Privacy Policy

Privacy Policy

BriefKlar is committed to protecting your personal data. This policy explains what we collect, why we collect it, how we use it, and what rights you have under the GDPR and BDSG.

Effective: 1 March 2026·Updated: 1 March 2026·Law: Federal Republic of Germany
01

Data Controller

BriefKlar operates as the data controller for all personal data processed through briefklar.app. We are established in Hamburg, Germany and are subject to the GDPR and BDSG.

FieldDetail
ControllerBriefKlar
AddressHamburg, Germany
General emailcontact@briefklar.app
Data protection emailprivacy@briefklar.app
Websitebriefklar.app
Supervisory authorityDer Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (HmbBfDI)
Authority websitedatenschutz.hamburg.de
02

Personal Data We Collect

Account Data

  • Full name and email address (via Clerk authentication).
  • Preferred language and country settings.
  • Subscription tier (Free / Pro / Plus), billing status, billing interval.
  • Stripe Customer ID for subscription and payment management.

Document Data

  • Text content of uploaded letters, extracted via OCR or direct text input.
  • Uploaded files stored in encrypted private Supabase storage (letters-private bucket).
  • AI-generated analysis: authority, letter type, urgency, deadline, required actions, consequences.
  • AI-generated plain-language explanation and formal reply text.
  • Deadlines and calendar entries extracted from letter content.

Usage Data

  • Credit transaction history: credits debited, credited, purchased, referred, expired.
  • Feature usage: upload count, reply generation count, TTS/STT usage.
  • Session data: login timestamps, session duration.
  • IP address, browser type, device identifiers for security and rate limiting.

Payment Data

  • Payment data is processed exclusively by Stripe. BriefKlar does not store card numbers or credentials.
  • BriefKlar stores only Stripe Customer ID and Subscription ID.

Incognito Mode

  • When you use Incognito Mode (uncheck 'Save to history'), your document is processed and the result delivered, then permanently deleted within one hour.
  • No letter content is retained after deletion in incognito mode.
04

Third-Party Sub-Processors

BriefKlar uses the following sub-processors. Transfers outside the EEA use Standard Contractual Clauses (SCCs).

ProcessorPurposeData TransferredLocation
ClerkAuthentication and session managementEmail, name, session tokensUSA (SCCs)
SupabaseDatabase and file storageAll user data, letters, replies, filesEU (AWS Frankfurt)
AnthropicPrimary AI — letter analysis and replyLetter text (transient)USA (SCCs)
Groq / OpenAIAI fallback, Whisper STTLetter text / audio (transient)USA (SCCs)
StripePayment processingPayment method dataUSA (SCCs)
VercelApplication hostingRequest logs, IP addressesUSA / EU
Letter text sent to AI providers is transmitted transiently for analysis only. BriefKlar does not permit AI providers to use your content to train their models.
05

Data Retention

Data CategoryRetention PeriodReason
Account dataUntil account deletion, then 30 days in backupService provision
Free tier — no historyNot retainedFree tier design
Pro tier — document history50 documents · 7 days from uploadPro plan feature
Plus tier — document history150 documents · 30 days from uploadPlus plan feature
Incognito mode documentsDeleted within 1 hour of result deliveryPrivacy-by-design
Credit transaction audit log3 years from transaction dateFinancial record-keeping
Billing and payment records7 years from transaction date§ 147 AO German tax law
Server access logs90 daysSecurity and debugging
06

Your Rights Under GDPR

RightArticleHow to Exercise
Right of AccessArt. 15Request a copy of your data. Email privacy@briefklar.app.
Right to RectificationArt. 16Request correction of inaccurate data.
Right to ErasureArt. 17Request deletion. Via Settings → Delete Account, or email privacy@briefklar.app.
Right to RestrictionArt. 18Request restriction of processing.
Right to Data PortabilityArt. 20Receive your data in JSON format.
Right to ObjectArt. 21Object to processing based on legitimate interest.
Right to Lodge a ComplaintArt. 77Complain to Hamburg DPA — datenschutz.hamburg.de.
BriefKlar implements a GDPR Article 17 data erasure endpoint at /api/user/delete-data that removes all files, letters, replies, and credit records. Requests are fulfilled within 30 days. Billing records are retained for 7 years as required by German tax law.
07

Data Security

  • All data in transit is encrypted using TLS 1.2 or higher. HTTPS enforced.
  • Document files are stored in private Supabase storage (letters-private) with signed URLs.
  • Row Level Security (RLS) on all database tables — users only access their own data.
  • Security headers: CSP, HSTS, X-Frame-Options, Referrer-Policy.
  • Input sanitization before passing to AI providers.
  • Rate limits: uploads 10/hour, AI 20/hour, TTS/STT 30/minute, GDPR deletion 2/day.
08

Children's Privacy

BriefKlar is not directed at children under 18. We do not knowingly collect personal data from children. If you believe your child has provided data to BriefKlar, contact privacy@briefklar.app and we will delete it promptly.

Questions? privacy@briefklar.app

briefklar.app · Hamburg, Germany