Draft for legal review. This addendum describes our intended security posture and must be validated by counsel and your security team before it is relied upon contractually.
Purpose
This addendum details the technical and organizational measures that protect data processed by Briefly. It exists because our security-conscious and enterprise users cannot adopt a tool without explicit, verifiable security commitments.
1. Data minimization & zero retention
Raw channel message text is processed only to generate a brief and is purged after the digest window via short time-to-live expiry and scheduled cleanup. We do not build a long-term archive of your source content.
2. Operational security (OPSEC)
- No account impersonation. We never use userbots (MTProto in user-account mode) to read channels. Private content is ingested only through staging groups you administer.
- Metadata stripping. “Forwarded from” metadata is removed from staged messages before processing.
- Scoped access. Each user’s configuration and data are isolated and scoped to their Telegram identity.
3. Encryption
Data in transit is protected with industry-standard TLS. Data at rest on our infrastructure is encrypted using provider-managed encryption. Authentication to the Mini App is performed via signed Telegram init-data, validated with HMAC-SHA256.
4. Sub-processors
We maintain a current list of sub-processors with the data each one processes on our Sub-processors page. Enterprise customers may request notice of material changes.
5. Incident response
We maintain an incident-response process and will notify affected customers of a confirmed breach of their data without undue delay, consistent with applicable law.
6. Requesting the full addendum
Enterprise procurement teams can request the complete, countersigned Data Security Addendum and any supporting documentation through our contact page.