Draft
Privacy Policy
Placeholder copy — not legal advice. Last updated September 5, 2026.
This is a short draft of how Rebrief handles data. It is not legal advice and will be replaced with reviewed copy before a public launch.
What we collect
When you sign in with Google we store your name, email, and profile image, plus OAuth tokens needed to list Google Business Profile locations and sync reviews. We store reviews, themes, pulse snapshots, action items (including completion timestamps), private floor feedback, and — on Pro — competitor summaries from a paid provider or a sample neighborhood when mock flags are on.
How we use it
We use this data to build your theme dashboard, send a Monday pulse email (via Resend) if you ask for it, and process Pro billing (via Stripe). We do not sell guest reviews. AI theme analysis, when enabled, sends review text to OpenAI to cluster complaints.
Processors
- Auth.js / Google — sign-in and Business Profile
- Neon — Postgres database
- Vercel — hosting
- Stripe — subscriptions
- Resend — transactional email (from Rebrief <hello@getrebrief.app>)
- Outscraper — optional live competitor reviews (never a key you paste in the UI)
Retention
We keep account and location data while your account is open. You can disconnect Google in Settings and cancel Pro through Stripe. Ask us to delete an account and we will remove personal rows we control, except where we must keep records (billing, abuse).
Contact
Privacy questions: use the email on your signed-in account. Guests who submit floor feedback should contact the shop that displayed the QR.