Privacy Policy
What BuiltBrief collects, why, who processes it, how long we keep it and the rights you have.
Last updated: 9 October 2026
This policy explains how coderband LLC, the company that operates BuiltBrief, handles personal data. It covers our customers, the people who receive briefs, visitors to builtbrief.com, and the developers and other contributors whose work BuiltBrief reads.
Who we are. coderband LLC, 75 E 3rd St, Ste 7, Sheridan, WY 82801, USA. Email: hello@builtbrief.com.
1. Two roles, in short
- Your account, billing and our website. We decide how this data is used, so we are the controller.
- Data from your GitHub repositories. We process it on our customer's behalf and on their instructions, so the customer is the controller and we are their processor. Our Data Processing Addendum governs that processing.
If you're a contributor whose work is read by BuiltBrief, see section 9.
2. What we collect
From customers and brief recipients
| Data | Examples | Source |
|---|---|---|
| Account data | GitHub username and user ID, name and email from your GitHub profile, workspace settings | You, through GitHub sign-in |
| Recipient data | Email addresses of the owner and up to 5 reader recipients | The account owner |
| Billing status | Plan, subscription status, renewal date, Stripe customer and subscription IDs | Stripe |
| Support messages | What you write to us | You |
| Security and service logs | IP address, browser type, request times, errors | Your device, through our hosting provider |
We don't receive your full card number. Payments are handled by Sold through Link, LLC, a Stripe affiliate, which acts as merchant of record and controls payment data under its own privacy policy.
From connected GitHub repositories
| Data | Examples | Stored? |
|---|---|---|
| Pull request, issue, check and deployment metadata | Titles, numbers, links, states, timestamps, check and deployment results, and whether the author was a bot or carried a coding-agent signal (not who the author or reviewers were) | Stored |
| Pull request and issue text | Descriptions, comments and review comments | Processed, not stored |
| Diff excerpts | Size-limited excerpts of pull request diffs | Processed, not stored |
| Generated content | Per-PR digests and the period brief | Stored |
"Processed, not stored" means we fetch the material into memory, send it to our AI model provider to write digests, and then discard it. We don't save it in our database. Our model provider keeps API inputs and outputs for a limited time (see section 5).
Repository content can contain personal data, such as names in commit messages or comments. We don't try to collect it, but it may pass through our processing.
3. What we don't do
- We don't produce per-person scores, rankings, leaderboards or activity tracking.
- We don't track working hours, presence or idle time.
- We don't sell personal data or use it for advertising.
- We don't use your data, or let our model provider use it, to train AI models.
4. Why we use data, and our legal bases
For people in the EU, UK and similar places, here is our legal basis under the GDPR for each purpose where we are controller.
| Purpose | Legal basis |
|---|---|
| Create and run your account, deliver briefs, provide support | Performance of a contract (Art. 6(1)(b)). Where the contract is with your employer, our legitimate interest in serving our business customer (Art. 6(1)(f)) |
| Manage subscriptions and billing status | Performance of a contract (Art. 6(1)(b)) |
| Keep the service secure, prevent abuse, fix errors | Legitimate interests in running a safe, reliable service (Art. 6(1)(f)) |
| Send service and legal notices | Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Keep business and tax records | Legal obligation (Art. 6(1)(c)) |
| Establish or defend legal claims | Legitimate interests (Art. 6(1)(f)) |
For repository data, the customer decides the legal basis, because it is the controller. Our customers usually rely on legitimate interests. Our notice templates explain this to contributors.
BuiltBrief doesn't make decisions about people that have legal or similarly significant effects (Art. 22 GDPR). Our terms forbid customers from using it to evaluate, discipline, pay or terminate individual workers.
5. Who processes data for us
We use these service providers ("sub-processors") to run BuiltBrief:
| Provider | What it does | Data involved | Location |
|---|---|---|---|
| Cloudflare, Inc. | Hosting (Workers), database (D1), email delivery (Cloudflare Email Service), cookieless website analytics | All stored data; brief emails and recipient addresses; service logs | Global network; USA company |
| Anthropic PBC | AI model (Claude API) that writes digests and briefs | PR and issue text, diff excerpts, metadata sent for each run, and the generated text | USA |
| Stripe (including Sold through Link, LLC) | Checkout, subscriptions, tax and payment support as merchant of record | Billing contact details, payment data, subscription status | USA and other Stripe locations |
| GitHub, Inc. | Sign-in (GitHub OAuth) and the source of repository data through the GitHub App | GitHub account identity; repository data you've connected | USA |
About Anthropic. Under its commercial terms, Anthropic may not train models on the content we send. By default, Anthropic deletes API inputs and outputs within 30 days. It may keep them longer where needed to enforce its usage policy (up to 2 years for flagged content) or where the law requires.
About Stripe and Link. As merchant of record, Link also uses payment data for its own purposes, such as fraud prevention, tax compliance and customer support, under its own privacy policy.
About GitHub. Your repositories already live on GitHub under your own agreement with GitHub. We read them through GitHub's API.
We'll update this list before adding a new sub-processor that handles repository data, as set out in the DPA.
We may also disclose data if the law requires it, to protect rights and safety, or as part of a merger or sale of BuiltBrief, in which case this policy will continue to apply to it.
6. International transfers
coderband LLC and our providers are based in the United States, so data is processed in the USA and possibly other countries. When we transfer personal data out of the EU, the UK or Switzerland, we rely on:
- the EU-US Data Privacy Framework (and its UK and Swiss extensions) for providers certified under it; and
- the EU Standard Contractual Clauses (with the UK Addendum where relevant) in all other cases, including transfers from our customers to us.
Contact us for a copy of the relevant safeguards.
7. How long we keep data
| Data | How long |
|---|---|
| Source code, diffs, PR and issue text | Not stored by us. Held in memory only while a brief runs. Our model provider keeps API data for up to 30 days by default (see section 5) |
| PR metadata | While the repository is connected, up to 13 months |
| Digests and briefs | Up to 13 months, then deleted |
| Account data and recipient emails | While your account is open |
| Billing records | As long as tax and accounting law requires (often up to 7 years) |
| Service logs | A short period, normally days |
| Support emails | Up to 2 years after the conversation ends |
After uninstall or account deletion, we delete repository data, digests, briefs and account data within 30 days, except records we must keep by law.
8. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- correct it;
- delete it;
- restrict or object to our use of it, including where we rely on legitimate interests;
- receive it in a portable format;
- withdraw consent, where we rely on consent;
- complain to your data protection authority.
Email hello@builtbrief.com with the subject "Privacy request". We'll reply within one month. We may need to confirm your identity first.
9. If BuiltBrief reads your work but you aren't our customer
If you contribute to a repository that a BuiltBrief customer has connected, your employer or the repository owner decides how BuiltBrief is used. They are the controller, and they should have told you about it. Our developers page explains what BuiltBrief does and doesn't do.
You can still contact us at hello@builtbrief.com with the subject "Contributor privacy". We will:
- tell you which customer connected the repository, where the law allows;
- pass your request or concern to that customer and help them answer it;
- act on requests ourselves where the law requires us to.
For a quick result, you can also ask the repository owner directly.
10. Cookies
- We use one cookie: a strictly necessary session cookie that keeps you signed in. It is deleted when you sign out or when it expires.
- We use no analytics, advertising or tracking cookies.
- Cloudflare may set a strictly necessary security cookie if its bot-protection features are triggered.
- Checkout runs on a Stripe page, which sets its own cookies under Stripe's and Link's policies.
Because we only use strictly necessary cookies, we don't show a cookie banner.
11. Security
We use encryption in transit and at rest, read-only GitHub access, short-lived access tokens and signed webhooks. Our Security page has the details.
12. Children
BuiltBrief is a business service. It isn't directed at children, and we don't knowingly collect data from anyone under 16. If you think we have, contact us and we'll delete it.
13. Changes
We'll post any changes here and update the date at the top. For material changes, we'll email account owners before they take effect.
14. Contact
coderband LLC, the company that operates BuiltBrief 75 E 3rd St, Ste 7, Sheridan, WY 82801, USA hello@builtbrief.com