1. Who we are
Briefly is operated by Locryn Thomas, a sole trader based in the United Kingdom. Our contact email is hello@brieflynews.org. This policy covers both the Briefly web app at brieflynews.org and the Briefly iOS app — they share the same account and backend service.
2. What we collect
We collect the following categories of personal data:
- Account data — your name, email address, and authentication tokens, provided when you sign up. On the web this is via Google OAuth; in the iOS app it's via Google or Sign in with Apple.
- Connected source data — with your explicit permission, we read email subjects and short previews, calendar event titles and times, Notion page titles, Slack direct-message text from the last 24 hours, GitHub notification, pull request, and issue titles, and Stripe and Shopify revenue summaries (including Shopify's top-selling products). We never read full email bodies beyond a 200-character preview, and we never access attachments or passwords.
- Generated briefs — the daily summaries Briefly produces for you, stored so you can review past briefs.
- Memory notes — preferences and context you add manually or that Briefly infers from your feedback.
- iOS device and notification data — if you enable notifications in the iOS app, we store an Expo push notification token together with your device platform and device name, used solely to deliver brief notifications; this is deleted when you delete your account. The voice input offered during onboarding is your device's own keyboard dictation feature — the Briefly app itself does not record or process audio.
- Purchase data — if you subscribe through the iOS app, Apple processes your payment via in-app purchase, and RevenueCat, which manages our subscription entitlements, receives the purchase details and Briefly's internal user id — never any advertising identifiers. Web subscriptions continue to be processed by Stripe.
- Technical data — IP address, browser type, and usage logs collected automatically for security and performance.
3. How we use your data
We use your data to:
- Compose your personalised daily brief
- Store your preferences and memory so briefs improve over time
- Send you your brief and transactional emails (billing, account alerts)
- Deliver brief notifications to your iOS device, if you enable them
- Send your brief to Telegram, if you choose that delivery method
- Process payments via Stripe on the web, or via Apple in-app purchase (managed by RevenueCat) on iOS
- Monitor service health and fix bugs
4. AI processing and our sub-processors
Generating your brief requires sending a subset of your data to AI providers. Specifically, email subjects, calendar titles, and Notion page titles may be included in prompts sent to:
Neither Anthropic nor OpenAI trains on data submitted via their APIs. Standard Contractual Clauses apply to these international transfers.
Our other sub-processors include:
- Supabase — database and authentication (hosted in EU)
- Vercel — application hosting (US)
- Resend — transactional email delivery (US)
- Google — OAuth sign-in and Gmail/Calendar access (US)
- Stripe — payment processing on the web (US)
- Notion — workspace data access, with your permission (US)
- Slack — workspace message access, with your permission
- GitHub — repository notification access, with your permission
- Shopify — store revenue access, with your permission
- Nango — holds the OAuth access you grant to connected accounts (Gmail, Google Calendar, Notion, Shopify, Stripe, Slack, GitHub) and proxies our reads from them; access is revoked when you disconnect a source or delete your account
- Sentry — server-side error monitoring, which may include technical metadata such as your IP address; on the web app, Sentry also records session replay (up to 5% of sessions, and any session in which an error occurs), in production only
- PostHog — product analytics on the web app, loaded only after you accept our cookie banner; events tied to signed-in actions are linked to your account. Not used in the iOS app
- Telegram — if you choose Telegram as your delivery method, we send your brief text to your Telegram chat via the Telegram Bot API
- RevenueCat — manages iOS in-app purchase entitlements; receives your purchase details and Briefly's internal user id, never advertising identifiers
- Apple — processes iOS in-app purchases and Sign in with Apple; your subscription is billed, renewed, and cancelled under Apple's own terms
- Expo — delivers push notifications to the iOS app using your device's push token
5. Legal basis
We process your data on the following legal bases:
- Contract performance — processing your account data and connected source data is necessary to provide the Briefly service you signed up for.
- Consent — sending your data to AI providers for brief generation. You consent to this during onboarding and may withdraw consent at any time via Settings → Privacy. Withdrawing consent will pause brief generation.
- Legitimate interests — security monitoring and service improvement, where this does not override your rights.
6. Data retention
- Your preferences and memory notes are retained while your account is active.
- Generated briefs are retained for 12 months.
- Upon account deletion, all your personal data is deleted within 30 days. This cancels any active Stripe subscription, revokes every connected-account grant at Nango, deletes your iOS push token, and deletes your profile, sign-in account, and all linked data. We also attempt to delete your RevenueCat customer record.
- If you subscribed through the iOS App Store, deleting your Briefly account does not cancel that subscription — Apple does not allow apps to do this on a user's behalf. You'll need to cancel it yourself in your Apple subscription settings.
- Error-monitoring events already sent to Sentry are retained under Sentry's own retention schedule and are not affected by account deletion.
7. Your rights
Under UK GDPR, you have the right to:
- Access — request a copy of your data
- Rectification — correct inaccurate data
- Erasure — request deletion of your data
- Portability — receive your data in a machine-readable format
- Withdraw consent — stop AI processing at any time
- Complain — lodge a complaint with the ICO
Exercise any of these rights via Settings → Privacy & Data on the web, via Settings → Account & data → Delete account in the iOS app, or by emailing hello@brieflynews.org.
8. International transfers
Some of our sub-processors are based in the United States. Where personal data is transferred outside the UK, we rely on Standard Contractual Clauses approved by the UK Information Commissioner.
9. Children
Briefly is intended for users aged 16 and over. We do not knowingly collect data from anyone under 16.
10. Changes to this policy
If we make material changes, we'll notify you by email at least 30 days before the changes take effect. Continued use after that date constitutes acceptance.
11. Contact
For any privacy-related questions, email hello@brieflynews.org.
Effective date: 8 September 2026.