SolutionsSolutionsSolucionesCompareComparatifComparativaResourcesRessourcesRecursosBlogBlogBlogContact usNous contacterContacto
Log inSe connecterIniciar sesiónGet startedDémarrerEmpezar ahora
SolutionsSolutionsSolucionesCompareComparatifComparativaResourcesRessourcesRecursosBlogBlogBlogContact usNous contacterContacto
Launch offerOffre de lancementOferta de lanzamientoUntil October 31Jusqu’au 31 octobreHasta el 31 de octubre
Security

Your data, and your visitors’ data

Brift sits on your site and talks to your prospects. That earns you a straight, specific answer on where everything goes and who can see it.

How we think about security

We are a small, fast-moving team, and we built the protections that actually matter for a widget handling real prospect conversations first: strict data isolation, no visitor tracking, and infrastructure run on providers built for this. Every point below is something you can verify in how the product actually runs, not a badge on a page.

How it actually works

  • Encrypted, always

    Every connection to Brift runs over HTTPS, and data at rest is encrypted by our database provider with industry-standard AES-256. There is no unencrypted hop between a visitor typing a message and it landing in your dashboard.

  • One account cannot read another

    Isolation is enforced by the database itself, not by application code. Every table carries a row-level policy tied to your account id, so a query that forgets a filter returns nothing rather than someone else’s conversations.

  • We never store a visitor IP

    The country shown in your dashboard is resolved at the edge and the address is dropped immediately. What lands in the database is a two-letter country code, a device class (mobile, tablet, desktop) and a browser language. Nothing that identifies a person.

  • No cookie on your visitors

    The widget sets no cookie at all. It keeps a random conversation id in the browser’s local storage so a visitor who reloads does not lose the thread, that value never leaves their browser except to attach messages to the same conversation.

  • Voice passes through, it is never kept

    A visitor can dictate their message instead of typing it. The recording is sent to a speech to text provider (OpenAI) for the seconds it takes to transcribe, and neither we nor they keep it: what is stored is the text, exactly as if it had been typed. Nothing is recorded unless the visitor taps the microphone, and their browser asks for permission first.

  • Your conversations do not train models

    Your agent’s replies are written by Anthropic’s API; its setup, read from your own site, by OpenAI’s. Both are business APIs, not the consumer Claude or ChatGPT apps, and by both providers’ own business terms, what businesses send through those APIs is not used to train their models, no opt-out required. We do not train anything ourselves either, and we do not sell your data. Your agent is configured from your own site content, it is not a model fine-tuned on other customers.

  • No card number reaches us

    Payment runs on a certified provider’s hosted checkout page. Card details are entered there and never transit through, nor rest on, a Brift server. We keep a subscription reference, nothing else.

  • Delete everything, from your settings

    Account deletion is self-service and it is not a soft flag: your agent, your widget, your conversations and the files attached to them are purged, and your login is removed. No email to write, no waiting on us.

FAQ

Is Brift GDPR compliant?

Brift is built to be used in compliance with GDPR: the widget sets no cookie, no visitor IP is stored, data is isolated per account, and deletion is self-service and complete. Compliance is a shared responsibility, you remain the controller for what your visitors write to your agent, so keep your own privacy notice up to date. Need a signed data processing agreement for your records? Ask and we will put one in place.

Where does the voice go when a visitor dictates?

To OpenAI’s speech to text API and nowhere else, for the few seconds the transcription takes. The audio is never written to our database and never leaves that request: only the resulting text is saved, as an ordinary message. It is a separate call from the one that writes replies, and the audio never reaches that one. If you would rather not offer dictation at all on your widget, tell us and we will turn the microphone off for your account.

Can I read what visitors said to my agent?

Yes, every conversation is stored in full and readable from your dashboard, message by message, with its qualification level. That transparency is the point of the product: you finally see the objections your traffic actually raises.

Does Brift see the rest of my website?

Only what is publicly reachable. When you paste your URL we read your public pages to configure the agent, exactly as a search engine would. The script you install renders the widget, it does not read your page content, your forms, or anything a logged-in user sees.

What happens to my data if I cancel?

Cancelling stops the billing and takes your agent offline; your conversations stay readable while the account exists, so you keep what you learned. If you want everything gone, delete the account from your settings, that purge is immediate and irreversible.

Where is the data hosted?

Your account, agents and conversations sit in a European Union database. Replies are generated by Anthropic’s API in the United States, and the agent’s setup by OpenAI’s, which means the text of a message transits there to be answered. If that transfer is a blocker for you, tell us before you subscribe rather than after.

Found a vulnerability?

Write to us directly and we will answer. There is no paid bug bounty programme, pretending otherwise would waste your time, but a report gets read by the person who wrote the code, usually the same day.

See what Brift would look like on your site.Voyez à quoi ressemblerait Brift sur votre site.Mira cómo quedaría Brift en tu web.

Enter your URL — live in 2 minutes, from $53/mo on annual billing.Collez votre URL — en ligne en 2 minutes, dès 53$/mois en annuel.Pega tu URL — en vivo en 2 minutos, desde 24$/mes en facturación anual.

Get startedDémarrerEmpezar ahora

Brift

ProductProduitProducto

  • Made for youFait pour vousHecho para ti
  • CompareComparatifComparativa
  • EnterpriseEntrepriseEmpresas
  • SecuritySécuritéSeguridad

ResourcesRessourcesRecursos

  • GuidesGuidesGuías
  • BlogBlogBlog

LegalLégalLegal

  • Terms of UseConditions d'utilisationCondiciones de uso
  • Privacy PolicyConfidentialitéPrivacidad
  • Cookie PolicyCookiesCookies
  • Legal noticeMentions légalesAviso legal

© 2026 Brift. All rights reserved.© 2026 Brift. Tous droits réservés.© 2026 Brift. Todos los derechos reservados.