← BRIEFMAKER

Privacy Policy

Last updated: July 22, 2026

This policy explains what data BRIEFMAKER collects, why we collect it, how we use it, and your rights over it. We keep this plain and direct — no legal fog.

01 Who We Are

BRIEFMAKER operates the BRIEFMAKER platform, an AI-powered tool for generating and managing image prompts for design briefs. We are the data controller for the personal data collected through the Service.

For privacy-related enquiries, contact us at privacy@briefmaker.ai.

02 Data We Collect

Account data

When you sign in via Google OAuth, we receive and store your name, email address, and profile picture URL as provided by Google. We do not store your Google password.

Usage data

We collect information about how you interact with the Service, including pages visited, features used, and actions taken (e.g. prompts created, filters applied).

User content

Prompts, briefs, design guidelines, questionnaire responses, and other content you create and save within the Service are stored on our servers to deliver the Service to you.

Technical data

We may collect your IP address, browser type, device type, operating system, and session identifiers for security and operational purposes. This data is not used for targeted advertising.

03 How We Use Your Data

PurposeData used
Provide and maintain the ServiceAccount data, User content
Authenticate your identityAccount data, Session identifiers
Improve and develop featuresUsage data (aggregated and anonymised)
Detect and prevent abuse or fraudTechnical data, Usage data
Respond to support requestsAccount data, User content
Send service communicationsEmail address

We do not sell your personal data. We do not use your data for targeted advertising.

We do not use your User Content to train AI models without your explicit consent.

05 Data Sharing

We do not sell or rent your personal data to third parties. We may share your data with:

  • Service providers — hosting, database, and infrastructure providers who process data on our behalf under data processing agreements.
  • Authentication providers — Google, for the purposes of sign-in only.
  • Law enforcement — where we are legally required to disclose data by applicable law, court order, or governmental authority.
  • Business transfers — in the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you before your data is transferred and becomes subject to a different privacy policy.

06 Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required by law to retain it longer.

Aggregated, anonymised usage data may be retained indefinitely as it cannot be used to identify you.

07 Security

We implement industry-standard security measures to protect your data, including encrypted connections (HTTPS/TLS), secure session management, and restricted database access controls.

No method of transmission over the internet is completely secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach that affects your rights, we will notify you as required by applicable law.

08 Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Correction — request that inaccurate data be corrected.
  • Deletion — request deletion of your personal data ("right to be forgotten").
  • Portability — request your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Restriction — request that we restrict processing of your data in certain circumstances.
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any of these rights, contact us at privacy@briefmaker.ai. We will respond within 30 days. We may need to verify your identity before processing your request.

09 Cookies

We use the following cookies:

  • Session cookies — essential for keeping you signed in. These are deleted when you close your browser.
  • Authentication tokens — persistent cookies used to maintain your logged-in state across sessions, expiring after 30 days.

We do not use third-party advertising or tracking cookies. You can control cookies through your browser settings, but disabling essential cookies will prevent you from using the Service.

10 Children's Privacy

The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided us with personal data, contact us at privacy@briefmaker.ai and we will delete it promptly.

11 Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and notify you via email or an in-app notice at least 7 days before the changes take effect.

Your continued use of the Service after the effective date of the revised policy constitutes acceptance of the changes.

12 Contact

For privacy questions, data requests, or complaints, contact our privacy team:

BRIEFMAKER — Privacy
privacy@briefmaker.ai

If you are located in the EU/EEA and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.