← Back to Home

Legal

Privacy Policy

Last updated July 31, 2026

1. Overview

This Privacy Policy explains what information Bref collects, how we use it, and what choices you have. Bref's entire product is built around handling your email newsletters, so we're deliberately specific below about what that involves.

2. Information we collect

Account information

Name, email address, your chosen bref handle, and a hashed (never plaintext) password.

Newsletter content

Every email sent to your @mail.brefdigest.com address — sender, subject, and full body (text and HTML) — is stored so it can be summarized and shown to you in your dashboard.

Digest content

The AI-generated summaries, groupings, and metadata (token usage, timestamps) produced for each digest.

Digest feedback

If you rate or comment on a digest, that rating/comment — along with the digest itself and the newsletters it was built from — is shared internally with the Bref team so we can review it. This only happens for a digest you've actively chosen to submit feedback on.

Billing information

If you subscribe to Pro, payment is handled entirely by Stripe — we never see or store your card details. We keep a reference to your Stripe customer/subscription ID and a summary of your billing history (amount, tax charged, renewal date) to show it back to you in Settings. Stripe, as our payment processor, retains full transaction records independently, as required by its own tax and financial recordkeeping obligations.

Usage data

Login timestamps, digest delivery history, and basic request metadata (e.g. IP address, for rate-limiting and abuse prevention).

3. How we use your information

We do not sell your personal information, and we do not use your newsletter content to train AI models.

4. Who we share it with

We share data only with the service providers needed to run Bref, each bound by their own data-processing terms:

ProviderPurposeWhat they see
PostmarkReceiving and sending emailNewsletter content, digest content, your email address
Anthropic (Claude)AI summarizationNewsletter content, your custom digest instructions (Pro)
StripePayment processingBilling/payment details (we never receive your card number)
RailwayApplication hosting and databaseAll account and application data, as our infrastructure provider
CloudflareDNS and domain routingDomain/routing metadata only

Newsletter senders themselves may also see a normal email-open signal when Bref loads a tracking image on your behalf (see "How we use your information" above) — the same signal they'd see if you opened their email directly. This doesn't share any Bref account data with them beyond what that open signal already reveals (typically your IP address and approximate location, the same as any email open).

We don't share your data with advertisers, and we don't run third-party analytics or ad-tracking on Bref.

5. Data retention and deletion

We keep your data for as long as your account is active. When you delete your account from Settings, it's marked for deletion and kept for a 30-day grace period (in case of accidental deletion), after which your digests, stored emails, and account data are permanently and irreversibly deleted from our systems. If you had an active Pro subscription, deleting your account also cancels it immediately with Stripe.

One exception: transaction and billing records (e.g. invoices, tax collected) are retained by Stripe, as our payment processor, for as long as its own legal and tax recordkeeping obligations require — this is independent of your Bref account and outlasts account deletion, the same way a receipt from any other purchase would.

6. Your choices and rights

If you're located in the EEA, UK, or California, you may have additional rights under GDPR or CCPA (e.g. the right to object to processing, or to data portability) — the mechanisms above cover the practical exercise of those rights, and you can also reach us directly with any request.

7. Security

Passwords are hashed, not stored in plaintext. Access to your account requires a signed authentication token, and changing your password invalidates any other active sessions. No system is perfectly secure, but we take reasonable technical and organizational measures to protect your data.

8. Children's privacy

Bref is not directed at children under 16, and we don't knowingly collect data from them.

9. Changes to this policy

If we make material changes to this policy, we'll notify you (for example, by email or a notice on brefdigest.com) before they take effect.

10. Contact

Questions about this policy or a request regarding your data? Reach out via the contact form on our About page.