Privacy Policy
Last updated: September 17, 2026
What we collect
- Account data: email, optional name, timezone, plan, billing status and interval, add-on counts, trial end date, and the identifiers Polar assigns to your customer record and subscription (payment details are held by Polar, never by us).
- Product data: your watchlists, tracked sources, keyword filters, Slack webhook URLs, digest history.
- Signup data: the answers you give when setting up your first brief — your role, and your company name if the brief is for a team or for clients — the campaign parameters the link you arrived on carried (utm_source, utm_campaign, utm_content or ref), and the country your timezone implies. The answers are optional and can be skipped; the parameters come from the link, not from you. All of it is held on your account record.
- Analytics data: two page-view counters run on these pages, and both report in aggregate. Cloudflare Web Analytics is added by Cloudflare to every page we serve, at the edge — it is their script rather than one we install — and reports the country, host, path, referring link, browser, operating system, device type and navigation type of a page view. Cloudflare states that it uses no client-side state, “like cookies or localStorage”, for analytics, and that it does not track visitors over time by IP address or user-agent string. Vercel Web Analytics is loaded by this site and stores, per page view, the time, the URL and its route pattern, the referring link, filtered query parameters, an approximate location, and the browser, operating system and device type. Vercel states that it uses no third-party cookies — a visitor is identified by a hash derived from the incoming request, discarded after 24 hours — and that it collects no identifier that would follow you to another site. Neither is connected to your account. The one thing we add is a named event when a button on a marketing page is pressed, carrying which button it was and what the link you arrived on already said — the same utm_source and utm_content described above, and the industry beat the link named; no name, email or account identifier is attached to it.
- Content data: structured insights derived from publicly available sources — videos, podcasts, blogs, changelogs, public regulatory filings and job postings (each ≤2 sentences, with a link to the source). Raw transcripts are processed transiently and deleted within 7 days. We never download or store audio or video files ourselves; when a podcast has no published transcript, its public audio URL may be passed to a speech-to-text provider (see Processors).
How we use it
To operate the service: ingesting the sources you chose, generating digests, sending the emails you double-opted into, and billing. The signup data above is used for a second, separate purpose: understanding who Briefwire is for, and contacting prospective customers about it — your role and company tell us which kind of reader you are, and the campaign parameters tell us which message you arrived on. It changes nothing about the brief you receive. We don't sell personal data or use it for advertising.
Legal basis. Operating the service and billing for it is performance of our contract with you (GDPR Art. 6(1)(b)). Sending digest and brief emails rests on your consent, given by double opt-in and withdrawable at any time (Art. 6(1)(a)). Using signup data to understand who Briefwire is for, and to contact you about it, rests on our legitimate interest in developing the product (Art. 6(1)(f)); you can object to that use at any time by emailing us, and we stop. The two page-view counters rest on the same legitimate interest (Art. 6(1)(f)): knowing which pages are read and which buttons are pressed is how the site gets written, and it is the reason they are the aggregate, no-cross-site-profile kind rather than the kind that follows a reader. The same objection covers them.
Processors
We use Supabase (database & auth), Vercel (hosting, and the second of the two page-view counters above), Cloudflare (the CDN in front of the site, and the first of those counters, which it injects itself), Polar (payments, acting as merchant of record), Resend (email), transcript providers (Supadata / Apify / TranscriptAPI — they receive only public video identifiers), a speech-to-text provider (Together AI — for podcasts with no published transcript it receives the episode's public audio URL, never your personal data), and an LLM provider (OpenAI, Anthropic, or Google — they receive transcript text, never your personal data). Public data sources we read from (SEC EDGAR, the Federal Register, public job boards) receive our requests, not your data.
Where your data is processed
Our database and hosting are in the United States (Supabase, us-east-1; Vercel), and the processors above are largely US companies, so if you are in the EU, EEA, UK or Switzerland your personal data is transferred outside your region. Each transfer is covered by the processor's data processing agreement, which incorporates the EU standard contractual clauses (and the UK addendum where it applies); several of these processors are also certified under the EU–US Data Privacy Framework. Email us for a copy of the clauses that apply to you.
Your rights (GDPR)
- Export: download a complete JSON export of your data from Settings → Data.
- Deletion: delete your account from Settings → Data. This cascades: profile, watchlists, team memberships, and digest history are permanently removed.
- Rectification & objection: email us and we'll handle it within 30 days.
Email consent
Digest emails use double opt-in: nothing is sent until you confirm via the link we email you. Every digest includes a manage-preferences link, and you can pause or stop digests in Settings at any time.
Retention & security
Account and signup data are kept while your account exists. Raw transcripts are deleted within 7 days of processing by a scheduled job. Data is encrypted in transit and at rest; database access is protected by row-level security.
Contact
Data controller: Briefwire. Privacy requests: [email protected]