Privacy Policy
Last updated: September 3, 2026Briefr ("Briefr," "we," "us") builds a daily email briefing by connecting to mailboxes you choose to link — Gmail, Microsoft/Outlook, and any IMAP account, including Yahoo. This policy explains what we access, why, and how you stay in control.
1. What We Access
When you connect a mailbox, Briefr requests read access to messages from roughly the last 24 hours, and — only when you explicitly send a reply through the app — the ability to send mail on your behalf. Specifically, we access:
- Message metadata (sender, recipients, subject, timestamps) needed to sort mail into Needs Reply, Updates & FYI, and Noise.
- Message body content, used only to generate a one-line summary and to determine the correct category.
- Your corrections (e.g., re-categorizing a sender), stored so the same decision doesn't need to be repeated.
- Basic account identifiers (email address, provider) needed to keep your connected mailboxes in sync.
We do not read email older than what's needed to build your daily briefing, and we do not access folders or labels beyond your primary mail unless you explicitly configure Briefr to do so.
2. Why We Access It
Every piece of data listed above exists to power a single, user-facing feature: generating your daily digest and remembering the decisions you've already made about your mail, so you aren't asked to re-triage the same message twice. We do not use your email data for any purpose beyond providing and improving this feature.
3. Google API Services — Limited Use Disclosure
Briefr's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically: data obtained via the Gmail API is not used for serving advertisements of any kind; is not transferred to third parties except where necessary to provide and improve Briefr's core, user-facing feature (the daily briefing) or to comply with applicable law; and is not used, in any form, for purposes unrelated to providing or improving that user-facing feature. Human review of Gmail data is limited to what's necessary for security, legal compliance, or with your explicit consent, and email content is never used to train general-purpose AI models — only to generate your own digest.
4. What We Never Do
- We never sell your email data or content to any third party.
- We never use your email content to serve ads, in Briefr or elsewhere.
- We never send a reply, archive, delete, or otherwise act on your mailbox without you tapping send or confirming the action yourself.
- We never flag a message you were only cc'd or bcc'd on as requiring your reply — this is enforced in how Briefr classifies mail, not left to chance.
5. Third-Party Processors
Briefr uses a small number of infrastructure and AI-model providers strictly to generate summaries and classifications on our behalf. These providers process data under contractual terms that prohibit them from using it for their own purposes, including model training beyond what's needed to return a result to Briefr, and prohibit any onward sale or advertising use.
6. Data Retention
We retain the minimum needed to keep your briefing coherent day to day: recent message metadata and summaries (rolling window), plus your categorization decisions and preferences, which persist so Briefr keeps "remembering" them. Full message bodies are not retained longer than needed to generate your digest.
7. Account & Data Deletion
You can disconnect any mailbox at any time from within the app's Accounts settings — this immediately revokes Briefr's access token with that provider. To delete your Briefr account and all associated data entirely, including stored summaries and learned preferences:
- Use the "Delete Account" option in the app's Settings, or
- Email privacy@mybriefr.com from your registered address with the subject "Delete my data" — we'll confirm deletion within 30 days.
You can also revoke Briefr's access directly from your provider at any time — for Google accounts, via Google Account Permissions.
8. Security
Access tokens are encrypted at rest and in transit. We use industry-standard OAuth flows for Gmail and Microsoft accounts rather than storing your password, and IMAP credentials are encrypted using the same standard.
9. Changes to This Policy
If this policy changes materially, we'll notify users in-app before the change takes effect. Continued use of Briefr after a change means you accept the updated policy.
10. Contact
Questions about this policy or how your data is handled: privacy@mybriefr.com.