Privacy Policy

Last updated: 20 September 2026

This English text is a translation provided for your convenience. The legally binding version is the German Datenschutzerklärung; in the event of any discrepancy, the German version prevails.

Thank you for your interest in Breev. Protecting your personal data is important to us. This privacy policy explains which personal data we collect when you visit our website breev.ai and use our software, for which purposes we use it, on which legal basis we do so, and which rights you have.

You can generally use our website without providing personal data. Using our services, however – in particular the meeting and transcription area, the AI assistant, the chatbot and the pages, projects and training modules – does require the processing of personal data.

We process personal data in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG). We have implemented numerous technical and organisational measures to protect the data we process as completely as possible. Please note that internet-based data transmissions can in principle have security gaps, so absolute protection cannot be guaranteed.

1. Controller and contact

The controller within the meaning of the GDPR is:

StudioFortyThree UG (haftungsbeschränkt)
Brookkämpe 6
48268 Greven
Germany

Represented by the managing director: Tom Kuhn
Commercial register: HRB 14874
Registering court: Amtsgericht Steinfurt
VAT identification number: DE368725775

E-mail: hello@breev.ai
Phone: +49 151 56090475

For any data protection matter, in particular to exercise your rights as a data subject, you can reach us at hello@breev.ai.

Data protection officer: We are not legally required to appoint a data protection officer and have therefore not designated one. Please address your data protection enquiries to the contact details above.

2. Our role: when we are controller and when we are processor

Breev is a software-as-a-service platform. For classifying the processing, a distinction has to be made:

3. Definitions

This privacy policy uses the terms of the GDPR. The most important of these are explained here:

4. Hosting and server log files

Our website and our application run on servers operated by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany, in a data centre located in Germany. A data processing agreement under Art. 28 GDPR is in place with IONOS. All application and database data (PostgreSQL), the task queue (Redis) and the files stored on the server remain in this data centre.

Each time our website is accessed, the system automatically collects data and information from the computer system of the calling computer. The following is collected in particular:

We need this data to deliver the content of our website correctly, to permanently ensure its functionality and system security, and to be able to provide the information required for law enforcement in the event of an attack. We do not merge this data with other personal data relating to you, and no evaluation for marketing purposes takes place.

The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in the technically faultless provision and the security of our systems. Log files are deleted after 14 days at the latest, unless they are required for longer to investigate a specific security incident.

5. Cookies and comparable technologies

We use cookies and comparable storage technologies (for example your browser's local storage). Cookies are small text files stored on your device via an internet browser.

We use strictly necessary cookies on the basis of § 25 (2) no. 2 TDDDG without your consent; the associated processing of personal data is based on Art. 6 (1) (b) and (f) GDPR. All other cookies and technologies – in particular those used for reach measurement – are only used after your express consent pursuant to § 25 (1) TDDDG and Art. 6 (1) (a) GDPR, which you give through our consent dialogue.

Our consent dialogue distinguishes four categories: Necessary, Analytics, Preferences and Marketing. We keep the Preferences and Marketing categories available for future functions with which we may tailor content and advertising to your interests; at present no active services are assigned to them, so your selection in these two categories currently does not trigger any data processing. Should we introduce services there, we will update this privacy policy beforehand accordingly.

In detail, we use:

Name Purpose Category Storage period
sessionid Recognises your logged-in session and keeps you signed in. Necessary Until the end of the session or until logout
csrftoken Protects forms against cross-site request forgery attacks. Necessary 1 year
django_language Stores the language you have selected. Necessary 1 year
device_id Random device identifier for logged-in users, used to detect abuse and multiple accounts (see section 9). Necessary 2 years
transcription_limit Counts the uses of the free transcription tool without an account in order to enforce the free quota. Necessary 30 days
consentMode (local storage) Stores your selection in the consent dialogue. Necessary Until deleted by you
_ga, _ga_* Reach measurement with Google Analytics (see section 6). Only set if you have given consent. Analytics Up to 2 years

You can change or fully withdraw your consent at any time with effect for the future. To do so, click “Settings” under “Cookies” in the footer of any page. The consent dialogue will reopen with your previous selection, which you can adjust as you wish. Withdrawing consent is therefore just as easy as giving it; the lawfulness of processing carried out up to the withdrawal remains unaffected.

In addition, you can generally prevent cookies from being set in your browser settings or delete cookies that have already been set. If you disable all cookies, you may no longer be able to sign in and functions of our website may become unusable.

6. Reach measurement with Google Analytics 4

We use Google Analytics 4 on this website, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).

Google Analytics uses cookies and similar identifiers to statistically evaluate the use of our website. The data processed includes in particular the pages visited, time spent on the site, approximate location (derived from the truncated IP address), device type, browser and operating system, and the source of the visit. IP addresses are truncated by Google within the EU; according to Google, the full IP address is not transmitted to Google servers.

We use Google Analytics together with Google Consent Mode. Before you give consent, no analytics or advertising cookies are set and no identifiers for recognition are transmitted. Only once you agree to the “Analytics” category in the consent dialogue are the corresponding cookies set and measurement data transmitted.

The legal basis for storing and reading information on your device is § 25 (1) TDDDG, and for the subsequent processing of your data your consent pursuant to Art. 6 (1) (a) GDPR. You can withdraw your consent at any time via “Settings” under “Cookies” in the footer of any page. You can also prevent collection by Google Analytics using the browser add-on provided by Google: https://tools.google.com/dlpage/gaoptout.

A transfer to Google LLC in the USA cannot be ruled out. Google LLC is certified under the EU-US Data Privacy Framework; in addition, Google has entered into the European Commission's standard contractual clauses. Further information on data protection at Google is available at https://policies.google.com/privacy.

7. External content and content delivery networks

To deliver program libraries and icon fonts quickly and reliably, we embed files from the following content delivery networks:

When you access our pages, your IP address is transmitted to the respective provider, because otherwise it could not deliver the files to your browser. A transfer to the USA cannot be ruled out in this context. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in providing our offering securely, up to date and with good performance.

8. Registration and user account

Using our services requires a user account. In this context we process the data you enter in the registration form, in particular your e-mail address, your name, your password (stored exclusively as a cryptographic hash), where applicable your company name, as well as the time of registration and the most recently used login data.

To confirm your e-mail address we send you a time-limited verification code, which is deleted once it expires. The same applies to codes you request when resetting your password.

Information stored in your account settings – such as your own instructions for meeting summaries and the AI assistant, your notification settings and your usage quota – is processed in order to provide the services you have booked.

The legal basis is Art. 6 (1) (b) GDPR (performance of the usage contract). The data is stored for the duration of your user relationship. You can delete your account yourself at any time via your account settings; deleting the account also deletes the associated content (meetings, transcripts, summaries, chats, pages, projects and training progress) and terminates any active subscriptions. Statutory retention obligations, in particular commercial and tax law obligations regarding invoice data, remain unaffected.

9. Abuse prevention and detection of multiple accounts

We grant new accounts a one-off free credit for premium functions. To prevent this credit from being claimed repeatedly by creating accounts over and over, we check when granting it whether an account from the same device or the same network has already received a credit.

For this purpose we set the device_id cookie for logged-in users with a randomly generated identifier and, together with your IP address and a coarse indication of your operating system, derive two non-reversible checksums (SHA-256) salted with a secret key. Only these checksums are stored, not the IP address or the browser identifier itself. The checksums can only be compared within our own installation and allow no conclusions to be drawn about the underlying data. Anonymous visitors do not receive such a cookie.

The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in preventing the abusive use of free services. The checksums are deleted together with the associated user account.

10. Meetings: audio recordings, transcription and summaries

The core function of our platform is converting audio recordings into a transcript and an automatically generated summary. This processes the content contained in the recording, including the voices and statements of all persons taking part in the conversation.

11. Free transcription tool without a user account

On our website we offer a free transcription tool that can be used without registration. The uploaded audio file (maximum ten minutes) is temporarily stored on our server, processed and subsequently deleted; the result is shown to you via a randomly generated task identifier and is automatically deleted from our cache after one hour. We do not attribute it to a person, and the transcript is not stored permanently.

To enforce the free quota of three uses within 30 days, we store only a counter and a start time in the transcription_limit cookie (see section 5). The legal basis is Art. 6 (1) (b) GDPR for carrying out the service you requested and Art. 6 (1) (f) GDPR for limiting free use.

12. AI assistant and knowledge search

The AI assistant answers questions on the basis of the content stored in your account or within your company. We store your queries, the generated answers, the time and technical metadata (model used and number of tokens). The chat histories are assigned to your user account and can be deleted by you.

To make content findable, we store text excerpts of your meetings, pages and projects in a search index. This index is operated exclusively using the full-text search of our own database (PostgreSQL) on our servers in Germany; no transfer to external providers for indexing takes place. The text excerpts required to answer a question are transmitted together with your question to OpenAI (see section 15).

The legal basis is Art. 6 (1) (b) GDPR.

13. Chatbot

Business customers can operate an AI chatbot with Breev. If a person uses this chatbot, we process the messages entered, the generated answers, the time and a randomly generated session identifier which holds the messages of one conversation together. We do not store the IP addresses of chatbot users.

The chat histories can be viewed and deleted by the administrators of the respective company. The controller for this processing is the company operating the chatbot; we act as a processor (see section 2). The messages are transmitted to OpenAI in order to generate answers (see section 15).

Note for chatbot users: Please do not enter sensitive personal data in the chat. For matters involving such data, please use the regular contact channels of the respective company.

14. Further modules: pages, projects and training
15. Use of AI services (OpenAI)

For generating summaries, for the answers of the AI assistant and the chatbot, and for premium transcription, we use application programming interfaces (APIs) provided by OpenAI. The provider for users in the European Economic Area is OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland; processing may take place on servers of OpenAI OpCo, LLC, 1960 Bryant Street, San Francisco, CA 94110, USA.

Only the content required for the respective function is transmitted:

Account data such as your name or your e-mail address is not transmitted. OpenAI processes the data transmitted via the interface as a processor on the basis of a data processing agreement under Art. 28 GDPR. According to OpenAI's contractual assurances, data transmitted via the interface is not used to train the models and is retained only for a limited period of up to 30 days for abuse detection, after which it is deleted.

The legal basis is Art. 6 (1) (b) GDPR, since processing by the AI services constitutes the essential content of the functions you have booked. For the transfer to the USA we rely on the European Commission's standard contractual clauses pursuant to Art. 46 (2) (c) GDPR together with supplementary safeguards. If you wish to avoid any transfer to OpenAI, please use only local transcription (standard method, see section 10 (b)) and refrain from using the AI-supported functions.

Further information can be found in OpenAI's privacy notice at https://openai.com/policies/privacy-policy and in the notes on data processing via the API at https://openai.com/policies/api-data-usage-policies.

Limits of automated results: Transcripts, summaries and answers generated by AI systems may be incomplete or incorrect. They do not replace your own review. No decision producing legal effects or similarly significantly affecting a person is taken on the basis of these results (see section 28).

16. Payment processing via Stripe

For paid subscriptions we use the payment service provider Stripe. The provider for users in the European Economic Area is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland.

When you take out a paid subscription, you are redirected to a payment page operated by Stripe. You enter your payment details – in particular credit card number, bank account details or comparable payment information – directly with Stripe. We never receive or store this payment data. What is transmitted to Stripe is your e-mail address, the selected service, the amount and, where applicable, a discount code. From Stripe we receive back a customer identifier, the status of your subscription and payment confirmations; we store the customer identifier in your account settings so that we can assign and manage your subscription. Through a customer portal provided by Stripe you can manage your payment details and your subscription yourself.

Stripe processes this data as a controller in its own right for payment processing and to fulfil its own legal obligations, in particular for fraud prevention and anti-money-laundering purposes. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (c) GDPR (compliance with legal obligations). A transfer to Stripe, Inc. in the USA is possible; that entity is certified under the EU-US Data Privacy Framework, and standard contractual clauses are additionally in place.

We retain invoice and payment data in accordance with the retention periods under commercial and tax law (§ 257 HGB, § 147 AO) for six and ten years respectively. Further information is available at https://stripe.com/privacy.

17. Contacting us, demo requests and campaign forms

If you contact us via our contact form, a demo request, a campaign form or by e-mail, we process the data you provide – depending on the form, your first and last name, your e-mail address, your telephone number, your company, the subject and your message – exclusively to handle your enquiry and in case of follow-up questions.

To protect against automated submissions, we use a captcha in the contact form which we operate ourselves on our own servers. No transfer to third parties, in particular not to Google reCAPTCHA, takes place.

The legal basis is Art. 6 (1) (b) GDPR for enquiries relating to a contract and otherwise Art. 6 (1) (f) GDPR based on our legitimate interest in responding to enquiries. We delete enquiries once they have been conclusively dealt with and no statutory retention obligations prevent deletion, and in any event after two years at the latest. You may object to the storage at any time.

18. Newsletter

On our website and during registration you can subscribe to our newsletter. For this purpose we process your e-mail address and the language you use. The newsletter provides information about our products, features and offers.

The legal basis is your consent pursuant to Art. 6 (1) (a) GDPR or, insofar as we send you information about our own similar services as an existing customer, § 7 (3) of the German Act Against Unfair Competition (UWG) in conjunction with Art. 6 (1) (f) GDPR.

You can unsubscribe from the newsletter at any time. Simply use the unsubscribe link at the end of every newsletter e-mail or send a message to hello@breev.ai. After you unsubscribe, we continue to store your e-mail address with a “do not contact” marker in order to ensure that you receive no further messages from us. The legal basis for this is our legitimate interest in observing your objection pursuant to Art. 6 (1) (f) GDPR. If you would instead like your e-mail address to be deleted completely, please let us know.

19. Sending e-mails

For sending system and notification e-mails – such as verification codes, notices about completed transcriptions, password resets and newsletters – we use the e-mail service of Google Workspace provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Your e-mail address and the content of the message are processed in this context. A data processing agreement is in place with Google; the safeguards referred to in section 6 apply to any transfer to the USA. The legal basis is Art. 6 (1) (b) and (f) GDPR.

Please note that communication by e-mail can have security gaps. For confidential information we recommend postal mail or another secured means of transmission.

20. Applications for employment

We collect and process the personal data of applicants for the purpose of handling the application process, including by electronic means, for example where application documents are submitted by e-mail. The legal basis is § 26 (1) BDSG in conjunction with Art. 6 (1) (b) GDPR.

If we enter into an employment contract with an applicant, the transmitted data is stored for the purpose of processing the employment relationship in compliance with statutory provisions. If no employment contract is concluded, application documents are deleted six months after notification of the rejection decision, provided that no legitimate interests on our part prevent deletion and no consent to longer storage – for example for a talent pool – has been given.

21. Recipients and processors at a glance

We only pass on your data where this is necessary to provide our services or where we are legally obliged to do so. Service providers engaged by us process data only on our instructions and on the basis of a data processing agreement under Art. 28 GDPR, unless stated otherwise below.

Recipient Purpose Location / place of processing
IONOS SE Hosting of the application, database and files Germany
OpenAI Ireland Ltd. / OpenAI OpCo, LLC Premium transcription, summaries, AI assistant, chatbot Ireland / USA
Stripe Payments Europe, Limited Payment processing (controller in its own right) Ireland / USA
Google Ireland Limited Sending e-mails (Google Workspace), reach measurement, program libraries Ireland / USA
Prospect One (jsDelivr) Delivery of program libraries and icon fonts Poland

In addition, data may be passed on to tax advisors, legal advisors or public authorities where this is necessary to comply with legal obligations or to enforce our rights. We do not sell your data.

22. Transfers to third countries

Where data is transferred to the USA – as described in sections 6, 7, 15, 16 and 19 – this takes place on the basis of the European Commission's adequacy decision on the EU-US Data Privacy Framework (Art. 45 GDPR), provided the respective recipient is certified, and additionally on the basis of the European Commission's standard contractual clauses (Art. 46 (2) (c) GDPR). We point out that, despite these safeguards, access to the data by state authorities in the USA cannot be entirely ruled out and that you may not have the same legal remedies available as within the EU.

23. Storage period and erasure

We process and store personal data only for the period necessary to achieve the purpose of storage or as provided for by European or national legislation. If the purpose of storage ceases to apply or a prescribed storage period expires, the data is routinely erased or its processing is restricted. In detail, the periods stated in the preceding sections apply, in particular:

24. Rights of the data subject

You have the following rights towards us. An informal message to hello@breev.ai is sufficient to exercise them.

25. Legal bases for processing at a glance

Art. 6 (1) (a) GDPR serves as the legal basis for processing operations for which we obtain consent – for example reach measurement and the newsletter. Art. 6 (1) (b) GDPR is the legal basis where processing is necessary for the performance of our usage or licence agreement or for pre-contractual measures; this applies to the entire functional scope of the platform. Art. 6 (1) (c) GDPR applies to processing necessary for compliance with legal obligations, such as retention obligations under tax law. Art. 6 (1) (f) GDPR serves as the legal basis for processing necessary to safeguard our legitimate interests.

26. Legitimate interests in the processing

Where we base processing on Art. 6 (1) (f) GDPR, our legitimate interests are ensuring the security and stability of our systems, preventing the abuse of free services, responding to enquiries, observing declared marketing objections, and carrying out our business activities economically for the benefit of all our employees and shareholders.

27. Necessity of providing personal data

The provision of personal data is partly required by law (for example by tax legislation) or arises from contractual provisions. To conclude a usage agreement it is necessary that you provide us with at least a valid e-mail address; without it we cannot set up an account or enter into a contract with you. Providing further data is voluntary. Before providing personal data you may contact us at any time; we will then explain on a case-by-case basis whether the provision is necessary and what the consequences of not providing it would be.

28. Automated decision-making and profiling

Automated decision-making within the meaning of Art. 22 GDPR which produces legal effects concerning you or similarly significantly affects you does not take place. Nor do we carry out profiling for evaluation purposes.

The results generated by our platform – transcripts, summaries, answers from the AI assistant and the chatbot, and project recommendations – are produced automatically but constitute work results which are reviewed and used by people, and not a decision about a person. The check described in section 9 when granting a free credit is limited to comparing technical checksums and has, as its only consequence, that a free additional service is not granted.

29. Data security

We take technical and organisational measures in line with the state of the art to protect your data against loss, destruction, access, alteration or distribution by unauthorised persons. These include in particular end-to-end encryption of transmissions using TLS (recognisable by https:// in the address bar and the padlock symbol in your browser), storage of passwords exclusively in encrypted form as hash values, a role-based authorisation concept, separation of the data of different customers, and operation on servers in a data centre located in Germany.

30. Currency of and changes to this privacy policy

This privacy policy is currently valid and dated September 2026. As our website and our services develop further, or as a result of changed statutory or regulatory requirements, it may become necessary to amend this privacy policy. The current version can be accessed at any time at https://breev.ai/privacy.