Privacy Policy
Effective from 10 September 2026
Anybrief LTD (“anybrief”, “we”) builds a platform that creative agencies use to write, share and manage briefs and proposals. We care about your privacy. This policy explains what data we collect, how we use it, where it is stored, who we share it with, and the choices you have.
It covers our website at anybrief.com, the anybrief app (including organisation subdomains such as youragency.anybrief.com), and the public brief and proposal pages that agencies share from it.
Who this policy is for
Different people touch anybrief in different ways, and we collect different things about each:
- Agency users: people with an anybrief account who belong to an organisation.
- Creatives: freelancers an agency invites to submit work against a brief. They do not need a password; they sign in with a single-use link or code sent to their email.
- People an agency enters into anybrief: client contacts, colleagues who have been invited, and creatives on a brief’s allowlist.
- Visitors: anyone browsing our website, viewing a shared brief or proposal, or booking a demo.
When an agency puts information about its clients, contacts or creatives into anybrief, the agency decides what is collected and why. We process that information on the agency’s behalf. If you are one of those people and have a question about your data, please contact the agency first. We will help them respond.
What we collect
If you have an anybrief account
- Your name, email address, password (stored only as a secure hash, never in plain text) and, if you add one, a profile picture.
- Your organisation’s name, logo and subdomain, and your role within it.
- Everything you create in the platform: briefs, proposals, deliverables, client records, labels, comments, submissions and the documents you upload.
- API keys you create (stored only as a hash) and when they were last used.
If you are a creative
- Your email address and, if the agency supplied one, your name.
- The files, links, notes and comments you submit against a brief.
If an agency enters your details
- For client contacts: your name, email address and phone number, alongside the client company’s name, website, background, target audience and brand guidelines.
- For invitees and allowlisted creatives: your email address, the role you were invited to, and who invited you.
Collected automatically
- Usage events tied to your account, such as creating a brief, sending an invitation or using the AI assistant, and the pages you view (see Analytics below).
- Error reports when something goes wrong, including your account and organisation identifiers.
- Your IP address, used briefly for rate limiting and to protect the service from abuse.
- On public brief pages, a view count and any optional rating or comment you leave. These are not linked to a name or email.
If you book a demo
Demo bookings are made through Calendly, which collects your booking details under its own privacy policy. We only record that a booking was made.
How we use your data
- To provide the service: accounts, organisations, briefs, proposals, sharing, submissions and reviews.
- To send emails the service needs: invitations, password resets, creative sign-in links and codes, and notifications when work is submitted or commented on. Notification emails name the person who acted and include the comment text. We do not send marketing email from the app.
- To power the AI features described below.
- To understand how the platform is used and to shape new features based on real behaviour and feedback.
- To keep the service secure: rate limiting, malware scanning of uploads and error monitoring.
Under UK data protection law we rely on our contract with you (or your agency) to provide the service, and on our legitimate interests in improving and securing it for analytics, error monitoring and abuse prevention.
AI features
Some features send content to third-party AI providers to generate or edit briefs and proposals. We use Anthropic (Claude), OpenAI and Perplexity through their business APIs, whose terms do not allow the content we send to be used to train their models.
What may be sent:
- The brief summary or project description you write, and the client’s background and target audience.
- Proposal text and, for proposals, the client’s company name and website.
- Documents and images you upload as references (PDF, PNG, JPEG or WebP).
- Your messages to the editor assistant, together with the brief or proposal being edited.
- A client’s website address, when you ask anybrief to draft a company background from it. Perplexity reads the public website; we store only the summary it returns.
What is never sent to AI providers:
- Client contact names, email addresses or phone numbers.
- Creative submissions, submission files or review comments.
- Your name or email address. Requests carry only an anonymous account identifier.
Reference documents uploaded to generate a brief are read once and then deleted, within 24 hours at the latest. Reference documents attached to a proposal are kept with that proposal so it can be regenerated.
Analytics, error monitoring and security
PostHog
We use PostHog, hosted in the European Union, to understand how the product is used. When you are signed in, PostHog events are linked to your account (your user identifier, name and email) and include actions such as creating a brief or sending an invitation, and the pages you view. PostHog may also record sessions so we can watch how a feature is used. We measure AI usage (tokens, cost and response time) but the content of prompts and responses is not sent to PostHog. PostHog runs across the website and the app, including shared brief and proposal pages.
Google Analytics
On our public marketing pages (the homepage, this policy, and our FAQ and blog pages) we use Google Analytics to understand how visitors find and use the site. It sets _ga and _ga_* cookies in your browser to tell visitors apart. It is not loaded inside the anybrief app or on organisation subdomains.
Sentry
We use Sentry, hosted in the European Union, to report errors. When an error happens in your browser, Sentry may capture a replay of that session with all text masked and all images and media blocked. Error reports can include your account and organisation identifiers, but not your email address.
Rate limiting
To protect the service from abuse we count requests per IP address, per account and, for creative sign-in, per email address. These counters are held in Upstash and expire within minutes (at most 15 minutes). When a limit is exceeded, the identifier is written to our logs.
Where your data is stored and who processes it
We use a small number of service providers to run anybrief. They process data only on our instructions and only for the purpose listed.
| Provider | What for | Where |
|---|---|---|
| Vercel | Hosts the website and app, and keeps short-lived server logs | United Kingdom (London) |
| Supabase | Our database: accounts, organisations, clients, briefs, proposals, comments | United Kingdom (AWS London) |
| Amazon Web Services | File storage (S3) for uploads and creative submissions, with malware scanning of submissions | United Kingdom (London) |
| Anthropic, OpenAI and Perplexity | AI generation and editing features (see AI features above) | United States |
| Resend | Sends our transactional emails | United States |
| PostHog | Product analytics and session recordings | European Union |
| Sentry | Error monitoring | European Union (Germany) |
| Upstash | Rate limiting (short-lived IP, account and email identifiers) | United Kingdom (London) |
| Google Analytics on our marketing pages only | United States | |
| Calendly | Demo bookings made from our website | United States |
Your account data, briefs, proposals and uploaded files live in the United Kingdom. Some providers process data outside the UK. Where that happens we rely on the safeguards recognised under UK data protection law, such as adequacy regulations and standard contractual clauses.
How long we keep your data
- Account, organisation and content data is kept for as long as your organisation uses anybrief. Briefs, proposals and clients you delete are hidden from the product straight away and permanently removed on request.
- Brief reference documents are deleted after generation, within 24 hours at the latest.
- Creative sign-in links and codes are single-use and expire shortly after they are sent.
- Rate-limiting records expire within 15 minutes.
- Your session lasts up to 30 days unless you sign out earlier.
To close your account or have your organisation’s data permanently deleted, email us at the address below.
How we protect your data
- All traffic to anybrief is encrypted in transit.
- Uploaded files and the database are encrypted at rest.
- Passwords and API keys are stored only as secure hashes.
- Files submitted by creatives are scanned for malware before anyone can download them.
- Creatives never set a password. Their sign-in links and codes are single-use and expire.
- Every organisation’s data is isolated, and access is checked on every request against the person’s role and client access.
Your rights
You have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to how we use it, and to receive a copy in a portable format. To exercise any of these, email us at support@anybrief.com.
If an agency entered your details into anybrief, please contact that agency first, and we will support them in responding to you.
Anybrief LTD is registered as a data controller with the UK Information Commissioner’s Office (ICO). If you are unhappy with how we have handled your data, you have the right to complain to the ICO at ico.org.uk, though we would appreciate the chance to help first.
Changes to this policy
When we change this policy we update the effective date at the top of this page. For significant changes we will let account holders know by email or inside the app.
Anybrief LTD
71-75 Shelton Street
Covent Garden
London, WC2H 9JQ
United Kingdom