BriefTether guide

Privacy and your data

Know what the service stores, which AI provider receives selected documents, and how to export or erase your workspace.

Updated 9 October 2026 · Free early access

Current stage: free early-access service hosted on Cloudflare at brieftether.com. The invited operator must complete initial setup and supply real legal identity details.

Data stored by the service

BriefTether stores your username, workspace name, password hash, recovery-code records, sessions, projects, extracted document text, requirements, source excerpts, estimates, baselines, changes, and settings in Cloudflare D1. Hashed network identifiers and attempt counters support abuse prevention. Upload only information you are authorized to process.

Cloudflare manages D1's storage encryption and encrypted transport. The application and authorized operator can read workspace contents; this is not end-to-end encryption. Provider API credentials receive separate AES-GCM application encryption, with the encryption key supplied through Cloudflare Worker secret configuration. See D1 data security.

Purposes and access

The service uses stored data to authenticate accounts, preserve workspaces, calculate estimates, verify quotation matches, compare scope, and provide exports. Account checks isolate projects between users. Cloudflare hosts the application and database; an authorized operator with platform access can access stored data for operation, recovery, and troubleshooting.

Which AI provider receives data

Saving an API key does not by itself send documents for analysis. When you select documents and consent to extraction, the service sends their text, request instructions, and the applicable credential to your selected provider: Google for Gemini or Anthropic for Claude. The consent screen identifies the actual destination. Only select documents you are authorized to share with that provider.

Your account's Gemini and Claude keys are stored separately and encrypted on the server. Changing the selected provider does not relabel another provider's output. The first local operator may receive a prepared connection during installation; that credential is not automatically shared with other registered accounts.

Google unpaid API conditions

Under Google's unpaid-service terms, API input and generated responses can support Google product improvement and may be processed by human reviewers. Use only public, nonpersonal, nonconfidential documents. BriefTether requires your separate confirmation; it cannot establish that your declaration is true. See the Gemini API terms.

Google requires paid services for API clients offered to users in the European Economic Area, Switzerland, or the United Kingdom. Free Gemini access must meet these regional conditions. The manual workflow does not transmit documents to an AI provider; a separately configured Claude connection follows Anthropic's terms.

Anthropic conditions

Claude requests follow Anthropic's commercial terms and privacy guidance. BriefTether does not promise zero provider retention, regulatory certification, or a special data-processing agreement. A prepared adapter does not mean live Claude extraction quality has been verified.

Browser storage and external assets

A session cookie supports sign-in and request protection. The site uses local interface assets and self-hosted or system fonts. It includes no advertising, third-party analytics tracker, or external font request. Clicking an external documentation link takes you to that provider's site.

Retention and deletion

Active workspace records remain until you delete the applicable project or account. Frozen baselines preserve their source text while the project remains, even if a live document changes. Export your records before erasing them if you need a copy.

Self-service deletion removes active workspace records and saved API credentials and invalidates sessions. It does not erase material already sent to Google or Anthropic, or files you downloaded. D1's automatic Time Travel can preserve recoverable database history within the Free plan's seven-day window, including records from before deletion. Removing live data does not immediately erase historical copies. Separate operator exports follow their own retention and deletion rules. See D1 Time Travel.

Operator and requests

The public website is brieftether.com and the incoming contact address is jaypark@brieftether.com. The invited operator must supply the real legal identity and location in settings; no registered company name or postal address is invented. Use account export and deletion for active workspace records, and contact the operator for other privacy requests. No support-response deadline is promised.

Changes to this notice

The operator should update this notice when hosting, subprocessors, contact details, or data handling changes. The update date is shown above. This notice describes the current service and does not claim compliance certification.