BriefNext

Privacy policy

What we keep about you, and why.

BriefNext keeps what it needs to know who you are and where you are going. This page tells you what that is, who else receives it, and how you remove it.

Last updated 11 October 2026

Who we are

Chime Stream B.V. runs BriefNext. We are the controller of your personal data. This means that we decide why and how it is used.

Chime Stream B.V., Rotterdam, the Netherlands. KvK 96563028. Email: hello@briefnext.com.

This policy covers this website (briefnext.com), the control panel at app.briefnext.com, and the BriefNext connector that you add to Claude, ChatGPT or Claude Code. A connector is the link that lets your AI call BriefNext's tools.

The short version

  • We keep what you give BriefNext, and what its research finds about you and your business.
  • We do not sell your data. We do not show ads. We do not train AI models on your data.
  • BriefNext does not see your chats. It sees only what your AI sends when it calls a BriefNext tool.
  • You can delete a profile, or your whole account, yourself in the panel.

What we store

An account holds one or more profiles. A profile is one person or one brand. For each part, we store:

Account
Your email address, and your sign-in data: the sign-in record at Supabase, sign-in times and your panel session. If you set a password, Supabase keeps it as a hash (a one-way scrambled form). BriefNext does not store your password.
Profile data
For each profile: the profile fields (who you are, your business, your brand, and your coordinates: niche, country, language, platform, audience, stage and goal), the plan, the content you save, keywords and your choices about them, the results you record, notes, and research results that we keep for a time (the research cache).
Files
Images that BriefNext makes for you, and the export packages of your content.
Activity and usage
Each tool call: which tool, when, what it did, and what its paid research cost. We use this for the Activity and Usage pages and for your spend cap.
Plan status
Whether your account has an active plan, and until when.
Support
The emails you send us, and our answers.
Server logs
A technical record of each request to our server, such as the IP address, the time and the address asked for.

Some profile data comes from public sources, not from you: your website, pages that name you, search results, and the answers of AI assistants about you. BriefNext collects it only for the profile that asks for it.

Research can also name other people who publish in your field, with links to their public work. We keep these names and links in the research results of the profile that asked. If you find yourself in BriefNext research and want it removed, write to us.

We keep the database, the sign-in records and the files at Supabase, in its EU region (Ireland). Our server, the server logs and the nightly backups are at Hetzner, in Nuremberg, Germany. Support emails are in Gmail, at Google.

Why we use it, and on what legal basis

The GDPR (the EU General Data Protection Regulation) lets us use personal data only for a stated purpose and on a legal basis. Ours are:

To give you the service
Sign-in, profiles, the plan, research, images, diagrams and exports.Basis: contract (GDPR article 6(1)(b)).
To check your plan and your spend
To unlock the tools when your account has a plan, and to stop paid research at your spend cap.Basis: contract.
To keep the service safe and working
Server logs, limits on requests, finding faults, and stopping abuse.Basis: legitimate interest (a secure service that works).
To research the people in your field
Names of other people and links to their public work, so that you see what works in your corner.Basis: legitimate interest. We use only public sources, and we remove a person on request.
To answer you
Support emails and questions about your account.Basis: contract, or legitimate interest if you do not have an account.
To obey the law
For example, a lawful order from an authority.Basis: legal obligation.

You need an email address to have an account. Without it we cannot give you the service.

BriefNext does not make decisions about you that have a legal effect or a similar large effect. It gives advice to you and your AI. You decide what to do with it.

Who else receives data

We use these companies (subprocessors) to run BriefNext. Each one receives only what its job needs. Each vendor processes data only on our instructions and under GDPR terms.

Supabase
Database, sign-in and file storage. It holds the data in "What we store", except the server logs, the support emails and the backups.EU region (Ireland). Supabase is a US company.
Resend
Sends the sign-in, confirmation and password emails. It receives your email address and the content of those emails.
RevenueCat
Keeps your plan status. It receives your account id and your email address.
Anthropic
Its AI model reads text for us. It receives the text of pages that you tell BriefNext to read and the facts that you type, to fill your profile. It also receives search results with your coordinates, to analyse research.
Tavily
Web search and page reading. It receives search queries made from your coordinates and topics, and the addresses (URLs) of sites to read.
DataForSEO
Search volumes, search results and AI answers. It receives keywords, search questions, and the country, language and city to search in. For a visibility check, it sends the questions a client would ask to ChatGPT, Claude, Gemini, Perplexity and Google for us.
Google (Gemini)
Makes images. It receives the image prompt (the description of the image), which can include your brand colours and style.
Hetzner
Hosts our server, which we run with Coolify, and this website. All requests to BriefNext pass through this server. It holds the server logs and our nightly backups of the database, kept 14 days.Nuremberg, Germany (EU).
Cloudflare
DNS for our domains, and email routing for hello@briefnext.com. It receives DNS lookups and the emails you send to us, and forwards those emails to our Gmail inbox.
Google (Gmail)
Our support inbox. It receives the emails you send to hello@briefnext.com, and keeps them with our answers.

We do not share your data with anyone else, except when the law requires it. If we add a subprocessor, we name it on this page first.

Transfers outside the EU

Some vendors process data outside the EU, mostly in the United States. There we rely on the vendor's GDPR transfer terms.

These vendors are Resend, RevenueCat, Anthropic, Tavily, DataForSEO, Google, Cloudflare and jsDelivr. Supabase is a US company too, but it keeps our data in the EU.

How long we keep it

  • Account and profile data: for as long as your account exists.
  • Research cache: each entry expires by itself, after one day to two weeks.
  • After you delete a profile or your account: the data goes from the live database and file storage at once.
  • Backups: we make one copy of the database each night and keep each copy for 14 days. Deleted data leaves the backups within 14 days.
  • Server logs: up to 30 days, for fault finding and security.
  • Support emails: up to 2 years after the last message, then deleted.

Delete your data

You do not need to ask us. Sign in to the panel at app.briefnext.com.

Delete your whole account

  1. Open Settings and press Delete my account.
  2. Read the list of what goes, and type your email address to confirm.
  3. Press Delete. BriefNext removes every profile with its data and files, your plan record at RevenueCat, your sign-in record at Supabase, your connected apps and your tokens.

If one step fails, the page tells you which step. Press Delete again to finish.

Delete one profile

Open Profiles and choose Delete this profile. Type the profile's name to confirm. BriefNext removes that profile's data and files, and ends the connections that use it. Your account and other profiles stay. You cannot delete the last profile of an account: delete the account instead.

Your rights

Under the GDPR, you have these rights:

  • Access: see what BriefNext knows on the panel's Profile page, or ask us for a full copy.
  • Correction: change it on the Profile page, or tell your AI. What you say always outranks what research found.
  • Deletion: delete a profile or your account in the panel (see above).
  • Export: write to us and we send your data in a file that a computer can read.
  • Restriction and objection: ask us to stop or limit a use of your data, for example research about you as a person in someone else's field.

Write to hello@briefnext.com from the email address of your account. We answer within one month.

You can also complain to a supervisory authority. In the Netherlands, this is the Autoriteit Persoonsgegevens. You can also go to the authority in the EU country where you live.

Cookies

We use no tracking, no analytics and no ad cookies. The cookies below are needed for sign-in to work, so we do not ask for consent.

briefnext.com
No cookies.
Google Fonts
This website (briefnext.com) and the panel (app.briefnext.com) load our fonts from Google Fonts, so Google receives your IP address.
Session cookie
Keeps you signed in to the panel.30 days.
Profile cookie
Remembers which profile the panel shows.
Connect cookie
Holds your AI's connect request while you sign in.30 minutes.
Local storage
The sign-in code from Supabase keeps its session in your browser's local storage. Sign out removes it. The panel loads that code from jsDelivr, a public code host, so jsDelivr receives your IP address.

Security

All traffic uses HTTPS. Each profile's data sits in its own separate area of the database. Files sit in private storage. We keep tokens only as hashes. If a breach puts your data at risk, we tell the Autoriteit Persoonsgegevens within 72 hours, and we tell you when the law requires it.

Children

BriefNext is for business use. It is not for people under 16.

Changes to this policy

When we change this policy, we change the date at the top. If a change is important, we also send you an email before it starts.

Contact

Chime Stream B.V., Rotterdam, the Netherlands. KvK 96563028.
hello@briefnext.com