Privacy Policy
Last updated: March 16, 2026
1. Introduction
Brieflo ("we", "us", "our") is a vendor brief management platform for small and medium businesses. We are committed to protecting your personal data and respecting your privacy in accordance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
This Privacy Policy explains how we collect, use, store, and share your personal data when you use our platform at brieflo.app and related services.
2. Data Controller
Brieflo is the data controller responsible for your personal data.
- Email: [email protected]
- Website: https://brieflo.app
If you have any questions about this policy or our data practices, please contact our Data Protection Officer at [email protected].
3. Data We Collect
3.1 Account Data
When you create an account, we collect your email address, full name, and optionally your job title, phone number, and profile picture. If you sign up via Google OAuth, we receive your name and email from Google.
3.2 Workspace and Project Data
We store workspace names, project briefs, proposals, milestones, comments, files, vendor information, and other content you create within the platform. Brief sections are stored as structured JSON data.
3.3 Payment Data
Payment information (credit card details, billing address) is processed directly by Stripe and is never stored on our servers. We retain only transaction references and subscription status.
3.4 Usage Data
We collect information about how you interact with our platform, including pages visited, features used, browser type, device information, IP address, and referring URLs. This data is collected via PostHog analytics only when you have consented to analytics cookies.
3.5 Cookies and Similar Technologies
We use cookies and similar technologies as described in our Cookie Policy.
4. Legal Basis for Processing
Under GDPR, we process your personal data based on the following legal grounds:
- Contract Performance (Art. 6(1)(b)): Processing necessary to provide our services, manage your account, and fulfill our contractual obligations.
- Consent (Art. 6(1)(a)): For analytics cookies, marketing communications, and optional data processing. You may withdraw consent at any time.
- Legitimate Interest (Art. 6(1)(f)): For security monitoring, fraud prevention, service improvement, and customer support. We balance our interests against your rights.
- Legal Obligation (Art. 6(1)(c)): To comply with tax, accounting, and other regulatory requirements.
5. How We Use Your Data
- Providing, maintaining, and improving our platform
- Managing your account and workspace
- Processing payments and managing subscriptions
- Sending transactional emails (account verification, password resets, project notifications)
- Providing customer support
- Analyzing usage patterns to improve our product (with consent)
- Detecting and preventing security incidents
- Complying with legal obligations
6. Data Sharing and Third-Party Processors
We do not sell your personal data. We share data with the following trusted service providers who act as data processors on our behalf:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU/US |
| Stripe | Payment processing | US |
| PostHog | Product analytics (with consent) | EU |
| Resend | Transactional email delivery | US |
| Sentry | Error monitoring and reporting | US |
All processors are bound by Data Processing Agreements (DPAs) that ensure GDPR-compliant handling of your data.
7. International Data Transfers
Some of our processors are based in the United States. For transfers outside the European Economic Area (EEA), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, or other approved transfer mechanisms to ensure your data remains protected.
8. Data Retention
- Account data: Retained for the duration of your account. Deleted within 30 days of account deletion.
- Project data: Retained for the duration of your account. Soft-deleted projects are permanently removed after 90 days.
- Payment records: Retained for 7 years to comply with tax and accounting regulations.
- Analytics data: Aggregated and anonymized after 26 months.
- Server logs: Retained for 90 days for security purposes.
- Support correspondence: Retained for 3 years after resolution.
9. Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of Access (Art. 15): Request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
- Right to Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten").
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to Restriction (Art. 18): Request that we limit the processing of your personal data.
- Right to Object (Art. 21): Object to processing based on legitimate interests or for direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
10. How to Exercise Your Rights
You can exercise your data rights in the following ways:
- Self-service: Use the Privacy & Data section in your account Settings to export or delete your data.
- Email: Send a request to [email protected]. We will respond within 30 days.
- Cookie preferences: Update your cookie settings at any time using the cookie settings button in our website footer.
We may ask you to verify your identity before processing your request. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.
11. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Row-level security (RLS) policies on all database tables
- Regular security audits and vulnerability assessments
- Access controls and principle of least privilege
- Automated backup and disaster recovery procedures
12. Children's Privacy
Brieflo is a business-to-business service and is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that data promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by posting the updated policy on our website and, where appropriate, by email. We encourage you to review this policy periodically.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:
- General privacy inquiries: [email protected]
- Data Protection Officer: [email protected]
- Support: [email protected]