Privacy Policy
Brieflin™ helps people turn source material into structured, shareable AI-powered context packages called Briefs™. This Privacy Policy explains how Brieflin (“Brieflin,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you visit our websites, create or use a Brieflin account, create or receive a Brief, communicate with us, or otherwise use our services (collectively, the “Services”).
This Policy applies to personal information that Brieflin controls. When an organization uses Brieflin to process information on its behalf, that organization may be the data controller or business, and Brieflin may act as its processor or service provider. In those cases, the organization’s privacy notice may also apply, and requests concerning information placed in a Brief may need to be directed to that organization.
1. Information we collect
Information you provide
We may collect:
- Account information, such as your name, email address, password credentials managed by our authentication provider, organization, job role, profile image, and account preferences.
- Billing information, such as plan, billing address, transaction identifiers, and limited payment details. Payment card information is processed by our payment provider and is not stored directly by Brieflin.
- Brief content, including text, notes, files, images, spreadsheets, documents, email content, conversation excerpts, project information, people and organizations, decisions, timelines, tasks, financial or deal information, and other materials you choose to add.
- Prompts and conversations, including questions submitted to a Brief, generated answers, feedback, and citations.
- Connection information, when you connect a third-party service, such as provider identity, connected account, authorized scopes, import selections, and synchronization status. Authentication tokens are handled through protected server-side systems.
- Communications, including support requests, survey responses, product feedback, sales communications, and other correspondence.
- Privacy requests, including the information needed to verify and complete a request.
Information collected automatically
We may collect:
- device and browser type;
- operating system;
- IP address and approximate location derived from it;
- pages and features used;
- referring URL and campaign attribution;
- timestamps, session activity, and diagnostic events;
- cookie and consent preferences;
- security, fraud-prevention, and authentication events;
- interaction with shared Briefs, such as approximate views and questions asked.
We do not intentionally send private Brief content, source text, filenames, questions, answers, financial values, participant names, or email addresses to third-party advertising analytics.
Information from third parties
We may receive information from:
- authentication providers when you use social sign-in;
- payment processors;
- services you authorize Brieflin to connect to;
- an organization that creates or manages your account;
- a person who includes information about you in a Brief;
- service providers supporting security, hosting, analytics, customer support, and communications.
2. How we use information
We use personal information to:
- provide, operate, and secure the Services;
- create, process, organize, search, and share Briefs;
- generate source-grounded summaries, structured knowledge, answers, and citations;
- authenticate users and maintain accounts;
- process subscriptions and transactions;
- honor sharing permissions and access controls;
- import information from services you authorize;
- personalize product settings and suggested workflows;
- provide customer support;
- monitor performance, prevent abuse, troubleshoot, and improve reliability;
- understand product adoption using appropriately limited analytics;
- communicate service, security, billing, and product updates;
- comply with law and enforce our agreements;
- establish, exercise, or defend legal claims;
- develop and improve Brieflin, subject to contractual commitments and your settings.
Brieflin will not use Customer Content to train generalized third-party AI models unless the applicable customer has expressly opted in and the relevant terms permit it. AI providers may process content solely to provide contracted functionality, subject to their applicable data-processing terms and Brieflin’s configuration.
3. Legal bases for processing
Where applicable law requires a legal basis, we rely on:
- Contract, when processing is necessary to provide the Services you request.
- Legitimate interests, such as securing, operating, supporting, and improving the Services, provided those interests are not overridden by your rights.
- Consent, including for certain cookies, marketing communications, connected services, or optional processing.
- Legal obligation, when processing is required to comply with law.
- Legal claims and vital interests, where applicable.
You may withdraw consent at any time. Withdrawal does not affect processing already performed and may prevent certain optional features from working.
4. How we disclose information
We may disclose personal information:
- To service providers and subprocessors that provide hosting, databases, authentication, storage, AI processing, file processing, security, analytics, support, communications, and payment services.
- At your direction, including when you publish a Brief, share a link, connect a service, invite a user, or otherwise choose to disclose information.
- To your organization, if your account is managed by an employer or other organization.
- For legal and safety reasons, when reasonably necessary to comply with law, protect people or rights, investigate fraud or security incidents, or enforce agreements.
- In a business transaction, such as a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate protections.
- With professional advisers, such as attorneys, auditors, insurers, and accountants.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising. If our practices change, we will update this Policy and provide any legally required choices before the change applies.
An up-to-date list of material subprocessors will be available at https://brieflin.com/legal#subprocessors.
5. AI processing
Brieflin uses artificial intelligence to organize source material, identify structured context, support conversational questions, and generate answers with supporting evidence.
AI output may be incomplete, inaccurate, outdated, or reflect conflicts in source material. Users should review important information before relying on it. Brieflin is not a substitute for legal, financial, investment, accounting, engineering, environmental, medical, or other professional advice.
We may send the minimum information reasonably needed to configured AI providers to perform a requested feature. We use contractual and technical controls intended to limit provider use of that information. Do not upload information you lack permission to process or share.
8. Data retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, satisfy contractual commitments, maintain security, resolve disputes, and comply with legal obligations.
Retention depends on the type of information:
- account information is generally retained while the account remains active and for up to 30 days afterward;
- Customer Content is generally retained until deleted by an authorized user, account deletion, or contract termination, plus a limited backup period of up to 35 days;
- security and system logs are generally retained for up to 12 months;
- billing and transaction records may be retained for legally required periods;
- privacy-request records may be retained to demonstrate compliance.
Deleted information may remain temporarily in encrypted backups until those backups rotate. We may retain deidentified or aggregated information that cannot reasonably identify you.
9. Security
We use administrative, technical, and organizational safeguards designed to protect personal information. These may include access controls, encryption in transit, protected storage, credential management, logging, monitoring, secure software-development practices, and vendor review.
No system is completely secure. You are responsible for maintaining the confidentiality of your credentials, using appropriate sharing controls, and notifying us of suspected unauthorized access. Report security concerns to security@brieflin.com.
10. International transfers
Brieflin and its service providers may process information in countries other than the country where you live. Where required, we use recognized transfer mechanisms and safeguards, which may include adequacy decisions, standard contractual clauses, and supplementary measures.
Contact privacy@brieflin.com for additional information about applicable transfer safeguards.
11. Your rights and choices
Depending on your location, you may have rights to:
- know or access personal information;
- correct inaccurate information;
- delete information;
- obtain a portable copy;
- object to or restrict processing;
- withdraw consent;
- opt out of sale, sharing, or targeted advertising where applicable;
- limit certain uses of sensitive personal information where applicable;
- appeal a denied request;
- complain to a data-protection authority.
Use Your Privacy Choices in the footer or email privacy@brieflin.com. We may need to verify your identity and authority. Authorized agents may submit requests where permitted by law. We will not discriminate against you for exercising privacy rights.
If Brieflin processes information on behalf of a customer organization, we may direct your request to that organization.
12. U.S. state privacy disclosures
Subject to applicable law, the categories of personal information we may collect include identifiers, customer records, commercial information, internet or electronic activity, approximate geolocation, professional information, inferences, account credentials, and content you choose to provide.
We collect and disclose these categories for the business purposes described above. The categories of recipients are described in How we disclose information.
Brieflin does not sell personal information for money and does not share personal information for cross-context behavioral advertising. If applicable technology is introduced, we will provide required notice and opt-out controls before using it.
We use sensitive personal information, if any, only as reasonably necessary to provide requested services, maintain security, process authorized content, and comply with law, unless we provide a separate notice and choice.
13. Children
The Services are not directed to children under 13, or a higher minimum age where required by local law. We do not knowingly collect personal information from children in violation of applicable law. Contact privacy@brieflin.com if you believe a child has provided information improperly.
14. Third-party services
The Services may link to or integrate with third-party services. Their privacy practices are governed by their own notices. Connecting a service authorizes Brieflin to access information within the scopes you approve. You can disconnect supported integrations through your account settings.
15. Changes to this Policy
We may update this Policy to reflect changes in the Services, law, or our practices. We will update the date above and provide additional notice when required. Material changes will apply prospectively unless otherwise permitted by law.
16. Contact us
Privacy questions and requests: privacy@brieflin.com
Legal notices: legal@brieflin.com
Security reports: security@brieflin.com