Who we are
Chime Stream B.V. runs BriefNext. We are the controller of your personal data. This means that we decide why and how it is used.
Chime Stream B.V., Rotterdam, the Netherlands. KvK 96563028. Email: hello@briefnext.com.
This policy covers this website (briefnext.com), the control panel at app.briefnext.com, and the BriefNext connector that you add to Claude, ChatGPT or Claude Code. A connector is the link that lets your AI call BriefNext's tools.
The short version
- We keep what you give BriefNext, and what its research finds about you and your business.
- We do not sell your data. We do not show ads. We do not train AI models on your data.
- BriefNext does not see your chats. It sees only what your AI sends when it calls a BriefNext tool.
- You can delete a profile, or your whole account, yourself in the panel.
What we store
An account holds one or more profiles. A profile is one person or one brand. For each part, we store:
- Account
- Your email address, and your sign-in data: the sign-in record at Supabase, sign-in times and your panel session. If you set a password, Supabase keeps it as a hash (a one-way scrambled form). BriefNext does not store your password.
- Profile data
- For each profile: the profile fields (who you are, your business, your brand, and your coordinates: niche, country, language, platform, audience, stage and goal), the plan, the content you save, keywords and your choices about them, the results you record, notes, and research results that we keep for a time (the research cache).
- Files
- Images that BriefNext makes for you, and the export packages of your content.
- Activity and usage
- Each tool call: which tool, when, what it did, and what its paid research cost. We use this for the Activity and Usage pages and for your spend cap.
- Plan status
- Whether your account has an active plan, and until when.
- Support
- The emails you send us, and our answers.
- Server logs
- A technical record of each request to our server, such as the IP address, the time and the address asked for.
Some profile data comes from public sources, not from you: your website, pages that name you, search results, and the answers of AI assistants about you. BriefNext collects it only for the profile that asks for it.
Research can also name other people who publish in your field, with links to their public work. We keep these names and links in the research results of the profile that asked. If you find yourself in BriefNext research and want it removed, write to us.
We keep the database, the sign-in records and the files at Supabase, in its EU region (Ireland). Our server, the server logs and the nightly backups are at Hetzner, in Nuremberg, Germany. Support emails are in Gmail, at Google.
Why we use it, and on what legal basis
The GDPR (the EU General Data Protection Regulation) lets us use personal data only for a stated purpose and on a legal basis. Ours are:
- To give you the service
- Sign-in, profiles, the plan, research, images, diagrams and exports.Basis: contract (GDPR article 6(1)(b)).
- To check your plan and your spend
- To unlock the tools when your account has a plan, and to stop paid research at your spend cap.Basis: contract.
- To keep the service safe and working
- Server logs, limits on requests, finding faults, and stopping abuse.Basis: legitimate interest (a secure service that works).
- To research the people in your field
- Names of other people and links to their public work, so that you see what works in your corner.Basis: legitimate interest. We use only public sources, and we remove a person on request.
- To answer you
- Support emails and questions about your account.Basis: contract, or legitimate interest if you do not have an account.
- To obey the law
- For example, a lawful order from an authority.Basis: legal obligation.
You need an email address to have an account. Without it we cannot give you the service.
BriefNext does not make decisions about you that have a legal effect or a similar large effect. It gives advice to you and your AI. You decide what to do with it.
Who else receives data
We use these companies (subprocessors) to run BriefNext. Each one receives only what its job needs. Each vendor processes data only on our instructions and under GDPR terms.
- Supabase
- Database, sign-in and file storage. It holds the data in "What we store", except the server logs, the support emails and the backups.EU region (Ireland). Supabase is a US company.
- Resend
- Sends the sign-in, confirmation and password emails. It receives your email address and the content of those emails.
- RevenueCat
- Keeps your plan status. It receives your account id and your email address.
- Anthropic
- Its AI model reads text for us. It receives the text of pages that you tell BriefNext to read and the facts that you type, to fill your profile. It also receives search results with your coordinates, to analyse research.
- Tavily
- Web search and page reading. It receives search queries made from your coordinates and topics, and the addresses (URLs) of sites to read.
- DataForSEO
- Search volumes, search results and AI answers. It receives keywords, search questions, and the country, language and city to search in. For a visibility check, it sends the questions a client would ask to ChatGPT, Claude, Gemini, Perplexity and Google for us.
- Google (Gemini)
- Makes images. It receives the image prompt (the description of the image), which can include your brand colours and style.
- Hetzner
- Hosts our server, which we run with Coolify, and this website. All requests to BriefNext pass through this server. It holds the server logs and our nightly backups of the database, kept 14 days.Nuremberg, Germany (EU).
- Cloudflare
- DNS for our domains, and email routing for hello@briefnext.com. It receives DNS lookups and the emails you send to us, and forwards those emails to our Gmail inbox.
- Google (Gmail)
- Our support inbox. It receives the emails you send to hello@briefnext.com, and keeps them with our answers.
We do not share your data with anyone else, except when the law requires it. If we add a subprocessor, we name it on this page first.
Transfers outside the EU
Some vendors process data outside the EU, mostly in the United States. There we rely on the vendor's GDPR transfer terms.
These vendors are Resend, RevenueCat, Anthropic, Tavily, DataForSEO, Google, Cloudflare and jsDelivr. Supabase is a US company too, but it keeps our data in the EU.
How long we keep it
- Account and profile data: for as long as your account exists.
- Research cache: each entry expires by itself, after one day to two weeks.
- After you delete a profile or your account: the data goes from the live database and file storage at once.
- Backups: we make one copy of the database each night and keep each copy for 14 days. Deleted data leaves the backups within 14 days.
- Server logs: up to 30 days, for fault finding and security.
- Support emails: up to 2 years after the last message, then deleted.
Delete your data
You do not need to ask us. Sign in to the panel at app.briefnext.com.
Delete your whole account
- Open Settings and press Delete my account.
- Read the list of what goes, and type your email address to confirm.
- Press Delete. BriefNext removes every profile with its data and files, your plan record at RevenueCat, your sign-in record at Supabase, your connected apps and your tokens.
If one step fails, the page tells you which step. Press Delete again to finish.
Delete one profile
Open Profiles and choose Delete this profile. Type the profile's name to confirm. BriefNext removes that profile's data and files, and ends the connections that use it. Your account and other profiles stay. You cannot delete the last profile of an account: delete the account instead.
Your rights
Under the GDPR, you have these rights:
- Access: see what BriefNext knows on the panel's Profile page, or ask us for a full copy.
- Correction: change it on the Profile page, or tell your AI. What you say always outranks what research found.
- Deletion: delete a profile or your account in the panel (see above).
- Export: write to us and we send your data in a file that a computer can read.
- Restriction and objection: ask us to stop or limit a use of your data, for example research about you as a person in someone else's field.
Write to hello@briefnext.com from the email address of your account. We answer within one month.
You can also complain to a supervisory authority. In the Netherlands, this is the Autoriteit Persoonsgegevens. You can also go to the authority in the EU country where you live.
Cookies
We use no tracking, no analytics and no ad cookies. The cookies below are needed for sign-in to work, so we do not ask for consent.
- briefnext.com
- No cookies.
- Google Fonts
- This website (briefnext.com) and the panel (app.briefnext.com) load our fonts from Google Fonts, so Google receives your IP address.
- Session cookie
- Keeps you signed in to the panel.30 days.
- Profile cookie
- Remembers which profile the panel shows.
- Connect cookie
- Holds your AI's connect request while you sign in.30 minutes.
- Local storage
- The sign-in code from Supabase keeps its session in your browser's local storage. Sign out removes it. The panel loads that code from jsDelivr, a public code host, so jsDelivr receives your IP address.
Security
All traffic uses HTTPS. Each profile's data sits in its own separate area of the database. Files sit in private storage. We keep tokens only as hashes. If a breach puts your data at risk, we tell the Autoriteit Persoonsgegevens within 72 hours, and we tell you when the law requires it.
Children
BriefNext is for business use. It is not for people under 16.
Changes to this policy
When we change this policy, we change the date at the top. If a change is important, we also send you an email before it starts.
Contact
Chime Stream B.V., Rotterdam, the Netherlands. KvK 96563028.
hello@briefnext.com