Legal
Privacy Policy
Last updated: 1 April 2026
1. Who we are
Briefd ("we", "our", "us") operates the website at briefd.uk and the Briefd AI meeting-preparation platform. We are registered in England and Wales. For data protection enquiries, contact us at support@briefd.uk.
2. What data we collect
- Account data: name, email address, and password (hashed) when you register.
- Billing data: payment method details are processed and stored by Stripe — we never see your full card number.
- Brief inputs: names and company names you enter to generate research briefs.
- Brief outputs: the AI-generated summaries, icebreakers, and talking points we store for your brief history.
- Usage data: how many briefs you have generated, timestamps, and which features you use.
- Technical data: IP address, browser type, and device information collected automatically for security and analytics.
- Calendar data (optional): if you connect Google Calendar, we access event titles and attendee names to auto-generate briefs. We do not read email.
3. How we use your data
- To provide, maintain, and improve the Briefd service.
- To process payments and manage your subscription via Stripe.
- To send transactional emails (brief delivery, account notices) — not marketing unless you opt in.
- To detect and prevent fraud, abuse, and security threats.
- To analyse aggregate usage patterns and improve our AI models (we never use individual brief content for training without consent).
4. Legal basis for processing (GDPR)
- Contract performance: processing your account and brief data to deliver the service you paid for.
- Legitimate interests: security monitoring, fraud prevention, and product analytics.
- Consent: optional features such as marketing emails and Google Calendar integration.
5. Third parties we share data with
- Supabase — database and authentication hosting (EU region).
- Stripe — payment processing. Subject to Stripe's own privacy policy.
- Vercel — hosting and CDN. Data processed in the EU/UK where possible.
- Anthropic / Z.AI — AI providers that process brief content to generate outputs. We use data processing agreements with all AI providers.
- Apify — web scraping for the Insider Deep Dive feature. Only processes publicly available information.
- Google — if you connect Google Calendar, Google processes that data under their own privacy policy.
We do not sell your personal data. Ever.
6. Data retention
- Free accounts: brief data is retained for 7 days then permanently deleted.
- Solo accounts: brief data is retained for 90 days.
- Pro and Team accounts: brief data is retained indefinitely while the account is active.
- Account data is retained for 30 days after account deletion to allow for recovery, then permanently purged.
7. Your rights (UK GDPR)
You have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Erase your data ("right to be forgotten") — you can delete your account from Settings → Danger Zone at any time.
- Restrict or object to processing in certain circumstances.
- Portability — receive your data in a machine-readable format on request.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, email support@briefd.uk. We respond within 30 days.
8. Cookies
We use the following cookies:
- Authentication cookies: set by Supabase to keep you logged in. Strictly necessary.
- Analytics: Vercel Analytics uses privacy-preserving, cookie-free analytics. No consent required.
We do not use advertising or tracking cookies.
9. Security
All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. We follow OWASP security guidelines, conduct regular dependency audits, and use row-level security in our database to ensure users can only access their own data.
10. Children
Briefd is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have done so, contact us immediately and we will delete the data.
11. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email to registered users at least 14 days before they take effect. The "last updated" date at the top of this page always reflects the current version.
12. Contact & complaints
For any privacy-related question, email support@briefd.uk.
If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.