Privacy Notice
Last updated 5 September 2026
This notice explains how Briefstarter, operated by Antonio Bortone, handles personal data. It is an editable first draft written for transparency, not certified legal advice.
Who is responsible
Antonio Bortone operates Briefstarter and acts as the data controller for the personal data described here. You can reach us at hello@getbriefstarter.com.
Where your data is stored
Accounts and application data are hosted on Lovable Cloud, which runs on Supabase (PostgreSQL database, authentication and storage) with hosting infrastructure in the European Union and the United States. These providers act as processors on our instructions.
Accounts and authentication
You can create an account with an email address and password, or sign in with Google. In either case we store your email address, an account identifier, the sign-in method, and timestamps for creation and last sign-in. Passwords are stored only as salted hashes by our authentication provider; we never see them. If you use Google sign-in, Google shares your email address and basic profile identifier with us.
Legal basis: performance of our contract with you.
Payments
Purchases are processed by Paddle.com, our online reseller and Merchant of Record. Paddle collects and processes your billing details, payment method and tax location directly; we do not receive or store card data. We store the resulting subscription status, plan, renewal or expiry dates, credit-pack purchases and the identifiers Paddle returns, so we can unlock the features you paid for.
Paddle is an independent controller for payment, invoicing and tax purposes and may retain invoices, transaction records and tax documentation for its own legal and accounting obligations even after you delete your Briefstarter account — typically for the statutory retention period applicable in the relevant jurisdiction (commonly up to 10 years). Deleting your account with us does not and cannot delete those records. See Paddle’s Buyer Terms.
Legal basis: contract performance and legal obligation.
AI brief generation
When you generate a brief, the discipline and difficulty you choose are sent to our server and then to our AI model provider, which writes the brief text. We do not send your name or email address with that request. Generated brief text is returned to your browser and is only stored if you save it.
Saved briefs
If you save a brief while signed in, the brief content and a timestamp are stored against your account so you can find it again. Only you can read your saved briefs; access is enforced at the database level. You can delete any saved brief at any time.
Usage records and abuse prevention
For every generation we record an event containing the discipline, difficulty level, model used, token counts, approximate cost and the time. This lets us enforce the one free brief for visitors who are not signed in and the monthly allowance on an account, detect abuse and understand cost.
For visitors who are not signed in, we do not store the raw IP address. We store a one-way, salted hash of it purely as an anonymous identifier for the one-free-brief limit. It is not used for profiling or advertising.
Legal basis: our legitimate interest in keeping the service available and preventing abuse.
Newsletter
The newsletter is not active yet. Once it is enabled, we will store the email address you submit and the date of your consent, use it only to send product updates about Briefstarter, and include an unsubscribe link in every message.
Legal basis: your consent, which you can withdraw at any time.
Cookies and local storage
We use only what the service needs to function: a session token so you stay signed in, a stored preference for light or dark appearance, an anonymous Briefstarter visitor cookie containing a random identifier that enforces the one free brief for people who are not signed in, temporary browser storage holding the brief you are currently looking at and any action you asked for before signing in (such as saving a brief or upgrading), and the checkout scripts Paddle needs to take a payment. We do not run advertising or cross-site tracking cookies.
Who we share data with
- Lovable Cloud / Supabase — hosting, database and authentication
- Google — only if you choose Google sign-in
- Our AI model provider — the brief request parameters and generated text
- Paddle — as Merchant of Record for sales, subscriptions, tax and invoicing
- Professional advisers (legal, accounting) where necessary
- Authorities where we are legally required to disclose
We do not sell personal data.
International transfers
Some providers process data outside the UK/EEA. Where that happens, transfers rely on adequacy decisions or Standard Contractual Clauses together with appropriate technical safeguards.
Retention
Account data and saved briefs are kept while your account exists. Records of briefs you generated are kept while your account exists, because they are what your monthly allowance and paid credits are counted from; they are removed when your account is deleted. Abandoned or failed generation attempts are deleted after 7 days. For visitors who are not signed in, the anonymous visitor identifier and the hashed network fingerprint of a brief that was actually generated are kept for as long as the one-free-brief limit applies, and are not linked to a name or email; other anonymous technical records are deleted after 90 days. We do not keep a network fingerprint at all for signed-in people. Subscription records are kept while a plan is active and afterwards for as long as needed for accounting.
Deleting your account
You can delete your account yourself at any time from the Danger zone on your account page, or by emailing hello@getbriefstarter.com. Deletion is permanent and immediate: your account, saved briefs, credit balance, usage records and the link between your account and your Paddle customer record are removed. Any running subscription is cancelled first, so you are never charged again; if that cancellation cannot be completed, nothing is deleted and we tell you so. As described above, Paddle keeps its own invoices and transaction records for legal and tax purposes.
Your rights
If you are in the UK or EEA you have the right to access, rectification, erasure, restriction, portability, objection, and to withdraw consent at any time. We respond within one month. You may also complain to your local data protection supervisory authority. Similar rights apply in many other jurisdictions.
Security
We apply appropriate technical and organisational measures: encryption in transit, row-level access rules so users can only read their own records, restricted server-side credentials, and least-privilege access to production systems. No system is perfectly secure, but we take this seriously.
Changes
We may update this notice as the product changes. The date at the top always shows the current version.