Privacy Notice
Last updated: July 2, 2026
This Privacy Notice explains how LinkBrief ("LinkBrief", "we", "us", or "our") collects, uses, shares, and protects personal data when you use our service at linkbrief.app (the "Service").
1. Who we are
LinkBrief is the operator of the Service and acts as the data controller for personal data processed in connection with your account and use of the Service. You can reach us at support@linkbrief.app.
2. Categories of personal data we collect
- Account data — email address, hashed password (or OAuth identifier), display name.
- Content you submit — URLs of videos you save, transcripts, generated summaries, action items, tags, and notes.
- Settings and preferences — briefing frequency, timezone, API keys you provide for third-party services (stored server-side).
- Usage and telemetry — pages viewed, features used, request timestamps, aggregate counts (e.g. saves per month, AI calls per day) used for enforcing plan limits and rate limits.
- Device and technical data — IP address, browser type, device identifiers, error logs.
- Support communications — the content of emails or messages you send us.
Payment card data is collected directly by our payment provider (Paddle) and is not stored by LinkBrief.
3. Purposes and legal bases
- Provide the Service — creating your account, transcribing and summarizing content you save, delivering briefings. Legal basis: performance of contract.
- Security and fraud prevention — detecting abuse, enforcing rate limits, protecting accounts. Legal basis: legitimate interests.
- Product improvement and analytics — understanding how features are used in aggregate. Legal basis: legitimate interests.
- Customer support — responding to your requests. Legal basis: performance of contract / legitimate interests.
- Legal compliance — tax, accounting, responding to lawful requests. Legal basis: legal obligation.
- Marketing emails — only if you opt in; you can withdraw consent at any time. Legal basis: consent.
4. Who we share your data with
We share personal data only with the following categories of recipients:
- Merchant of Record — Paddle: for processing payments, handling subscriptions, calculating and remitting taxes, and issuing invoices. Paddle is an independent controller for the payment data it collects.
- Infrastructure providers: our hosting, database, edge, and email delivery providers, which process data on our behalf as processors under written agreements.
- AI providers: transcription and summarization providers (e.g. providers of speech-to-text and large language models) process the content you submit strictly to return AI results to us; they do not use it to train models on your behalf where their terms allow us to opt out.
- Third-party actors you enable: if you supply your own API keys (e.g. for Apify), the URLs you process are sent to those providers under their terms.
- Professional advisers: legal, accounting, and tax advisers where necessary.
- Authorities: where required by law, regulation, or valid legal process.
5. International transfers
Some of our providers are located outside your country of residence, including in the United States. Where data is transferred out of the UK or EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision.
6. Data retention
We keep your personal data for as long as your account is active and for a reasonable period afterwards to comply with legal, accounting, or reporting obligations. Content you save (transcripts, summaries) is kept until you delete it or close your account. When data is no longer needed, we delete or anonymize it.
7. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- request deletion of your data ("right to be forgotten");
- restrict or object to certain processing;
- request a portable copy of your data;
- withdraw consent where processing is based on consent;
- lodge a complaint with your local data protection authority.
To exercise any of these rights, email support@linkbrief.app. We will respond within one month.
8. Security
We use appropriate technical and organizational measures to protect your data, including encryption in transit (HTTPS), encryption at rest for the database, row-level access controls, hashed credentials, and least-privilege access for our staff and services. No system is 100% secure — please use a strong, unique password and enable additional protections where offered.
9. Cookies
We use a small number of essential cookies to keep you signed in and to maintain your session. We do not currently use advertising cookies. If we add analytics or marketing cookies in the future, we will present a cookie banner allowing you to accept or reject non-essential cookies.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us and we will delete it.
11. Changes to this notice
We may update this Privacy Notice from time to time. Material changes will be communicated through the Service or by email. The "Last updated" date at the top of this page shows when it was last revised.
12. Contact
Questions about this notice or how we handle your data? Email support@linkbrief.app.