BriefBridge · briefbridge.ai · Last updated 19 July 2026
BriefBridge is built for lawyers. We know the material you work with — client information, matter details, litigation strategy — is among the most sensitive information there is, and may be subject to strict duties of confidentiality and legal professional privilege. We designed BriefBridge, and this policy, on that assumption: your content is treated with the same gravity as health information, and this document sets out — completely and specifically — what we collect, why, where it goes, how it is protected, and the rights and choices you have.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and the Notifiable Data Breaches scheme.
BriefBridge (“BriefBridge”, “we”, “us”, “our”) operates the BriefBridge platform at briefbridge.ai (the “Platform”) — an AI-assisted legal research and matter workspace for Australian legal practitioners. This policy applies to all personal information we handle in connection with the Platform, our website, and our communications with you. It applies whether you use an individual account or a firm workspace. Where you use the Platform through a firm, your firm may have its own privacy obligations to its clients; this policy governs our handling, not theirs.
Name, email address, password hash (never your plaintext password), and — if you sign in with Google — your name, email and Google profile identifier as provided by Google. If you join or create a firm workspace: your firm name and role within it.
The matters you create, documents and files you upload, research questions you ask, AI conversations you conduct, and notes you keep. You control what you put into the Platform. Your Content may include third-party personal information (for example, names of parties, witnesses or practitioners in matter documents); you are responsible for ensuring you are entitled to handle that information, and we handle it strictly as your service provider under this policy.
Event records such as: feature used, timestamps, counts of sources retrieved, retrieval quality scores, session and device information (browser type, operating system, approximate region derived from IP), and error logs. Usage Data is engineered to exclude the substantive content of your research: our analytics events record, for example, that a research query was run and how many sources it returned — never the text of the query or the response.
If you purchase a subscription, payment is processed by our payment provider. We receive and store your plan, billing status, and partial card details (such as last four digits and expiry) for account management. We never store full card numbers.
Support requests, feedback, and correspondence you send us, including the contact details you use to send them.
| Purpose | Information used |
|---|---|
| Providing the Platform: running your searches, generating research responses, storing matters and files, operating firm workspaces | Account information; Your Content |
| Securing the Platform: authentication, abuse and fraud prevention, incident investigation | Account information; Usage Data |
| Operating and improving the product: aggregate feature usage, retrieval quality measurement, error diagnosis | Usage Data (metadata only — never the content of queries or documents) |
| Billing and account management | Account information; billing information |
| Communicating with you: service notices, security alerts, support responses; product updates only with your consent | Account information; communications |
| Complying with law: responding to lawful requests, meeting record-keeping obligations | The minimum necessary for the obligation |
We do not use your information for any purpose not listed above without telling you first. In particular: we do not use Your Content to train, fine-tune or evaluate AI models; we do not sell personal information; and we do not share Your Content with other users except within a firm workspace you have expressly joined and only for matters you or your colleagues have shared.
The Platform is designed as a confidential working tool, and we treat Your Content as confidential information — not merely as personal information. Specifically:
We use a small number of infrastructure providers to operate the Platform. Each receives only the information necessary to perform its function, under contractual terms consistent with this policy:
| Provider | Function | Location of processing |
|---|---|---|
| Supabase | Database and authentication hosting — the primary store for account information and Your Content | Singapore (AWS ap-southeast-1) |
| Vercel | Application hosting and content delivery | Global edge network; compute primarily US/AP regions |
| Anthropic | AI model provider — processes your research questions and relevant retrieved material to generate responses. API inputs/outputs are not used by Anthropic to train models | United States |
| Voyage AI | Embedding provider — processes query text to enable semantic search. API data is not used for model training | United States |
| Resend | Transactional email (account, invitation and security emails) | United States |
| Sign-in (only if you choose Google authentication) | Global |
We may also disclose information: where required by law, court order or compulsory process (subject to §6); to our professional advisers under confidentiality; or as part of a bona fide sale or restructure of our business, in which case the recipient will be bound by this policy and you will be notified. We do not disclose personal information to any other third parties.
Our primary database is hosted with Supabase in Singapore (AWS ap-southeast-1). AI processing occurs in the United States (Anthropic and Voyage AI), and application hosting (Vercel) may process requests in multiple regions. This is cross-border disclosure for the purposes of APP 8, and by using the Platform you consent to it. We choose providers with strong, audited security practices and contractual protections consistent with the APPs. We are working towards Australian-region data hosting; this policy will be updated when that changes.
No system is perfectly secure, and we do not promise that security incidents can never occur — but we design so that the impact of any single failure is contained, and we respond as set out in §14.
The Platform uses strictly necessary cookies for authentication and session management. We do not use third-party advertising cookies or cross-site tracking. Any website analytics we operate are first-party and measure aggregate page usage only.
We send product and feature communications only where you have opted in or would reasonably expect them, and every such message contains a working unsubscribe. We never use Your Content for marketing, never disclose your details to third-party marketers, and honour opt-outs immediately (APP 7).
You may browse our public pages without identifying yourself. Because the Platform stores confidential working material against authenticated accounts, we cannot provide the logged-in service anonymously — identification is required to secure your data to you (APP 2).
If a data breach occurs that is likely to result in serious harm to any individual, we will: contain and investigate the incident; notify affected users promptly with a description of the breach, the information involved, and the steps we recommend; and notify the Office of the Australian Information Commissioner, all in accordance with the Notifiable Data Breaches scheme. Given the professional sensitivity of Your Content, our notification to you will be specific enough for you to assess any obligations you may have to your own clients.
The Platform is designed for Australian legal practice. If you access it from outside Australia, you do so on the basis that your information will be handled in accordance with this policy and Australian law. Where overseas privacy laws grant you additional rights, we will honour reasonable requests to exercise them.
We may update this policy from time to time. Material changes will be notified in the Platform or by email before they take effect. The “last updated” date at the top reflects the current version, and prior versions are available on request.
Privacy questions, access or correction requests, deletion requests, and complaints: privacy@briefbridge.com.au.
See also our Terms of Service.