obligations, enforce our agreements, and protect our rights and other people's.

The uses described in this section do not apply to mobile information you give us for a text messaging program. That information is governed by the SMS and Text Messaging section below, which is narrower.

Who else handles it

  • Our service providers, who work for us on our instructions and may use it only to do that work: Amazon Web Services hosts our site and the service that checks and forwards our contact form; Google runs our email and documents, and checks our contact form for spam with reCAPTCHA; HubSpot keeps our contacts and what our contact form sends us, and works out each sender's approximate location from their IP address; and our messaging providers deliver our text messages.
  • Google, through its tags on our site. Google uses what they collect to provide Google Analytics and Google Ads to us, including showing our ads to people who've visited our site, and in the other ways it describes in How Google uses information from sites or apps that use its services.
  • Meta, through its pixel on our site. Meta uses what it collects to measure our ads and to show them to people who've visited our site, on Facebook, Instagram, and elsewhere, and in the other ways its Privacy Policy describes, such as improving its own ads and products.
  • LinkedIn, through its Insight Tag on our site. LinkedIn matches what the tag collects to LinkedIn members, including across their devices, to tell us, without naming anyone, how our LinkedIn ads perform and what kinds of professionals visit our site, and to show our ads to people who've visited it, on LinkedIn and elsewhere. LinkedIn also uses it for its own purposes, such as improving its advertising, under its own privacy policy.
  • Our professional advisers, such as our lawyers, accountants, and auditors, who keep it confidential.
  • When the law requires it, or when we believe in good faith that it's needed to protect someone's safety, or our rights or other people's.
  • If our business changes hands, through a merger, an acquisition, or a sale of assets, with this policy still applying to it.
  • With your consent, or when you ask us to.

We don't sell personal information for money. Some US state laws treat advertising tags like Google's, Meta's, and LinkedIn's, which we use to show our ads to people who've visited our site, as selling or sharing personal information, or as targeted advertising. To opt out, turn on Global Privacy Control in your browser, and our site won't load them. Cookies, tags, and your choices has other ways.

None of the sharing in this section applies to mobile information collected for a text messaging program. The SMS and Text Messaging section below governs it.

SMS and Text Messaging

Bryllyant operates XipID Verification Messages, a text messaging program described in the Bryllyant Terms of Use. This section covers the information Bryllyant collects to run that program.

What is collected. Your mobile phone number, the record that you consented to be texted and when, the messages sent to you and their delivery status, and whether you approved or declined the request a message refers to. Bryllyant collects this to send the message you asked for, to confirm your decision to the business that asked, and to honor STOP and HELP.

How it is used. Only to carry out the verification you were contacted about, to keep a record that it happened, and to meet legal and carrier obligations. It is not used to advertise anything to you.

We do not sell or share your SMS opt-in data or personal information with third parties for marketing purposes. Mobile information and opt-in consent are not shared with third parties or affiliates for marketing or promotional purposes. Bryllyant shares your mobile number only with the service providers that deliver the messages on its behalf, and with the business whose request you were asked to confirm, which already had your number.

How to stop. Reply STOP to any message. Reply HELP for help, or write to legal@bryllyant.com. Full program terms are in the Bryllyant Terms of Use.

Cookies, tags, and your choices

Our site sets no cookies of its own. It keeps one thing in your browser's session storage, how you came to the site, for the contact form, until you close the tab. Google's, Meta's, and LinkedIn's services set these cookies:

  • Google Analytics tells us how visitors find and use the site. Its cookies last up to two years. To opt out everywhere, use Google's Analytics opt-out add-on.
  • Google Ads tells us whether someone who clicked one of our ads went on to write to us, and lets us show our ads to people who've visited our site. Its cookies on our site last up to 90 days. Google describes its own advertising cookies in How Google uses cookies.
  • Google reCAPTCHA, on the contact form only, sets a cookie that Google uses to tell people from bots.
  • Meta's pixel tells us whether people who saw or clicked our ads on Facebook or Instagram went on to write to us, and lets us show our ads there to people who've visited our site. Its cookies on our site last up to 90 days. When you arrive from one of Meta's ads, it also keeps that click's identifier in your browser's local storage. Meta describes its own cookies in its Cookies Policy.
  • LinkedIn's Insight Tag tells us what kinds of professionals visit our site and whether someone who saw or clicked one of our LinkedIn ads went on to write to us, and lets us show our ads to people who've visited our site. Its cookies on our site last up to 30 days, and it also keeps an identifier in your browser's local storage until you clear it. LinkedIn lists its own cookies, and how long they last, in its cookie table.

Our ads, shown to past visitors. We use the remarketing features of Google Ads and Google Analytics to show our ads to people who've visited our site. Third-party vendors, including Google, show our ads on sites across the internet. They use first-party cookies, such as Google Analytics' cookies, and third-party cookies, such as Google's advertising cookies, together, to choose, measure, and show our ads based on your past visits to our site.

We also use Meta's pixel to show our ads on Facebook and Instagram to people who've visited our site. Meta, like other companies, uses cookies, pixels, and similar technologies to collect or receive information from our site and from elsewhere on the internet, and uses it to measure ads and to choose and show them.

We also use LinkedIn's Insight Tag to show our ads on LinkedIn, and on other sites and apps that show LinkedIn's ads, to people who've visited our site. LinkedIn matches visitors to its members through its cookies, including across their devices.

Google, Meta, and LinkedIn may collect information about your activity on our site and on other sites over time, under their own privacy policies. Your choices:

  • Global Privacy Control or Do Not Track. If your browser sends either signal, our site doesn't load Google's, Meta's, or LinkedIn's tags at all, and doesn't note how you came to the site. reCAPTCHA still runs on the contact form, because it keeps out spam.
  • Google's ads: turn off personalized ads in Google's My Ad Center, which also stops Google linking your visits here to your Google account. You can see and delete that activity in Google's My Activity.
  • Meta's ads: in Meta's ad settings, choose whether Meta uses information from other sites, like ours, to show you ads.
  • LinkedIn's ads: if you're a LinkedIn member, choose how LinkedIn uses data from other sites in your LinkedIn advertising settings; if you're not, opt out in LinkedIn's guest controls.
  • Many advertising companies at once: opt out of their cookies with the Digital Advertising Alliance's WebChoices tool, or on the Network Advertising Initiative's opt-out page.
  • In the European Economic Area, the United Kingdom, and Switzerland, our site tells Google's tags not to use cookies, and not to use your visit to show you ads, and we don't record how you came to the site. LinkedIn's tag and Meta's pixel don't load there at all. Our hosting provider tells our site which country your connection comes from, and where it can't tell, they don't load either.
  • Your browser can block or delete cookies.
  • Marketing email: use the unsubscribe link in any message, or write to us.

Your rights

Depending on where you live, you may have the right to ask us what personal information we hold about you and for a copy of it; to correct it; to delete it; to object to or limit how we use it; and to opt out of its sale or sharing, of targeted advertising, or of marketing.

To ask, write to privacy@bryllyant.com. Someone you've authorized can ask for you. We'll confirm that a request comes from you before we act on it, we'll answer within the time the law allows, and we won't treat you differently for asking. If we turn a request down, we'll say why, and where the law gives you a right to appeal, you can do it by replying to our answer.

If you're in Europe or the UK

Bryllyant is the controller of the personal information this policy describes. We use it on these legal bases: to take steps toward, or perform, a contract with you or your organization; our legitimate interests in running and growing our business, which we weigh against your rights; your consent, where we ask for it, which you can withdraw at any time; and our legal obligations. You can complain to your data protection authority, though we'd be glad of the chance to help first.

Where it's processed

We're based in the United States, and your information is processed there and wherever our service providers work. When personal information leaves the European Economic Area, the United Kingdom, or Switzerland, it's protected by safeguards the law recognizes, such as the standard contractual clauses in our providers' data processing terms.

How long we keep it

We keep personal information for as long as we have a business or legal reason to, such as staying in touch, doing and supporting our work, keeping our business, tax, and legal records, and protecting our rights.

How we protect it

Bryllyant is SOC 2 audited, and we protect personal information with administrative, technical, and physical safeguards suited to it. No system is perfectly secure, so we can't promise that information will never be reached by someone who shouldn't have it. If a breach affects your information, we'll tell you as the law requires.

Children

Our site and our services are for businesses. We don't knowingly collect personal information from anyone under 16. If you believe a child has given us information, write to privacy@bryllyant.com and we'll delete it.

Changes to this policy

When we change this policy, we'll post the new version here with its effective date. If a change matters, we'll also say so on our site, or by email if we work with you. The current version is always at bryllyant.com/legal/privacy/.

Contact us

Bryllyant, Inc., at privacy@bryllyant.com.

On this page
  1. The short version
  2. Work we do for clients
  3. What we collect
  4. How we use it
  5. Who else handles it
  6. SMS and Text Messaging
  7. Cookies, tags, and your choices
  8. Your rights
  9. If you're in Europe or the UK
  10. Where it's processed
  11. How long we keep it
  12. How we protect it
  13. Children
  14. Changes to this policy
  15. Contact us
Bryllyant

AI efficiency. Human integrity.

Software development for businesses of every size.

hello@bryllyant.com

AI
  • AI Readiness Assessment
  • Agentic AI
  • AI app review
  • AI and the work
Services
  • Data and analytics
  • System integrations
  • Custom software
  • Design and websites
Our process
  • Strategy and roadmaps
  • How we work
  • Launch and support
Company
  • About
  • Industries
  • Use cases
  • Contact
© 2026 Bryllyant, Inc. All rights reserved.
  • Terms
  • Privacy
  • Ad choices
  • Attributions