Privacy

Privacy Policy

How Brivium collects, uses, and shares account, business, telephony, messaging, analytics, and advertising data.

Last updated: July 11, 2026

1. Overview

Brivium, Inc. ("Brivium," "we," "us," or "our"), based in Charlotte, North Carolina, provides a software platform for trade and service businesses. This Privacy Policy describes how we collect, use, store, and share information when you use the Brivium web and mobile applications, business phone and text messaging features, our marketing website, and related services (collectively, the "Service"). The Service is offered in the United States.

This policy covers two groups of people: (1) our users — the businesses and team members who create Brivium accounts — and (2) the customers of those businesses, whose information our users store in Brivium. If you are a customer of a business that uses Brivium, see Section 14. By using the Service, you agree to this policy.

2. Information We Collect

Account and profile data: name, email address, phone number, password credentials (stored securely by our authentication provider), Sign in with Apple or Google identifiers, workspace and company settings, team role, profile photo, language and display preferences, and support and feedback communications.

Business and customer data: information you or your team enter into Brivium, including customers, leads, jobs, quotes, invoices, schedules, files, photos, notes, contracts, messages, and portal content. This may include personal information about your customers, employees, contractors, or other contacts.

Business verification data: if you enable business texting, we collect your legal business name, business type, EIN/tax ID, business address, and authorized representative details, as described in Section 6.

Device, usage, and diagnostic data: device type, operating system, app version, IP address, browser type, log data, crash reports, product usage events, and performance metrics. We also keep telephony diagnostic logs used to troubleshoot calling issues, which may include the phone numbers involved in a call.

3. How We Use Information

We use information to provide, maintain, and secure the Service; authenticate users and manage workspaces; process telephony and messaging; display call history, voicemails, and recordings; process payments and subscriptions; send transactional notifications and emails; power features you request (such as the AI Coach described in Section 8); prevent fraud and abuse; comply with law; analyze and improve product quality; and communicate with you about the Service.

We do not sell personal information. Your product and workspace data — including your customers' information — is never used for advertising. The only advertising-related data practices we have involve visitors to our marketing website, as described in Section 13.

4. Telephony: Calls, Voicemail, and Call Logs

If you enable Brivium business phone features, we and our telecommunications provider (Twilio) process voice calls, voicemail, caller ID, phone numbers you provision or dial, call direction, duration, status, timestamps, and related metadata.

Voicemail: when a caller reaches your voicemail and leaves a message, that message is always recorded and stored so you can listen to it later. Voicemail audio is hosted by Twilio and accessed through the Service.

Call recording: beyond voicemail, calls are recorded only when call recording is enabled for your workspace. You are responsible for complying with call recording laws, including notifying and, where required, obtaining consent from call participants.

Call logs: we store call logs associated with your workspace, including the phone numbers involved, direction, status, timestamps, duration, and links to recordings or voicemails. This data is used to display call history, match calls to customer records, support billing, troubleshoot telephony issues, and meet legal or regulatory obligations.

Push notifications: voice calls on iOS use Apple's PushKit and CallKit to deliver incoming call notifications and present the native call interface. Notifications may include details such as a caller's phone number or a message preview. We never use VoIP push notifications for marketing or promotional messages.

You are responsible for obtaining appropriate consent before contacting individuals and for the content of calls and messages sent through your account, in compliance with the TCPA, carrier rules, and other applicable requirements.

5. SMS / Text Messaging Program

Brivium enables businesses to send and receive SMS/MMS text messages with their customers using phone numbers provisioned through the Service. Message content, phone numbers, attachments, timestamps, and delivery status are processed by Twilio and stored in your workspace so conversations can be displayed and continued.

Consent: text messages are sent only to recipients who have opted in to receive them — for example, by providing their phone number to a business and agreeing to receive text messages from that business. Businesses using Brivium are responsible for obtaining and honoring that consent before texting anyone.

Program disclosures: Message frequency varies. Message and data rates may apply. Reply STOP to cancel, HELP for help. Opting out stops further messages from the number you replied to, except a single confirmation of your opt-out.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be sold, rented, or shared with any third parties. Sharing with service providers acting on our behalf solely to deliver the messaging service (such as our messaging platform provider, Twilio) is limited to what is necessary to send and receive the messages recipients have consented to.

6. Business Verification for Business Texting

US carriers require businesses to be verified before sending application-to-person (A2P 10DLC) text messages. To enable texting for your business, we collect your legal business name, business type, EIN/tax ID, business address, and the name, title, email address, and mobile number of an authorized representative. We share this information with Twilio and carrier registration registries to register your business and messaging campaign, and we retain it as a compliance record for as long as your messaging registration is active or as required by carrier rules and law.

7. Device Permissions

Microphone: Brivium requests microphone access so you can speak during business phone calls placed or received through the app. Microphone audio is used only for active calls and is not recorded by Brivium except when call recording is enabled for your workspace (see Section 4). Voicemail messages left by callers are always recorded, as described in Section 4.

Contacts: on mobile devices, Brivium requests Contacts access only when you choose to import a contact to create a customer record, using the system contact picker. We do not upload your full contact list, and no contact data leaves your device without that explicit action.

Camera and photos: camera and photo library access may be used to attach job and project photos, upload logos and profile photos, and send photo attachments in messages.

Location: in our mobile app, when you begin typing a customer's or job's address, we may ask permission to use your device location to suggest nearby addresses. We use a single approximate location only to improve those address suggestions; we do not track your location, store a location history, or use it for advertising. You can grant or deny this permission, and change it later in your device settings, without losing any other app functionality. When you open navigation to a customer address, we pass that address to the maps app you choose; any location use happens in that app under its own policies.

8. AI Features

The AI Coach feature lets you ask business questions in a chat. When you use it, we send your message, recent conversation history, and a summary of your business — including your company name, activity counts, revenue and invoice metrics (such as monthly revenue and unpaid invoice totals), and the names and balances of partner businesses you track — to the Google Gemini API to generate a response. To answer questions about specific records, the AI Coach can also look up and send relevant details from your workspace — such as a customer's name, contact information, and their quote, invoice, and balance amounts — for that request. Your coach conversation history is stored in your workspace.

We use the paid tier of the Google Gemini API; under Google Cloud's terms, data submitted through the paid API is not used to train Google's models. AI features are optional — data is sent only when you use them. Please do not enter sensitive personal information about identifiable individuals into AI chats, and verify important answers before acting on them.

9. Electronic Signatures

When a business sends a quote or contract for signature through a public link, we collect information directly from the signer: the drawn signature image, the signer's name, and the date and time of signing. This information is recorded on the document, embedded in the signed PDF, and stored with the business's records as evidence of the agreement. If you signed a document for a business that uses Brivium, contact that business with questions about the agreement (see Section 14).

10. Payments

Brivium subscriptions: web subscriptions are processed by Stripe, which receives the business owner's email address and company name along with payment details. iOS subscriptions are processed by Apple through the App Store. We use RevenueCat to manage subscription state; it identifies your subscription by a workspace identifier and purchase records rather than your name or email.

Payments you collect from your customers: businesses can accept deposits and invoice payments through Stripe. When your customer pays, their email address, payment details, and the related quote or invoice information are provided to Stripe to process the payment.

Payment processors may collect payment card details, bank account information, identity verification data, tax information, and transaction records under their own terms. Brivium does not store complete payment card numbers or bank account credentials on our servers.

11. Service Providers

We share personal information with the following service providers, each only for the purpose described:

Supabase — database hosting, authentication, file storage, and serverless functions (our primary infrastructure).
Twilio — voice calls, SMS/MMS, voicemail recordings, phone number provisioning, and business texting registration.
Stripe — subscription billing and payment processing, including payments businesses collect from their customers.
Apple — app distribution, in-app subscriptions, push notification delivery, and Sign in with Apple.
Google (platform services) — Sign in with Google and app distribution on Google platforms.
Google Maps Platform — address autocomplete: address text you type, and (if you grant location permission in the mobile app) your approximate location, are sent to Google to power and localize address suggestions.
Google Gemini API — AI Coach responses, as described in Section 8.
Sentry — crash reporting and diagnostics, including IP address and device information.
PostHog — product analytics identified by user ID, email address, and name, as described in Section 12.
RevenueCat — subscription management keyed to a workspace identifier.
Resend — transactional email delivery, including recipient email addresses and delivery, bounce, and complaint events.
Expo (EAS) — delivery of app updates; devices contact Expo's servers to check for and download over-the-air updates.

We contractually require these providers to protect personal information to at least the same standard described in this policy and to use it only to provide their services to us.

12. Analytics and Product Diagnostics

Product analytics (PostHog): in our web application we use PostHog to understand how the product is used. PostHog builds an identified profile tied to your user ID, email address, and name, and automatically captures interactions such as page views, clicks, and form activity, along with product events (for example, creating a quote or starting a checkout), application errors, and, if enabled, session recordings of in-app activity. We use this data to improve the product, not for advertising.

Crash and error reporting (Sentry): our web and mobile apps send crash reports, error details, performance data, and diagnostic context (such as screens visited and interface interactions leading up to an error) to Sentry. These reports include your IP address and device information.

Cookies and local storage: we use cookies, local storage, and similar technologies in the app to keep you signed in, remember preferences, and measure performance. Our mobile apps do not include advertising SDKs. Advertising cookies exist only on our marketing website, as described in Section 13.

13. Website Advertising and Cookies

Our marketing website uses advertising pixels and cookies from Google Ads and Meta to measure ad conversions and improve our ad campaigns. These tools collect information about website visitors, such as device and browser information, IP address, pages viewed, and cookie identifiers, and share it with the advertising platform. Under some US state privacy laws, this is considered "sharing" personal information for cross-context behavioral advertising. It applies only to visitors of our marketing website — data from the Brivium product, your workspace, and your customers is never used for advertising.

We do not sell personal information for money. You can opt out of website advertising cookies by: enabling the Global Privacy Control (GPC) signal in your browser, which we honor as an opt-out of this sharing; blocking or deleting cookies in your browser settings; or using the platform controls at Google Ads Settings, Meta Ad Preferences, and optout.aboutads.info.

14. Your Customers' Information (Our Role as a Processor)

Businesses use Brivium to store and manage information about their own customers — names, contact details, addresses, job details, messages, photos, documents, and signatures. For that information, the business is the controller and Brivium acts as a service provider (processor): we process it only to provide the Service to the business, we do not sell it, and we do not use it for advertising or any other purpose of our own.

If you are a customer of a business that uses Brivium and want to access, correct, or delete your information, contact that business directly — it controls your data. We assist businesses in responding to such requests. If you contact us directly at support@briviumapp.com, we will forward your request to the business where feasible.

15. Data Retention

We retain information for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, and maintain security. Call logs, messages, and business records remain in your workspace until you or an administrator delete them or delete the account.

After deletion, residual copies may remain in encrypted backups and in operational or diagnostic logs for a limited period (generally up to 90 days) before being overwritten or removed. Telephony records (including business texting registration and consent records), billing and tax records, and fraud-prevention records may be retained longer where required by law, carrier rules, or our legitimate compliance needs.

16. Account Deletion

You can delete your account directly in the app from the account settings screen. Deleting your account removes your account record and profile along with your workspace data, including customers, quotes, invoices, jobs, messages, call history, notes, and uploaded files.

App Store subscriptions: deleting your account does not cancel a subscription billed through Apple. Cancel it separately in your App Store subscription settings, or Apple will continue to bill you.

What may remain: residual copies may persist in backups and logs for a limited period as described in Section 15; telephony, billing, and compliance records are retained where legally required; and we request deletion of associated personal information from our service providers where their platforms support it. You can also request deletion by emailing support@briviumapp.com.

17. Security

We protect personal information with technical and organizational measures appropriate for a SaaS product, including encryption in transit and access controls that limit workspace data to authorized team members.

Be aware that content shared through links — such as public quote, invoice, and customer portal links, signed documents, and photos or attachments delivered via shared links — is accessible to anyone who has the link. Share those links only with the people who need them. No method of transmission or storage is completely secure, and you are responsible for safeguarding your login credentials and managing team access appropriately.

18. US State Privacy Rights

This section applies to residents of US states with comprehensive privacy laws, including the Texas Data Privacy and Security Act, the Nebraska Data Privacy Act, and similar laws.

Categories we collect: identifiers (name, email address, phone number, account IDs); commercial information (subscription and payment records); internet and network activity (product usage, device, and diagnostic data); audio information (voicemail messages, and call recordings when enabled); professional information (business details, including verification data such as EIN); and user content (messages, documents, photos, and signatures). We collect this information from you, your team, your customers, your devices, and our service providers, for the purposes described in Section 3, and we disclose it to the service providers listed in Section 11. The only "sharing" for cross-context behavioral advertising is the website advertising described in Section 13, and we do not sell personal information.

Your rights: depending on your state, you may have the right to know and access the personal information we hold about you, obtain a portable copy, correct inaccuracies, delete it, and opt out of targeted advertising. We honor Global Privacy Control (GPC) browser signals as an opt-out of the website advertising described in Section 13. We will not discriminate against you for exercising your rights.

How to exercise them: email support@briviumapp.com. We may need to verify your identity before responding. If we decline your request, you may appeal by replying to our decision or emailing the same address with "Privacy Appeal" in the subject line; if your appeal is denied, you may contact your state attorney general. If you are a customer of a business that uses Brivium, direct your request to that business as described in Section 14.

19. International Data Transfers

Brivium is a US-based service offered in the United States. Information is processed in the US and in other locations where our service providers operate. If you access the Service from outside the US, you understand that your information will be transferred to and processed in the United States.

20. Children

The Service is intended for business use and is not directed to children under 13. We do not knowingly collect personal information from children under 13; if we learn that we have, we will delete it.

21. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the "Last updated" date. Material changes may be communicated through the Service or by email where appropriate.

22. Contact Us

Privacy questions or requests: support@briviumapp.com
Brivium, Inc. — Charlotte, North Carolina, United States