SolutionsSolutionsSolucionesCompareComparatifComparativaResourcesRessourcesRecursosBlogBlogBlogContact usNous contacterContacto
Log inSe connecterIniciar sesiónGet startedDémarrerEmpezar ahora
SolutionsSolutionsSolucionesCompareComparatifComparativaResourcesRessourcesRecursosBlogBlogBlogContact usNous contacterContacto
Security

Your data, and your visitors’ data

Brift sits on your site and talks to your prospects. That earns you a straight, specific answer on where everything goes and who can see it.

How we think about security

We are a small, fast-moving team, and we built the protections that actually matter for a widget handling real prospect conversations first: strict data isolation, no visitor tracking, and infrastructure run on providers built for this. Every point below is something you can verify in how the product actually runs — not a badge on a page.

How it actually works

  • Encrypted, always

    Every connection to Brift runs over HTTPS, and data at rest is encrypted by our database provider with industry-standard AES-256. There is no unencrypted hop between a visitor typing a message and it landing in your dashboard.

  • One account cannot read another

    Isolation is enforced by the database itself, not by application code. Every table carries a row-level policy tied to your account id, so a query that forgets a filter returns nothing rather than someone else’s conversations.

  • We never store a visitor IP

    The country shown in your dashboard is resolved at the edge and the address is dropped immediately. What lands in the database is a two-letter country code, a device class (mobile, tablet, desktop) and a browser language. Nothing that identifies a person.

  • No cookie on your visitors

    The widget sets no cookie at all. It keeps a random conversation id in the browser’s local storage so a visitor who reloads does not lose the thread — that value never leaves their browser except to attach messages to the same conversation.

  • Your conversations do not train models

    We call OpenAI through its business API, not the consumer ChatGPT product — by OpenAI’s own policy, data sent through the API is excluded from model training by default, no opt-in required. We do not train anything ourselves either, and we do not sell your data. Your agent is configured from your own site content — it is not a model fine-tuned on other customers.

  • No card number reaches us

    Payment runs on a certified provider’s hosted checkout page. Card details are entered there and never transit through, nor rest on, a Brift server. We keep a subscription reference, nothing else.

  • Delete everything, from your settings

    Account deletion is self-service and it is not a soft flag: your agent, your widget, your conversations and the files attached to them are purged, and your login is removed. No email to write, no waiting on us.

FAQ

Is Brift GDPR compliant?

Brift is built to be used in compliance with GDPR: the widget sets no cookie, no visitor IP is stored, data is isolated per account, and deletion is self-service and complete. Compliance is a shared responsibility — you remain the controller for what your visitors write to your agent, so keep your own privacy notice up to date. Need a signed data processing agreement for your records? Ask and we will put one in place.

Can I read what visitors said to my agent?

Yes — every conversation is stored in full and readable from your dashboard, message by message, with its qualification level. That transparency is the point of the product: you finally see the objections your traffic actually raises.

Does Brift see the rest of my website?

Only what is publicly reachable. When you paste your URL we read your public pages to configure the agent, exactly as a search engine would. The script you install renders the widget — it does not read your page content, your forms, or anything a logged-in user sees.

What happens to my data if I cancel?

Cancelling stops the billing and takes your agent offline; your conversations stay readable while the account exists, so you keep what you learned. If you want everything gone, delete the account from your settings — that purge is immediate and irreversible.

Where is the data hosted?

Your account, agents and conversations sit in a European Union database. Replies are generated by the OpenAI API in the United States, which means the text of a message transits there to be answered. If that transfer is a blocker for you, tell us before you subscribe rather than after.

Found a vulnerability?

Write to us directly and we will answer. There is no paid bug bounty programme — pretending otherwise would waste your time — but a report gets read by the person who wrote the code, usually the same day.

See what Brift would look like on your site.Voyez à quoi ressemblerait Brift sur votre site.Mira cómo quedaría Brift en tu web.

Enter your URL — live in 2 minutes, from $24/mo on annual billing.Collez votre URL — en ligne en 2 minutes, dès 24$/mois en annuel.Pega tu URL — en vivo en 2 minutos, desde 24$/mes en facturación anual.

Get startedDémarrerEmpezar ahora

Brift

  • Terms of UseConditions d'utilisationTérminos de uso
  • Privacy PolicyConfidentialitéPrivacidad
  • Cookie PolicyCookiesCookies
  • Legal noticeMentions légalesAviso legal
  • Who it's forPour quiPara quién es
  • ResourcesRessourcesRecursos
  • BlogBlogBlog
  • CompareComparatifComparativa
  • SecuritySécuritéSeguridad
  • EnterpriseEntrepriseEmpresa

© 2026 Brift. All rights reserved.© 2026 Brift. Tous droits réservés.© 2026 Brift. Todos los derechos reservados.