Privacy policy
What Briefly stores, and what leaves your browser
Written to be read rather than to be defensible. Every statement here describes something the extension actually does, and most of them can be checked from Chrome’s own dialogs without taking our word for anything.
1. The short version
- Briefly does nothing until you click its icon. It has no content script and no background activity, so it is not running on the pages you read.
- On the free tier, we receive nothing at all. Your page text goes from your browser directly to the model provider whose key you configured.
- On Pro, page text reaches our server carrying no identifier of you — the request that proves your licence and the request that carries your reading are separate calls, by design.
- There is no analytics, no tracking and no advertising. We do not sell or share personal information, and there is no pipeline that could.
- Everything you save stays on your device until you delete it.
2. What Briefly stores, and where
All of it is in chrome.storage.local, on your own
machine. None of it is uploaded, backed up by us, or readable by us.
| What | Why it exists |
|---|---|
| Your consent record | So the consent screen is shown once rather than every time. |
| Your provider, model and API key | So Briefly knows where to send a request. The key is used as authentication to that provider and is sent nowhere else, ever. |
| Saved summaries | The ones you chose to save: the page title, its URL, the claims and their source sentences. Unlimited, and never dropped to make room. |
| An install identifier | A random value generated on this device. It is used only to bind a Pro licence to an installation, and it never travels alongside page text. |
| Your licence status | Whether this install is Free or Pro, and when that was last checked. |
3. What is sent on the free tier
One request, made only when you click the Briefly icon on a page with a readable article in it. Where it goes depends on whether you have added an API key of your own, and the consent screen names the recipient before anything is sent.
If you have not added a key — the default
The request goes to Briefly’s server, which holds our API key and passes the text to Groq, our model provider. It contains the title and article text of the page you are on, and nothing else — no URL, no account, and no identifier of you or your install.
- Our server does not store the text. It exists in memory for the length of one request and is written to no database, no log and no file.
- Groq does not train on it. Their Services Agreement excludes using customer inputs and outputs for training or fine-tuning, on every plan.
- This route has a daily limit. When you reach it, Briefly tells you and offers the option below; it does not silently keep sending.
If you have added a key of your own
The request goes from your browser straight to the provider you chose, carrying the page text, the model id you selected, and your API key as authentication to them.
It does not pass through any server of ours. Briefly’s server is not in the path and receives nothing about it — not the page, not the URL, not the fact that it happened. There is no limit on this route.
Two outcomes send nothing at all, on either route: a page with no readable article, and a page short enough that reading it is quicker than summarising it. Both say so on screen.
4. What is sent on Pro
On Pro we run the model, so page text does reach our server. It is deliberately arranged so that the server cannot connect that text to you.
Two separate requests, on purpose
- The licence check sends your install identifier and no page text. It returns an opaque token that records a tier and an expiry and nothing else. The token is valid for one hour.
- The summarise request sends the page title and article text with that token, and no install identifier of any kind. There is no account, cookie, or device value attached to it.
Because the token records only a tier, the part of our server that handles page text is structurally unable to learn whose reading it is handling. This is a build-time guarantee rather than a policy promise: the packaged extension is checked before every release and rejected if an identifier ever appears beside page text.
What buying Pro records on our server
One row, and it holds no customer in it:
| What | Why it exists |
|---|---|
| Your install identifier | The random value your browser generated. It is what the licence is attached to, so that the extension can be told it is Pro. |
| A Freemius licence number | So we can ask Freemius, hourly, whether the licence is still good — which is how a cancellation or a refund reaches the product. |
| A one-way hash of your licence key | So that pasting your key after a reinstall is recognised. The key itself is never stored, so a copy of this table cannot be used to claim anything. |
| Billing cycle, status and expiry | Whether the licence is live, and until when. The cycle is recorded for support and never changes what you get. |
There is no name, email address, country or payment detail in it, and no column that could hold one. Freemius is the merchant of record and holds the customer record; we hold a pointer to it. That is also why we cannot look your purchase up by email — support requests need the licence key or the receipt.
Activating the licence on another browser moves it there and tells the previous one why, on its next check. Nothing about which pages either browser summarised is recorded, because that is never stored anywhere in the first place.
Abuse limits
To stop one licence being shared across a hundred machines, the server derives a salted hash of a device value. It is not reversible without a secret held only on the server, it is retained for 48 hours and then deleted, and it is never joined to a licence, an email address or a page.
The translation request works the same way: the claim text and the target language, with the same opaque token and no identifier.
Article text is used to produce your summary and is not retained afterwards. It is not stored, logged, used for training, or shared with anyone other than the model vendor that produces the response.
5. What Briefly never collects
- Analytics, telemetry or usage events of any kind.
- Your browsing history, or a record of which pages you summarised.
- Your name, email address or account — there is no account.
- Cookies, advertising identifiers or cross-site tracking.
- Anything at all from pages you did not explicitly click the icon on.
We do not sell, rent or share personal information, and we do not use it for advertising or for training any model of our own. There is no data pipeline in the product that could do either.
6. Permissions, and what each is for
| Permission | What it is used for |
|---|---|
activeTab |
Read the article in the tab you are on, granted by your click and only for that tab at that moment. |
scripting |
Inject the extraction script into that tab at the moment of the click. It is the only way to read the article without a permanent script on every page. |
storage |
Keep your settings, your key and your saved summaries, all locally. |
| Host access | Reach the one provider you configured. Requested individually, at the moment you configure it, and revocable at any time. |
Briefly requests no host access at install. A fresh install can reach nothing, which is why Chrome shows no site-access warning when you add it.
7. Other companies involved
- Groq, Inc. is the model provider behind Briefly’s own key. If you have not added a key of your own, they receive your page text from our server to produce the summary, with no identifier of you attached. Their Services Agreement excludes using customer inputs and outputs for training or fine-tuning.
- The model provider you choose, if you add your own key, receives your page text directly from your browser under the API agreement you hold with them. Their privacy terms govern what happens next, and our server is not involved. Thirteen are offered and you pick one.
- Freemius, Inc. will be our reseller and Merchant of Record for Pro, which is not yet on sale. They will handle checkout, payment, tax and invoicing, and hold whatever billing information you give them. We never receive card details.
There are no other third parties. There is no analytics vendor and no ad network.
8. How long anything is kept
- On your device: until you delete it. Saved summaries, your key and your settings stay until you clear them or remove the extension.
- Page text on our server (Pro): for the duration of the request that produced your summary. It is not written to storage or to logs.
- The tier token (Pro): one hour, then it expires and is discarded.
- The salted abuse hash (Pro): 48 hours, then deleted.
- Our licence row (Pro): for as long as the licence is live. Once it ends — cancelled, refunded, expired, or moved to another browser — the row is deleted after 90 days. Long enough that renewing or coming back to an old machine still recognises you; short enough that an identifier for somebody who left does not sit there indefinitely.
- Your purchase record: kept by Freemius for as long as your purchase requires, under their terms. We never hold a copy.
9. Your choices
Because almost everything is local, most of these take effect immediately and need no request to us.
- Stop Briefly reaching the network: remove your key in Settings, which also withdraws the host permission. Chrome’s own extension settings will revoke site access at any time.
- Delete your data: clear your saved summaries in Briefly, or remove the extension, which deletes everything it stored.
- Revoke a provider’s copy of your key: delete the key in that provider’s dashboard. It stops working instantly, everywhere.
- Ask us anything about your data: email us. Since we hold no identifier for a free install, there is usually nothing of yours for us to find — which is the intended outcome rather than an evasion.
10. This website
These pages set no cookies, load no third-party fonts, scripts or images, and run no analytics. The only thing stored in your browser is your light or dark theme choice, which never leaves it.
Our web host records ordinary server access logs, as every web server does. We do not use them to build any profile of visitors.
11. Children
Briefly is not directed at children under 13 and we do not knowingly collect information from them. Since the extension collects no personal information from anyone, there is nothing of a child’s for us to hold.
12. Changes, and how to reach us
If this policy changes, the date at the top of this page changes with it and the new version is published here. A change that materially reduces your privacy would be announced in the extension itself, not only on this page.
Briefly is made by WaaFaa. Questions about this policy go to our support inbox.