Privacy Policy
Last updated: 6 August 2026
This Privacy Policy explains how Lengin OÜ(“ Briefkits”, “we”, “us”) collects, uses, shares, and retains information when you use the Briefkits application at app.briefkits.com and the briefkits.com website (together, the “Service”).
Briefkits is an advertising-analytics tool for businesses. You connect your own advertising account, and we analyse the performance of your own ads and creatives to produce insights and creative briefs.
We are the data controller for the information described below. You can reach us at info@lengin.com, or by post at Kaupmehe tn 7-120, Kesklinna district, Tallinn city, Harju county, 10114, Estonia.
1. Information we collect
1.1 Information you give us
- Account information — your email address and full name, created when you sign up. You can sign up with an email and password, or with Google. Authentication (passwords, sessions, email confirmation, password resets) is handled by our infrastructure provider, Supabase. We never see or store your password in readable form.
- Organisation and workspace information — the names of the organisations and workspaces you create, the members you invite (their email addresses), and their roles. If someone invites you to their organisation, we receive your email address from them, and use it solely to deliver the invitation and set up your membership.
- Content you enter — brand context, product categories, notes, hypotheses, and similar text you add to your workspaces.
- Support and billing correspondence — messages you send us, including credit requests and subscription-cancellation feedback.
1.2 Information we receive from Meta when you connect an ad account
When you connect a Meta (Facebook/Instagram) advertising account, you are asked to grant a specific set of permissions: ads_read (read your ads and their performance metrics), pages_show_list (see the list of Facebook Pages you manage), and pages_read_engagement (read the content your Pages have published, such as the posts and videos behind your ads). Based on the permissions you grant, we receive and store:
- An access token for the connection, so we can retrieve data on your behalf. Tokens are stored encrypted and are never exposed to your browser or to other customers.
- Basic profile of the connecting user — your Facebook user ID and name, received as part of the authorisation dialog. We use them only to identify and label the connection; they are not used to sign you in or to create a Briefkits account, and we do not post to Facebook on your behalf.
- The list of ad accounts and Pages you administer — so you can choose which of them to connect. We store details only for the ones you select.
- Ad account details — account ID, name, currency, and account status.
- Page details — the Page ID and name of the Pages covered by your authorisation, shown to you when you connect. We use them to locate the published posts and videos behind your ads; we do not keep a separate register of your Pages.
- Ads and creatives — ad names, IDs, and the creative assets themselves (video and image files, including thumbnails and video URLs).
- Aggregated performance metrics — spend, impressions, clicks, CTR, CPM, reach, frequency, video plays, ThruPlays, average watch time and retention curves, link clicks and landing-page views, conversion counts and values (such as purchases, leads, add-to-cart, and associated revenue), and aggregate engagement counters (reactions, comments, shares, saves), together with the dates they relate to.
We do not receive, request, or store personal data about the people who saw or interacted with your ads. We only access aggregated, ad-level statistics and the creative assets you yourself published. We do not read comments, messages, follower lists, or any other information about individual people, and we do not access your personal Facebook timeline, friends, or private messages.
1.3 Information collected automatically
- Technical logs — our hosting and infrastructure providers keep short-lived technical request logs (including IP address and browser user-agent string) as part of operating the platform. We use them solely to operate the Service, secure accounts, and investigate abuse.
- Cookies — strictly necessary session cookies set by Supabase to keep you signed in, plus a small number of functional first-party cookies (your selected workspace, invitation and Facebook-connection flow state). We do not use advertising, analytics, or third-party tracking cookies, and we do not run analytics or tracking scripts in the application.
1.4 Payment information
Subscriptions are processed by Stripe. Stripe collects and stores your payment-card details directly; we never receive or store your full card number. We store your Stripe customer ID, your plan, subscription status, billing period, and credit usage.
2. How and why we use your information
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Create and secure your account, sign you in | Account information, session cookies | Performance of a contract |
| Retrieve and display your advertising performance | Meta access token, ad account details, ads, creatives, metrics | Performance of a contract |
| Generate AI analyses, insights, and creative briefs | Creative assets, metrics, brand context | Performance of a contract |
| Team collaboration — invitations, roles, shared reports | Account and organisation information | Performance of a contract |
| Process subscriptions, credits, invoices | Billing information | Performance of a contract; legal obligation |
| Send transactional emails (invitations, confirmations, notices) | Email address | Performance of a contract |
| Prevent fraud and abuse; investigate security incidents | Technical logs | Legitimate interests |
| Meet legal, accounting, and tax obligations | Billing records | Legal obligation |
We do not sell your personal data, do not share it with data brokers, and do not use it to target advertising to you or to anyone else.
You are not legally obliged to provide us with any of this information, but without the data described above we cannot provide the Service to you.
3. Automated processing by AI providers
To produce creative analyses and briefs, we send your ad creatives (video and image content) and the associated performance metrics to AI providers who process them on our behalf:
- Google Cloud (Vertex AI / Gemini) — describes and analyses video and image creatives and generates the written analyses, hypotheses, and creative briefs.
- Anthropic (Claude)— structures the brand context and product categories you set up for a workspace. If you provide your website address as part of that context, Anthropic’s systems retrieve publicly available pages of that website on our behalf.
These providers act as our processors under contract. They process the content only to return a result to us, and are not permitted to use it to train their models. For the creative-analysis pipeline we log request metadata (model used, token counts, cost) for billing and monitoring.
These analyses are advisory. They do not produce legal effects for you and are not used to make automated decisions about you.
4. Who we share information with
We share information only with service providers that make the Service work:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, background processing | EU (Ireland) |
| Vercel | Application hosting | Global edge network |
| Meta Platforms | Source of the advertising data you authorise | US |
| Google Cloud (Vertex AI) | AI analysis of creatives | US |
| Anthropic | AI generation of analyses and briefs | US |
| Stripe | Payment and subscription processing | US/EU |
| Resend | Transactional email delivery | US |
We may also disclose information where legally required — to comply with a valid legal process, to enforce our terms, or to protect the rights and safety of our users. If we are ever involved in a merger or acquisition, we will notify you before your information becomes subject to a different privacy policy.
5. Data we obtain from Meta: specific commitments
In line with the Meta Platform Terms, we commit that data obtained through the Meta Marketing API is:
- used only to provide analytics and creative insights to the account owner who authorised the connection;
- never sold, licensed, or transferred to data brokers, advertising networks, or any third party other than the processors listed above;
- never used to build user profiles, to target advertising, or for any purpose unrelated to the Service;
- deleted as follows: the stored access token is deleted when you disconnect Facebook, and imported advertising data is deleted when you detach the ad account, delete the workspace, or delete your account (see Section 7).
You can revoke our access at any time:
- In Briefkits — press Disconnect in Settings → Workspaces. This deletes the stored access token and also revokes Briefkits’s authorisation on Facebook’s side for you.
- In Facebook — go to Settings & Privacy → Settings → Apps and Websites, select Briefkits, and remove it. For connections made through a Business account, use Business Settings → Integrations → Connected Apps.
Revoking access in Meta stops any further data retrieval immediately. To also have the data we already imported deleted, follow Section 7.
Briefkits is an independent product and is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc.
6. How long we keep information
- Account, organisation, and workspace data — for as long as your account is active.
- Advertising data, creatives, and AI analyses — for as long as the workspace exists and the ad account they came from remains attached, so that historical comparisons remain available to you.
- Meta access tokens — until you disconnect Facebook in Briefkits, which deletes the stored token. Revoking access in Meta or token expiry makes the stored token permanently unusable.
- Technical logs — kept by our hosting providers for their standard short retention periods.
- Billing records — 7 years from the end of the financial year in which the transaction was recorded, as required by Estonian accounting and tax law.
When you delete your account, the corresponding database records are deleted immediately, and stored copies of creative files are removed by an automated cleanup shortly afterwards — in all cases within 30 days. The exceptions are records we must retain by law (principally billing records) and backups, which are overwritten on our provider’s normal backup cycle of seven days.
7. How to delete your data
You have two ways to have your data deleted:
- Delete your account in the app. Sign in and go to Settings → Account → Delete account. This permanently deletes your profile and personal data. If you own an organization, this also permanently deletes that organization — all of its workspaces, connected ad-account tokens, imported advertising data, and AI analyses — together with the accounts of its members, and you will be shown exactly what will be removed before you confirm. The action cannot be undone.
- Ask us. Email info@lengin.comfrom the address associated with your account with the subject “Data deletion request”. We will verify the request and complete the deletion within 30 days, and confirm by email when it is done.
If you are a member of an organisation owned by someone else, be aware that the organisation’s owner can delete the organisation. That deletes all of its workspaces and data, and — if that organisation is your only footprint in Briefkits — your account with it. If you also own or belong to another organisation, your account survives and only the membership is removed.
If you connected a Meta ad account and later removed Briefkits in your Facebook settings, we can no longer retrieve any data from Meta, but the data already imported remains in your Briefkits account until you delete it. Disconnect the ad account (see below) or use either method above to have it removed.
To remove only your Meta advertising data while keeping your Briefkits account: detach the ad account (or delete the workspace that contains it) in Settings → Workspaces — this deletes the data imported from that account — and press Disconnect there to delete the stored access token.
8. Your rights
Depending on where you live, you have the right to access, correct, delete, or export your personal data; to restrict or object to certain processing; and to withdraw consent where processing relies on it. You can exercise most of these directly in the app, or by emailing info@lengin.com. We respond within 30 days.
If you are in the EEA or the UK and believe we have handled your data improperly, you may lodge a complaint with your local data-protection authority.
9. International transfers
We are based in Estonia, and several of our providers are located in the United States. Where personal data is transferred outside the EEA/UK, we rely on the European Commission’s Standard Contractual Clauses or an equivalent safeguard offered by the provider.
10. Security
Access to your data is restricted at the database level by row-level security, so members of one organisation cannot read another’s data. Stored creative files are held in private storage and served only through short-lived signed links issued to authorised viewers. Data is encrypted in transit (TLS) and at rest by our infrastructure providers, and ad-platform access tokens are additionally encrypted at the application level before they reach the database. Access by our staff is limited to what is necessary to operate and support the Service.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority as required by law.
11. Children
The Service is a business tool and is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the Service evolves. We will post the revised version at this URL and update the “Last updated” date. If the changes are material, we will notify account holders by email before they take effect.
13. Contact
Lengin OÜ
Kaupmehe tn 7-120, Kesklinna district, Tallinn city, Harju county, 10114, Estonia
Email: info@lengin.com