What BriefWork accesses, and why
BriefWork is operated by Growth Insights Limited. This notice describes the data paths in the current product, including the additional data available only when you choose to connect a provider.
Last updated 28 September 2026
Data we collect or process
- Account data: your Google account identifier, email address, name, and the session information needed to keep you signed in.
- Workspace data: the website, brand profile, ideal-customer profiles, voice rules, approved business facts, sender identity, limits, and preferences you provide.
- Connected-provider credentials: API keys, application passwords, and OAuth refresh tokens for services you choose to connect. These are encrypted before storage.
- Marketing operations data: business-contact records and provenance, suppression records, campaign assets, replies, publishing drafts, plans, approvals, provider results, and performance metrics needed for the features you use.
- Operational records: audit events, security events, errors, and model-usage records used to operate and protect the service.
Google user data
Google Sign-In gives BriefWork your Google account identifier, email address, and name so it can create your account and session. It does not give BriefWork access to Gmail, Drive, or Calendar.
Google Ads, Search Console, Google Workspace and Gmail are separate, optional connections requested in context. When you connect Ads or Search Console, BriefWork can access the selected Ads customer's account settings, campaign structure, budgets, conversion readiness, and performance metrics, and the selected Search Console property's queries, pages, clicks, impressions, click-through rate, and position. BriefWork stores the OAuth refresh token and the selected customer or property so it can provide the connected features until you disconnect them.
When you connect Google Workspace, BriefWork can read events from your primary Calendar for meeting reporting, create Sheets and Docs for approved work, and read individual source files you explicitly select with Google Picker. This connection does not grant access to arbitrary Drive files, Gmail messages or Calendar changes.
The separate Gmail connection reads recent inbox headers and the selected thread to prepare a one-to-one reply. BriefWork retains the reviewed recipient, message identifiers, source fingerprint and reply copy with the plan. It creates a draft after review; sending the exact reply requires individual approval. This workflow does not support attachments, CC, BCC or bulk Gmail sending.
Google API Limited Use
BriefWork's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide or secure the user-facing features you request; BriefWork does not sell it, use it for advertising, or use it to train a general-purpose AI model.
How we use data
We use the data above to authenticate users, maintain workspaces, retrieve provider data, prepare reviewable plans and content, execute an approved action, enforce limits and suppression rules, generate reports, keep an audit record, troubleshoot failures, and protect the service.
When a visible writing or planning feature requires an AI model, BriefWork may send the minimum relevant workspace context and evidence to the configured model provider. Provider credentials are not included in model prompts.
Weekly workspace learning uses recorded decisions and copy-edit measurements to propose bounded style preferences. An owner must accept a proposed rule before it changes the workspace's writing preferences. Private cross-workspace reviews use aggregate counts across at least five workspaces and do not export customer copy, contacts or workspace identifiers.
When data is shared
Data is sent to the external services you choose to connect when necessary to read data or carry out an approved action. It is also processed by infrastructure providers that host the application, database, transactional email, and model requests. We may disclose information where necessary to investigate security abuse or comply with a binding legal requirement. BriefWork does not sell personal data.
If you create a BriefWork MCP token for an external client, that client can access the workspace information allowed by its grants until the token expires or is revoked. Preparation and dispatch permissions are separate from read access. Gmail inbox metadata requires another explicit grant, off by default. The client cannot grant approval to a pending plan; dispatch requires an approval already recorded in BriefWork.
Retention and deletion
Connected-provider credentials remain until they are replaced, disconnected, or the workspace is deleted. Where raw provider request or response evidence is stored, it is separated from the longer-lived redacted audit record and scheduled for deletion after 30 days. Workspace records, plans, suppressions, and audit summaries can be kept longer so the product can maintain state, honour opt-outs, and explain past decisions.
You can disconnect a provider in BriefWork to remove its stored credential. You can also revoke Google access from your Google Account permissions. To request access, correction or deletion of retained personal records, contact luca@briefwork.ai. Workspace owners can export records and close a workspace in Settings → Workspace data. Closure stops new BriefWork work, revokes local credentials and deletes working data after a 30-minute drain period. Audit, suppression, aggregate usage, billing, account membership and closure records remain without an automatic deletion deadline. External campaigns, subscriptions and backup copies are handled separately. We will verify requests for retained data before acting and explain if a record must be retained for security, an opt-out, or another applicable obligation.
Cookies and payment data
BriefWork uses an essential signed session cookie for authentication. When you start or manage a software subscription, payment and billing details are collected and processed by Stripe through its hosted Checkout and customer portal. BriefWork receives the resulting customer, subscription, status, and plan identifiers needed to provide the service; it does not receive or store your full payment-card number.
Security and changes
BriefWork uses encrypted transport, encrypts connected-provider credentials before storage, and separates those credentials from planning prompts. No service can promise absolute security. Material changes to how Google user data is used require an updated disclosure and consent before the new use begins.
Questions
Privacy questions and requests should go to luca@briefwork.ai. Commercial terms are described separately in the Terms and any written customer agreement.