Privacy Policy

Privacy Policy

Effective July 31, 2026

A briefing needs to read your day to write about it. The trick is reading without hoarding. Here is exactly what we keep and what we throw away.

01The part most people skip

We do not store your calendar events, your tasks, or the names of your contacts. Briefed fetches them at briefing time, uses them to write that morning's edition, and discards them. The briefing itself is sent to your inbox; the raw material behind it does not live in our database. Everything below explains how that works and what we do keep.

02Who controls your data

Briefed operates briefed.ink and decides how the data described here is handled. For questions or requests, write to hello@briefed.ink.

03What we store

We keep the small amount needed to run an account and send a briefing on time:

  • your email address and account identifier;
  • your preferences, including delivery time, news topics, sports teams, the stock tickers you want tracked, and your theme;
  • billing records held by our payment processor, and your subscription status;
  • encrypted access tokens for the accounts you connect, plus the Apple ID and app-specific password if you connect iCloud, which works without OAuth;
  • a lightweight delivery log for each briefing (the date, whether it sent, and any error) so we can tell whether your morning edition went out.

04What we deliberately do not store

This is the rule the product is built around. Briefed fetches the following at the moment it writes your briefing, passes it through the editorial layer, and discards it. None of it is written to our database:

  • your calendar events;
  • your task names and task content;
  • the names of your contacts. We read birthdays so a briefing can note "Sarah's birthday Saturday," but we do not keep the underlying contact list.

The day's news, weather, sport, and market figures come from public feeds and are not personal to you. They are not stored against your account either.

05Accounts you connect

You choose what Briefed reads. Each connection is read-only and you can revoke it at any time from your settings or from the provider directly.

Google

With your permission we request read-only access to your Google Calendar and to your Google Contacts. Calendar access lets the briefing frame your day. Contacts access reads names and birthdays, which is what lets a briefing say “Sarah's birthday Saturday” rather than reciting a date with nobody attached to it. We never write to either account, and we ask for the narrowest scopes that make the feature work.

Todoist

With your permission we request read-only access to your Todoist tasks so the briefing can reflect what is due. We never add, complete, or change tasks.

iCloud

Apple does not offer an OAuth connection for calendars and reminders, so iCloud works differently from the two above. You give us your Apple ID and an app-specific password that you generate at appleid.apple.com and can revoke there at any moment. We store both, encrypted, and use them only to read the calendars and reminder lists you picked. An app-specific password is narrower than your real Apple ID password, and revoking it in your Apple account cuts our access immediately, whatever we have stored.

Linear

If you connect Linear, the briefing can reflect what is assigned to you. Being precise about the scope, because it is the one exception to the sentence below: Linear offers a single account-wide read permission rather than an issues-only one, so that is what we request, and we use it to list your teams and read your issues. We never create, close, or change anything.

Briefed's use of information from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

06How we protect the keys to your accounts

The access tokens that let Briefed read your connected accounts are encrypted at rest with AES-256-GCM before they touch our database, and decrypted only at the moment a briefing is being built. The same applies to the Apple ID and app-specific password behind an iCloud connection: both are encrypted, never one and not the other. The encryption key lives on the server, never in the database, and tokens are never written to our logs in plain text. If you disconnect a source, its stored credentials are deleted outright rather than flagged as unused.

California law has a specific name for credentials that grant access to an account: sensitive personal information. The iCloud app-specific password is exactly that, so we should be plain about it. We use it for one purpose, which is reading the calendars and reminder lists you selected, and for nothing else. We do not sell it, share it, or use it to infer anything about you. Because that single use is what the service needs to function, the right to limit how sensitive information is used does not add anything here. Disconnecting iCloud deletes it, and revoking the password at appleid.apple.com stops it working wherever it sits.

07Where your day goes when we write about it

Section 04 says your calendar events, tasks, and contact names pass through the editorial layer. This is what that means, stated plainly, because it is the one part of Briefed you cannot infer from the rest of this page.

To write your briefing, we assemble that morning's material into a prompt and send it to Anthropic, whose Claude model does the writing. Your calendar events, your task titles, and the contact names behind a birthday line are in that prompt. There is no way to have an edited briefing without a writer reading the day first.

What we can tell you about it: Anthropic does not use content sent through its API to train its models, we send only the material needed for that day's edition, and none of it is written to our database. Your name and email address are not part of the prompt. The one caveat worth stating: while you are still on the page, a rendered preview can sit in server memory for about five minutes so a reload does not rebuild it. That is memory, not storage, and it is gone long before the next edition. If this is not a trade you want to make, disconnecting a source stops that source's data being sent, and closing your account stops all of it.

08The companies that see your data

Briefed is a small operation that leans on a few trusted providers. Each one sees only the data it needs to do its job:

  • Clerk, for sign-in and account management. Privacy policy (opens in a new tab).
  • Cloudflare, whose Turnstile check runs on Clerk's sign-up form to keep bots out. It sees your IP address at that one moment and nowhere else on the site. Listed here rather than folded into the Clerk line above, because a list that reads as complete should be complete. Privacy policy (opens in a new tab).
  • Stripe, for payments and billing. We never see your full card number. Privacy policy (opens in a new tab).
  • Resend, for delivery of your briefings and account emails. Privacy policy (opens in a new tab).
  • Anthropic, whose Claude model writes the editorial layer of your briefing. The content sent for writing is not used to train their models. Privacy policy (opens in a new tab).
  • PostHog, for product analytics, in two lanes worth keeping apart. In your browser it never loads at all for readers in Europe, as the Cookie Notice explains. From our own servers it also records the operational events in section 09, for everyone, against your account identifier rather than your name or email. Privacy policy (opens in a new tab).
  • Upstash, the key-value store behind rate limiting, a small cache of sports fixtures, and the heartbeat that tells us the nightly job is alive. The rate limiters key on whichever identifier fits the thing being limited: a visitor IP address on the public forms, your account identifier once you are signed in, a one-way hash of the Apple ID on the iCloud connect form, and on a couple of internal routes no identifier at all. These are counters, not records, and the longest lives a day. Privacy policy (opens in a new tab).
  • Linear, where product feedback you send us becomes a tracked issue. What you wrote, your account identifier, and your browser's full user-agent string go with it, so we can reproduce the problem. Linear is also a source you can connect, which is a separate thing covered in section 05. Privacy policy (opens in a new tab).
  • Neon, the Postgres database that holds the account data listed above. Privacy policy (opens in a new tab).
  • Vercel, which hosts and delivers the site, and whose Web Analytics and Speed Insights measure how pages perform. Neither writes a cookie, and both follow the same regional switch as PostHog above, so neither loads for readers in Europe. Privacy policy (opens in a new tab).

Where the facts come from, which is a different question

The news, weather, sport, and market figures in your briefing come from outside sources: the New York Times, the Guardian, Open-Meteo, Finnhub, and Football-Data. They are not on the list above, and the distinction is worth drawing. We query them from our own servers, on your behalf. They receive the question, never your identity, and they have no idea who it was asked for. Which publications and feeds we draw on is an editorial matter rather than a privacy one, so it lives in the Terms of Service.

This list is current as of the effective date at the top of this page. If we add a provider that handles your personal data, we will add it here and move that date.

10How long we keep things

Account data lives for as long as your account does. The day's calendar, task, and contact data is discarded as soon as the briefing is written, so there is nothing to retain. When you close your account, we delete or anonymise your account data within a reasonable period, except where we are required to keep a record. Billing history is one example, since tax rules oblige us to hold it.

One detail we would rather name than have you discover. If you joined the early-access list before creating an account, that email address sits in a separate signup list. Closing your account removes that entry as well. The one case where it does not: if we had recorded the account's address as unverified, the signup entry stays where it is, because an address we could not tie to you is one that could be used to remove somebody else's. Write to us and we will sort it out by hand.

11Your rights

Depending on where you live, you have some or all of these rights over your data:

  • Access and export. Ask for a copy of the account data we hold about you.
  • Correction. Fix anything inaccurate, much of which you can edit yourself in settings.
  • Deletion. Close your account and have your data removed.
  • Opt-out. Disconnect any source, or stop the briefings, without losing the rest of your account.

To exercise any of these, write to hello@briefed.ink. We will not charge you or make you jump through hoops, and we will not sell your data to anyone, ever.

Most of this you can do yourself, without asking us. Settings has a button that downloads everything we hold about you as a single file, and a button that closes the account and removes it. Correction and opt-out are settings too. Write to the address above for anything those do not cover, or if one of them did not do what you needed: we answer within thirty days, and sooner than that in practice. If you are in California, we will acknowledge your request within ten business days and answer within forty-five.

12Cookies

No advertising cookies, anywhere. The signed-in app uses what it needs to keep you logged in, and product analytics run everywhere except Europe, where they are switched off rather than consented to. The full account is in our Cookie Notice.

13Where your data lives

Briefed and its providers are based in the United States, so your data is processed there. If you are in a region with stricter transfer rules, the providers above use standard safeguards, such as the European Commission's standard contractual clauses, to cover the transfer.

14Changes to this policy

When we change how we handle your data, we update the effective date above and, for anything material, tell you by email or in the app before it takes effect.

15Talk to us

Privacy questions and requests go to hello@briefed.ink.