ADDRESS, ANSCHRIFT, COMPANY, COMPETENT GERMAN STATE DATA PROTECTION AUTHORITY, DATE, DATENSCHUTZ-E-MAIL, DATUM, Impressum: URL, JURISDICTION, Managing director(s): NAME, POSTCODE, CITY, PRIVACY EMAIL, STREET, NO., SUPPORT EMAIL, SUPPORT-E-MAIL, URL, legal form. Complete docs/legal/site/entity.json, rebuild and redeploy before submitting the app to App Review.Effective date: [DATE]
App: Brief — understand official letters ("the App")
Applies to: the iOS application distributed via the Apple App Store in Germany.
The controller within the meaning of Art. 4(7) GDPR is:
[COMPANY] ([legal form])
[STREET, NO.]
[POSTCODE, CITY], Germany
E-mail: [PRIVACY EMAIL]
[Managing director(s): NAME]
[If applicable: Data Protection Officer contact — [DPO NAME / EMAIL], or note that no DPO is required under Art. 37 GDPR / § 38 BDSG]
Brief is designed to be privacy-first. Text recognition (OCR) of your document photos happens entirely on your device. Only when you request an AI analysis is a sanitized text excerpt of the recognized text sent — through our own secure backend proxy — to an AI service for processing. Your documents are never stored on our servers after processing, we run no advertising SDKs, no third-party tracking, and document content never appears in our logs.
| Processing | Legal basis | |
|---|---|---|
| Providing the core service you request (OCR on device; AI analysis of text you submit; returning results; free-tier/fair-use accounting; subscription entitlement checks) | Art. 6(1)(b) GDPR — performance of a contract / steps at your request | |
| Security, abuse prevention, ensuring technical stability, defense of legal claims | Art. 6(1)(f) GDPR — legitimate interests (secure and reliable operation of the App; interests balanced against your rights, given the minimal data involved) |
| [If ever introduced: optional features requiring consent, e.g. optional cloud backup] | [Art. 6(1)(a) GDPR — consent; NOT currently used] |
|---|
Official letters you choose to scan may contain special categories of personal data within the meaning of Art. 9(1) GDPR — for example health information (medical or insurance letters), data revealing legal proceedings, or other sensitive content.
We use a small number of service providers as processors under Art. 28 GDPR, bound by data processing agreements:
| Processor | Purpose | Location / transfer safeguard |
|---|---|---|
| [AI PROVIDER — NAME, ENTITY, ADDRESS] | Generating AI analyses from the text excerpts you submit | [EU region / third country — specify. If outside EU/EEA: transfer mechanism per Section 6.1] · [CONFIRM: zero data retention / no-training terms in the DPA] |
| [HOSTING PROVIDER — NAME, ENTITY, ADDRESS] | Hosting our backend proxy | [EU region preferred — specify] |
| Apple Inc. / Apple Distribution International Ltd. | App distribution, in-app purchases, subscription management | Apple acts largely as an independent controller for App Store transactions |
|---|
We do not share personal data with any other third parties, except where required by law or to establish, exercise, or defend legal claims.
Where a processor processes data outside the EU/EEA, we ensure an adequate level of protection via: an adequacy decision of the European Commission (Art. 45 GDPR — including, for certified US providers, the EU-U.S. Data Privacy Framework), or the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) with supplementary measures where needed. [SPECIFY per provider once contracts are final. Preference: EU-region processing endpoints for the AI provider where available.]
The App contains no advertising SDKs and no third-party tracking. We do not track you across apps or websites. Accordingly, the App does not request App Tracking Transparency permission, and the App Store privacy label reflects "Data Not Linked to You" categories only [ALIGN FINAL PRIVACY LABEL WITH IMPLEMENTATION].
You have the following rights under GDPR:
The App is not directed at children. It is intended for persons who receive official correspondence, i.e. generally 16 years or older [COUNSEL TO CONFIRM age threshold / App Store age rating alignment]. We do not knowingly process children's data.
We use appropriate technical and organizational measures (Art. 32 GDPR): TLS encryption in transit, iOS on-device encryption at rest, minimal-data architecture (on-device OCR, transient server processing), access controls, and no content logging. No method of transmission is 100% secure; we continuously review our measures.
We may update this policy when the App or legal requirements change. The current version is always available in the App and at [URL]. For material changes we will inform you in the App. The "Effective date" above shows the latest revision.