Clear about your data. Careful by design.
This page explains what Briefable collects, how your information is used, where it is processed, who it may be shared with, and the choices you have. It also explains how artificial intelligence is used and where human review remains essential.
Briefable reads information from services you choose to connect so it can organise, summarise and prepare useful outputs for you.
The policy governing Briefable and your information.
Effective date: 24 July 2026
Last updated: 24 July 2026
Briefable is operated by Steve Wilson, trading as Briefable, a sole trader based in Taranaki, New Zealand.
Questions about this policy can be sent to hello@briefable.co.nz.
Who we are
Because Briefable is operated by a sole trader, the person responsible for your information is Steve Wilson personally. There is no separate company standing between you and that responsibility.
Our approach in plain terms
Briefable connects to accounts you already use, including your email, calendar, files and notes, and organises what is in them so you can see what matters. To do that, it has to read your information.
Three commitments govern how we handle that information:
Not to advertisers, data brokers or anyone else.
Your information is sent to AI providers to produce your results. Those services are configured so your content is not used to improve their models. See section 7.
Briefable prepares drafts, suggestions and summaries. It does not send email, publish content or take external action unless you review it and choose to proceed. See section 7.4.
What information we collect
3.1 Information you give us
- Account details – your name and email address when you sign up, obtained from your Google or Microsoft account, or entered directly.
- Settings and preferences – module choices, email signatures, brand information, follow-up intervals and similar configuration.
- Content you enter – tasks, notes, personal items, pipeline entries, contact records and anything you type or dictate into the application.
- Voice input – where you use voice capture, speech is converted to text in your browser using the Web Speech API. The resulting text is treated the same as typed text.
3.2 Information from services you connect
Briefable only accesses services you explicitly connect, and only with the permissions you grant. You can disconnect any service at any time in Settings.
| Service | What Briefable accesses | Why |
|---|---|---|
| Gmail / Outlook Mail | Message content, senders, recipients, subjects and timestamps | To classify what needs a reply, extract tasks, prepare drafts and summarise your inbox |
| Google Calendar / Outlook Calendar | Events, attendees, times, locations and response status | To show your schedule, calculate focus time and prepare you for meetings |
| Google Drive / OneDrive / SharePoint | File names and content of files matching your searches | To answer questions from your own documents |
| Notion | Page and database content in the workspace you authorise | To answer questions from your knowledge base, sync tasks and read enquiries |
| Google Search Console and WordPress | Site performance data and post metadata, where configured | To provide the optional Analytics module |
Briefable requests the narrowest permissions that allow these features to work. Where a permission is read-only, we request read-only.
3.3 Information collected automatically
- Technical data – IP address, browser type and device information, collected in server logs by our hosting providers.
- Authentication data – session tokens and access tokens for the services you connect.
- Usage data – which features you use and when, to keep the service working and diagnose faults.
Briefable does not use advertising trackers or third-party analytics cookies on the application.
How we use your information
We use your information to:
- Provide the features you have enabled, including briefings, inbox classification, task extraction, meeting preparation, knowledge search, pipeline tracking and contact management
- Authenticate you and keep your account secure
- Send service-related messages, such as confirmation and password reset emails
- Diagnose faults and improve reliability
- Respond when you contact us for support
- Meet our legal obligations
We do not use your information for advertising, profiling unrelated to the service, or any purpose you would not reasonably expect from a product that organises your working day.
Where your information is stored
Files you upload, such as business card images or brand assets, are stored in Supabase Storage in the same Sydney region.
Who we share information with
Briefable relies on a small number of service providers to operate. Each processes information on our behalf under its own security and privacy commitments. We do not share your information with anyone else except where section 9 applies.
| Provider | Purpose | Where processed |
|---|---|---|
| Supabase | Database, authentication, file storage and server functions | Australia (Sydney) |
| Vercel | Application hosting and delivery | Global CDN, United States |
| Anthropic (Claude) | AI processing for classification, drafting, summarising and prioritising | United States |
| OpenAI | AI processing for image generation and text-to-speech where used | United States |
| Gmail, Calendar, Drive and Search Console access where you connect them | United States and global | |
| Microsoft | Outlook Mail, Calendar, OneDrive and SharePoint access where you connect them | United States and global |
| Notion | Knowledge base, task sync and enquiry access where you connect it | United States |
| Resend | Sending service emails | United States |
| Railway | Social image rendering for the optional Publish module | United States |
| Postoria | Social media scheduling for the optional Publish module | United States |
Overseas disclosure. Several providers are located outside New Zealand. Under Information Privacy Principle 12 of the Privacy Act 2020, we may only send your personal information overseas where the recipient is subject to comparable safeguards. We rely on the contractual protections in each provider’s data processing terms. By connecting a service and using Briefable, you acknowledge that your information will be processed in the countries listed above.
If you are not comfortable with overseas processing, Briefable is not a suitable product for you because AI processing outside New Zealand is fundamental to how it works.
How AI is used, and its limits
7.1 What the AI does
Briefable sends your content to AI providers, primarily Anthropic’s Claude, and OpenAI for image generation and speech, to:
- Classify emails by whether they need a reply, an action, a review or no response
- Extract tasks from email and conversation
- Draft replies for you to review
- Summarise your day, inbox and pipeline
- Answer questions from your connected knowledge sources
- Prioritise your task list
- Prepare context for upcoming meetings
7.2 Training
We have configured our AI provider accounts so that your content is not used to train their models. This is a setting we maintain, and we will tell you if it changes.
7.3 What AI cannot do reliably
AI output is generated by statistical models. It can be wrong, incomplete or confidently incorrect. Specifically:
- Classifications can be wrong. An urgent email may be marked low priority, or the reverse.
- Summaries can omit things. A briefing is not a substitute for reading your own inbox and calendar.
- Drafts may contain errors. Always read a draft before sending it.
- Knowledge answers may be incomplete or misinterpreted. Verify anything that matters against the source.
- Briefable is not professional advice. It does not provide legal, financial, tax, medical or employment advice, and its output should not be treated as such.
You remain responsible for decisions you make and messages you send. Briefable is a preparation tool, not a decision-maker.
7.4 Human review before external action
Briefable is deliberately built so that nothing goes out without you seeing it first.
- Email drafts are shown to you and sent only when you press send
- Content in the optional Publish module passes through a manual gate before publishing
- No feature sends, posts or publishes automatically on a schedule
This is a design principle, not a configuration option.
Security
We take the following measures:
- All connections use HTTPS encryption
- Access tokens for connected services are stored encrypted and are never exposed to your browser
- Database access is protected by row-level security, so each account can only reach its own data
- Server functions require authentication before processing any request
- File storage is private by default
- Password accounts require a minimum of eight characters including upper case, lower case, digits and symbols
- Sign-in is available through Google and Microsoft, which support their own multi-factor authentication
No system is perfectly secure. If you discover a vulnerability, please tell us at hello@briefable.co.nz rather than disclosing it publicly, and we will work with you to fix it.
In the event of a breach. If a privacy breach occurs that is likely to cause serious harm, we will notify affected users and the Office of the Privacy Commissioner as required by the Privacy Act 2020.
When we may disclose information
We may disclose your information without your consent only where:
- Required by New Zealand law or a lawful order
- Necessary to prevent or lessen a serious threat to someone’s life, health or safety
- Necessary to investigate suspected unlawful activity or a serious breach of our Terms of Use
- Necessary to establish, exercise or defend a legal claim
We will tell you if this happens unless we are legally prevented from doing so.
How long we keep information
Your rights
Under the Privacy Act 2020, you have the right to:
- Access the personal information we hold about you
- Correct information that is wrong or incomplete
- Complain if you believe we have breached your privacy
You can also, at any time:
- Disconnect any connected service in Settings, which stops further access immediately
- Delete individual records, including tasks, contacts and pipeline entries
- Close your account by emailing hello@briefable.co.nz
We will respond to access and correction requests within 20 working days.
If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner at privacy.org.nz or call 0800 803 909.
Revoking access to connected services
You can revoke Briefable’s access directly with the provider at any time, independently of anything you do in Briefable:
Revoking access stops Briefable reading new information immediately. It does not delete information already stored. Use the account deletion process for that.
Cookies
Briefable uses cookies and browser storage only to keep you signed in and remember your preferences. We do not use advertising or tracking cookies, and we do not run third-party analytics on the application.
Blocking these essential cookies will prevent sign-in from working.
Children
Briefable is a business tool intended for adults. It is not designed for or directed at anyone under 16, and we do not knowingly collect information from children.
Early access
Briefable is currently in early access. During this period:
- Features may change, be added or be removed
- The service may be unavailable at times
- Data loss, while not expected, is possible. Keep your own records of anything critical
- We may contact you for feedback about your experience
We will give reasonable notice of significant changes that affect how your information is handled.
Changes to this page
We may update this page as the product changes. The effective date at the top shows when it was last revised. Where a change materially affects how we handle your information, we will notify you by email before it takes effect.
Contact
Have a question about your information?
Contact Briefable at hello@briefable.co.nz for an access request, correction request, account deletion or any other privacy concern.