This privacy policy explains which personal data the Brief Monster app processes, for what purposes, and what rights you have. It applies to the app and to the website briefmonster.de.
This is an English translation of our Datenschutzerklärung. If the two versions differ, the German version prevails.
1 Controller
- Controller
- multiangular UG (haftungsbeschränkt)
- Address
- Urbanstraße 71, 3. Hof, 4. TRH, 10967 Berlin, Germany
- Represented by
- Wladimir Alexi
- Contact for privacy requests
- privacy@briefmonster.de
We are currently not legally required to appoint a data protection officer. Please send privacy requests to the address above.
2 Overview
Brief Monster is an AI-based assistant: you photograph or upload letters, official notices and bills, ask questions about them and receive explanations, check results, deadline reminders and editable draft texts. To do this, we have to process the content of your documents and your messages on our servers, among other things with text recognition (OCR) and generative AI models.
Our systems run in data centres within the European Union. We do not use your documents, chats or health data to train AI models. We only analyse the content of health data after your separate, explicit consent; the automatic check that comes first, whether a document contains health data, is described under Health data. You can delete your account, including all data, yourself in the app at any time.
3 Cookies and local storage
The website briefmonster.de sets no marketing cookies and does not embed advertising networks or social media plugins. Web analytics with PostHog only takes place if you choose “Accept” in the banner (see Usage analytics).
Without your consent we only use technically necessary storage within the meaning of Section 25(2) No. 2 TDDDG:
- Your choice in the banner: “Accept” or “Decline” is stored in your browser’s local storage (
localStorage, keybm.analytics-consent) so that the banner does not appear again on every visit. The value does not leave your device. - Server logs: as with any website, technical log data is generated when pages are accessed (see section 4, “Log data”).
You can change your choice at any time via “Cookie settings” at the bottom of every page. The Brief Monster app does not use cookies; its optional usage statistics are described in the section Usage analytics.
4 What data we process
- Account data: e-mail address, password (stored only as a hash), with Sign in with Apple the identifier provided by Apple and, where applicable, a relay address, sign-in times, language setting.
- Onboarding profile: information you provide during setup, such as your housing situation, your city or municipality and your health insurance. This information is used to tailor explanations to your situation (for example the rent cap, “Kappungsgrenze”, in your municipality).
- Chats: your messages, the assistant’s answers and the related history data (times, chosen scenario, status of a request).
- Documents: uploaded photos and PDF files, the text obtained from them by text recognition and the extracted information (for example amounts, senders, deadlines). More under Uploaded documents.
- Drafts: letters created by Brief Monster that you edit, save and send yourself.
- Deadlines and scenarios: deadlines that were detected and confirmed by you, and the progress of each scenario.
- Consents: type of consent, text version, time, scope (account or a single chat), IP address and device identifier at the time it was given, and any withdrawal. This data serves as proof under Art. 7(1) GDPR.
- Log data: technical server logs (time, function called, status code, shortened IP address, app version) to keep the service running and for troubleshooting.
- Push token: the device identifier assigned by Apple or Expo for push notifications, if you enable notifications.
- Subscription status: whether and until when a subscription or the free trial is active, and which chat is used during the trial. We do not receive payment data; billing is handled by the App Store.
5 Purposes and legal bases
- Providing the app and your account (registration, sign-in, chats, document analysis, drafts, deadlines, purchase status): Art. 6(1)(b) GDPR (performance of a contract).
- Processing health data from medical bills and medical documents: Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR (explicit consent).
- Push notifications about deadlines and progress: Art. 6(1)(a) GDPR (consent via your device’s system prompt).
- Proof of consents and account deletions, statutory retention: Art. 6(1)(c) GDPR (legal obligation).
- Security, abuse prevention, error analysis and usage statistics in aggregated form: Art. 6(1)(f) GDPR (legitimate interest in secure and stable operation).
6 Uploaded documents
When you photograph or upload a document, the file is transferred encrypted to our storage in the EU. The text is then captured by text recognition, and an AI model extracts the information relevant to the respective scenario. The original file, the recognised text and the extracted information are assigned to your account and – if you start the upload from a chat – to that chat.
Before your first upload we ask for your consent to the processing of your documents. You can give this consent for your entire account or only for the current chat. Without consent no upload is possible; the other functions of the app remain available.
Please only upload documents you are entitled to have processed, and black out data of third parties that is not needed. Uploaded documents, together with the recognised text and the extracted information, are removed when your account is deleted; you can request the deletion of individual documents by e-mail to the address given under Contact.
7 Health data
Medical bills, treatment and cost plans, sick notes and similar documents contain health data within the meaning of Art. 9 GDPR. To detect whether a document contains health data, every uploaded document is first classified automatically. For this, the page images are sent via our gateway to an AI model (see Use of AI models), which only returns the document type, the language, a short description and an assessment of whether health data is included; this result is stored with the document. If a document is classified as medical, further analysis is stopped and the document gets the status “waiting for consent”. Only when you explicitly consent in the app is the information read from the document and are explanations or drafts created. Until then, only the encrypted file and the classification result exist.
Consent is voluntary. You can give it for your account or only for the current chat and withdraw it at any time with effect for the future: in the app under Profile → Consents. After a withdrawal no further medical documents are analysed; explanations and drafts already created remain in your account until you delete your account or request their deletion.
Health data is processed solely to explain and check the plausibility of the respective document and to create the draft texts you request. It is not used for advertising, not passed on to insurers or other third parties and not used to train AI models.
8 Use of AI models
For explanations, check results and draft texts we use generative language models from OpenAI, which we access through the intermediary platform OpenRouter. Requests are routed through a gateway we operate, which secures the requests technically, restricts them to the approved models and logs which model was used. We transmit the content needed for the respective request: your message, the relevant chat history, the pages of uploaded documents or the text recognised from them, and the information from your onboarding profile. Account data such as your e-mail address is not transmitted to the model providers.
We choose model providers and contract terms so that the transmitted content is not used to train the models. Where a model provider processes data outside the EU or the EEA, the transfer is based on the European Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR) or an adequacy decision. The providers we use are listed under Recipients.
For general legal questions, the assistant can run a web search via the search service Keenable or retrieve a public page. Only the search query or the address of the page is transmitted, phrased as a general legal question and not as your case. Recognisable identifiers such as IBANs, e-mail addresses, file references, customer or contract numbers are intercepted on our servers before transmission; names cannot be detected reliably by technical means, and the assistant is instructed not to include them in search queries. Account data is not transmitted to Keenable.
AI output is generated automatically and is for your information. It does not make any legally binding decision about you within the meaning of Art. 22 GDPR; you make all decisions yourself, in particular whether and how you use a draft.
9 Recipients and processors
We use the following service providers. Processors are contractually bound under Art. 28 GDPR and process data only on our instructions.
- Supabase – database, authentication (account, sign-in, Sign in with Apple) and file storage for documents; hosting in the EU. Processor.
- Railway – hosting of the API, of the background service for text recognition and document analysis, and of the AI gateway in a data centre in the EU. Processor.
- OpenAI via OpenRouter – generative language models from OpenAI, accessed through our gateway and the intermediary platform OpenRouter (both based in the USA). The content is processed only to answer the respective request; transfer to third countries based on Standard Contractual Clauses (see Use of AI models).
- Keenable – web search and retrieval of public pages for general legal questions. Only the search query or the address of the page is transmitted, no account data (see Use of AI models).
- Resend – sending the e-mails from noreply@briefmonster.de (sign-in codes, password reset links and, if you turn them on, notifications about finished answers). Your e-mail address and the content of the e-mail are transmitted. Processor.
- Lovable and Cloudflare – delivery of the website briefmonster.de. This involves the technical data described under “Log data”. Processors.
- RevenueCat (RevenueCat, Inc., USA) – management of the subscription status (linking your App Store purchases to your account via your user ID, showing the offer page, checks by our servers whether a subscription or the trial is active). Processed are the user ID, App Store purchase and subscription data and technical device data, no content of your chats or documents; transfer to the USA based on Standard Contractual Clauses. Processor.
- Apple – App Store (purchase, billing, subscription management), Sign in with Apple and the push service APNs. Apple is an independent controller for these services; Apple’s privacy policy applies.
- Expo – delivery of push notifications to APNs via Expo’s push service. The push token and the notification text are transmitted. Processor.
- PostHog (PostHog Inc., USA; processing in the EU cloud in Frankfurt) – usage analytics for the app and the website, only with your consent (see Usage analytics). Processor.
Beyond this, we only pass on personal data if we are legally obliged to or you have expressly consented. We do not pass data on to authorities, insurers, landlords or other recipients of your letters; you send your drafts yourself.
Access by our team: individual, specifically authorised staff members can view your account (e-mail address, registration and activity times, subscription status, consents) and the text of your chats in a protected administration area – to answer your requests, to analyse errors and assure the quality of our answers, and to investigate abuse (Art. 6(1)(b) and (f) GDPR). Uploaded documents, the information recognised from them and drafts created are not shown there; chats with health data are excluded entirely. Every access is logged.
10 Retention and deletion
We store your data as long as your account exists. You can archive chats in the app and mark deadlines as done; individual documents, chats, drafts or deadlines are deleted on request by e-mail to the address given under Contact, or by deleting your account.
You can delete your account in the app under Profile → Account → “Delete account…”. Deletion removes your account data, your profile, all chats, documents, drafts, deadlines, push tokens and consents from our systems. Only the time of the deletion request and of its completion is kept for the duration of the statutory documentation obligations. Backups are overwritten at the end of the backup cycle.
Technical log data is deleted after 30 days at the latest unless it is needed to investigate a security incident. Purchase receipts at the App Store are subject to Apple’s retention periods.
11 Push notifications
If you allow notifications, Brief Monster reminds you of confirmed deadlines and tells you when the analysis of a document is complete or a consent is needed. For this we store your device’s push token. Delivery is via Expo and Apple’s push service (APNs). You can turn notifications off at any time in your device settings or in the app under Profile → Notifications; the token is then deleted.
12 Usage analytics (PostHog)
Only if you agree – in the app under Profile → Consents → “Usage statistics”, on the website via “Accept” in the banner – do we use PostHog to measure how the app and the website are used: which screens and pages are opened and which functions are used (for example “chat started”, “document uploaded”), with information on device, operating system, app version and language.
We process a pseudonymous identifier (in the app your user ID, never your e-mail address or your name) and these events. The content of your chats, your documents and your profile information is not transmitted; there are no screen recordings. The IP address is only used for the transmission and is not stored.
The provider is PostHog Inc. (USA); the data is processed in PostHog’s EU cloud in Frankfurt am Main. Standard Contractual Clauses apply to any access from the USA. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). Without consent no data is sent to PostHog. You can withdraw your consent at any time with effect for the future: in the app with the “Usage statistics” switch, on the website via “Cookie settings”. Event data is deleted after 12 months at the latest.
13 Your rights
You have the following rights towards us:
- access to the data stored about you (Art. 15 GDPR);
- rectification of inaccurate data (Art. 16 GDPR);
- erasure (Art. 17 GDPR) – possible yourself at any time by deleting your account in the app, individual deletions on request by e-mail;
- restriction of processing (Art. 18 GDPR);
- data portability (Art. 20 GDPR);
- objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR).
To exercise your rights, an e-mail to privacy@briefmonster.de is enough. You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), Alt-Moabit 59–61, 10555 Berlin, www.datenschutz-berlin.de.
14 Withdrawing consent
You can withdraw consents you have given (processing of uploaded documents, health data, creation of letters) at any time with effect for the future: in the app under Profile → Consents or by e-mail to the address above. The lawfulness of the processing carried out before the withdrawal remains unaffected. The withdrawal is logged with its time; for consents that applied only to a single chat, their effect ends with the withdrawal.
If we change the text of a consent significantly, the text gets a new version and we ask for your consent again. Earlier versions are kept as proof as long as your account exists.
15 Security
Documents and personal data are encrypted in transit (TLS) and at rest in line with the state of the art. Access to your data is restricted to your account and enforced at database level. For the analysis you request, document content has to be decrypted temporarily within a protected processing environment. There is therefore no end-to-end encryption when Brief Monster or a processor we use analyses the content on the server.
16 Contact
Please send questions about data protection to privacy@briefmonster.de or by post to multiangular UG (haftungsbeschränkt), Urbanstraße 71, 3. Hof, 4. TRH, 10967 Berlin, Germany.
17 Last updated and changes
This privacy policy was last updated on 23 September 2026. We adapt it when the app, the service providers we use or the legal situation change. The current version is available at briefmonster.de/privacy, in German at briefmonster.de/datenschutz, and in the app.
Brief Monster