Privacy Policy
Effective Date: August 1st, 2026
Last Updated: August 1st, 2026
1. Introduction
This Privacy Policy describes how Riveting Agency, Inc. d/b/a SalesBriefAI.com ("we," "us," "our," or "Company") collects, uses, processes, and protects information when you use our SalesBriefAI™ service (the "Service") and visit our website at salesbriefai.com (the "Website").
Contact Information:
Company: Riveting Agency, Inc. d/b/a SalesBriefAI.com
Address: 29751 N El Mirage Rd, Suite 150, PMB-137, Peoria, AZ 85383, United States
Email: legal@salesbriefai.com
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Name, work email address, password, and billing information
- Order Information: Identifying details (name, business email, company website), company information, sales methodology preferences, and briefing specifications
- Communications: Messages, feedback, and support inquiries you send to us
2.2 Information We Collect Automatically
- Technical Data: IP address, browser type, device information, and operating system
- Usage Data: Pages visited, time spent on our Website, click-through rates, and Service usage patterns
- Cookies and Similar Technologies: We use cookies that are strictly necessary to run the Service — keeping you signed in, protecting sign-in forms against automated abuse, and carrying an invitation link across a third-party sign-in round trip. Our product analytics are cookieless: analytics state is held in page memory for the duration of a browser tab and is not written to a cookie or to browser storage. We do not use advertising or cross-site tracking cookies. See Section 6.1 for details of the analytics we run.
2.3 Information We Obtain from Third Parties
- Prospect Data: Publicly available professional information about prospects obtained from authorized data providers
- Payment Information: Processed securely by Stripe (we do not store payment card information)
3. How We Use Your Information
3.1 Service Delivery
- Generate AI-powered sales briefings and prospect intelligence
- Process orders and deliver requested briefings via email
- Provide customer support and respond to inquiries
- Manage user accounts and billing
3.2 Service Improvement
- Analyze usage patterns to improve our Service functionality
- Develop new features and enhance user experience
- Conduct quality assurance and testing
3.3 Communications
- Send transactional emails related to your orders and account
- Provide customer support responses
- Send important Service updates and security notifications
4. Legal Basis for Processing (EU Users)
For users in the European Union, we process personal data based on the following legal grounds:
- Contract Performance:Processing necessary to provide the Service you've requested
- Legitimate Interests: Improving our Service, preventing fraud, conducting business operations, running product analytics on signed-in usage (Section 6.1), and researching prospects you ask us to brief you on. Where we process information about a person we did not collect it from — a prospect named in an order — this is the basis we rely on, and that person may object using the contact details in Section 10
- Consent:When you've given explicit consent, such as for marketing communications
- Legal Obligation: When required by applicable law
5. Artificial Intelligence and Automated Processing
5.1 AI Service Providers
We use artificial intelligence services from OpenAI, Anthropic, and Google to generate sales briefings and analyze prospect data. These providers process data via secure APIs and do not use your data to train their models.
5.2 Automated Decision-Making
Our Service uses AI to automatically generate sales briefings and recommendations. While these outputs may influence your sales strategies, they do not make decisions with legal or similarly significant effects without human review.
6. Data Sharing and Third-Party Services
6.1 Service Providers
We share information with trusted third-party service providers who assist in operating our Service:
- Supabase: Database hosting and user authentication
- Cloudflare: Security, content delivery, and analytics
- PostHog: Cookieless product analytics, served first-party from our own domain. When you are signed in, your product activity is associated with your account — including your account email and name — so we can understand and improve your experience. This happens automatically for every signed-in session; we do not ask for separate analytics consent and we do not offer an in-product analytics opt-out today. We rely on our legitimate interest in operating and improving the Service (see Section 4), and you can object to that processing using the contact details in Section 10. Visitors who are not signed in are counted anonymously and are not built into a person profile. To understand product usage we may also record user sessions with content masking: form inputs and on-page text are redacted in your browser before any replay data leaves it, and URLs are stripped of tokens and other sensitive parameters. We do not use advertising or cross-site tracking.
- Stripe: Payment processing
- AI Providers: OpenAI, Anthropic, and Google for AI processing services
7. Data Retention
We are describing what our systems actually do today, not a target. Most of the data below is retained until it is deleted on request; only the operational logs expire on a schedule.
- Account and Billing Data: Retained for as long as your account exists, and after closure for as long as we need it to meet tax, accounting, and other legal obligations. There is no automatic expiry.
- Generated Briefings and Brief PDFs: Retained indefinitely so they stay available in your history. There is no automatic expiry. Access to a brief shared directly with a named individual is cut off 365 days after delivery, but the brief itself is not deleted at that point.
- Prospect Research and Enrichment Data: Retained indefinitely. We previously operated a 90-day purge of raw provider data and deliberately turned it off in July 2026 so that we can evidence where each fact about a person came from. We delete this data on request — see Section 9.
- Operational Logs: API and error logs are deleted automatically after 30 days. Platform request logs and webhook records are deleted automatically after 7 days.
- Product Analytics Data:Held by PostHog under that service's retention settings. We do not apply an additional automatic deletion schedule to it.
Deleted data can persist for a further period in encrypted database backups and point-in-time-recovery snapshots until those windows lapse. We do not restore backups in order to recover data you have asked us to delete.
8. Data Security
- All data is encrypted in transit and at rest
- Secure authentication protocols managed by Supabase Auth
- Regular security monitoring and updates
- Access controls and audit logging
- No storage of unhashed passwords or payment card information
9. Your Privacy Rights
These rights apply whether or not you have an account with us. If a briefing was written about you and you have never been our customer, you have the same rights, and the same contact address.
- Access: Request information about the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data (subject to legal obligations)
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Suppression: Ask us not to research or write briefings about you in future. We keep a suppression list that is checked when an order is placed and again before any research runs, so a suppressed person generates no new data
To exercise your privacy rights, contact us at legal@salesbriefai.com. We acknowledge requests and complete or respond substantively within 30 days. These requests are handled by a person following an internal procedure — there is no self-service deletion button in the product today, so please use the email address above rather than looking for one in your account settings.
What deletion can and cannot reach. We delete your personal data from our own systems: our database, the files we store, and our product analytics. We cannot recall a briefing that has already been emailed to or downloaded by a customer — that copy is outside our control. Deleted data may also persist in encrypted backups until those retention windows lapse, as described in Section 7. We keep a minimal record that a request was made and completed, so that we can evidence compliance; that record does not retain the data we deleted.
10. Contact Information
For questions about this Privacy Policy or our privacy practices, please contact us at:
Email: legal@salesbriefai.com
Company: SalesBriefAI.com
Address: 29751 N El Mirage Rd, Suite 150, PMB-137, Peoria, AZ 85383, United States
This Privacy Policy was last updated on August 1st, 2026 and is effective as of August 1st, 2026.