Brev.

Last updated 31 July 2026

Privacy policy

Who is the data controller?

Brev is operated by Thomas J.R. Marthinsen, editor.

For privacy and GDPR questions: use the privacy request form, or contact us at the email address listed on sendbrev.eu when the service is live.

What is Brev?

Brev is a platform for writing and sending newsletters. We collect what is needed to run the service, send email on behalf of writers, and show simple statistics — no more.

Who does this policy apply to?

  • Writers who request an invitation, create an account and use the dashboard.
  • Readers who subscribe to a newsletter via a writer's archive page.
  • Visitors to public pages (front page, Readfest, About, etc.).

What data do we process?

Writers: email address, password (hashed via Supabase Auth), publication and sender name, postal address in outgoing email, optional welcome and farewell text, country code (ISO, e.g. «NO») set at first login, technical logs at providers.

Readers: email address, status (awaiting confirmation / active / unsubscribed), time of signup and confirmation, unique tokens for confirmation and unsubscribe.

When you are a reader: By signing up on a writer's archive page you consent to receive email. On confirmation (double opt-in via link in email) you also consent to simple statistics in sendings — see the next section. You get an explanation in the confirmation email and can read more here before you confirm.

Statistics (when a writer sends a letter):

  • Opens: an invisible 1×1 image (technical «pixel») in the email may register that the message was opened. It gives the writer a human number («X people opened») and, for each sending, an overview of which subscribers have opened and who has not — not a marketing «open rate» dashboard.
  • Clicks: links in the letter may route via our server so we count clicks (number and which URLs).
  • Country code: on open and click we store country code (e.g. «NO») — not full IP address.
  • Inaccuracy: some email clients (especially Apple Mail and others with mail privacy) do not load images or mask opens. The number the writer sees may then be lower than those who actually read.

Writers: on your account you see aggregated statistics for your own sendings, and for each sent letter you can see which subscribers opened it (same level as per-reader clicks). When registering you accept the terms and this policy, including that sendings you send may include tracking as described above.

Legal basis

  • Contract / use of the service — for writers with an account.
  • Consent — for readers who confirm their email address (double opt-in), including simple statistics (opens and clicks) as described above.
  • Contract / use of the service — for writers with an account (incl. statistics for own sendings).
  • Legitimate interest — secure operation and abuse prevention.
  • Legal obligation — where Norwegian law requires it (e.g. postal address in commercial email).

Sub-processors and storage

ServicePurposeCompanyData typically in
SupabaseDatabase, loginSupabase Inc. (USA)EU (Frankfurt)
VercelWebsite and APIVercel Inc. (USA)EU (Frankfurt)
ResendEmail deliveryResend Inc. (USA)Send from EU region; account/logs may be in USA

We aim to place code, functionality and storage with providers based in the EU — database and app run in Frankfurt, and email is sent from the EU region where possible.

Several partners are American companies. Transfer outside the EEA uses standard data-processing agreements and SCCs where required. We do not promise complete, impenetrable data sovereignty — but we choose the EU where we can. More about the machinery behind Brev.

How long do we keep data?

As long as the account or subscription is active. When a user or publication is deleted, related data in our database is deleted. Email providers may have their own retention rules for technical logs.

Your rights

You may request access, rectification, erasure, restriction of processing and data portability where GDPR gives you the right.

Use the privacy request form — provide the email address we should look up, and what you want. We respond within GDPR deadlines (normally within one month).

You may also complain to the Norwegian Data Protection Authority.

Cookies

We use necessary cookies for login (Supabase Auth). We do not set advertising or tracking cookies on public pages.

Changes

We update this policy when the product changes significantly. The date at the top shows the last revision.