Privacy Policy

Last updated 11 September 2026

What Brevik collects, why it is collected, and who else sees it.

1.What we collect

Only what the product needs to work:

  • Account — your email address, and your name and profile picture if you sign in with Google or add them yourself.
  • Prompts — the rough prompt you paste, your answers to the interview questions, and the compiled result, saved to your history so you can return to it.
  • Attached context — text, files or links you attach. See section 3, which describes how these are handled differently.
  • Usage — a per-day count of refinement sessions, used to enforce the free plan’s daily limit.
  • Subscription status — your plan, its state and renewal date, synced from Paddle.

We use Datafa.st for page-view analytics. It records which pages are visited, the referring site, screen size, language and country, and stores a small identifier on your device to count return visits. We run no advertising trackers and do not sell personal data. Card details never reach us — Paddle handles payment entirely.

2.Who else processes your data

  • Supabase — authentication, database and file storage.
  • OpenRouter — our AI provider. Your prompt, your answers, any attachment summaries and any screenshot you upload are sent to OpenRouter to generate the interview questions, describe images and compile the final prompt. OpenRouter passes each request to the model provider it routes to — currently OpenAI for text and Google for images. This is the processor that receives your prompt content.
  • Paddle.com Market Ltd — payments, as merchant of record. Receives your email and billing details directly.
  • Datafa.st — page-view analytics. Receives the page URL, referrer, screen size, language and your IP address (used to derive a country, then discarded by them).
  • Cloudflare and our hosting provider — serve the site and process request logs, including IP addresses.

Each processor handles your data under its own privacy policy: Supabase, OpenRouter, Paddle and Datafa.st, Cloudflare.

If we change AI provider we will update this section and the date at the top before your prompts are sent anywhere new.

3.Attachments and screenshots

When you attach a document, link or block of text, it is read, summarised into a short context note, and then discarded. The original file is never written to disk and the fetched page is never retained. Only the summary is kept, as part of the prompt it belongs to.

Uploaded files are parsed, never executed. We accept PDF, DOCX, TXT and Markdown, and check the file’s actual contents rather than trusting its extension.

Screenshots are the exception, and are stored. An image you upload is sent to our vision provider to be described, and the file itself is kept on our server so you can see it again alongside the prompt it produced. It is readable only by your account. Deleting the prompt or your account deletes the image with it, and you can delete an image on its own from the prompt it belongs to.

4.How long we keep it

  • Saved prompts — until you delete them or your account
  • Account details — until you delete your account
  • Daily usage counts — one row per day, removed with your account
  • Attachment originals — never stored
  • Screenshots — until you delete the prompt or your account

Deleting your account from Settings removes your profile, prompts, usage records and subscription rows immediately. It does not remove records Paddle must retain for tax and accounting.

Server access logs, which include IP addresses, are kept for 30 days and then deleted. Cloudflare retains its own edge logs under its policy, which we do not control.

5.Your rights

Depending on where you live you may have the right to access, correct, export or delete your personal data, and to object to certain processing. Account deletion is available directly in Settings; for anything else, contact us.

If you are in the UK or EU, we rely on these legal bases under the UK GDPR and GDPR: performance of a contract for your account, your prompts and your subscription — this is the service you asked us to provide; and legitimate interests for security logging and preventing abuse of the free plan. We do not process your data for marketing, and we do not rely on consent, so there is no consent for you to withdraw.

Your prompts and any screenshot are sent to OpenRouter for processing, which may involve a transfer outside the UK and EEA. Where that happens we rely on the provider’s standard contractual clauses. You can also complain to your local data protection authority — in the UK, the Information Commissioner’s Office.

To exercise any of these rights, email [email protected] or call +44 7480 263734. We will respond within one month, as the GDPR requires.

6.Security

Traffic is encrypted in transit. Database access is row-level restricted so one account cannot read another’s data. Payment webhooks are signature-verified before anything is written.

No system is perfectly secure. If a breach affects your data we will notify you and any regulator we are required to inform.

7.Changes and contact

We will post any update here and change the date at the top. Material changes will be notified by email or in the app. Questions about this policy, or the Terms of Service, can be sent to [email protected].