Privacy Policy

This policy explains how CollabBrief handles personal data when you use the service or receive a public document.

Information we process. We process account and workspace details, team membership, sponsor contacts, deal and contract records, uploaded files, invoices, payments, inbound email, support messages, and configuration. Security records include opaque session hashes, keyed IP fingerprints, audit events, and delivery logs.

Why we process it. Processing is necessary to provide the service, secure accounts, deliver requested email, operate billing, prevent abuse, maintain auditability, improve reliability, and comply with applicable obligations. We do not sell personal data or use it for third-party advertising.

Public links and analytics. Invoice, proposal, media-kit, and calendar links are bearer links protected by random tokens. Media-kit and proposal views create cookie-free first-party events with a timestamp and keyed IP fingerprint for rate limiting and aggregate analytics. No third-party tracker is embedded.

Service providers. Cloudflare provides compute, database, object storage, queues, and network security. Resend provides transactional email when configured. Paddle acts as merchant of record for CollabBrief plan subscriptions and processes checkout, payment, tax, and billing data under its own privacy terms. CollabBrief does not store Paddle card details or customer card data. Providers process data only for their contracted service.

International processing and security. Infrastructure may process data outside your country. Controls include tenant-scoped access, encryption for stored secrets, hash-only bearer lookups, secure cookies, CSRF checks, restrictive response headers, rate limits, and auditable privileged actions.

Retention. Active workspace data is retained while the service is used. Cancelled workspaces are retained for 90 days and then deleted. Requested export files expire after seven days. Operational security records are retained only as needed for security and reliability.

Your choices and rights. Workspace owners can export or delete tenant data, revoke sessions and public links, remove team members, and close the workspace. Depending on applicable law, you may request access, correction, restriction, objection, portability, or deletion by emailing privacy@collabbrief.com.

Cookies and contact. CollabBrief uses first-party cookies only for authentication, CSRF protection, and a local theme preference. It does not use advertising cookies. Privacy questions may be sent to privacy@collabbrief.com.