Brizka Privacy Policy

Last updated: 8 October 2026

Também disponível em português europeu: Política de Privacidade do Brizka

Brizka is a free Chrome extension that uses AI to summarize YouTube videos. This policy covers the Brizka extension, the server it talks to (api.brizka.com) and this website (brizka.com). It explains what data they use and why, who else receives it, how long it is kept, and what you can do about it.

The short version

  • Brizka sends a video to us only when you ask it to summarize that video.
  • To write a summary, Brizka sends the video's ID, length and captions to our server. Our server passes the captions to our AI provider, OpenAI, unless someone has already summarized that video with the same settings. We don't store the captions.
  • Brizka doesn't collect your browsing history or your YouTube watch history.
  • To apply the free limits, we use a random install ID and a code made from your IP address that changes every day.
  • No ads. No analytics or tracking tools. We never sell your data.
  • Your first 2 summaries need no account. After that, a free account needs only your email address.

Who we are

Brizka is provided by Karma Kai Design Studio, Lda., Incubadora da Universidade do Algarve, Campus de Gambelas, Pavilhão B1, 8005-226 Faro, Portugal, VAT number PT515218510 ("we", "us"). We are the controller of your personal data. That means we decide how it is used.

We have not appointed a Data Protection Officer, because the law doesn't require one for what we do. Mail to privacy@brizka.com reaches the people responsible for privacy at Brizka.

What Brizka does not collect

  • Your browsing history. Brizka works only on YouTube (www.youtube.com). It can't read other websites.
  • Your YouTube watch history. We receive a video only when you ask for its summary. When Brizka checks how many summaries you have left, it doesn't tell us which video you're watching.
  • Your YouTube account, cookies or passwords.
  • The title or channel of the videos you summarize. Brizka doesn't send them to us. It keeps the titles of your recent summaries on your device only (see Data stored on your device).
  • Payment details. Brizka is free and takes no payments.
  • Data for ads or tracking. Brizka has no ads, no analytics, no tracking cookies and no error-reporting tools. We don't sell personal data or use it for advertising.

What we collect, and why

When you install Brizka

A random install ID. When you install Brizka, it creates a random code and saves it on your device. The code contains nothing about you. Brizka sends it to our server in only two cases: when you ask for a summary, and when it checks how many summaries you have left. It sends the ID even when you're signed in, but then we count your summaries under your account and don't store the install ID. Without an account, we use it to count your 2 free summaries. It can single out one installation, so we treat it as personal data. Reinstalling Brizka creates a new ID.

Technical settings from our server. Brizka downloads technical settings from our server, such as where to place its card on a YouTube page. It does this when you install or update it, when Chrome starts, and when you use it if its copy is more than 6 hours old. This request carries no ID, only the version of the extension. Like every request on the internet, it also carries your IP address and browser information. Our server doesn't store or log anything about it. Cloudflare handles it like any other request (see Who receives your data). Brizka needs these settings to show its card, so it downloads them even before you agree to anything.

Before your first summary

Brizka explains what it sends and asks you to agree. It does this on the welcome page after you install it, or before your first summary. It then saves a note on your device with the date and the version of the text you agreed to. That note is never sent to us. If that text changes, Brizka shows it again and asks you to agree again. Until you agree or sign in, Brizka contacts our server only to download its technical settings.

When you ask for a summary

  1. Brizka reads the captions in your YouTube tab. These requests go from your browser to YouTube, like the YouTube player's own requests. Like the YouTube page itself, some of them include your YouTube cookies, but they go only to YouTube. To get the captions, Brizka may switch captions on for a moment or briefly open YouTube's transcript panel. We never receive your YouTube cookies or account details. YouTube handles these requests under Google's own privacy policy.
  2. Brizka sends a request to our server (api.brizka.com). The request contains:
    • the video's ID and its length;
    • the captions, with their timestamps;
    • the language of the captions, and how Brizka read them;
    • the summary language and length you chose;
    • your install ID and the version of the extension;
    • if you're signed in, a sign-in token that shows which account is asking. The token also contains your email address, but our server doesn't use it.
    Like every request on the internet, it also carries your IP address and basic information about your browser (the "User-Agent").
  3. Our server applies the rate limit and checks the video's length. Then it looks for a shared summary of the same video, made from the same captions with the same settings (see Shared summaries). If there is one, you get it straight away and it doesn't count toward your limit. If there isn't, our server checks your free limit and asks OpenAI to write the summary.
  4. You get the summary. Brizka saves it on your device. A new summary is also kept in our shared summaries.

Checking how many summaries you have left. Once you have agreed or signed in, Brizka asks our server how many summaries you have left. It asks when its card appears on a YouTube video page, or when you open its side panel or toolbar popup, if it last checked more than a minute ago. If a Brizka page is open at the daily reset (midnight UTC), it checks again just after. This request carries your install ID, plus your sign-in token if you're signed in. It doesn't say which video you're watching.

Your IP address

Our server uses your IP address only to prevent abuse, in two ways:

  • a rate limit of 20 summary requests a minute, and a separate limit of 20 checks of your remaining summaries a minute;
  • without an account, a cap of 6 new summaries per IP address per day. This stops one computer from getting endless free summaries by reinstalling Brizka.

Before using your IP address, our server turns it into a code. The code is a hash made from the address, a secret value and the date, so it is different each day. For an IPv4 address, the whole address is used. For an IPv6 address, only the first half is used (the part that identifies the network). The rate limit uses this code as its key, and Cloudflare keeps the rate-limit counters for us. The code is also saved in our daily usage counters, but only for new summaries without an account. Our server never stores or logs your raw IP address. We hold the secret value, though, so the code is pseudonymized rather than anonymous, and we treat it as personal data.

Two of our providers also see your IP address: Cloudflare, which runs our server and this website, and Supabase, when you sign in (see If you create an account and Who receives your data).

If you create an account

Your first 2 summaries need no account. After that, a free account gives you 3 new summaries a day. The count resets at midnight UTC, and shared summaries stay free. You sign in with your email address and a 6-digit one-time code. There is no password. To sign you in and keep you signed in, Brizka connects directly from your browser to our sign-in service, Supabase.

Supabase stores:

  • your email address and account ID;
  • when you created and confirmed your account, and when you last signed in;
  • a hash of the code you were sent (not the code itself), which stops working once it is used or expires;
  • your sign-in sessions, including the IP address and browser information used;
  • security logs of sign-in events: the time, the account, the action, the IP address and browser information.

Asking for a code creates your account, even if you never enter the code. If you never enter one, we delete that account 30 days after the last code was sent.

Our server checks your sign-in token and takes only your account ID from it, to count your summaries and look up your plan. It doesn't store your email address or the token.

The emails with sign-in codes come from login@brizka.com. Cloudflare sends them for us. It receives your email address and the email itself, which contains the code, but doesn't keep a copy of the email.

Usage records

Our server keeps two kinds of record to apply the free limits:

  • Usage counters. These record how many new summaries an install ID has used in total, how many an account has used each day, and how many new summaries an IP code has received each day without an account. Each counter also records when it last changed.
  • Recent-request records. For each new summary (not shared ones), these record which install or account asked for it, and when. If you ask for the same summary again within 15 minutes (after a dropped connection, for example), it isn't counted twice. Each summary belongs to a video, so these records show which videos you asked to summarize. They also include requests that were refused because you had reached your limit. We delete them after 24 hours.

Shared summaries

When Brizka writes a new summary, we keep it. The next person who asks for the same video, with the same captions and settings, gets it straight away, and it doesn't count toward their limit. Brizka labels it "Shared summary, free".

A shared summary is stored with:

  • the video ID;
  • the summary language and length;
  • the AI model;
  • a fingerprint of the captions;
  • how often it has been reused, and when.

The fingerprint is a hash, not the captions themselves. The shared summary itself contains nothing about you. Only the recent-request records above connect it to your install or account, for 24 hours. Summaries of unlisted or private videos are stored the same way.

Server logs

For each summary request, our server writes one log line. It records:

  • the result;
  • the type of plan;
  • whether the summary was a shared one;
  • how the captions were read;
  • a rough video length;
  • the AI model;
  • whether you closed the connection early;
  • how long it took.

When our server starts writing a new summary, it also writes a shorter line with only the type of plan and a rough video length. Other log lines record technical errors.

Our server is built so that these logs don't contain your IP address, install ID, account ID, email address, video ID or captions. We keep them for up to 7 days.

When you email us

If you write to privacy@brizka.com or support@brizka.com, we use your email address and your message to reply. Messages pass through Cloudflare, which forwards them to our mailbox at Dominios.pt, in Portugal, without keeping a copy. Cloudflare keeps only a record of each message (sender, recipient, subject and delivery status) for up to 31 days. We keep your messages for 2 years.

This website

This website (brizka.com) is a set of static pages. It sets no cookies, runs no scripts, uses no analytics and loads nothing from other websites. Like every request on the internet, a visit carries your IP address and browser information to Cloudflare, which serves the website for us (see Who receives your data). Our own code doesn't log or store anything about your visit.

Data stored on your device

Brizka keeps these items in Chrome's extension storage on your device:

What Why How long
Install ID To count free summaries without an account Until you uninstall Brizka
Record of your agreement (date and version) To remember that you agreed Until you uninstall
Your settings: summary language and length, interface language, whether the card starts collapsed To remember your choices Until you change them or uninstall. If Chrome Sync is on, Chrome copies them to your Google account
Technical settings from our server, and when they were downloaded To show the card in the right place Replaced when Brizka downloads a new copy
Your sign-in session: sign-in tokens and your account details from Supabase, such as your email address and account ID To keep you signed in and show which account you're using Until you sign out or the session ends
Your last 20 summaries (video ID, video title, settings, summary, whether it was shared, date) To show a summary again without asking our server Until newer summaries replace them, or you uninstall. Signing out doesn't remove them. They are never sent to us
Your latest usage count (and the account it belongs to), and summaries in progress To show how many summaries you have left, and to avoid making the same summary twice Until you close the browser

The captions of up to 8 recent videos stay in the YouTube tab's memory while the tab is open, so Brizka can show the transcript without reading it again. They are never saved to storage.

Brizka uses no cookies, analytics or advertising trackers. Everything it stores is needed for Brizka to work. Uninstalling Brizka removes this data from your device.

Purpose Legal basis (GDPR)
Writing and showing summaries; your account and sign-in Performance of a contract: providing the summaries and account you ask for (Art. 6(1)(b))
Free limits, rate limits, abuse prevention and running this website: the install ID, the IP code, usage and recent-request records, and server, network and security logs Legitimate interests: keeping a free service available, fair and secure (Art. 6(1)(f))
Shared summaries Legitimate interests: faster summaries at lower cost, free for whoever asks next (Art. 6(1)(f))
Answering your emails Contract, or legitimate interests if you're not a user (Art. 6(1)(b) or (f))
Complying with the law, such as requests from authorities Legal obligation (Art. 6(1)(c))

The "Agree" step before your first summary makes sure you know what is sent before anything leaves your browser. It is not the legal basis for this processing. You can stop at any time: just stop asking for summaries, or uninstall Brizka. If we ever ask for your consent to something, you can withdraw it at any time, as easily as you gave it.

Who receives your data

We share data only with service providers that process it for us, on our instructions:

  • Cloudflare, Inc. runs our server at api.brizka.com, this website, and the network that requests pass through. It sees your IP address and the details of each request. It applies our rate limits and stores our server logs. It sends the emails with sign-in codes, so it receives your email address and the code. It also forwards email sent to privacy@brizka.com and support@brizka.com, without keeping a copy.
  • Supabase (Supabase Pte. Ltd.) provides our sign-in service and our database. The database is in Frankfurt, Germany. Supabase receives your email address, IP address and browser information when you sign in. It also keeps technical logs of our server's database requests. These can include your install ID or account ID and which summary was requested.
  • OpenAI (OpenAI Ireland Ltd) writes the summaries. It is our only AI provider.
  • Dominios.pt (DMNS – DOMINIOS, S.A.) hosts the mailbox where your emails to us arrive and from which we reply. Its servers are in Portugal.

What OpenAI receives. OpenAI receives only the captions with timestamps, the video's length, and instructions (the summary language and length). The captions include whatever is said in the video. OpenAI doesn't receive the video ID, title or channel, or your install ID, account ID, email address or IP address.

Under its terms with us, OpenAI doesn't use this data to train its models. OpenAI keeps API data only in its abuse-monitoring logs, for up to 30 days unless the law requires longer. Shared summaries are delivered without contacting OpenAI.

Others who handle data under their own responsibility:

  • YouTube (Google) receives the caption requests your browser sends to it.
  • Google stores your Brizka settings in your Google account if you use Chrome Sync.
  • Public authorities receive data if the law requires us to share it.

We don't sell personal data, and we don't share it for advertising.

International transfers

Our database is in the EU, in Frankfurt. Some providers may process data outside the European Economic Area, including in the United States:

  • OpenAI;
  • Cloudflare;
  • Supabase (a Singapore company with sub-processors in other countries).

We protect these transfers with the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). Where a provider is certified under the EU-US Data Privacy Framework, that also applies (Art. 45 GDPR). To get a copy of these safeguards, write to privacy@brizka.com.

How long we keep data

Data How long
Captions We don't store them. OpenAI keeps them only in its abuse-monitoring logs, for up to 30 days unless the law requires longer
Your raw IP address Our server doesn't store it. If you have an account, Supabase keeps the IP address used with your sign-in sessions and in its security logs (see below). For Cloudflare, see Cloudflare network and security data
Rate-limit counters Short-lived; they cover a 60-second window
Daily usage counters (for accounts and IP codes) 7 days after the day they count
An install ID's total count 13 months after the install's last new summary
Recent-request records 24 hours
Shared summaries Until no one has used them for 180 days, or sooner if we remove them on request
Your account (email address and account ID) Until you ask us to delete it
Accounts whose code was never entered 30 days after the last code was sent
Sign-in sessions, including their IP address and browser information Until you sign out, the session goes 90 days without use, or your account is deleted
Sign-in security logs and technical logs at Supabase Up to 7 days
Database backups Up to 7 days
Our server logs Up to 7 days
Cloudflare's records of the emails it sends and forwards for us, such as the sender, recipient, subject and delivery status Up to 31 days. If a sign-in email to you can't be delivered or you mark it as spam, Cloudflare may put your address on a suppression list and stop sending to it. After most delivery problems, the address stays on the list for 24 hours to 7 days. If the address doesn't exist, delivery keeps failing or you marked the email as spam, it stays until we remove it, which we do if you ask us or delete your account
Cloudflare network and security data For the limited periods Cloudflare sets for operating and securing its network, as described in Cloudflare's privacy policy
Emails you send us 2 years
Data on your device See Data stored on your device

We keep data longer only if the law requires it, or if we need it to establish, exercise or defend a legal claim.

Your rights

Under the GDPR, you can ask us to:

  • give you a copy of your personal data (access);
  • correct it (rectification);
  • delete it, including your account (erasure);
  • limit how we use it (restriction);
  • send it to you or to another service in a machine-readable format (portability).

Your right to object. You can object at any time, on grounds relating to your particular situation, to our use of your data based on legitimate interests. That covers free limits, abuse prevention, logs and shared summaries. We will then stop, unless we have compelling legitimate grounds that override your interests, rights and freedoms (such as preventing abuse), or we need the data for a legal claim.

How to make a request. Email privacy@brizka.com. If you have an account, write from your account's email address. We may send you a one-time code to confirm it's you. Requests are free. We reply within one month. If a request is complex, we may need up to two more months, and we will tell you why.

Deleting your account. Email privacy@brizka.com from your account's email address. Within one month, we delete your account and its usage counters and recent-request records, and we remove your address from Cloudflare's suppression list if it's there. Any copies in backups and logs disappear on the schedule above. Signing out in Brizka only signs you out of that browser. It doesn't delete your account.

Without an account. All we know is a random install ID, which Brizka doesn't show you, so we usually can't tell which data is yours. If you can give us information that lets us find it, we will act on your request. Uninstalling Brizka deletes everything stored on your device. The records we still hold about that install are deleted on the schedule above.

Complaints. You can complain to the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD):

  • address: Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, Portugal;
  • phone: +351 213 928 400;
  • email: geral@cnpd.pt;
  • website: www.cnpd.pt.

You can also complain to the authority in the EU country where you live or work. We'd appreciate the chance to help first, at privacy@brizka.com.

Do you have to give us data?

No law requires you to give us any data. But Brizka needs the video ID and captions to write a summary, and it needs your install ID and IP address to apply the free limits. An email address is needed only for an account, which you need after your first 2 summaries.

Automated decisions

We don't make decisions about you based solely on automated processing that have legal or similarly significant effects. Free limits are applied automatically, but all they do is cap free use.

Children

Brizka is not meant for children. You must be at least 13 years old to use it, or older if the law in your country requires it. If you think a child below that age has given us personal data, write to privacy@brizka.com and we will delete it.

Security

  • Data travels between Brizka, our server and our providers over encrypted connections (HTTPS). Emails, such as the sign-in codes and the messages you send us, are encrypted in transit whenever the other mail server supports it.
  • Only our server can access Brizka's database tables. They aren't open to the extension or to the public.
  • Our server never stores your raw IP address or the captions.
  • Your sign-in tokens are kept only on your device and by our sign-in service. Our server checks them but doesn't store them.

People who appear in videos

A summary can mention people who appear in a video or are talked about in it. That information comes from the video's captions on YouTube. To have a summary removed from our shared summaries, write to privacy@brizka.com with a link to the video. We will then delete the shared summaries of that video. Removing them doesn't stop Brizka from writing a new summary if someone asks for that video again.

Users in Brazil

If you are in Brazil, the Lei Geral de Proteção de Dados (LGPD) also applies. Our legal bases are performance of a contract (Art. 7, V) and legitimate interests (Art. 7, IX).

Under Art. 18 of the LGPD, you can ask us for:

  • confirmation that we process your data;
  • access to it;
  • correction of incomplete, inaccurate or outdated data;
  • anonymization, blocking or deletion of data that is unnecessary or excessive, or that is processed unlawfully;
  • portability;
  • information about who we share your data with;
  • where processing is based on consent: deletion of that data, information about the option not to consent, and withdrawal of consent.

You can also object to processing based on legitimate interests.

To use these rights, write to our encarregado (LGPD Art. 41), the contact for data protection under the LGPD. Our encarregado is the company itself, Karma Kai Design Studio, Lda., at privacy@brizka.com. We reply within 15 days. After contacting us, you can also petition the Agência Nacional de Proteção de Dados (ANPD) at www.gov.br/anpd.

Your data is transferred outside Brazil:

  • to the European Union, whose level of protection Brazil recognizes as adequate;
  • to other countries, including the United States, with the safeguards Art. 33 of the LGPD requires, such as standard contractual clauses.

Changes to this policy

If we change how we use your data, we will update this policy and tell you in the extension before the change takes effect.

We plan to offer a paid Pro plan later. Paddle will handle paid plans as merchant of record. Before that plan launches, we will update this policy and let you know.

The date at the top shows when this policy was last updated.

Chrome Web Store Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

We use the data Brizka collects only for its single purpose: summarizing the YouTube videos you ask for. We transfer it only:

  • to the service providers this policy describes;
  • to comply with the law;
  • to protect against abuse, fraud or security threats.

We don't use it for advertising. We never use it to judge creditworthiness or for lending.

People at Brizka don't read your data, except:

  • with your permission, for example when you ask us for help;
  • to investigate security issues or abuse;
  • to comply with the law;
  • when it is aggregated so that no one can be identified.

If the Brizka business is ever sold or merged, we will transfer your data only with your explicit consent.

Contact

Karma Kai Design Studio, Lda.
Incubadora da Universidade do Algarve
Campus de Gambelas, Pavilhão B1
8005-226 Faro, Portugal

Privacy: privacy@brizka.com
Support: support@brizka.com