Privacy Policy

Last updated: Aug 4, 2026 · Starter policy; review with legal counsel before client contracts.

What we collect

Account information you provide (name, email, password), the content you create in Brieful (uploaded documents, interview answers, requirements, process flows, screen designs, and prototypes), and operational metadata (usage counts, security audit events such as sign-ins).

How we use it

Only to provide the service: to run the AI analysis, generate documents and prototypes, save your projects, secure your account, and meter usage. We do not sell your data and we do not use your content for advertising.

AI processing & training

Your content is processed by Anthropic's Claude API to generate analysis and prototypes. Your content is not used to train AI models. Anthropic does not train its models on data submitted through its API. Content is sent only as needed to produce your output.

Security

  • Encryption in transit (HTTPS/TLS) and at rest (database and hosting providers).
  • Passwords stored hashed with bcrypt; never stored or logged in plain text.
  • Per-account data isolation: you can only access your own projects.
  • Brute-force protection (account lockout) and a security audit log of key events.

Your data rights

You can export all your data (Account → Export my data) and permanently delete your account and associated data (Account → Delete account) at any time. You may also contact us to exercise access, correction, or deletion rights.

Data retention

Your projects are retained while your account is active. When you delete your account, your projects, prototypes, and settings are removed. Aggregate usage records may be retained for billing and security for a limited period.

Data processing agreement

Organizations requiring a Data Processing Agreement (DPA) or a sub-processor list for procurement can request one; email us below.

Contact

Questions about privacy, security, or a DPA? Email info@brieful.ai.