← Back to Home

Legal

Privacy Policy

Last updated August 29, 2026

1. Overview

This Privacy Policy explains what information Bref collects, how we use it, and what choices you have. Bref's entire product is built around handling your email newsletters, so we're deliberately specific below about what that involves. "Service" below has the same meaning as in our Terms of Service.

2. Information we collect

Account information

Name, email address, your chosen bref handle, and a hashed (never plaintext) password.

Newsletter content

Every email sent to your @mail.brefdigest.com address — sender, subject, and full body (text and HTML) — is stored so it can be summarized and shown to you in your dashboard.

Digest content

The AI-generated summaries, groupings, and metadata (token usage, timestamps) produced for each digest.

Digest feedback

If you rate or comment on a digest, that rating/comment — along with the digest itself and the newsletters it was built from — is shared internally with the Bref Team so we can review it. This only happens for a digest you've actively chosen to submit feedback on.

Billing information

If you subscribe to Pro, payment is handled entirely by Stripe — we never see or store your card details. We keep a reference to your Stripe customer/subscription ID and a summary of your billing history (amount, tax charged, renewal date) to show it back to you in Settings. Stripe, as our payment processor, retains full transaction records independently, as required by its own tax and financial recordkeeping obligations.

Referral program

If you refer another user or are referred by one, we store which accounts are linked, the referral's status, and — for reward verification and fraud review only — the last four digits and brand of the card used to complete the referred subscription. We never see or store the full card number, which Stripe alone retains.

Usage data

Login timestamps, digest delivery history, whether a digest email was opened (see below), and basic request metadata (e.g. IP address, for rate-limiting and abuse prevention) are retained.

3. How we use your information

We do not sell your personal information, and we do not use your newsletter content to train AI models.

4. Who we share it with

We share data only with the service providers needed to run Bref, each bound by their own data-processing terms:

ProviderPurposeWhat they see
PostmarkReceiving and sending emailNewsletter content, digest content, your email address
Anthropic (Claude)AI summarizationNewsletter content, your custom digest instructions (Pro)
StripePayment processingBilling/payment details (we never receive your card number)
Our hosting and infrastructure providersApplication hosting, database, and domain/network routingAccount and application data as needed to operate the Service

In addition to these third-party providers, the Bref Team can access account and content data through internal administrative tools — for example, to investigate a support request you've submitted, review digest-quality feedback you've submitted (see "Digest feedback" above), or diagnose a delivery issue. This access is limited to what's needed for these purposes and isn't used to read your newsletters or digests for any other reason.

Newsletter senders themselves may also see a normal email-open signal when Bref loads a tracking image on your behalf (see "How we use your information" above) — the same signal they'd see if you opened their email directly. This doesn't share any Bref account data with them beyond what that open signal already reveals (typically your IP address and approximate location, the same as any email open).

We don't share your data with advertisers, and we don't run third-party analytics or ad-tracking on Bref.

5. Data retention and deletion

We keep your data for as long as your account is active. When you delete your account from Settings, it's marked for deletion and kept for a 30-day grace period (in case of accidental deletion) — during that window, signing back in with your original email and password reactivates your account, with all of your data intact. After 30 days, your digests, stored emails, and account data are permanently and irreversibly deleted from our systems. If you had an active Pro subscription, deleting your account also cancels it immediately with Stripe.

One exception: transaction and billing records (e.g. invoices, tax collected) are retained by Stripe, as our payment processor, for as long as its own legal and tax recordkeeping obligations require — this is independent of your Bref account and outlasts account deletion, the same way a receipt from any other purchase would.

6. Your choices and rights

If you're located in the EEA, UK, or California, you may have additional rights under GDPR or CCPA (e.g. the right to object to processing, or to data portability) — the mechanisms above cover the practical exercise of those rights, and you can also reach us directly with any request.

7. Security

Passwords are hashed, not stored in plaintext. Access to your account requires a signed authentication token, and changing your password invalidates any other active sessions. No system is perfectly secure, but we take reasonable technical and organizational measures to protect your data.

8. Children's privacy

Bref is not directed at children under 16, and we don't knowingly collect data from them.

9. Changes to this policy

If we make material changes to this policy, we'll notify you (for example, by email or a notice on brefdigest.com) before they take effect.

10. Contact

Questions about this policy or a request regarding your data? Reach out via the contact form on our About page.