Legal
Privacy Policy
Last updated: 27 September 2026
The short version
- We only ask for read-only access to Gmail and Google Calendar, and only use it to build your briefing.
- Raw email content is read when your brief is generated and then discarded. It is never stored.
- We never sell your data, never use it for advertising, and never use it to train general-purpose AI models.
- You can disconnect DailyBrief from your Google account at any time and ask us to delete everything.
01Who we are
DailyBrief (“DailyBrief”, “we”, “us”) is a web application that connects to your Gmail and Google Calendar and prepares a prioritised morning briefing: what needs your attention, why it matters, and a suggested next step. This policy explains what information we collect, how we use it, and the choices you have. It applies to the DailyBrief website and web application.
02Information we collect
From your Google account when you sign in
- Basic profile: your name, email address, profile picture and Google account ID (via the
openid,emailandprofilepermissions). - Access credentials: the OAuth access and refresh tokens Google issues to us, their expiry time and the list of permissions you granted. These let us prepare your briefing each morning without asking you to sign in again. They are stored on our servers only and are never sent to your browser.
Gmail data (read-only, gmail.readonly)
- Message metadata such as sender, recipients, subject line, dates and thread information. On your first briefing this covers emails received in the last 30 days only; after that, only messages that arrived since your previous briefing.
- Full message content only for a small number of messages (up to 20 per briefing) that look potentially urgent, so they can be summarised accurately.
- We cannot send, delete, move or modify your email. Our access is read-only.
Google Calendar data (read-only, calendar.readonly)
- Events in your upcoming window (the next 48 hours by default, up to 7 days if you choose), including titles, times, descriptions and attendees, so we can flag upcoming meetings and prepare meeting prep notes.
- We cannot create, edit or delete your calendar events.
Information you provide or generate in DailyBrief
- Your settings, such as delivery time, notification preference and a list of important contacts.
- How you respond to briefing items (for example acting on or dismissing an item). We use this to adjust how items are ranked for you.
Technical information
- Standard server logs (such as IP address, browser type, timestamps and the pages or endpoints requested) used to keep the service secure and working.
- The cookies described in the Cookies section.
03How we use your information
We use the information above only to provide and improve the features you use in DailyBrief:
- Ranking your emails, meetings and tasks and organising them into your daily briefing.
- Writing short summaries, meeting prep notes and suggested draft replies for your review.
- Personalising the ranking to your behaviour over time.
- Delivering your briefing notification at the time you choose.
- Keeping the service secure, preventing abuse and fixing problems.
We do not sell your information, use it for advertising, build advertising profiles, or use it to train general-purpose AI or machine-learning models.
04AI processing
To classify and summarise items, the relevant parts of your emails and calendar events (for example a subject line, a message excerpt or meeting details) are sent to a third-party large language model provider through its API, at the moment your briefing is generated. We use the provider only as a processor on our behalf, under terms that do not permit it to use this data to train its models. The output (for example a one-line summary) is returned to us and the provider is not permitted to use your data for any other purpose.
05What we store and for how long
- Raw email content is not stored. It is read from Gmail at processing time and discarded once your items have been classified and summarised.
- What we do store: your account details and Google access credentials, your settings, and the outputs DailyBrief creates for you: briefing summaries, meeting prep notes, draft replies awaiting your approval, and the ranking history used to personalise your briefings.
- We keep this information while your account is active. If you ask us to delete your account, we delete your data within 30 days, except where we are legally required to keep something.
07Google API Services: Limited Use
DailyBrief's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We only use Google user data to provide and improve the user-facing features of DailyBrief.
- We do not transfer Google user data to others except as needed to provide those features, to comply with the law, or as part of a merger or acquisition.
- We do not use Google user data for serving advertisements.
- People do not read your Google user data unless you give us permission for specific messages, it is necessary for security purposes (such as investigating abuse), or it is required by law.
- We do not use Google user data to develop, improve or train generalised AI or machine-learning models.
09How we protect your information
- All traffic between your browser, our servers and our database is encrypted with HTTPS/TLS.
- Google access credentials stay on our servers and are never exposed to your browser.
- We request read-only Google permissions only, and access to our database is restricted.
- No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you as required by law.
10Your choices and rights
- Disconnect Google at any time from your Google Account permissions page. DailyBrief will immediately lose access to your Gmail and Calendar.
- Delete your account and data by emailing contact@dailybrief.com. We will confirm once it is done.
- Access or correct your information by contacting us. Depending on where you live, you may have additional rights under local data-protection laws, which we will honour.
11Children
DailyBrief is not intended for children under 13, and we do not knowingly collect information from them. If you believe a child has provided us with information, contact us and we will delete it.
12Changes to this policy
We may update this policy from time to time. We will change the “Last updated” date above and, for significant changes, let you know in the app or by email before they take effect.
13Contact us
Questions or requests about your privacy? Email us at contact@dailybrief.com.