▮ BIT BRIEF

[00]Privacy Policy · BitBrieflast updated 2026-09-10

Privacy Policy

Summary — not part of this Policy

The Software executes entirely upon Your own equipment. No user account exists, no Provider-operated server receives Your recordings, and the Software contains no analytics, telemetry, or crash-reporting instrumentation. The Provider does not collect Your Meeting Content because it has no technical means of receiving it. This summary is provided for convenience only and forms no part of this Policy. The numbered sections below govern.

[01]Introduction and Scope

This Privacy Policy (the “Policy”) describes how Ethique AI Inc., a Delaware corporation, publisher of BitBrief through its Barebones division (the “Provider”, “We”, “Us”, “Our”) collects, uses, discloses and retains personal information in connection with the BitBrief desktop application (the “Software”), the Notion Connection, and the website published at bitbrief.ai (the “Site”).

This Policy forms part of, and is incorporated by reference into, the Terms of Use. Capitalised terms not defined in this Policy bear the meanings given in the Terms of Use.

Meeting Content residing upon Your equipment is Yours. The Provider is not a custodian of it, exercises no control over it, and has no technical means of accessing it. Section 08 states this in the negative and should be read together with this Section.

[02]Definitions

TermMeaning
“Personal information”Information that identifies, relates to, describes, or is reasonably capable of being associated with an identified or identifiable natural person, as that term is defined under applicable law including the California Consumer Privacy Act.
“Meeting Content”Audio recorded or supplied by You, and all transcripts, speaker attributions, summaries and other materials derived from it by the Software.
“Server Logs”Records generated automatically when a device requests a resource from the Site, comprising internet protocol address, user-agent string, requested resource, and timestamp.
“Hosted Model Provider”A third-party service that performs summarization remotely, used only where You have configured the Software to do so in place of the local default.

[03]Personal Information We Collect

The Provider collects the following categories of personal information, and no others:

CategorySourceBusiness purposeRetention
Identifiers and network activity information (Server Logs: IP address, user agent, requested resource, timestamp)Collected automatically when Your device requests a resource from the SiteSecurity, abuse prevention, and diagnosis of technical faults30 days

The Provider operates no user accounts and collects no registration data. The Software contains no analytics, telemetry, behavioural measurement, advertising identifier, or crash-reporting instrumentation. The Site sets no tracking cookie, employs no analytics service, and loads no third-party script for any such purpose.

The Provider does not collect personal information from any source other than those stated in the table above. In particular, the Provider does not purchase, licence, or otherwise obtain personal information from data brokers or other third parties.

[04]Network Requests Made by the Software

The following is an exhaustive statement of the circumstances in which the Software transmits a network request. The Software makes no request other than those enumerated below.

CircumstanceRecipientContent transmitted
First execution following installationHuggingFace; GitHub release infrastructureA request for model weight files. No personal information and no Meeting Content is transmitted.
Periodic check for a later versionProvider-operated update manifestA request for the current version identifier.
Upon Your instruction to deliver a noteNotionThe Output You have directed the Software to write, to the workspace You have authorised.
Only where You have configured summarization to a Hosted Model ProviderThe Hosted Model Provider You selectedThe transcript, transmitted under Your own credentials. See Section 07.

The request described in the first row retrieves the speech-to-text and speaker models, which are approximately 200 megabytes in aggregate and are not included in the installer. It is a retrieval of files only.

[05]The Notion Connection

Where You elect to connect the Software to a Notion workspace, You create an integration within that workspace Yourself and supply the token it issues to the Software. The scope of access is that which You grant to Your own integration, and it reaches only those pages You have shared with it. The Provider does not receive, process, or store Your Notion credentials at any point. No step of the authorisation traverses infrastructure operated by the Provider, because there is none to traverse.

Within the scope so authorised, the Software writes only such pages as You direct and reads only such resources as You have selected. The Software does not browse, crawl, enumerate, search, or index Your workspace, and does not transmit workspace contents to the Provider.

The token You supply is stored upon Your equipment together with Your other application settings, in a file whose permissions restrict access to Your operating-system user account. The Provider is undertaking work to migrate such storage to the operating-system keychain.

Revocation

You may revoke access at any time, whether by removing the token from the Software or by revoking or deleting the integration within Your Notion workspace. Revocation within Notion is effective irrespective of whether the Software remains installed. Revocation terminates all further access with immediate effect. Output already written to Your workspace remains there, as it is Your property.

[06]Data Stored Upon Your Equipment

Recordings, transcripts, generated notes, a local database of processing jobs, and Your configuration settings are stored within the application-data directory of the Software upon Your equipment. The configuration file, which holds any credentials You have supplied, is written with permissions restricting access to Your operating-system user account.

The Software is additionally capable of exporting copies of audio, transcripts and summaries to a directory of Your choosing. Each export category is disabled by default and operates only where You have expressly enabled it.

Deletion of that directory, together with removal of the Software, erases all such data. No action by the Provider is required, and none is possible.

[07]Summarization Configuration

By default, summarization is performed by a model executing upon Your own equipment. In that configuration the transcript is not transmitted to any third party for that purpose.

You may instead configure the Software to use a Hosted Model Provider under Your own account and credentials. Where You do so, the transcript is transmitted to that provider, and that provider's privacy terms govern its subsequent handling. The Provider is not a party to that relationship, exercises no control over that provider, and gives no undertaking as to its practices.

Matter to be considered before configuring a Hosted Model Provider

The Software attempts to identify participants by name from the content of the transcript, and this function is enabled by default. A transcript transmitted to a Hosted Model Provider may accordingly contain personal information relating to third parties who are not You, including the names of other participants. You should satisfy Yourself that such transmission is lawful before enabling this configuration.

[08]Information the Provider Does Not Receive

For the avoidance of doubt, none of the following is transmitted to, received by, or accessible to the Provider at any time:

  • Audio recorded or supplied by You, in any form
  • Transcripts, speaker attributions, or detected participant names
  • Summaries, decisions, action items, or any other Output
  • The contents of Your Notion workspace
  • Your API keys, access tokens, or other credentials
  • The identity of any participant in any meeting You record

[09]Service Providers and Disclosure

The Provider engages Vercel Inc. to host the Site, and Google Cloud Storage to distribute installers and the update manifest. Those two are the whole of the Provider's processing arrangements. They process information solely upon the Provider's instructions and for the business purposes stated in Section 03.

All other services with which the Software interacts are contacted directly by the Software upon Your equipment, without the involvement of the Provider. These comprise HuggingFace and GitHub (retrieval of model weights on first execution), Notion (delivery of Output at Your instruction), and any Hosted Model Provider You have configured. The Provider engages no processor in connection with Your Notion integration, no part of which traverses infrastructure it operates.

The Provider may disclose personal information where required to do so by law, by valid legal process, or by order of a court or regulatory authority of competent jurisdiction, and may disclose personal information in connection with a merger, acquisition, reorganisation, or sale of assets, subject to the recipient being bound by terms no less protective than this Policy.

[10]Security

Network requests made by the Software and by the Site employ encrypted transport. Configuration files upon Your equipment are written with restrictive file permissions; credentials are masked within the interface of the Software; and access requested through the Notion Connection is limited to that necessary to perform the function You have requested.

The most material security characteristic of the Software is structural rather than procedural: the Provider does not hold Meeting Content, and a compromise of the Provider's systems therefore cannot expose it. The corollary is that the security of Your equipment is a matter for You.

No method of transmission or storage is entirely secure. While the Provider takes reasonable measures to protect the limited information it holds, it cannot warrant absolute security, and gives no such warranty.

[11]Retention

Server Logs are retained for 30 days and are thereafter deleted.

All other data resides upon Your equipment and is retained until You delete it. The Provider applies no retention schedule to such data, holds no copy of it, and cannot delete it on Your behalf. Section 06 describes the method of deletion.

[12]California Privacy Rights

This Section applies to residents of the State of California and is provided pursuant to the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (together, the “CCPA”).

The categories of personal information collected, the sources from which they are collected, the business purposes for which they are collected, and the periods for which they are retained are set out in Section 03. The categories of third parties to whom personal information is disclosed for a business purpose are set out in Section 09.

The Provider does not sell personal information, and does not share personal information for cross-context behavioural advertising, as those terms are defined in the CCPA. The Provider has never done either, and does not collect or process sensitive personal information.

Subject to the CCPA and to verification of Your identity, You have the right to: (a) know the categories and specific pieces of personal information collected about You; (b) request deletion of personal information; (c) request correction of inaccurate personal information; (d) opt out of the sale or sharing of personal information, which is inapplicable as stated above; (e) limit the use and disclosure of sensitive personal information, which is inapplicable as stated above; and (f) not be subject to discriminatory treatment for exercising any of these rights.

Requests may be submitted to [email protected]. The Provider shall acknowledge a request within ten business days and respond within forty-five calendar days, which period may be extended once by a further forty-five days where reasonably necessary, with notice to You. An authorised agent may submit a request on Your behalf upon provision of evidence of authority.

The practical effect of the Provider holding so little

The only personal information the Provider is likely to hold concerning You is Server Logs, and a request may therefore be satisfied promptly. Meeting Content is not within the Provider's possession or control and cannot be produced, corrected, or deleted by the Provider. Section 06 describes how You may delete it Yourself.

[13]Server Edition

This Policy does not describe any deployment of the server edition upon infrastructure You control. Where You operate such a deployment, You determine the purposes and means of processing and act as controller of the personal information it handles.

The default configuration of the server edition differs materially from that of the Software, and in particular is configured to transmit transcripts to a hosted model provider. You should review its configuration before operating it in respect of any person other than Yourself.

[14]Children

The Software, the Notion Connection and the Site are not directed to children under the age of thirteen, and the Provider does not knowingly collect personal information from such children. Where the Provider becomes aware that it has done so, it shall delete that information.

[15]Changes to this Policy

The Provider may amend this Policy from time to time. The date stated at the head of this document shall be updated upon any amendment, and any material amendment shall be identified on this page. Your continued use following the effective date of an amendment constitutes acceptance of the amended Policy.

[16]Contact

Enquiries and requests concerning this Policy may be directed to [email protected].

Formal notices shall be addressed to Ethique AI Inc., [email protected].