Control
Password plus mandatory TOTP two-factor authentication; recovery codes are available for recovery sign-in.
Security and data handling · private preview
See what each control does, what it protects, and where its boundary remains.
01 · account access
Password plus mandatory TOTP two-factor authentication; recovery codes are available for recovery sign-in.
Sessions use an opaque cookie, expire after 30 minutes idle or 8 hours absolutely, and can be revoked.
Recovery codes are single-use and stored as keyed hashes. No security control makes an account invulnerable.
02 · buyer details
Buyer masking withholds buyer-identifying facts from the client; it fails closed when the setting is absent or unreadable.
A separate display-blur treatment changes how visible content looks on screen. It does not replace masking or change stored data.
Unmasked buyer-data disclosure creates an audit row recording who, when, and which order—not the disclosed values.
03 · retention boundary
Buyer name, address, and contact facts are redacted 90 days after fulfillment or dispute closure.
The clock uses the later of fulfillment and dispute closure, while an open dispute or pending/active legal hold pauses it.
Ninety days is a floor, not a guaranteed erasure date. The retention window is fixed; stores cannot change it.
04 · backups and restore
Backups are encrypted, read back, decrypted, authenticated, and checked against their manifest when created.
Backups contain inventory, mappings, settings, and redacted audit facts; credentials, sessions, MFA material, messages, and buyer addresses are excluded.
Restore needs two separate approval steps and recent reauthentication. Verification at creation is not a promise that every restore will succeed.
05 · scan photos
The scan photo goes to api.brickognize.com for recognition. Saving it for a future in-house recognizer starts unticked on every scan.
Without consent, the photo is not kept. Consented photos can be deleted from the privacy settings danger zone.
Deletion is account-wide and irreversible, with no per-photo choice; it cannot untrain a model that already used a photo. There is no automatic retention sweep.
06 · connected services
BrickLink is used for marketplace reads when that connection is active. Its requests are credentialed and scoped to the supported read flow.
BrickLink is a user-directed marketplace, not automatically a Brick Pulse data processor. Pirate Ship is a CSV upload path, not an API integration.
Marketplace writes remain disabled and shadow-only in this preview. No live synchronization or write outcome is promised.
07 · questions and reports
Email support@brickpulse.app with the task, screen, and exact error wording, after removing passwords, payment details, recovery codes, buyer exports, and other private data. This is an inbound reporting channel; the preview does not promise a response time or a public incident program.
Read the Privacy PolicyRead the Terms of ServiceReview provider boundaries