Legal Effective 01 April 2026 · Last updated 16 September 2026

Privacy Policy

Your briefing is built from your mail and calendar, so this policy matters. The short version: read-only access, nothing stored after your briefing is produced, nothing sold, nothing used to train AI models and you can revoke access at any time.

Briefly Daily AI ("Briefly Daily", "we", "us", or "our") is operated by Jarrod Blaine Ward, a sole trader (ABN 13 205 484 161) based in Paddington, Queensland, Australia, trading as Briefly Daily AI. We provide a personalised daily briefing delivered by email, generated from your email and calendar data at Google (Gmail and Google Calendar) or Microsoft (Outlook mail and calendar), depending on which account you connect.

This Privacy Policy explains what personal information we collect, how we use and share it, how we protect it, and the choices and rights you have. It applies to our website, app, and services (together, the "Services"). We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and, where applicable, other data protection laws.

If you do not agree with this policy, please do not use the Services.

01

Information we collect

1.1 Account and identity information

When you sign up or sign in with Google or Microsoft, we receive your name, email address, and the profile identifier issued by that provider.

Google account data (read-only). With your explicit consent through Google's OAuth screen, we access:

Gmail gmail.readonly

We read your inbox to identify and summarise your important recent emails inside your daily briefing. We do not send, compose, modify, label, or delete anything in your Gmail.

Google Calendar calendar.readonly

We read your calendar events to include your schedule context in your briefing. We do not create, modify, or delete events.

Microsoft account data (read-only). If you connect a Microsoft account instead of, or as well as, Google, then with your explicit consent through Microsoft's consent screen we access:

Outlook mail Mail.Read

We read your mailbox to identify and summarise your important recent emails inside your daily briefing. We do not send, compose, modify, or delete anything in your mailbox.

Outlook calendar Calendars.Read

We read your calendar events to include your schedule context in your briefing. We do not create, modify, or delete events.

Basic profile User.Read

Your name and the email address associated with your Microsoft account, so we know where to deliver your briefing.

Offline access offline_access

This is what allows Microsoft to issue the refresh token described below. Without it we could not generate your briefing on a schedule.

  • Google and Microsoft OAuth tokens. To generate your briefing on a schedule, we securely store the access and refresh tokens the provider issues, so the service can retrieve your data at your chosen delivery time. You can revoke this access at any time (see Your choices and rights).
  • Preferences. Your delivery time, briefing days, and the country and postcode you provide. We convert your postcode to approximate coordinates to include local weather in your briefing. We do not collect precise GPS location.
  • Payment information. If you subscribe, payments are processed by Stripe. We receive subscription status and limited billing metadata. We do not collect or store your full card details; Stripe handles those.
  • Technical and usage data. Standard logs such as delivery status of your briefings, timestamps, error events, and basic device or browser information needed to operate and secure the Services.
02

How we use your information

We use your information only to:

  • generate and deliver your personalised daily briefing;
  • operate, maintain, secure, and improve the Services;
  • provide customer support and respond to your requests;
  • process subscriptions and billing; and
  • send you service-related messages (for example, sign-up confirmation, password reset, and notices that your Google or Microsoft connection needs reconnecting).

We do not use your mail or calendar data for advertising, and we do not sell your personal information.

03

Google API Services: Limited Use

Briefly Daily AI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: we use Google Gmail and Calendar data only to provide and improve the user-facing daily briefing feature that you have asked us to deliver.

  • We do not transfer this data to others except as necessary to provide or improve that feature, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you.
  • We do not use this data for serving advertisements.
  • We do not allow humans to read this data unless: you give specific consent; it is necessary for security purposes (such as investigating abuse) or to comply with applicable law; or the data has been aggregated and anonymised for internal operations.
  • We do not use your Gmail or Calendar data to develop, improve, or train generalised or non-personalised artificial intelligence or machine-learning models.

The same commitments apply to data we receive from Microsoft Graph. We treat your Outlook mail and calendar data on exactly the terms set out above.

04

How your briefing is generated (AI processing)

Your briefing is generated by an AI language model provided by Anthropic (the Claude API). To create each briefing, the relevant content from your mail and calendar is sent to Anthropic's API, processed to produce your briefing, and returned to you.

We send this content solely to produce your own briefing. It is not used to train or improve any AI model. We rely on Anthropic's commercial API terms, under which inputs and outputs are not used to train Anthropic's models.

05

How we share information

We share personal information only with service providers ("sub-processors") who help us run the Services, and only as needed for them to perform their function:

Google

Source of your Gmail and Calendar data (read-only), and the service used to deliver your briefing email.

Microsoft

Source of your Outlook mail and calendar data (read-only), and the delivery service if you connect a Microsoft account.

Anthropic

AI generation of your briefing (see section 4).

Supabase

Authentication and database, hosted in the Australia (Sydney) region.

n8n Cloud

Workflow orchestration that assembles and sends your briefing.

Resend

Transactional emails such as sign-up, password reset, and reconnect reminders.

Stripe

Subscription payments and billing information. If your account is deleted this information is kept to resolve billing issues.

Tomorrow.io & Zippopotam.us

Weather and postcode-to-coordinates lookup for the weather section of your briefing.

Twilio

Operational alerts to our team if the system detects a delivery problem (alerts may include an affected email address).

Vercel

Hosting of the application.

We do not sell your personal information. We may disclose information if required by law, to enforce our terms, or to protect the rights, safety, and security of our users or the Services.

06

Data retention

We keep personal information only for as long as needed for the purposes in this policy.

  • Mail and calendar content is processed to generate each briefing and is not retained by us after the briefing is produced. We do not keep a stored copy of your email or calendar contents.
  • Google and Microsoft OAuth tokens are retained while your account is active and the relevant connection is in place. They are destroyed when you delete your account. You can also revoke our access at any time from your Google or Microsoft account settings, which immediately stops all further access to your mail and calendar.
  • Account, preference, and billing records are retained while your account is active and for a reasonable period afterwards to meet legal, tax, and accounting obligations.
  • Operational logs (delivery status, error events) are retained for a limited period for reliability and security.
07

Security

We use technical and organisational measures to protect your information, including encryption in transit, access controls, and storing data with reputable providers. Our database is hosted in the Australia (Sydney) region. No method of transmission or storage is completely secure, but we work to protect your information and to limit what we collect to what the briefing genuinely needs.

08

International data transfers

We are based in Australia and store core data in the Australia (Sydney) region. Some of our service providers, including Anthropic, may process data outside Australia, including in the United States. Where personal information is transferred overseas, we take reasonable steps to ensure it is handled consistently with this policy and applicable law.

09

Your choices and rights

You can:

  • Revoke our access at any time, from your Google account at myaccount.google.com/permissions or your Microsoft account at account.live.com/consent/Manage. This immediately stops all further access to your mail and calendar. Revoking access stops us using the tokens we hold; to have them destroyed, delete your account.
  • Access or correct the personal information we hold about you.
  • Delete your account and associated personal information, from your dashboard or at brieflydaily.app/delete-account. Deletion is permanent and cannot be undone.
  • Manage your delivery preferences, or unsubscribe from briefings using the link in any briefing email.

To exercise any of these rights, contact us at privacy@brieflydaily.ai. Under the Australian Privacy Principles you may also ask how we handle your information and make a complaint (see Contact). Depending on where you live, you may have additional rights under laws such as the GDPR (EU/UK) or the CCPA (California), including rights to portability, restriction, or objection; we will honour these where they apply.

10

Children

The Services are intended for adults and are not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it: privacy@brieflydaily.ai

11

Changes to this policy

We may update this policy from time to time. We will post the updated version here and revise the "Last updated" date. If changes are material, we will take reasonable steps to notify affected users.

12

Contact us

Questions, requests, or privacy complaints: privacy@brieflydaily.ai

If you are in Australia and are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Privacy questions

Briefly Daily AI — Attn: Jarrod Ward

Trading as Briefly Daily AI · Paddington, Queensland, Australia

Email: privacy@brieflydaily.ai