Legal

Privacy Policy

Last updated: July 21, 2026

1. Introduction

Briefico ("Briefico", "we", "us") is a Facebook group marketing automation platform for agencies and marketers. Briefico is currently operated as an independent project, not yet as an incorporated company — this policy applies regardless, and describes exactly how we handle your data.

This policy covers the Briefico website (briefico.com), the web app at app.briefico.com, and the Briefico Poster Chrome extension.

2. Data We Collect

  • Account data — email address, password (handled by our authentication provider, Supabase — we never see or store your raw password), organization membership, and role (admin, creator, or publisher).
  • Campaign & content data — post text, images, group lists, and schedules you create in the web app.
  • Facebook group content, while posting— the Poster extension reads the group's post composer to publish your content and confirm it went through. It only interacts with what's already visible to you as a group member — nothing private, nothing hidden.
  • Usage & log data — technical logs of posting tasks (timestamps, success or failure status, error messages) used to keep the service reliable and to support you if something goes wrong.

3. Data We Don't Collect

  • We never store your Facebook password. The Poster extension works inside your own already-logged-in Facebook session in your browser — we never see or handle your Facebook credentials.
  • Briefico never joins Facebook groups automatically. You join groups yourself; only then do they become available to manage in Briefico.
  • We don't collect private messages, private profile data, or anything not already visible to group members.

4. How We Use Data

We use the data above to:

  • Operate the service — authenticate you, run your campaigns, assign and track posting tasks.
  • Generate AI-based category and engagement insights for the Facebook groups you manage.
  • Communicate with you about your account or in response to your inquiries.

5. Third-Party Processors

We rely on a small number of infrastructure providers to run Briefico, listed below. We only share data with these providers, and with law enforcement if legally required — never for advertising, and never by selling or renting it to anyone.

Supabase
Database, authentication, and file storage.
Hetzner
Server hosting for our backend and web app.
Anthropic (Claude API)
Generates the AI category and engagement insights shown on Facebook groups in your dashboard, based on that group's public information — not your private data.
Google (Gemini API)
Used internally to keep our Facebook automation working when Facebook changes its page layout — it only ever sees generic interface text (button labels), never post content or personal data.

6. Cookies & Tracking

briefico.com does not set any analytics or tracking cookies today. app.briefico.com uses only essential session cookies from our authentication provider, needed to keep you signed in — nothing used for advertising or cross-site tracking.

7. Chrome Extension Permissions

Here is exactly why each extension asks for the permissions it does:

storage
Save your extension settings and session locally.
activeTab
Know which Facebook tab to post into or read from — only the tab you're actively on.
scripting
Type post content and read group content on the active Facebook tab.
alarms
Keep checking in reliably for new posting tasks, even if the browser suspends the extension in the background.
Host access to *.facebook.com
Required to post and read content inside your own logged-in Facebook session.
Host access to app.briefico.com
Talk to your Briefico account to fetch tasks and report results.
Host access to 127.0.0.1:47832
Optional — lets the extension talk to the Briefico desktop app on your own computer, if you've installed it, for scheduled automation. Nothing leaves your machine through this connection.

8. Data Retention

  • Account and campaign data is kept for as long as your account is active. If you ask us to delete your account, we'll delete it within 90 days.
  • Task activity logs (what was posted, when, and whether it succeeded) are automatically purged after 90 days.

9. Your Rights

Under GDPR and Israel's Privacy Protection Law, you can ask us to access, correct, delete, or export your data, or object to how we use it. Contact privacy@briefico.com and we'll respond as quickly as we can.

10. Children's Privacy

Briefico is a business tool, not directed at children. We don't knowingly collect data from anyone under 16.

11. International Data Transfers

Our infrastructure providers may process data outside your home country. Where that happens, we rely on our providers' own compliance safeguards (such as Standard Contractual Clauses) for cross-border transfers.

12. Security

  • All traffic is encrypted in transit via HTTPS (Let's Encrypt certificates).
  • Our database enforces row-level security so one organization's data is never visible to another.
  • We never store Facebook credentials, as described above.

13. Changes to This Policy

We may update this policy as Briefico changes. We'll update the "last updated" date above when we do — check back occasionally.

14. Contact

Questions about this policy or your data? Reach us at privacy@briefico.com. Briefico currently operates out of Israel.