Legal

Privacy Policy

Effective from 10 September 2026

Anybrief LTD (“anybrief”, “we”) builds a platform that creative agencies use to write, share and manage briefs and proposals. We care about your privacy. This policy explains what data we collect, how we use it, where it is stored, who we share it with, and the choices you have.

It covers our website at anybrief.com, the anybrief app (including organisation subdomains such as youragency.anybrief.com), and the public brief and proposal pages that agencies share from it.

Who this policy is for

Different people touch anybrief in different ways, and we collect different things about each:

  • Agency users: people with an anybrief account who belong to an organisation.
  • Creatives: freelancers an agency invites to submit work against a brief. They do not need a password; they sign in with a single-use link or code sent to their email.
  • People an agency enters into anybrief: client contacts, colleagues who have been invited, and creatives on a brief’s allowlist.
  • Visitors: anyone browsing our website, viewing a shared brief or proposal, or booking a demo.

When an agency puts information about its clients, contacts or creatives into anybrief, the agency decides what is collected and why. We process that information on the agency’s behalf. If you are one of those people and have a question about your data, please contact the agency first. We will help them respond.

What we collect

If you have an anybrief account

  • Your name, email address, password (stored only as a secure hash, never in plain text) and, if you add one, a profile picture.
  • Your organisation’s name, logo and subdomain, and your role within it.
  • Everything you create in the platform: briefs, proposals, deliverables, client records, labels, comments, submissions and the documents you upload.
  • API keys you create (stored only as a hash) and when they were last used.

If you are a creative

  • Your email address and, if the agency supplied one, your name.
  • The files, links, notes and comments you submit against a brief.

If an agency enters your details

  • For client contacts: your name, email address and phone number, alongside the client company’s name, website, background, target audience and brand guidelines.
  • For invitees and allowlisted creatives: your email address, the role you were invited to, and who invited you.

Collected automatically

  • Usage events tied to your account, such as creating a brief, sending an invitation or using the AI assistant, and the pages you view (see Analytics below).
  • Error reports when something goes wrong, including your account and organisation identifiers.
  • Your IP address, used briefly for rate limiting and to protect the service from abuse.
  • On public brief pages, a view count and any optional rating or comment you leave. These are not linked to a name or email.

If you book a demo

Demo bookings are made through Calendly, which collects your booking details under its own privacy policy. We only record that a booking was made.

How we use your data

  • To provide the service: accounts, organisations, briefs, proposals, sharing, submissions and reviews.
  • To send emails the service needs: invitations, password resets, creative sign-in links and codes, and notifications when work is submitted or commented on. Notification emails name the person who acted and include the comment text. We do not send marketing email from the app.
  • To power the AI features described below.
  • To understand how the platform is used and to shape new features based on real behaviour and feedback.
  • To keep the service secure: rate limiting, malware scanning of uploads and error monitoring.

Under UK data protection law we rely on our contract with you (or your agency) to provide the service, and on our legitimate interests in improving and securing it for analytics, error monitoring and abuse prevention.

AI features

Some features send content to third-party AI providers to generate or edit briefs and proposals. We use Anthropic (Claude), OpenAI and Perplexity through their business APIs, whose terms do not allow the content we send to be used to train their models.

What may be sent:

  • The brief summary or project description you write, and the client’s background and target audience.
  • Proposal text and, for proposals, the client’s company name and website.
  • Documents and images you upload as references (PDF, PNG, JPEG or WebP).
  • Your messages to the editor assistant, together with the brief or proposal being edited.
  • A client’s website address, when you ask anybrief to draft a company background from it. Perplexity reads the public website; we store only the summary it returns.

What is never sent to AI providers:

  • Client contact names, email addresses or phone numbers.
  • Creative submissions, submission files or review comments.
  • Your name or email address. Requests carry only an anonymous account identifier.

Reference documents uploaded to generate a brief are read once and then deleted, within 24 hours at the latest. Reference documents attached to a proposal are kept with that proposal so it can be regenerated.

Analytics, error monitoring and security

PostHog

We use PostHog, hosted in the European Union, to understand how the product is used. When you are signed in, PostHog events are linked to your account (your user identifier, name and email) and include actions such as creating a brief or sending an invitation, and the pages you view. PostHog may also record sessions so we can watch how a feature is used. We measure AI usage (tokens, cost and response time) but the content of prompts and responses is not sent to PostHog. PostHog runs across the website and the app, including shared brief and proposal pages.

Google Analytics

On our public marketing pages (the homepage, this policy, and our FAQ and blog pages) we use Google Analytics to understand how visitors find and use the site. It sets _ga and _ga_* cookies in your browser to tell visitors apart. It is not loaded inside the anybrief app or on organisation subdomains.

Sentry

We use Sentry, hosted in the European Union, to report errors. When an error happens in your browser, Sentry may capture a replay of that session with all text masked and all images and media blocked. Error reports can include your account and organisation identifiers, but not your email address.

Rate limiting

To protect the service from abuse we count requests per IP address, per account and, for creative sign-in, per email address. These counters are held in Upstash and expire within minutes (at most 15 minutes). When a limit is exceeded, the identifier is written to our logs.

Cookies and local storage

  • Session cookie (essential): keeps you signed in for up to 30 days and is shared across anybrief subdomains so you stay signed in when you switch organisation. A companion cookie protects sign-in forms from forgery.
  • Preference cookies: remember the filters and sort order you chose on your brief and proposal lists, for 30 days.
  • Google Analytics cookies: marketing pages only, as described above.
  • Local storage: PostHog stores its identifiers in your browser’s local storage rather than cookies. We also use local storage for your theme choice, AI suggestions you have not yet applied, and checklist progress on a brief.
  • Session storage: while you use the app, your browser keeps a copy of the briefs, proposals and client records (including client contact details) you have opened, and the lists you have viewed, so pages load faster. Each copy is reused for at most five minutes, and everything in session storage is discarded when you close the tab.

You can clear or block cookies and local storage in your browser settings. Blocking the session cookie will sign you out. Google offers a browser add-on to opt out of Google Analytics.

Where your data is stored and who processes it

We use a small number of service providers to run anybrief. They process data only on our instructions and only for the purpose listed.

ProviderWhat forWhere
VercelHosts the website and app, and keeps short-lived server logsUnited Kingdom (London)
SupabaseOur database: accounts, organisations, clients, briefs, proposals, commentsUnited Kingdom (AWS London)
Amazon Web ServicesFile storage (S3) for uploads and creative submissions, with malware scanning of submissionsUnited Kingdom (London)
Anthropic, OpenAI and PerplexityAI generation and editing features (see AI features above)United States
ResendSends our transactional emailsUnited States
PostHogProduct analytics and session recordingsEuropean Union
SentryError monitoringEuropean Union (Germany)
UpstashRate limiting (short-lived IP, account and email identifiers)United Kingdom (London)
GoogleGoogle Analytics on our marketing pages onlyUnited States
CalendlyDemo bookings made from our websiteUnited States

Your account data, briefs, proposals and uploaded files live in the United Kingdom. Some providers process data outside the UK. Where that happens we rely on the safeguards recognised under UK data protection law, such as adequacy regulations and standard contractual clauses.

Who can see your data

We never sell, rent or trade your personal information, brief content or client data. Beyond the providers above, data is visible only in these ways:

  • Within your organisation: members see briefs, proposals and clients according to their role and the clients they have been given access to.
  • Shared links: a published brief or proposal can be viewed by anyone with its link. Shared pages show the client company’s name, logo, website and background, but never client contact details. Profile pictures and organisation logos are served from public URLs so they can appear on shared pages.
  • Creatives: a creative you invite sees the brief and their own submissions. Their name appears on their submissions and comments and in the notification emails sent about them.
  • Agency integrations: an agency can ask us to post new submissions to its own systems. That message contains the submitter’s name, email and note, but never the files themselves.
  • Legal requirements: if we are required to by law, or to protect the rights and safety of our users or the public.

How long we keep your data

  • Account, organisation and content data is kept for as long as your organisation uses anybrief. Briefs, proposals and clients you delete are hidden from the product straight away and permanently removed on request.
  • Brief reference documents are deleted after generation, within 24 hours at the latest.
  • Creative sign-in links and codes are single-use and expire shortly after they are sent.
  • Rate-limiting records expire within 15 minutes.
  • Your session lasts up to 30 days unless you sign out earlier.

To close your account or have your organisation’s data permanently deleted, email us at the address below.

How we protect your data

  • All traffic to anybrief is encrypted in transit.
  • Uploaded files and the database are encrypted at rest.
  • Passwords and API keys are stored only as secure hashes.
  • Files submitted by creatives are scanned for malware before anyone can download them.
  • Creatives never set a password. Their sign-in links and codes are single-use and expire.
  • Every organisation’s data is isolated, and access is checked on every request against the person’s role and client access.

Your rights

You have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to how we use it, and to receive a copy in a portable format. To exercise any of these, email us at support@anybrief.com.

If an agency entered your details into anybrief, please contact that agency first, and we will support them in responding to you.

Anybrief LTD is registered as a data controller with the UK Information Commissioner’s Office (ICO). If you are unhappy with how we have handled your data, you have the right to complain to the ICO at ico.org.uk, though we would appreciate the chance to help first.

Changes to this policy

When we change this policy we update the effective date at the top of this page. For significant changes we will let account holders know by email or inside the app.

Anybrief LTD

71-75 Shelton Street

Covent Garden

London, WC2H 9JQ

United Kingdom

support@anybrief.com