Privacy Policy

Effective date: 2026-08-05

App: Brief — understand official letters ("the App")

Applies to: the iOS application distributed via the Apple App Store in Germany.

1. Controller

The controller within the meaning of Art. 4(7) GDPR is:

Vasile Piciriga
Odenwaldstr. 1
63820 Elsenfeld, Germany
E-mail: vasilepiciriga@gmail.com

We are established in Germany, so no representative under Art. 27 GDPR arises. For any question

about this policy or about your rights, write to the address above.

2. Our privacy approach in one paragraph

Brief is designed to be privacy-first. Text recognition (OCR) of your document photos happens entirely on your device. Only when you request an AI analysis is a sanitized text excerpt of the recognized text sent — through our own secure backend proxy — to an AI service for processing. Your documents are never stored on our servers after processing, and document content never appears in our logs. The App shows no advertisements. With your permission — and only then — it measures its own advertising through two advertising networks (Section 8); your letters, their text and your replies are never part of that measurement.

3. What data is processed, where, and why

3.1 Document photos and OCR text — on your device only

3.2 Text excerpts sent for AI analysis — via our backend proxy

3.3 Anonymous install identifier

3.4 Subscription status via Apple

3.5 Technical data strictly necessary for operation

3.6 What we do NOT do

4. Legal bases (Art. 6 GDPR)

ProcessingLegal basis
Providing the core service you request (OCR on device; AI analysis of text you submit; returning results; free-tier/fair-use accounting; subscription entitlement checks)Art. 6(1)(b) GDPR — performance of a contract / steps at your request
Security, abuse prevention, ensuring technical stability, defense of legal claimsArt. 6(1)(f) GDPR — legitimate interests (secure and reliable operation of the App; interests balanced against your rights, given the minimal data involved)
Sending recognised text to the AI service for analysisArt. 6(1)(a) and Art. 9(2)(a) GDPR — your explicit consent, requested before the first analysis that leaves your device and withdrawable at any time in Settings
Advertising measurement with the advertising identifier (attributing an installation and generic in-app milestones to our own advertisements via Meta and TikTok)Art. 6(1)(a) GDPR — your consent, given in the App Tracking Transparency prompt and withdrawable at any time in iOS Settings → Privacy & Security → Tracking
Aggregated advertising measurement that works without the advertising identifier (Apple SKAdNetwork, Meta Aggregated Event Measurement)Art. 6(1)(f) GDPR — our legitimate interest in knowing whether our advertising works; no identifier, no content, and you may object at any time by declining tracking

5. Special categories of data (Art. 9 GDPR) — important notice

Official letters you choose to scan may contain special categories of personal data within the meaning of Art. 9(1) GDPR — for example health information (medical or insurance letters), data revealing legal proceedings, or other sensitive content.

6. Recipients and processors

We use a small number of service providers as processors under Art. 28 GDPR, bound by data processing agreements:

ProcessorPurposeLocation / transfer safeguard
Anthropic PBC (Claude API)Generating the AI analysis and the reply draft from the text excerpt you submitUnited States — a third country. See Section 6.1.
Cloudflare, Inc. (Workers, KV, Durable Objects)Hosting our backend proxy, the fair-use counters and the entitlement recordsProcessing at the edge, including outside the EU/EEA. See Section 6.1.
Apple Inc. / Apple Distribution International Ltd.App distribution, in-app purchases, subscription managementApple acts largely as an independent controller for App Store transactions

Advertising-measurement partners — independent controllers, not processors. With your App Tracking Transparency permission, Meta Platforms Ireland Limited (Meta App Events SDK; privacy policy) and TikTok Technology Limited (TikTok App Events SDK; privacy policy) receive your device's advertising identifier together with the generic events listed in Section 8, and process them under their own privacy policies and for their own purposes as independent controllers. Neither receives any content of your letters, and neither is involved in the AI analysis or our backend. Both may process the data outside the EU/EEA under the safeguards described in Section 6.1.

We do not share personal data with any other third parties, except where required by law or to establish, exercise, or defend legal claims.

6.1 International transfers

Where a processor processes data outside the EU/EEA, we ensure an adequate level of protection via: an adequacy decision of the European Commission (Art. 45 GDPR — including, for certified US providers, the EU-U.S. Data Privacy Framework), or the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) with supplementary measures where needed.

For the AI provider this is the mechanism we rely on, and we are not able to tell you today that the standard contractual clauses are already concluded for your data. Until we can, the App offers on-device analysis: it never leaves your phone, and you can decline the cloud analysis at the consent screen and at any time afterwards in Settings.

7. Retention

8. Advertising measurement (App Tracking Transparency)

The App shows no advertisements. It does contain two advertising-measurement SDKs — Meta App Events (Meta Platforms) and TikTok App Events (TikTok) — whose only job is to tell those two networks whether an installation of Brief came from an advertisement we paid for, and whether a few generic milestones followed. That is the definition of tracking under Apple's App Tracking Transparency, and the App treats it as such.

What is asked. During onboarding — or, for installations that predate this feature, once on the home screen — the App explains this and then shows iOS's App Tracking Transparency prompt, once. Declining changes nothing about how the App works. You can change your answer at any time in iOS Settings → Privacy & Security → Tracking, and see your current answer in the App under Privacy & security.

What can be sent. The events are a fixed list built into the App: installation, app launch, onboarding completed, the paywall shown (and which of its three reasons), the first successful analysis of a letter (once per installation, carrying no information about the letter), a free trial started, and a first paid subscription period (the plan, Apple's price and the currency). With your permission the device's advertising identifier (IDFA) travels with them.

What can never be sent — because the App has no code path that could send it: your letter photos and PDFs, the recognised text, summaries and explanations, your replies, names, addresses, reference numbers, amounts, dates or any other content of a letter, the sender or the type of a letter, and the anonymous installation identifier used with our own backend.

Without your permission. No advertising identifier is read or sent. iOS blocks the TikTok SDK from contacting TikTok's servers at all; what TikTok then receives is Apple's own SKAdNetwork postback, which reports in aggregate that an installation happened without identifying you or your device. The Meta SDK likewise relies on SKAdNetwork and on Meta's Aggregated Event Measurement, which work without the identifier.

Recipients and legal basis. Meta and TikTok process this data as independent controllers under their own privacy policies (Section 6). With your permission the legal basis is your consent (Art. 6(1)(a) GDPR); the aggregated measurement that works without the identifier rests on our legitimate interest in knowing whether our advertising works (Art. 6(1)(f) GDPR), and you may object to it at any time by declining or withdrawing tracking permission in iOS Settings.

App Store label. In addition to the three data types of Section 3, the App Store privacy label declares Device ID, Purchase History and Product Interaction as used for tracking, which matches the PrivacyInfo.xcprivacy in the shipped binary. The share extension contains neither SDK and tracks nothing.

9. Your rights — and how the App maps to them

You have the following rights under GDPR:

10. Children

The App is not directed at children. It is intended for persons who receive official correspondence, i.e. generally 16 years or older. We do not knowingly process children's data.

11. Data security

We use appropriate technical and organizational measures (Art. 32 GDPR): TLS encryption in transit, iOS on-device encryption at rest, minimal-data architecture (on-device OCR, transient server processing), access controls, and no content logging. No method of transmission is 100% secure; we continuously review our measures.

12. Changes to this policy

We may update this policy when the App or legal requirements change. The current version is always available in the App and at https://brief-legal.pages.dev. For material changes we will inform you in the App. The "Effective date" above shows the latest revision.

13. Contact and supervisory authority