Privacy Policy · Data · Responsible AI

Clear about your data. Careful by design.

This page explains what Briefable collects, how your information is used, where it is processed, who it may be shared with, and the choices you have. It also explains how artificial intelligence is used and where human review remains essential.

Effective 24 July 2026 New Zealand operated Privacy Act 2020
Privacy commitments active
Briefable privacy approach
Your connected information is used to prepare your work, not monetise it.

Briefable reads information from services you choose to connect so it can organise, summarise and prepare useful outputs for you.

Your data is not sold Not to advertisers, data brokers or any other third party.
Your content is not used to train AI models AI providers process content to produce your results under configured data protections.
You review external actions Briefable prepares drafts and suggestions. You decide what is sent, posted or actioned.
At a glance: No advertising trackers Connected services can be revoked Human approval before external action Account deletion available
Privacy, Data and Responsible AI

The policy governing Briefable and your information.

Effective date: 24 July 2026
Last updated: 24 July 2026

Briefable is operated by Steve Wilson, trading as Briefable, a sole trader based in Taranaki, New Zealand.

Questions about this policy can be sent to hello@briefable.co.nz.

Section 01

Who we are

Service Briefable, a connected AI operating assistant for solo operators and small teams.
Operator and data controller Steve Wilson, trading as Briefable.
Location Taranaki, New Zealand.
Privacy contact hello@briefable.co.nz
Websites briefable.co.nz for product information and app.briefable.co.nz for the application.

Because Briefable is operated by a sole trader, the person responsible for your information is Steve Wilson personally. There is no separate company standing between you and that responsibility.

Section 02

Our approach in plain terms

Briefable connects to accounts you already use, including your email, calendar, files and notes, and organises what is in them so you can see what matters. To do that, it has to read your information.

Three commitments govern how we handle that information:

We do not sell your data.

Not to advertisers, data brokers or anyone else.

We do not use your data to train AI models.

Your information is sent to AI providers to produce your results. Those services are configured so your content is not used to improve their models. See section 7.

Nothing leaves your accounts without you.

Briefable prepares drafts, suggestions and summaries. It does not send email, publish content or take external action unless you review it and choose to proceed. See section 7.4.

Section 03

What information we collect

3.1 Information you give us

  • Account details – your name and email address when you sign up, obtained from your Google or Microsoft account, or entered directly.
  • Settings and preferences – module choices, email signatures, brand information, follow-up intervals and similar configuration.
  • Content you enter – tasks, notes, personal items, pipeline entries, contact records and anything you type or dictate into the application.
  • Voice input – where you use voice capture, speech is converted to text in your browser using the Web Speech API. The resulting text is treated the same as typed text.

3.2 Information from services you connect

Briefable only accesses services you explicitly connect, and only with the permissions you grant. You can disconnect any service at any time in Settings.

Service What Briefable accesses Why
Gmail / Outlook Mail Message content, senders, recipients, subjects and timestamps To classify what needs a reply, extract tasks, prepare drafts and summarise your inbox
Google Calendar / Outlook Calendar Events, attendees, times, locations and response status To show your schedule, calculate focus time and prepare you for meetings
Google Drive / OneDrive / SharePoint File names and content of files matching your searches To answer questions from your own documents
Notion Page and database content in the workspace you authorise To answer questions from your knowledge base, sync tasks and read enquiries
Google Search Console and WordPress Site performance data and post metadata, where configured To provide the optional Analytics module

Briefable requests the narrowest permissions that allow these features to work. Where a permission is read-only, we request read-only.

3.3 Information collected automatically

  • Technical data – IP address, browser type and device information, collected in server logs by our hosting providers.
  • Authentication data – session tokens and access tokens for the services you connect.
  • Usage data – which features you use and when, to keep the service working and diagnose faults.

Briefable does not use advertising trackers or third-party analytics cookies on the application.

Section 04

How we use your information

We use your information to:

  • Provide the features you have enabled, including briefings, inbox classification, task extraction, meeting preparation, knowledge search, pipeline tracking and contact management
  • Authenticate you and keep your account secure
  • Send service-related messages, such as confirmation and password reset emails
  • Diagnose faults and improve reliability
  • Respond when you contact us for support
  • Meet our legal obligations

We do not use your information for advertising, profiling unrelated to the service, or any purpose you would not reasonably expect from a product that organises your working day.

Section 05

Where your information is stored

Database and uploaded files Supabase, hosted in Sydney, Australia (ap-southeast-2).
Application delivery Vercel’s global content delivery network.

Files you upload, such as business card images or brand assets, are stored in Supabase Storage in the same Sydney region.

Section 06

Who we share information with

Briefable relies on a small number of service providers to operate. Each processes information on our behalf under its own security and privacy commitments. We do not share your information with anyone else except where section 9 applies.

Provider Purpose Where processed
Supabase Database, authentication, file storage and server functions Australia (Sydney)
Vercel Application hosting and delivery Global CDN, United States
Anthropic (Claude) AI processing for classification, drafting, summarising and prioritising United States
OpenAI AI processing for image generation and text-to-speech where used United States
Google Gmail, Calendar, Drive and Search Console access where you connect them United States and global
Microsoft Outlook Mail, Calendar, OneDrive and SharePoint access where you connect them United States and global
Notion Knowledge base, task sync and enquiry access where you connect it United States
Resend Sending service emails United States
Railway Social image rendering for the optional Publish module United States
Postoria Social media scheduling for the optional Publish module United States

Overseas disclosure. Several providers are located outside New Zealand. Under Information Privacy Principle 12 of the Privacy Act 2020, we may only send your personal information overseas where the recipient is subject to comparable safeguards. We rely on the contractual protections in each provider’s data processing terms. By connecting a service and using Briefable, you acknowledge that your information will be processed in the countries listed above.

If you are not comfortable with overseas processing, Briefable is not a suitable product for you because AI processing outside New Zealand is fundamental to how it works.

Section 07

How AI is used, and its limits

7.1 What the AI does

Briefable sends your content to AI providers, primarily Anthropic’s Claude, and OpenAI for image generation and speech, to:

  • Classify emails by whether they need a reply, an action, a review or no response
  • Extract tasks from email and conversation
  • Draft replies for you to review
  • Summarise your day, inbox and pipeline
  • Answer questions from your connected knowledge sources
  • Prioritise your task list
  • Prepare context for upcoming meetings

7.2 Training

We have configured our AI provider accounts so that your content is not used to train their models. This is a setting we maintain, and we will tell you if it changes.

7.3 What AI cannot do reliably

AI output is generated by statistical models. It can be wrong, incomplete or confidently incorrect. Specifically:

  • Classifications can be wrong. An urgent email may be marked low priority, or the reverse.
  • Summaries can omit things. A briefing is not a substitute for reading your own inbox and calendar.
  • Drafts may contain errors. Always read a draft before sending it.
  • Knowledge answers may be incomplete or misinterpreted. Verify anything that matters against the source.
  • Briefable is not professional advice. It does not provide legal, financial, tax, medical or employment advice, and its output should not be treated as such.

You remain responsible for decisions you make and messages you send. Briefable is a preparation tool, not a decision-maker.

7.4 Human review before external action

Briefable is deliberately built so that nothing goes out without you seeing it first.

  • Email drafts are shown to you and sent only when you press send
  • Content in the optional Publish module passes through a manual gate before publishing
  • No feature sends, posts or publishes automatically on a schedule

This is a design principle, not a configuration option.

Section 08

Security

We take the following measures:

  • All connections use HTTPS encryption
  • Access tokens for connected services are stored encrypted and are never exposed to your browser
  • Database access is protected by row-level security, so each account can only reach its own data
  • Server functions require authentication before processing any request
  • File storage is private by default
  • Password accounts require a minimum of eight characters including upper case, lower case, digits and symbols
  • Sign-in is available through Google and Microsoft, which support their own multi-factor authentication

No system is perfectly secure. If you discover a vulnerability, please tell us at hello@briefable.co.nz rather than disclosing it publicly, and we will work with you to fix it.

In the event of a breach. If a privacy breach occurs that is likely to cause serious harm, we will notify affected users and the Office of the Privacy Commissioner as required by the Privacy Act 2020.

Section 09

When we may disclose information

We may disclose your information without your consent only where:

  • Required by New Zealand law or a lawful order
  • Necessary to prevent or lessen a serious threat to someone’s life, health or safety
  • Necessary to investigate suspected unlawful activity or a serious breach of our Terms of Use
  • Necessary to establish, exercise or defend a legal claim

We will tell you if this happens unless we are legally prevented from doing so.

Section 10

How long we keep information

Account data For as long as your account is active.
Connected service content Cached only as long as needed to provide the feature, then refreshed from the source.
Generated content Briefings, drafts, meeting preparation and similar content are kept so you can refer back to them.
After account deletion Your data is deleted within 30 days, except where we are legally required to keep records.
Server logs Retained by our providers according to their own retention periods, typically under 90 days.
Section 11

Your rights

Under the Privacy Act 2020, you have the right to:

  • Access the personal information we hold about you
  • Correct information that is wrong or incomplete
  • Complain if you believe we have breached your privacy

You can also, at any time:

  • Disconnect any connected service in Settings, which stops further access immediately
  • Delete individual records, including tasks, contacts and pipeline entries
  • Close your account by emailing hello@briefable.co.nz

We will respond to access and correction requests within 20 working days.

If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner at privacy.org.nz or call 0800 803 909.

Section 12

Revoking access to connected services

You can revoke Briefable’s access directly with the provider at any time, independently of anything you do in Briefable:

Notion Use your workspace settings under Connections.

Revoking access stops Briefable reading new information immediately. It does not delete information already stored. Use the account deletion process for that.

Section 13

Cookies

Briefable uses cookies and browser storage only to keep you signed in and remember your preferences. We do not use advertising or tracking cookies, and we do not run third-party analytics on the application.

Blocking these essential cookies will prevent sign-in from working.

Section 14

Children

Briefable is a business tool intended for adults. It is not designed for or directed at anyone under 16, and we do not knowingly collect information from children.

Section 15

Early access

Briefable is currently in early access. During this period:

  • Features may change, be added or be removed
  • The service may be unavailable at times
  • Data loss, while not expected, is possible. Keep your own records of anything critical
  • We may contact you for feedback about your experience

We will give reasonable notice of significant changes that affect how your information is handled.

Section 16

Changes to this page

We may update this page as the product changes. The effective date at the top shows when it was last revised. Where a change materially affects how we handle your information, we will notify you by email before it takes effect.

Privacy support

Have a question about your information?

Contact Briefable at hello@briefable.co.nz for an access request, correction request, account deletion or any other privacy concern.

Contact Briefable →