Legal · Updated 2026-10-09

Privacy Policy

What BuiltBrief collects, why, who processes it, how long we keep it and the rights you have.

Last updated: 9 October 2026

This policy explains how coderband LLC, the company that operates BuiltBrief, handles personal data. It covers our customers, the people who receive briefs, visitors to builtbrief.com, and the developers and other contributors whose work BuiltBrief reads.

Who we are. coderband LLC, 75 E 3rd St, Ste 7, Sheridan, WY 82801, USA. Email: hello@builtbrief.com.

1. Two roles, in short

If you're a contributor whose work is read by BuiltBrief, see section 9.

2. What we collect

From customers and brief recipients

Data Examples Source
Account data GitHub username and user ID, name and email from your GitHub profile, workspace settings You, through GitHub sign-in
Recipient data Email addresses of the owner and up to 5 reader recipients The account owner
Billing status Plan, subscription status, renewal date, Stripe customer and subscription IDs Stripe
Support messages What you write to us You
Security and service logs IP address, browser type, request times, errors Your device, through our hosting provider

We don't receive your full card number. Payments are handled by Sold through Link, LLC, a Stripe affiliate, which acts as merchant of record and controls payment data under its own privacy policy.

From connected GitHub repositories

Data Examples Stored?
Pull request, issue, check and deployment metadata Titles, numbers, links, states, timestamps, check and deployment results, and whether the author was a bot or carried a coding-agent signal (not who the author or reviewers were) Stored
Pull request and issue text Descriptions, comments and review comments Processed, not stored
Diff excerpts Size-limited excerpts of pull request diffs Processed, not stored
Generated content Per-PR digests and the period brief Stored

"Processed, not stored" means we fetch the material into memory, send it to our AI model provider to write digests, and then discard it. We don't save it in our database. Our model provider keeps API inputs and outputs for a limited time (see section 5).

Repository content can contain personal data, such as names in commit messages or comments. We don't try to collect it, but it may pass through our processing.

3. What we don't do

4. Why we use data, and our legal bases

For people in the EU, UK and similar places, here is our legal basis under the GDPR for each purpose where we are controller.

Purpose Legal basis
Create and run your account, deliver briefs, provide support Performance of a contract (Art. 6(1)(b)). Where the contract is with your employer, our legitimate interest in serving our business customer (Art. 6(1)(f))
Manage subscriptions and billing status Performance of a contract (Art. 6(1)(b))
Keep the service secure, prevent abuse, fix errors Legitimate interests in running a safe, reliable service (Art. 6(1)(f))
Send service and legal notices Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))
Keep business and tax records Legal obligation (Art. 6(1)(c))
Establish or defend legal claims Legitimate interests (Art. 6(1)(f))

For repository data, the customer decides the legal basis, because it is the controller. Our customers usually rely on legitimate interests. Our notice templates explain this to contributors.

BuiltBrief doesn't make decisions about people that have legal or similarly significant effects (Art. 22 GDPR). Our terms forbid customers from using it to evaluate, discipline, pay or terminate individual workers.

5. Who processes data for us

We use these service providers ("sub-processors") to run BuiltBrief:

Provider What it does Data involved Location
Cloudflare, Inc. Hosting (Workers), database (D1), email delivery (Cloudflare Email Service), cookieless website analytics All stored data; brief emails and recipient addresses; service logs Global network; USA company
Anthropic PBC AI model (Claude API) that writes digests and briefs PR and issue text, diff excerpts, metadata sent for each run, and the generated text USA
Stripe (including Sold through Link, LLC) Checkout, subscriptions, tax and payment support as merchant of record Billing contact details, payment data, subscription status USA and other Stripe locations
GitHub, Inc. Sign-in (GitHub OAuth) and the source of repository data through the GitHub App GitHub account identity; repository data you've connected USA

About Anthropic. Under its commercial terms, Anthropic may not train models on the content we send. By default, Anthropic deletes API inputs and outputs within 30 days. It may keep them longer where needed to enforce its usage policy (up to 2 years for flagged content) or where the law requires.

About Stripe and Link. As merchant of record, Link also uses payment data for its own purposes, such as fraud prevention, tax compliance and customer support, under its own privacy policy.

About GitHub. Your repositories already live on GitHub under your own agreement with GitHub. We read them through GitHub's API.

We'll update this list before adding a new sub-processor that handles repository data, as set out in the DPA.

We may also disclose data if the law requires it, to protect rights and safety, or as part of a merger or sale of BuiltBrief, in which case this policy will continue to apply to it.

6. International transfers

coderband LLC and our providers are based in the United States, so data is processed in the USA and possibly other countries. When we transfer personal data out of the EU, the UK or Switzerland, we rely on:

Contact us for a copy of the relevant safeguards.

7. How long we keep data

Data How long
Source code, diffs, PR and issue text Not stored by us. Held in memory only while a brief runs. Our model provider keeps API data for up to 30 days by default (see section 5)
PR metadata While the repository is connected, up to 13 months
Digests and briefs Up to 13 months, then deleted
Account data and recipient emails While your account is open
Billing records As long as tax and accounting law requires (often up to 7 years)
Service logs A short period, normally days
Support emails Up to 2 years after the conversation ends

After uninstall or account deletion, we delete repository data, digests, briefs and account data within 30 days, except records we must keep by law.

8. Your rights

Depending on where you live, you may have the right to:

Email hello@builtbrief.com with the subject "Privacy request". We'll reply within one month. We may need to confirm your identity first.

9. If BuiltBrief reads your work but you aren't our customer

If you contribute to a repository that a BuiltBrief customer has connected, your employer or the repository owner decides how BuiltBrief is used. They are the controller, and they should have told you about it. Our developers page explains what BuiltBrief does and doesn't do.

You can still contact us at hello@builtbrief.com with the subject "Contributor privacy". We will:

For a quick result, you can also ask the repository owner directly.

10. Cookies

Because we only use strictly necessary cookies, we don't show a cookie banner.

11. Security

We use encryption in transit and at rest, read-only GitHub access, short-lived access tokens and signed webhooks. Our Security page has the details.

12. Children

BuiltBrief is a business service. It isn't directed at children, and we don't knowingly collect data from anyone under 16. If you think we have, contact us and we'll delete it.

13. Changes

We'll post any changes here and update the date at the top. For material changes, we'll email account owners before they take effect.

14. Contact

coderband LLC, the company that operates BuiltBrief 75 E 3rd St, Ste 7, Sheridan, WY 82801, USA hello@builtbrief.com