Skip to content
Briefpfleger
← Back to home

Privacy Policy

Last updated: September 2026

This is an English translation provided for convenience. In case of any discrepancy, the German version prevails.

1. Controller

IT Consulting & Development Tino Sanchez Ross
Sole proprietorship, owner: Tino Sanchez Ross
Bismarckring 6
65185 Wiesbaden
Germany
Email: kontakt@briefpfleger.de

2. Core principle: no storage on our servers – Google as the central provider

Briefpfleger stores no personal data on its own servers. The application is built as a purely client-side web application (Progressive Web App, PWA) and runs entirely in your browser. All documents, images and metadata are stored exclusively in your personal Google account (Google Drive).

Important: Briefpfleger is essentially an interface to your own Google services. The actual storage and processing of your data – including Google Drive, Google Calendar, Google Contacts, Google Docs and the text recognition described below – is carried out by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) on the basis of the terms of service and privacy terms agreed between you and Google. The Google Privacy Policy governs that processing, and we recommend reading it, as it is the central basis for how your stored content is handled.

Who is responsible for what? Even though your data resides in your own Google account: for the processing triggered by your use of the app – the decision that text recognition takes place, how documents are classified and which folder structure is created – we are the controller within the meaning of Art. 4(7) GDPR. Google Ireland Limited is separately responsible for the storage within your Google account.

3. What data is processed?

3.1 Google account (OAuth 2.0)

To use the app you sign in through the standard Google OAuth 2.0 process. The following data is processed:

  • Your name and email address (displayed inside the app)
  • A temporary access token for the Google services you have authorised

The access token is held in your browser's memory only and is never stored persistently; after closing or reloading the page it is requested again through your existing Google session. This information is never transmitted to our servers or to third parties.

Briefpfleger requests permissions (OAuth scopes) incrementally and only when you actively use the corresponding feature. By default only the restricted drive.file scope is used, which grants Briefpfleger access solely to files the app created itself – not to the rest of your Google Drive.

In total Briefpfleger requests exactly four permissions, each separately and only when needed:

  • drive.file – access only to files created by the app itself (see 3.2)
  • calendar.events – creating calendar entries for deadlines (see 3.3)
  • contacts.readonly – reading your address book (see 3.5)
  • contacts – exporting a contact into your address book (see 3.5)

Google sign-in library: In order to offer sign-in at all, the app loads Google's official sign-in script (accounts.google.com/gsi/client) when it starts. For technical reasons your IP address is transmitted to Google at that point, before you sign in or grant any permission. Without this script no sign-in – and therefore no use of the app – is possible.

Legal basis: Art. 6(1)(b) GDPR (performance of the user contract) for sign-in, the loading of the sign-in library and all core features. Art. 6(1)(a) GDPR (consent) for the optional additional permissions and device access described in sections 3.3, 3.6 and 3.9 – granted through the respective consent dialogue and revocable at any time (see section 8).

3.2 Google Drive

Using the OAuth token you granted, Briefpfleger accesses your Google Drive in order to:

  • Create an app folder ("Briefpfleger") in your Drive
  • Upload documents, images and PDFs into that folder
  • Store metadata (file name, description containing recognised text, deadlines) in the Google Drive file properties

Legal basis: Art. 6(1)(b) GDPR (performance of the user contract – without this access the app has no function).

3.3 Google Calendar (optional)

If you set a deadline with a reminder, Briefpfleger creates an entry in your primary Google Calendar after separate consent (scope calendar.events). The reminders are managed by Google Calendar (pop-up notifications and email reminders). Briefpfleger itself sends neither emails nor push notifications. The scope permits access to calendar events only, not to other calendar data. Legal basis: Art. 6(1)(a) GDPR (consent).

3.4 Text recognition (OCR) via Google

So that you can find your documents again through full-text search, the text of your uploaded images and PDFs is recognised automatically (OCR). This recognition is performed by Google: the file is processed within your own Google Drive using your own Google access (temporary conversion into a Google document, extraction of the text, then automatic deletion of the temporary file). No images or text are transmitted to Briefpfleger servers – the processing takes place entirely inside your Google account and is subject to the Google Privacy Policy. The recognised text is then stored in the description field of the respective file in your Drive. Legal basis: Art. 6(1)(b) GDPR (performance of the user contract).

3.5 Google Contacts (optional)

The connection to your Google address book is optional and consists of two separate permissions. Google shows you its own consent dialogue for each, and you may grant only one of them:

  • Reading (scope contacts.readonly): Briefpfleger matches senders recognised on your documents against your address book and shows you the corresponding contact details.
  • Writing (scope contacts): When you explicitly export a contact maintained inside Briefpfleger to your Google address book, the app creates a new contact there – with the name and, where available, company, email address and phone number. This scope technically also permits modifying and deleting contacts. Briefpfleger uses it solely to create new contacts and never modifies or deletes existing entries.

Matching happens in your browser; no contact data is transmitted to us. Legal basis: Art. 6(1)(a) GDPR (consent). You can revoke both permissions at any time in your Google account. Contacts already exported remain in your address book and can be deleted by you there.

3.6 Encryption & app lock

You can optionally encrypt documents with a password before uploading (AES-GCM, 256-bit). Encryption takes place entirely in the browser. The password is not stored permanently and cannot be recovered by us.

You can additionally set up a local app lock (Face ID / Touch ID / device biometrics or a PIN). Only a WebAuthn credential and a cryptographic hash of your PIN are stored in your local browser storage – never the PIN in plain text and no biometric data. This data never leaves your device.

Legal basis for both features: Art. 6(1)(a) GDPR (consent) – you set them up voluntarily and can switch them off again in the app at any time.

3.7 Camera & microphone (optional)

Camera: To photograph documents, your browser asks for camera access. The image is processed in the browser and uploaded straight to your Google Drive.

Microphone: When you record a voice note for a document, your browser asks for microphone access. The recording is created on your device, offered to you for playback before saving, and only placed into the same Google Drive folder as the document once you click save. If you discard it, it never leaves your device.

Both permissions are voluntary, are requested only at the moment you use the feature, and can be revoked at any time in your browser settings. There is no automatic or unnoticed recording, and neither images nor audio pass through a server of ours – we do not have one.

In browsers that support it (essentially Google Chrome), Briefpfleger additionally offers dictation for text fields. This uses the browser's own speech recognition; depending on the browser, what you say may be transmitted to the browser vendor for recognition. The feature only starts when you click "Dictate". If you prefer to avoid this, use a voice note instead – it stays entirely on your device and in your Drive.

Legal basis for camera, microphone and dictation: Art. 6(1)(a) GDPR (consent), which you give through your browser's permission prompt.

3.8 Compliance with Google API Services User Data Policy (Limited Use)

Briefpfleger's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Hosting & technical infrastructure

The website and the web app are hosted by Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA). Vercel processes the following technical access data by default (server logs):

  • IP address
  • Date and time of access
  • Amount of data transferred
  • Browser type and operating system

Further information can be found in Vercel's privacy policy.

Processing agreement and international transfers: For hosting, a data processing agreement under Art. 28 GDPR (Data Processing Addendum) is in place with Vercel. As Vercel is based in the USA, the transfer is safeguarded by Standard Contractual Clauses under Art. 46(2)(c) GDPR; Vercel is additionally certified under the EU-US Data Privacy Framework.

The legal basis for processing the server logs is Art. 6(1)(f) GDPR (legitimate interest in secure and trouble-free operation). Retention: Vercel keeps the logs only for a short period – typically a few days to weeks; details are set out in Vercel's privacy policy linked above. We neither access nor analyse these logs ourselves.

Error monitoring: For the stability of the app, an integration with the service Sentry (Functional Software, Inc., 45 Fremont Street, San Francisco, CA 94105, USA) is planned, through which technical error reports may be transmitted (error message, affected part of the program, browser type, timestamp). This integration is currently not active – no data is being sent to Sentry at present. As soon as it is activated we will update this section accordingly. The legal basis would then be Art. 6(1)(f) GDPR (legitimate interest in trouble-free operation).

5. Fonts

The font used, Lexend, is served from our own server. No connection to Google servers is established and no IP address is transmitted to third parties. Google Fonts are not embedded.

6. Analytics, cookies & local storage

Briefpfleger uses no tracking cookies, no Google Analytics, no Matomo and no advertising pixels.

To measure anonymous usage figures we use Vercel Web Analytics (Vercel Inc., address above). It records page views, referrer, approximate region as well as browser and device type in aggregated form. The service works without cookies and stores no identifiers on your device; individuals are not identified and no cross-device recognition takes place. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in measuring the reach of our service). As no information is stored on or read from your device, no consent under § 25 TDDDG is required. Retention: Only aggregated statistics without any personal reference are produced; retention follows Vercel's own policy (see their privacy policy). We never establish a link to an individual person.

Beyond that, only the following technically necessary data is stored locally in your browser storage (LocalStorage/IndexedDB):

  • App settings (language, reading-aid preference, view options)
  • The details you gave during setup: first name or display name, housing situation, selected topic areas and the folder structure chosen from them – used to address you personally and to suggest suitable folders
  • Which Google permissions you have already granted (no token content)
  • Local cache data of the app (folder structure, document lists including file names, your own sort order) for faster loading
  • If configured: the data of the local app lock (see 3.6)
  • Queued scans that have not been uploaded yet
  • A note of which hints and tips you have already dismissed

Your Google access token is deliberately not placed in LocalStorage but held only transiently in memory (see 3.1). Retention: This data stays on your device until you sign out, use the "delete everything" function or clear your browser data – there is no automatic time limit, because the data never leaves your device. Signing out or using "delete everything" removes the local cache and app data.

7. Disclosure to third parties

We do not disclose personal data to third parties. Processors acting on our behalf and bound by our instructions – such as our host (see 4.) – are not considered third parties under Art. 4(10) GDPR. External communication takes place exclusively between your browser and the Google APIs (Drive, Calendar, Contacts, Docs and OCR processing), to each of which you explicitly consent via OAuth. When you create a share link, the file in question is made accessible through the Google Drive sharing function ("anyone with the link"); you can revoke such sharing at any time in the app.

8. Your rights (Art. 15–21 GDPR)

You have the right at any time to:

  • Access the data we process about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Object to processing (Art. 21 GDPR)

Since Briefpfleger stores no personal data on its own servers, the right of access primarily concerns the data stored in your own Google Drive. You can view, export and delete it yourself at any time – including directly via the built-in "delete everything" function in the app.

Withdrawal of consent (Art. 7(3) GDPR): Where processing is based on your consent – calendar, contacts, camera, microphone and app lock – you may withdraw it at any time with effect for the future: the Google permissions at myaccount.google.com/permissions, camera and microphone in your browser settings, the app lock in the app's settings. The lawfulness of processing carried out before withdrawal remains unaffected.

Automated decision-making (Art. 22 GDPR): Based on the recognised text, Briefpfleger automatically suggests a category and a storage location for your documents. This is purely a sorting aid without legal effect – every suggestion can be changed before saving. No automated decision in an individual case within the meaning of Art. 22 GDPR takes place.

9. Deletion of data

You can remove all data created by Briefpfleger from your Google Drive completely and without residue at any time by using the app's built-in deletion function (confirmation phrase "ALLES LÖSCHEN"). Alternatively you can delete the "Briefpfleger" folder from your Google Drive manually.

10. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR.

The authority responsible for us is:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Postfach 3163
65021 Wiesbaden, Germany
datenschutz.hessen.de

You may equally contact the supervisory authority of your habitual residence or place of work.

11. Notice for users in the United States

Briefpfleger is operated from Germany. If you access the service from the United States, the processing described above applies in the same way. We do not sell or share personal information for cross-context behavioural advertising within the meaning of the California Consumer Privacy Act (CCPA/CPRA). Since we store no personal data on our own servers, requests regarding access or deletion concern the data held in your own Google account, which you control directly.

© 2026 Briefpfleger. Built for order & privacy.

Privacy Legal Notice Terms