Privacy & Cookie Statement
What Brixus does with your personal data, why, who else touches it, and what you can ask us to do about it.
1. Who we are
Brixus is a platform for turning documents into interactive books. The controller for the personal data described here is:
- Brixus
- Middenhof 97
- 1354 EK Almere, the Netherlands
- Email: k.t.tarhan@brixus.eu
We have not appointed a Data Protection Officer. We are not required to: we are a small organisation, and our core activity is not large-scale monitoring or large-scale processing of special categories of data. Privacy questions go to the address above and are handled by us directly.
2. What this statement covers
This statement applies to the Brixus marketing website at brixus.eu and to the Brixus application at app.brixus.eu. Both are operated by us and report into the same systems.
It does not cover third-party websites you reach from ours, or content that other Brixus users publish. If you buy a book from a creator on our marketplace, we are the controller for the account and transaction data described here; the creator does not receive your payment details.
3. What we collect
Account data
When you register we store your first name, last name and email address, and either a hashed password or, if you sign in with Google, the Google account identifier, email address, name and profile picture URL that Google returns. We also store whether you have opted in to marketing emails, and the dates your account was created and last updated.
Content you upload and create
Documents you upload for book generation (for example PDF, Word or slide files), the books, chapters, pages, questions, key terms, mind maps and images generated from them or written by you, and any edits you or your collaborators make. If you upload a document containing personal data, that data is processed as part of your content — think before uploading material about identifiable people.
Learning activity
Your answers to questions, page-by-page reading progress, flashcard review history and scheduling, practice session results, and feedback you submit on a page or on the platform.
Collaboration and community data
Book collaborators and their permissions, invitations you send or receive (including the invited email address), community memberships and roles.
Payment and marketplace data
Card details are entered directly with our payment provider Stripe and never reach our servers. We store the record of what you bought, when, for how much, the resulting invoices and tax data, your credit balance and the ledger of credit movements.
If you earn money as a creator, we additionally store the payout details you provide: account holder name, IBAN, BIC and country. The IBAN is stored so we can pay you; in the interface we only ever display the last four digits.
Technical and diagnostic data
Our servers and monitoring (Azure Application Insights) record IP address, browser and device information, request paths, timestamps and error traces. This is how we keep the service running, investigate faults and detect abuse.
Analytics data
Only if you accept analytics cookies. See section 5.
4. Why we use it, and on what legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Creating and securing your account, signing you in | Account data, technical data | Performance of a contract |
| Generating, storing, editing and publishing your books | Uploaded documents, content, collaboration data | Performance of a contract |
| Tracking your progress, flashcards and practice results | Learning activity | Performance of a contract |
| Processing purchases, credits, creator payouts and VAT | Payment and marketplace data | Performance of a contract, and legal obligation for invoicing and tax records |
| Service emails: verification, password reset, invitations, receipts | Account data | Performance of a contract |
| Keeping the platform available, debugging, preventing abuse and fraud | Technical and diagnostic data | Legitimate interests — running a secure, working service |
| Understanding how the site and app are used, so we can improve them | Analytics data | Consent |
| Sending product news and marketing emails | Account data | Consent — withdrawable at any time |
Where we rely on legitimate interests, we have weighed those interests against your privacy and concluded that the processing is limited to what a user would reasonably expect from a hosted service. You can object to that processing — see section 10.
5. Cookies and similar technologies
We use a small number of cookies and browser storage entries. Nothing that is not strictly necessary is set before you accept it in the banner.
Strictly necessary — always active
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
refreshToken | HttpOnly cookie | Keeps you signed in to app.brixus.eu without re-entering your password | 30 days |
brixus-cookie-consent | Local storage | Remembers your answer to the cookie banner so we stop asking | Until you clear it |
preferred-theme | Local storage | Remembers light or dark mode | Until you clear it |
These do not require consent: without them you could not stay signed in, and we could not honour the choice you just made in the banner.
Analytics — only after you accept
| Name | Set by | Purpose | Lifetime |
|---|---|---|---|
_ga | Google Analytics 4 | Distinguishes one browser from another so visits can be counted | 2 years |
_ga_<container id> | Google Analytics 4 | Maintains session state | 2 years |
We run Google Analytics in Consent Mode with every storage type denied by default. Until you press Accept, Google receives only cookieless signals with no identifier that can be tied back to you. If you decline, it stays that way. We do not use advertising cookies, we have not enabled Google Signals, and we do not sell or share your data with advertisers.
Changing your mind: clear your browser storage for the site and the banner will appear again, or email us and we will confirm what we hold. Because browser storage is per-domain, your choice on brixus.eu and your choice on app.brixus.eu are recorded separately.
6. AI processing of your content
Generating a book means sending the document you uploaded, and the text of your book, to AI providers acting on our behalf:
- OpenAI — book and page generation. Processed via the OpenAI API in the United States.
- Amazon Web Services (Bedrock) — question generation, using an Amazon Nova model in the eu-west-1 (Ireland) region.
Both providers act as processors under agreements that prohibit them from using content submitted through their APIs to train their models. Content is sent for the purpose of producing your output and is not used to build a general model of anyone's material.
AI output can be wrong. We do not make automated decisions that produce legal effects for you or similarly significantly affect you within the meaning of Article 22 GDPR.
7. Who else processes your data
We work with the following processors and service providers:
| Provider | What for | Where |
|---|---|---|
| Microsoft Azure | Hosting of both brixus.eu and app.brixus.eu, database, file storage, monitoring and diagnostics | European Union |
| OpenAI | AI book and page generation | United States |
| Amazon Web Services | AI question generation (Bedrock) | Ireland (eu-west-1) |
| Stripe | Payments, payouts, invoicing and tax calculation | United States and European Union |
| Resend | Transactional email delivery | United States |
| Sign in with Google; Google Analytics, only with your consent | United States and European Union |
We also disclose data where the law requires it — for example to tax authorities, or in response to a valid order from a competent authority. We do not sell personal data.
8. Transfers outside the EEA
Some of the providers above process data in the United States. Those transfers are covered by the European Commission's Standard Contractual Clauses, and where the provider is certified, by the EU–US Data Privacy Framework. You can ask us for a copy of the safeguards that apply to a specific transfer.
9. How long we keep it
- Account: for as long as your account exists. Deleting your account revokes your access immediately and anonymises your identity record on the spot — your name, email address, profile picture and any linked Google identifier are overwritten and cannot be recovered.
- Content you created: deleted or irreversibly anonymised within 30 days of account deletion, except where the next two points apply.
- Books you have published: if you have sold or published a book, we may need to keep the published content available to the people who bought it. Your name is removed from it on request where we are not obliged to keep the attribution.
- Invoices, payment and tax records: seven years, as required by Dutch tax law.
- Payout bank details: until you remove them or close your account, then within the tax retention period above where they form part of a payment record.
- Diagnostic logs: up to 90 days.
- Analytics data: 14 months in Google Analytics.
10. Your rights
Under the GDPR you can ask us to:
- confirm what personal data we hold about you, and give you a copy (access);
- correct data that is wrong or incomplete (rectification);
- delete your data (erasure), where we have no overriding obligation to keep it;
- pause processing while a dispute is resolved (restriction);
- hand over the data you gave us in a machine-readable form (portability);
- stop processing based on legitimate interests (objection);
- withdraw a consent you gave, at any time, without affecting what happened before you withdrew it.
Write to k.t.tarhan@brixus.eu. We answer within one month. We may ask you to confirm your identity first, so that we do not hand your data to someone else.
If you are not satisfied with how we handle it, you can complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens , or to the authority in your own EU country of residence.
11. Security
Traffic to and from Brixus is encrypted with TLS. Passwords are stored hashed, never in readable form. Session tokens are short-lived and the long-lived refresh token is held in an HttpOnly cookie that JavaScript cannot read. Access to production systems is limited to people who need it. No system is perfectly secure; if a breach occurs that is likely to put your rights at risk, we will tell you and the Autoriteit Persoonsgegevens as required by law.
12. Children
Brixus is not directed at children under 16, and we do not knowingly create accounts for them. In the Netherlands, 16 is the age at which a person can consent to online services on their own. If you are an educator using Brixus with pupils under 16, you are responsible for the legal basis covering those pupils; get in touch and we will work out the right arrangement. If you believe a child has given us personal data, contact us and we will delete it.
13. Changes to this statement
We update this statement when our processing changes. The date at the top always reflects the current version. If a change materially affects how we use your data, we will tell account holders by email before it takes effect.
14. Contact
Questions, requests or complaints go to k.t.tarhan@brixus.eu, or by post to Brixus, Middenhof 97, 1354 EK Almere, the Netherlands.