DebriefStudio logoDebriefStudio

Last updated · July 2026

Privacy Policy

DebriefStudio ("we", "us") is the data controller for personal data you provide when using the Service.

1. What we collect

Account data: email, hashed password (or OAuth identifier), display name.
Project data: everything you paste into a brief, attachments you upload, and the AI-generated outputs.
Billing data: plan, subscription status, invoice details you enter. Payment card data is handled by Stripe — we never see it.
Usage: basic access logs (IP, user-agent) for security and anti-abuse.

2. How we use it

To provide the Service, generate your briefs, process payments, send service emails, and protect against abuse.

3. AI processing

Your project inputs are sent to Google's Gemini via a secure gateway to generate outputs. Google does not use your inputs to train models. If you enable Confidential mode, sensitive terms you list are replaced with placeholders in your browser before anything leaves your device.

4. Storage & security

Data is stored on Supabase (EU region). Row-Level Security means only your account can read your rows. Attachments live in a private bucket accessible only to you and our server.

5. Sharing

We don't sell your data. We share only with sub-processors necessary to run the Service: Supabase (hosting), Stripe (payments), Google (AI), and our email provider. All under standard data-processing agreements.

6. Your rights (GDPR/UK GDPR)

Access, correction, deletion, portability, restriction, objection. Email privacy@debriefstudio.app and we'll respond within 30 days.

7. Retention

We keep account and project data until you delete them or request account removal. Billing records are kept for 7 years for tax/audit compliance.

8. Cookies

We use strictly-necessary cookies for authentication and CSRF protection only. No third-party tracking.

9. Contact

privacy@debriefstudio.app