The principle
Executive context is more sensitive than passwords or documents. It reveals how you think, who you trust, and what you are about to decide. Brief is built for that from the start, not wrapped in policy afterward.
Reading your content is not something anyone at Brief can do in the ordinary course of their work.
How that is built
- Your sensitive content is encrypted with a key that belongs to your account alone, held separately from the database it protects.
- Standing production access carries no key that can decrypt it.
- The needed operational and legal guidelines are written into the Terms of Service and the Data Processing Addendum, not left to trust.
This is architecture, not policy. A policy can be rewritten in an afternoon. The paths into your content are few, named, and built in.
What Brief stores, and what stays in your source systems
Brief stores encrypted copies of the content it needs to do its job: relevant emails, chat messages, calendar events, documents, and transcripts. Brief also generates metadata such as summaries, keywords, tags, and inferred relationships, which power your briefings and answers.
Your source systems stay authoritative. Your originals remain in Gmail, Outlook, Google Calendar, Microsoft Calendar, Google Chat, Zoom, and the rest, and Brief maintains a pointer back to each one. Brief maintains a model of your work rather than becoming your system of record for it.
When you delete content at its source, Brief stops ingesting it and marks its stored copy for deletion. The mechanics, including how backup copies clear, are in the Terms of Service.
Sign-in security
Brief does not have its own password. Sign-in goes through Google or Microsoft OAuth. The implication is direct: the security posture of your Brief account is the security posture of the underlying Google or Microsoft account. Use a strong password and two-factor authentication on that account.
How language models reason over your content
To generate your briefings and answer your questions, Brief decrypts the relevant portions of your content and sends them to a language model to process on Brief's behalf. The providers Brief uses, and the terms that govern what each may do with your content, are listed in the Privacy Notice and the Data Processing Addendum. Those documents, not this page, are the record of that processing.
Where the specifics live
This page states the posture. The Terms of Service and any applicable Data Processing Addendum are the agreement; the Privacy Notice is the disclosure that explains the processing. Between them they carry the specifics: what is encrypted and where, how deletion and backups work, and the narrow circumstances under which elevated access is granted. Where this page and those documents differ, the documents govern.