ListenBrief
Home

Privacy Policy

Last updated: June 16, 2026

This Privacy Policy explains what data the ListenBrief service ("ListenBrief", "we", "us") collects, why, how we use it, and the choices you have. ListenBrief is a service of Zamforge BV, a private limited company registered in the Netherlands under VAT number NL869600825B01. We try to keep this short and clear.

1. What we collect

  • Account data: email address, name (optional), and authentication credentials.
  • Subscription data: plan, billing status, payment-method identifiers returned by Stripe (we never see your full card number).
  • Briefing preferences: the topics you select, the RSS feeds, YouTube channels, newsletters, and other source URLs you add, your chosen language, voice, briefing length, and delivery time/timezone.
  • Generated content: the briefings we generate for you and the delivery status of each.
  • Operational data: IP address, user agent, and timestamps for security, abuse prevention, and debugging.
  • Support correspondence: emails you send us.

2. What we do not collect

We do not track you across other sites. We do not sell your data. We do not run third-party advertising on the Service.

3. Why we use it (legal basis under GDPR)

  • To provide the Service you signed up for (Art. 6(1)(b)): generating and delivering your briefings, processing payment, and authenticating you.
  • To keep the Service secure and operational (Art. 6(1)(f)): rate limiting, abuse prevention, debugging, and preventing fraud.
  • To comply with legal obligations (Art. 6(1)(c)): tax, accounting, and law-enforcement requests where required.
  • With your consent (Art. 6(1)(a)): optional product updates and newsletters; you can withdraw consent at any time.

4. Who we share it with

We share the minimum data needed with:

  • Stripe — to process payments.
  • OpenRouter — to run the language model that drafts your briefing. We send your selected topics and the source content fetched on your behalf. OpenRouter is a data processor under our instructions.
  • Our self-hosted text-to-speech service — to synthesize the audio. It receives the script we generated.
  • Google (Gmail API) — to send your briefing by email.
  • Cloudflare — for hosting, queues, object storage, and DNS.

We do not sell your data to anyone, and we do not share it with advertisers.

5. International transfers

Some of our processors (notably Google, OpenRouter, Stripe, and Cloudflare) may process your data in countries outside the European Economic Area. Where this happens, we rely on the European Commission's Standard Contractual Clauses or the processor's equivalent safeguards.

6. Cookies

We use a small set of first-party cookies for authentication and to remember your language preference (lb_locale). We do not use third-party advertising or analytics cookies.

7. How long we keep your data

  • Account and billing data: for as long as your account is active, plus 7 years for tax and accounting.
  • Generated briefings, transcripts, and audio: retained for 90 days after generation, then automatically purged. You may delete any briefing sooner from your dashboard.
  • Delivery records (including recipient email addresses): retained for 90 days, then automatically purged.
  • API audit logs (including IP address and user agent): retained for 30 days, then automatically purged.
  • Source content items (persisted feed data): retained for 30 days, then automatically purged.
  • Operational and security event logs: retained for 90 days. Longer retention only when needed for security investigations.
  • Stripe payment metadata: retained for 90 days in our systems; Stripe retains its own records per its policy.

Automated purge jobs run daily. Data is deleted permanently; we do not maintain shadow copies.

8. Your rights

If you are in the EEA, UK, or a similar jurisdiction, you have the right to access, correct, port, delete, and restrict the processing of your personal data, and to object to processing based on our legitimate interests. Email hermes@zamforge.shop to exercise these rights. We respond within 30 days.

You also have the right to lodge a complaint with your local data protection authority.

9. Security

We use industry-standard safeguards: TLS in transit, encryption at rest for storage, role-based access for staff, and audit logs for sensitive operations. No system is perfectly secure; if you discover a vulnerability, please email hermes@zamforge.shop.

10. Children

The Service is not directed at children under 16, and we do not knowingly collect personal data from them.

11. Changes to this policy

If we make material changes, we will notify you by email at least 14 days before they take effect. The "last updated" date at the top of this page reflects the current version.

12. Contact

Data controller: Zamforge BV (operating ListenBrief) · hermes@zamforge.shop

This Privacy Policy is provided as a working draft. We recommend legal review before relying on it in a dispute.

© 2026 Zamforge BV - ListenBrief · About · Terms · Privacy