PREVIEW — not the final published text. The following entity details are still unset: ADDRESS, ANSCHRIFT, COMPANY, COMPETENT GERMAN STATE DATA PROTECTION AUTHORITY, DATE, DATENSCHUTZ-E-MAIL, DATUM, Impressum: URL, JURISDICTION, Managing director(s): NAME, POSTCODE, CITY, PRIVACY EMAIL, STREET, NO., SUPPORT EMAIL, SUPPORT-E-MAIL, URL, legal form. Complete docs/legal/site/entity.json, rebuild and redeploy before submitting the app to App Review.

Privacy Policy

Effective date: [DATE]

App: Brief — understand official letters ("the App")

Applies to: the iOS application distributed via the Apple App Store in Germany.

1. Controller

The controller within the meaning of Art. 4(7) GDPR is:

[COMPANY] ([legal form])
[STREET, NO.]
[POSTCODE, CITY], Germany
E-mail: [PRIVACY EMAIL]
[Managing director(s): NAME]
[If applicable: Data Protection Officer contact — [DPO NAME / EMAIL], or note that no DPO is required under Art. 37 GDPR / § 38 BDSG]

2. Our privacy approach in one paragraph

Brief is designed to be privacy-first. Text recognition (OCR) of your document photos happens entirely on your device. Only when you request an AI analysis is a sanitized text excerpt of the recognized text sent — through our own secure backend proxy — to an AI service for processing. Your documents are never stored on our servers after processing, we run no advertising SDKs, no third-party tracking, and document content never appears in our logs.

3. What data is processed, where, and why

3.1 Document photos and OCR text — on your device only

3.2 Text excerpts sent for AI analysis — via our backend proxy

3.3 Anonymous install identifier

3.4 Subscription status via Apple

3.5 Technical data strictly necessary for operation

3.6 What we do NOT do

4. Legal bases (Art. 6 GDPR)

ProcessingLegal basis
Providing the core service you request (OCR on device; AI analysis of text you submit; returning results; free-tier/fair-use accounting; subscription entitlement checks)Art. 6(1)(b) GDPR — performance of a contract / steps at your request
Security, abuse prevention, ensuring technical stability, defense of legal claimsArt. 6(1)(f) GDPR — legitimate interests (secure and reliable operation of the App; interests balanced against your rights, given the minimal data involved)
[If ever introduced: optional features requiring consent, e.g. optional cloud backup][Art. 6(1)(a) GDPR — consent; NOT currently used]

5. Special categories of data (Art. 9 GDPR) — important notice

Official letters you choose to scan may contain special categories of personal data within the meaning of Art. 9(1) GDPR — for example health information (medical or insurance letters), data revealing legal proceedings, or other sensitive content.

6. Recipients and processors

We use a small number of service providers as processors under Art. 28 GDPR, bound by data processing agreements:

ProcessorPurposeLocation / transfer safeguard
[AI PROVIDER — NAME, ENTITY, ADDRESS]Generating AI analyses from the text excerpts you submit[EU region / third country — specify. If outside EU/EEA: transfer mechanism per Section 6.1] · [CONFIRM: zero data retention / no-training terms in the DPA]
[HOSTING PROVIDER — NAME, ENTITY, ADDRESS]Hosting our backend proxy[EU region preferred — specify]
Apple Inc. / Apple Distribution International Ltd.App distribution, in-app purchases, subscription managementApple acts largely as an independent controller for App Store transactions

We do not share personal data with any other third parties, except where required by law or to establish, exercise, or defend legal claims.

6.1 International transfers

Where a processor processes data outside the EU/EEA, we ensure an adequate level of protection via: an adequacy decision of the European Commission (Art. 45 GDPR — including, for certified US providers, the EU-U.S. Data Privacy Framework), or the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) with supplementary measures where needed. [SPECIFY per provider once contracts are final. Preference: EU-region processing endpoints for the AI provider where available.]

7. Retention

8. No advertising, no tracking

The App contains no advertising SDKs and no third-party tracking. We do not track you across apps or websites. Accordingly, the App does not request App Tracking Transparency permission, and the App Store privacy label reflects "Data Not Linked to You" categories only [ALIGN FINAL PRIVACY LABEL WITH IMPLEMENTATION].

9. Your rights — and how the App maps to them

You have the following rights under GDPR:

10. Children

The App is not directed at children. It is intended for persons who receive official correspondence, i.e. generally 16 years or older [COUNSEL TO CONFIRM age threshold / App Store age rating alignment]. We do not knowingly process children's data.

11. Data security

We use appropriate technical and organizational measures (Art. 32 GDPR): TLS encryption in transit, iOS on-device encryption at rest, minimal-data architecture (on-device OCR, transient server processing), access controls, and no content logging. No method of transmission is 100% secure; we continuously review our measures.

12. Changes to this policy

We may update this policy when the App or legal requirements change. The current version is always available in the App and at [URL]. For material changes we will inform you in the App. The "Effective date" above shows the latest revision.

13. Contact and supervisory authority