Privacy policy

Your privacy

BriefMe stores as little as the product needs, keeps it for a stated length of time, and never sells it. This page says exactly what we hold, why, and how to make us stop.

Last updated: 2026-08-27

1. Who is responsible for your data

Lignologic Solutions LLC, a company formed in Wisconsin, at USA, is the controller of the personal data described on this page. For anything in this policy — including a request to access or delete your data — write to support at briefme.us .

2. What we store

We store only what running the product requires, grouped here by category.

  • Agenda content. Whatever you or your assistant give us to build the agenda: its title, each block's title, description and duration, and — when creation went through the connector — the original text you described the meeting in (raw_input).
  • Agenda access tokens. The share_token that opens the read-only view and the edit_token that unlocks the owner page, plus the timer's current position (which block, and since when).
  • Web server access logs. IP address, user agent, requested path and timestamp for every request. Paths that carry credentials, such as /edit/*, are redacted in the log.
  • Analytics. We run our own, self-hosted Matomo instance, configured to track without cookies and with your IP address anonymised before it is stored. This data never leaves our own server, and no third-party analytics or advertising script runs on any page.
  • Accounts. Signing in is optional and goes through Google or Microsoft. We store the provider's name, the stable account id it gives us, your name and email address as the provider reports them, and your avatar URL. No passwords exist anywhere in this system. Authorizing an assistant connector (such as Claude) to act on your account issues it an OAuth access token through our authorization server; disconnecting the connector, or letting the token expire, ends that access.
  • Feedback submissions. What you write on the feedback board or send us by email, plus the email address only if you chose to give one, and a one-way keyed hash of the IP address the submission came from, used only to rate-limit abuse — the address itself is never stored.
  • Cookies. All of ours are strictly necessary — nothing optional, nothing tracking-related: the per-agenda owner cookie (proves you hold the edit link), the bm_voter cookie (stops one browser voting twice on the feedback board), and Laravel's session and CSRF cookies. The server-side session record behind the session cookie includes your IP address and browser user agent for the session's lifetime.
  • Billing. If you subscribe to Plus, we keep your subscription status, current billing period end, the identifiers Stripe gives us for that subscription, and a record of the billing events Stripe notifies us of. Card details are entered on Stripe's own hosted checkout page — BriefMe never sees your card number, only the card's brand and last four digits, which Stripe passes back so you can recognise the card on file.
  • Brand logos (Plus). A logo you upload for your agenda pages is stored on Cloudflare R2 and served from a public assets domain. A logo you upload is public by design — anyone with the link to your agenda can load it, the same way they can already see the agenda it brands.

3. Why we process it

We do not rely on consent for any of the processing described on this page — which is also why there is no cookie banner: there is nothing on this site that consent would be the legal basis for. We rely instead on legitimate interest to operate the service, keep it secure, and understand product usage through analytics; and on contract to bill and provide a Plus subscription to the people who buy one.

4. How long we keep it

  • An anonymous agenda — one nobody has signed in to claim — is deleted 7 days after it was created, on a schedule, with no manual step and no way to extend it short of signing in and claiming it.
  • An agenda attached to an account is retained until you delete it, or release it back to anonymous (after which the ordinary 7-day clock applies again).
  • Web server access logs are kept for 30 days and then rotated out.
  • Feedback submissions are kept while open, and for 12 months after the item is closed.
  • Billing records are kept for as long as accounting and tax obligations require.
  • Matomo's raw visit data is kept for 180 days and purged automatically after that; aggregated reports are retained longer so we can see trends without holding raw request data indefinitely.

5. Who else sees it

We share data with the infrastructure providers that make the service work, and with nobody else. Those providers are: Hetzner (hosting), Cloudflare (DNS, CDN and proxy, and R2 storage for Plus logo uploads), Stripe (payments), our transactional mail provider, and — only for users who choose to sign in — Google or Microsoft (identity). Agenda content also reaches BriefMe through your own assistant provider (Anthropic's Claude, or whichever you connect) when it calls our tools on your behalf; that provider is your processor, not ours, and BriefMe itself sends your data to no language model at all — we only store and time what your assistant already built.

6. Where your data lives

Data is stored at rest on servers in Germany. Lignologic Solutions LLC is a United States entity, so personal data is also accessible from the US by the staff who operate the service.

7. Your rights under GDPR

If GDPR applies to you, you have the right to access, correct, erase, restrict or object to our processing of your data, and the right to receive it in a portable format. You also have the right to lodge a complaint with your local data protection supervisory authority. In practice, the fastest route for an anonymous agenda is to delete it yourself from the owner page — you hold the only key, so we cannot do it faster than you can; failing that, email us the share token and we will locate and delete it. If your account has a live subscription, it must be canceled before the account itself can be deleted — our billing records are kept linked to an account on purpose, so a subscription in payment cannot be silently orphaned; cancel it from the billing page first and the deletion then proceeds normally.

8. Your rights under CCPA/CPRA

If you are a California resident, you have the right to know what personal information we hold about you, to delete it, to correct it, to opt out of its sale or sharing, to limit the use of sensitive personal information, and to not be discriminated against for exercising any of these rights. We do not sell or share personal information — "sell" and "share" here carry the meaning CCPA gives them, and neither happens: we run no advertising network, no data broker relationship and no third-party analytics or advertising script anywhere on the site. That is also what keeps this sentence true on a free agenda that shows a sponsor screen: the sponsor screen is capped by localStorage on your own device, with no cookie, no ad network, and nothing personalised or shared about you to make it happen.

9. Children

BriefMe is not directed to children, and accounts are not offered to anyone we know to be under the age required by their jurisdiction to consent to this kind of service on their own.

10. Changes to this policy

When this policy changes, we update it in place and change the date at the top — we do not keep a separate changelog for legal text. The Last updated date at the top of this page is the record of when it last changed; check back here if you want to know.

See also Terms of service.