Privacy Policy
Last updated: August 23, 2026
In short: We only store what's necessary to provide the service. We never sell your data. Audio recordings are processed and immediately discarded.
1. Information We Collect
BriefPad collects minimal data to provide AI-powered meeting intelligence for freelancers:
- Account information: Name, email address, and hashed password — required for authentication.
- Client information: Names and company details of your clients that you manually enter.
- Interaction logs: Meeting notes, summaries, and commitments you create or dictate.
- Audio recordings: Voice memos uploaded for transcription. These are sent to our AI provider (Groq) for processing and never stored on our servers.
- Billing information: Processed by Stripe. We never see or store your credit card number.
2. How We Use Your Data
- To generate AI meeting briefings, summaries, and commitment tracking.
- To provide the Pre-Meeting Prep Score and client health insights.
- To authenticate your account and prevent fraud.
- To process payments through Stripe.
- To improve BriefPad's AI accuracy and product quality.
3. Audio Processing & Transcription
Audio recordings are sent to Groq's API for transcription and are immediately discarded after processing. We do not store, cache, or retain audio files.
When you upload a voice memo, the audio is transmitted to Groq's servers for real-time transcription. The transcription result is returned to BriefPad and stored as text. The original audio file is never saved to our database or file storage.
4. AI Processing
BriefPad uses Groq's AI models to generate meeting briefings, extract commitments, and analyze client health. Your interaction text is sent to Groq for processing. Groq does not use your data to train their models. AI-generated content is stored in your BriefPad account for your use.
5. Data Sharing
We do not sell, rent, or share your personal data with third parties except:
- Groq: For AI processing (transcription and language model inference). Data is processed in transit and not retained.
- Stripe: For payment processing. We only receive payment status, not card details.
- FastAPI Cloud: Our hosting provider, which stores our database. Data is encrypted at rest.
6. Data Security
- Passwords are hashed with bcrypt (one-way hashing).
- All communication uses TLS/HTTPS encryption.
- Authentication cookies are HttpOnly and Secure.
- Account lockout after 5 failed login attempts.
- Database connections are encrypted in transit.
- Content Security Policy headers protect against XSS attacks.
7. Data Retention
We retain your data for as long as your account is active. You may delete your account and all associated data at any time from Settings. Account deletion is permanent and irreversible.
8. Your Rights (GDPR)
If you are in the European Economic Area, you have the right to:
- Access your personal data.
- Correct inaccurate data.
- Delete your data (right to erasure).
- Export your data in a portable format.
- Object to data processing.
To exercise these rights, contact us at privacy@briefpad.app.
9. Cookies
We use only essential cookies for authentication. See our Cookie Policy for details.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email or in-app notification.
11. Contact
For privacy-related questions: privacy@briefpad.app