Legal · Briefico CRM
Privacy Policy
Last updated: September 14, 2026
1. Who We Are
Briefico CRM is a sales CRM for teams whose customers write to them on WhatsApp and Telegram. Briefico is the registered trade name of מולוצ'ניקוב גוזל, a sole trader (exempt dealer, עוסק פטור) registered with the Israel Tax Authority and based in Yokneam Illit, Israel. You can reach us at guzel@briefico.com. This policy explains what data the CRM holds, why, who else receives it, and how to have it deleted.
This policy covers the Briefico CRM: the web app at crm.briefico.com and the API behind it. Read it together with the CRM Terms of Service. Briefico's Facebook-group automation (app.briefico.com, the Chrome extension and the desktop app) is a separate product with its own privacy policy.
Visiting briefico.com.The website sets no cookies and runs no analytics or advertising trackers. It is hosted on Cloudflare Pages, which, like any web host, receives your IP address and browser details to deliver the page. Our font (Inter) is loaded from Google Fonts, so Google also receives your IP address. The accessibility toolbar saves your display preferences in your own browser's local storage; they never reach us. The download page asks our storage provider, Supabase, for the latest app version. The contact form sends nothing to us itself — it opens a message in your own email app.
In short
2. Our Two Roles
A team works in the CRM inside an organization. Who is responsible for a piece of data depends on whose it is.
If you messaged a business that uses Briefico, that business is responsible for your data. Please send your questions and requests to the business first. If you write to us instead, we will pass your request to the business and help it respond. If the business does not act on the request within 30 days of our passing it on, or no longer uses Briefico, we handle the request ourselves as the law requires and tell the business.
3. Data We Collect
Account data
- Email address and password. We pass your password to our authentication provider, Supabase Auth, which stores it only as a hash. We do not keep it.
- Google sign-in.If you choose "Continue with Google", the email address, name and profile picture Google shares. We ask Google for nothing else: no access to your Gmail, contacts, calendar or files.
- Organizations and memberships.The name of an organization you create, the organizations you belong to, your role in each (admin or agent), and invitations: the invited person's email address, who invited them, and whether they have joined. Inviting someone who has no Briefico login creates a login record for their email address straight away, so that the invitation link works.
- What teammates see. The other members of your organizations see your email address, your role, whether you have joined, and the date you last signed in. They see the same for pending invitations.
- Your own settings.How far you have read each lead's internal chat, and which channels you have muted for notifications.
- Push notifications, only if you turn them on.The subscription address and encryption keys your browser creates, your browser's user-agent string, stored with the subscription, and when the subscription was created and last refreshed. It is refreshed each time you open the app.
- Password reset.The link and the one-time code we email you. We store the code only as a hash. The code is also in the email's subject line, which our email provider keeps in its record of the email (see section 9).
- Sign-in records and server logs.Supabase Auth keeps records of your login's sign-ins and sessions: when and how you signed in, the email address used and an IP address. Most sign-ins go through the CRM's server, and for those the IP address recorded is our server's, not yours. Some steps, such as "Continue with Google", send your browser to Supabase and Google directly, and they receive your IP address and browser details. Our servers also keep request logs for security and troubleshooting.
Organization content
- Members' work.A member's name, if Google shared one, or otherwise their email address, is shown as the author of the notes, tasks and internal messages they write, and of their actions in the activity history (for example, moving or exporting a record). The CRM also records which customer messages each member sends, and which leads, contacts, companies, tasks and conversations are assigned to them.
- Contacts. Name, job title, phone numbers, email addresses, WhatsApp number, Telegram user ID and @username, an Instagram username if a member enters one, and any custom fields the business adds.
- Business records. Companies, with their website, phone, email and address. Leads on boards, with their value, currency, the member responsible and any loss reason. Tasks and reminders, notes, and custom fields.
- Internal team messages. Messages between teammates about a lead, with any files attached. Every active member of the organization can read them. The customer never sees them.
- Activity history. Entries such as a lead being created, moved, won or lost, or a conversation starting. Entries keep the names involved and, when an incoming message opens a new lead, the first 120 characters of that message.
- Conversation exports.A member can download a conversation as an archive. It is built on request and sent straight to them, not stored on our servers. The exporting member's email address is written into the archive and into our server log, and the export is noted in the record's activity history.
Conversations over WhatsApp and Telegram
- Messages. Text, files (with their name, type and size), reactions and delivery status, in both directions.
- The technical record. The full data WhatsApp or Telegram sends with each incoming message, kept for troubleshooting. It is never shown in the app, returned by the API or included in exports.
- Files sent through upload links.Files a customer uploads through a link the organization's automatic reply gave them (see section 6).
- Files sent as shared file links. Files a member sends to a customer as a link because they are too large for the channel, with a preview image of each (see section 6).
- Channel credentials. Telegram bot tokens and WhatsApp access tokens. They are encrypted when saved and never shown again, apart from at most their last 4 characters. For WhatsApp, also the App Secret and webhook verify token described in section 6.
4. Data We Don't Collect
- The CRM runs no analytics, advertising or tracking tools.
- No payment data. The CRM is free today and has no billing, so we hold no card or bank details.
- We do not sell or rent personal data to anyone.
- We do not use message content or contact data for advertising or profiling, and we do not use it to train AI models. The CRM sends no message content to any AI service.
- We make no decisions about anyone based solely on automated processing, including profiling, that have legal or similarly significant effects. The automatic replies in section 6 only send a message the organization has set up.
- We look at an organization's content only to provide the service, to give support you ask for, to investigate a security or abuse problem, or to comply with the law.
5. How We Use Data
We use account data only for the purposes below. Each purpose is followed by its legal basis.
For organization content, the business that controls it decides the purpose and the legal basis. We process that content only to provide the CRM to that business. That includes checking that incoming WhatsApp and Telegram deliveries are genuine before storing them.
6. WhatsApp and Telegram Data
An organization's admin can connect the business's own WhatsApp Business number, through the WhatsApp Business Platform (Cloud API), or its own Telegram bot, through the Telegram Bot API. To connect WhatsApp, the admin enters the phone number ID and an access token from the business's own Meta account. To connect Telegram, the admin enters the bot's token. From then on, Briefico receives and sends that number's or bot's messages for that one organization.
A business that connects WhatsApp through its own Meta app, as the in-app guide describes, also gives us that app's App Secret and the webhook verify token it chose. We keep them in our server configuration, not in the organization's records, and use them only to check that deliveries and subscription requests come from Meta.
What we receive from WhatsApp
- The customer's WhatsApp number and WhatsApp profile name.
- The messages they send the business: text, photos, videos, voice messages, documents, stickers, locations and shared contacts, with message IDs, times and the message they reply to. Files are downloaded and kept in the organization's private storage.
- Reactions, and delivery and read statuses for messages the business sends.
- The full technical record of each delivery, as described in section 3.
What we receive from Telegram
- The sender's Telegram user ID, first and last name, and @username.
- The messages they send the bot, and their edits: text, photos, videos and video notes, GIFs, voice and audio messages, documents, stickers, locations and shared contacts, with message IDs, times and the message they reply to. Files are downloaded and kept in the organization's private storage. For a shared location or contact, the technical record keeps the coordinates, or the shared person's name and phone number.
- Reactions, and a notice when a person blocks the bot.
- Groups.If the business adds its bot to a Telegram group, the group messages Telegram delivers to the bot are stored as one conversation for that group. The technical record of each message includes its sender's name and user ID, and the person whose message arrives first is saved as a contact. The first-message greeting is never sent into a group. The file-too-large reply is meant only for one-to-one chats, but when a file turns out to be too large only while we download it (for example, because Telegram did not report its size in advance), that reply can be sent into the group, and then every member of the group can use its upload link.
How this data is used
- Only to run that organization's inbox: show the conversation to its members, link it to a contact and a lead, notify its members, and send the replies they write.
- Messages go out only when a member sends a message or a reaction, or when an automatic reply is triggered by an incoming message. There are two kinds. A greeting for a customer's first message is sent only if an admin sets it up. A reply with an upload link, sent when a customer's file is too large to receive, is switched on when a channel is connected, and an admin can edit, pause or remove it. Briefico sends no bulk or marketing messages and no WhatsApp message templates.
- WhatsApp's 24-hour window.Briefico sends a free-form WhatsApp reply only within 24 hours of the customer's last message (WhatsApp's customer service window). Outside that window the CRM refuses to send.
- It is never shared with other Briefico customers. A number or bot can be connected to only one organization at a time, conversations stay with the organization that received them, and every request from a member is checked against the organization the data belongs to.
- It is never sold, never used for advertising and never used to train AI models.
Upload links
Telegram and WhatsApp limit the size of files a bot or business number can receive. When a customer sends a file that is too large, the automatic reply can send them a link to upload it instead. The link works for 24 hours and accepts up to 20 files, up to 1 GB in total and 400 MB per file. Files go only into that one conversation. The upload page shows the channel's name and nothing about the conversation. Anyone who has the link can upload through it until it expires.
Shared file links
The same limits apply in the other direction. When a member sends a file that is too large for the channel (over 50 MB on Telegram or over 100 MB on WhatsApp, up to 400 MB), the CRM keeps the file in the organization's private storage and sends the customer a message with a link to a page on crm.briefico.com that shows it. The page shows the file with its name, type and size, the channel's name and when the link expires, and nothing else about the organization or the conversation. It asks search engines not to index it.
- The link works for 7 days. Any member of the organization can switch it off sooner, which cannot be undone. A page that is already open can keep showing the file for up to 2 hours after that.
- Anyone who has the link can open the file while it works, including anyone the customer forwards it to and, in a group chat, every member of the group.
- Downloading is allowed unless the member turns it off. With downloading off, a file a browser can show, such as a picture, a video or a PDF, is shown without a download button, which discourages saving it but cannot prevent it. A file a browser cannot show is then not handed out at all.
- To draw a preview card in the chat, WhatsApp or Telegram fetches the page and, if there is one, a preview image (a scaled picture, a video frame or a first page, made by the member's browser when sending). The messenger may keep that preview.
- When the link stops working, the file stays with the message in the organization, like any other attachment.
What the business is responsible for
The business decides whom it messages and what it keeps. Under the Terms of Service it must have its customers' opt-in where WhatsApp requires it, honor requests to stop, give its customers any notice the law requires, and follow WhatsApp's and Telegram's policies. A business that connects its own Telegram bot is responsible for that bot's privacy policy toward its users; this page describes how Briefico handles the data on the business's behalf.
Meta and Telegram
WhatsApp and Telegram carry these messages under their own terms and privacy policies: the WhatsApp Privacy Policy, the WhatsApp Business Solution Terms and the Telegram Privacy Policy. Messages already delivered stay with those services and on the recipients' devices, even after they are deleted from Briefico.
7. Service Providers
These are the only services the CRM uses to handle personal data, and each receives only what its job needs. Apart from them, the CRM's personal data is available only to the people at Briefico, including contractors, whose work needs it and who are bound by confidentiality; to the members of each organization, as section 3 describes; to a business, when we pass it a request about its data; and to authorities, where the law requires it.
For the data businesses keep in their organizations, our sub-processors are Supabase and Hetzner Online, as section 5.3(f) of the Terms of Service says. Resend handles only account emails, for which Briefico is the controller.
Providers that process data for us
Services you choose to use, under their own terms
These act under their own terms and privacy policies, not as our sub-processors. They receive data only when an organization connects WhatsApp or Telegram, or when you sign in with Google or turn on notifications.
What a push notification contains.For a customer message: the contact's name, the channel name and up to 120 characters of the message. For an internal message: the author's name, the lead name and up to 200 characters of the message. For a task reminder: the task title and the name of its record. The notification is encrypted on our server, so the push service passes it on without being able to read it. Your device then shows it, including on the lock screen if your device settings allow.
9. Data Retention
- We keep your account and your organization's data until we delete them at your request, or at the request of an admin of your only organization when that organization is deleted (see section 10). We do not delete inactive accounts automatically. If no member of an organization has signed in for 24 months, we may delete it after emailing its admins at least 30 days in advance.
- Deleting a contact, lead, company, note, task or internal message in the app hides it. The data stays in the database until the organization is deleted, or until we erase it at the organization's request or as described in section 2. A hidden contact reappears if that person messages the organization again.
- Conversations, messages and activity history cannot be deleted in the app. They, and stored files, stay until the organization is deleted, or until we erase them at the organization's request or as described in section 2.
- Removing a member, or leaving an organization, ends that membership only. What the person wrote there stays with the organization. Their login stays until they ask us to delete it, or until an organization they belong to is deleted and they belong to no other organization.
- Disconnecting a channel stops new messages from arriving. Conversations already received stay in the organization. The channel's stored token also stays, encrypted, until the organization is deleted or you ask us to remove it, and so do any App Secret and verify token in our server configuration.
- Inviting someone who has no Briefico login creates a login record for their email address. If the invitation is cancelled or never accepted, that record stays until the person or the organization's admin asks us to delete it.
- Upload links stop working after 24 hours. Files uploaded through them stay in the conversation.
- Shared file links stop working after 7 days, or sooner if a member switches them off. The file and its preview image stay with the message.
- Password-reset links work for 1 hour and codes for 10 minutes. The record of a reset request stays until the account is deleted.
- A notification subscription is removed when you turn notifications off on that device, when you sign out there, or when the push service reports it is no longer valid.
- Server request logs are used only for security and troubleshooting. They have no fixed expiry: they are deleted when the server container that wrote them is replaced, which normally happens each time we release a new version of the CRM.
- Sign-in records.Our authentication provider, Supabase, keeps a log of sign-ins that includes the email address and an IP address. For sign-ins that go through our server, that is our server's IP address, not yours. These entries are not removed automatically when an account is deleted. If your deletion request asks for them to be removed too, we remove them. Supabase's own short-term platform logs, which we cannot edit, expire on Supabase's schedule.
- Email records.Our email provider, Resend, keeps its own record of the emails we sent, such as invitations and password-reset emails, including the recipient's address and the subject line, for the period its own retention rules set.
- Backups. Any backup copies kept by our database provider, Supabase, remain until they expire.
- Legal obligations. Anything the law requires us to keep, for as long as it requires.
- We complete a request to delete a user account, an organization or records in it within 30 days. A request from someone who messaged a business follows the steps in section 2.
10. Deleting Your Data
There is no delete button for accounts or organizations in the CRM. To delete your data, email guzel@briefico.com from the address on your account and say what to delete: your user account, a whole organization, or particular records in an organization, such as one contact's data. Only an admin of an organization can ask us to delete the organization or records in it. Say also if you want your sign-in records removed (see section 9). We complete the request within 30 days and confirm by email.
If you messaged a business that uses Briefico, ask that business to delete your data. If you email us instead, we will pass your request to the business. If the business does not act on the request within 30 days of our passing it on, or no longer uses Briefico, we handle the request ourselves as the law requires and tell the business. Messages already delivered through WhatsApp or Telegram stay with those services and on the recipients' devices.
What is deleted, what remains and how to ask are set out step by step on the data deletion page.
11. Your Rights
Under Israel's Privacy Protection Law and, where it applies, the GDPR, you can ask us to:
- Access the personal data we hold about you.
- Correct data that is wrong, incomplete or out of date.
- Delete your data (see section 10).
- Object to or restrict how we use it.
- Receive a copy in a portable format. Members can download a conversation archive in the app; for anything else, ask us.
Email guzel@briefico.com. We reply within 30 days. We may ask you to confirm that the request comes from you, for example by writing from the address on your account.
Do you have to give us your data? No law requires you to provide personal data to Briefico; you do so by your own choice. An email address is required to create an account, and without it we cannot provide the CRM. Signing in with Google and turning on notifications are optional.
If your data is held in a business's organization, for example because you messaged that business, send your request to the business. If you write to us instead, we handle it as described in section 2.
You can also complain to the Israel Privacy Protection Authority or, if you are in the EU, the EEA or the United Kingdom, to your local data protection supervisory authority (in the United Kingdom, the Information Commissioner's Office).
12. International Transfers
- The CRM's database, file storage and server are in Germany, in the EU.
- Briefico is run from Israel. The European Commission and the United Kingdom recognize Israel as providing an adequate level of protection for personal data.
- Resend, which delivers the CRM's account emails, processes email addresses and email content mainly in the United States. These transfers rely on the European Commission's Standard Contractual Clauses in Resend's Data Processing Addendum (with the UK Addendum for data from the United Kingdom) and on Resend's certification under the EU-U.S. Data Privacy Framework and its UK Extension.
- Meta, Telegram, Google and browser push services receive data only when an organization connects WhatsApp or Telegram, or when you sign in with Google or turn on notifications. They may process it outside the EU under their own terms and privacy policies.
Email guzel@briefico.com for a copy of the safeguards we rely on.
13. Security
- All connections to the CRM use HTTPS, with certificates our web server obtains and renews automatically.
- Passwords are stored only as hashes, by Supabase Auth.
- Telegram bot tokens and WhatsApp access tokens are encrypted with AES-256-GCM before they are stored.
- Files are kept in private storage. The app opens them through links that expire after 1 hour. A shared file link (see section 6) lets anyone who has it open its one file for up to 7 days, and each address it hands out for the file itself expires after at most 2 hours.
- Every request from a signed-in member is checked against the organization the data belongs to. Requests that do not come from a member are limited too: a WhatsApp or Telegram delivery is verified (see below) and filed only under the organization that connected that number or bot, an upload link lets files into its own conversation only, and a shared file link shows only its own file. Any server-to-server key we use for our own operations is held only by Briefico and is not limited to one organization.
- The database also refuses direct access from browsers: the database roles a browser could use hold no privileges on any table, and row-level security is turned on for every table as a second barrier against such access.
- Session cookies are HttpOnly and Secure.
- Incoming WhatsApp and Telegram deliveries are verified (Meta's signature, Telegram's secret token) before anything is stored.
- Password-reset codes are stored in our database only as hashes, and stop working after 10 minutes or 3 wrong attempts.
No system is perfectly secure. If a security breach affects your personal data, we will notify you and the authorities as the law requires.
14. Children
The CRM is a service for businesses. You must be 18 or older to create an account or join an organization.
15. Changes to This Policy
We update this policy when the CRM or the law changes. We tell account holders about material changes by email or in the app. The "Last updated" date at the top shows when the policy last changed.
16. Contact
Briefico is the registered trade name of מולוצ'ניקוב גוזל, a sole trader (exempt dealer, עוסק פטור) registered with the Israel Tax Authority and based in Yokneam Illit, Israel. You can reach us at guzel@briefico.com. Write to us with questions about this policy, about your data, or to ask for your data to be deleted.