Privacy Policy
This translated version is provided for convenience. The English version is the legally binding one.
1. Overview
BriefPort ("we", "us", "our") operates a requirements management platform that helps development teams and clients collaborate on software project specifications. This Privacy Policy explains what data we collect, why we collect it, and your rights regarding that data.
By using BriefPort, you agree to the data practices described in this policy. If you do not agree, please do not use our services.
2. Data We Collect
2.1 Account Data
- Name, email address, and password (hashed via bcrypt)
- OAuth identifiers (if you sign in with Google/GitHub/Apple — we store only the ID, not your password)
2.2 Project & Evidence Data
- Project details (name, client info, budget, timeline)
- Uploaded files (chat screenshots, audio files, documents) — used for AI analysis
- AI-generated requirements, clarifications, and exported documents
2.3 Billing Data
- Subscription plan and payment status (processed by Creem — we do not store your credit card number)
- Billing email and invoice history
2.4 Usage & Technical Data
- IP address, browser type, access timestamps (for security and abuse prevention)
- API request logs (retained for 90 days)
3. How We Use Your Data
- Core service: Process your uploads, generate requirements, manage project workflows
- Communication: Send verification emails, project notifications, and customer support
- Billing: Manage your subscription and process payments via Creem
- Security: Detect fraud, abuse, and unauthorized access
- Improvement: Analyze aggregate usage patterns to improve features (never individual content)
We do not sell your data to third parties. We do not use your project content to train AI models — all AI processing uses third-party model providers (such as SiliconFlow, OpenAI, or other configured OpenAI-compatible providers) under their data processing agreements.
4. Data Sharing
We share data only with these categories of processors, under appropriate data processing agreements:
- AI Model Providers: To analyze your uploaded evidence and generate requirements. The specific provider depends on your instance configuration (e.g., SiliconFlow, OpenAI, or another OpenAI-compatible provider). Your data is sent for processing and is subject to the provider's retention policy.
- Payment Processor (Creem): To process subscription payments. Payment card data never touches our servers.
- Cloud Infrastructure: Object storage (Cloudflare R2 / S3), database hosting, and email delivery.
- Legal compliance: If required by law, court order, or to protect our rights and safety.
5. Data Retention
- Active accounts: All data retained while your account is active
- After cancellation: Data retained for 30 days, then permanently deleted (including all uploads, requirements, and exports)
- API logs: 90 days
- Audit logs: 7 years (for billing/legal compliance)
6. Your Rights (GDPR / CCPA)
You have the following rights regarding your personal data:
- Access: Request a copy of your data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Data Portability: Export your data in a machine-readable format
- Objection: Object to certain processing activities
- Withdraw Consent: Withdraw consent for optional data processing at any time
To exercise any of these rights, email us at privacy@briefport.io. We respond within 30 days.
7. Security
We protect your data with industry-standard measures: TLS encryption in transit, AES-256 encryption at rest, bcrypt password hashing, file type validation and security scanning on uploads, and IP-based rate limiting. Access to production data is restricted to authorized personnel under NDA.
8. International Transfers
Your data may be processed in countries other than your own (e.g., US cloud servers, Chinese AI model providers). We rely on Standard Contractual Clauses and provider DPA agreements to ensure appropriate safeguards for cross-border data transfers.
9. Children's Privacy
BriefPort is not intended for users under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be notified by email at least 30 days before taking effect.
11. Contact
Questions about this Privacy Policy? Email privacy@briefport.io.