Privacy Policy
Effective date: August 11, 2026 Last updated: August 11, 2026
This Privacy Policy explains how Noah Consulting Services (operating as "Briefo"; "we," "us," or "our") collects, uses, stores, discloses, and protects information in connection with the Briefo service, websites, and applications (collectively, the "Service"). By using the Service or authorizing Briefo to connect to a data source on your or your organization's behalf, you acknowledge the practices described in this Policy.
Briefo is an AI-powered knowledge base: with authorization, we ingest an organization's documents, emails, and calendar events and make them queryable through a chat interface that returns cited answers.
1. Who this Policy covers, and our role
Briefo is primarily a business-to-business service. In most cases:
- The organization that engages Briefo (the "Customer") is the data controller of the information Briefo processes on its behalf, including the Customer's users' emails, calendars, and files.
- Briefo acts as a data processor / service provider, processing that information only to provide the Service under our agreement with the Customer and our Data Processing Agreement ("DPA").
For information Briefo collects for its own purposes (for example, account registration and website analytics), Briefo acts as a controller. Where Briefo is a processor, the Customer's own privacy notices and instructions govern the underlying personal data, and this Policy is provided for transparency. Individuals whose data is processed on a Customer's behalf should direct requests to that Customer.
2. Information we collect
2.1 Account and business information
Names, business email addresses, organization name, role, authentication identifiers, billing/contact details, and support communications.
2.2 Connected Data (the core of the Service)
With authorization, Briefo accesses content from the data sources a Customer chooses to connect ("Connected Data"). Depending on which connectors are enabled, Connected Data may include:
- Email (Gmail, Microsoft Outlook): message content, subjects, senders, recipients, dates, folders/labels, and attachments contained within messages.
- Calendar (Google Calendar, Microsoft Outlook Calendar): event titles, descriptions, times, locations, attendees, organizers, meeting links, and attachments.
- Files (Google Drive): documents, spreadsheets, presentations, and their metadata (author, dates, file name, path) from folders explicitly shared with Briefo.
- Additional sources the Customer may connect in the future, subject to the same practices.
Connected Data may contain personal data of the Customer's employees, contacts, and correspondents. The Customer is responsible for having a lawful basis and all necessary consents and authority to connect these sources and to authorize Briefo's access. See the Terms of Service and DPA.
2.3 Derived data
To provide the Service, Briefo generates derived artifacts from Connected Data, including derived text extracts and search indexes used for retrieval and citation.
2.4 Usage and device data
Log data, IP address, browser/device type, pages viewed, feature usage, and diagnostic data, collected to operate, secure, and improve the Service.
2.5 Cookies
The Briefo website and application use only strictly necessary cookies required to sign you in and keep the Service secure. We do not use advertising cookies. If we later add optional analytics cookies, we will present a cookie notice and obtain consent where required.
3. How we access Connected Data (scopes and method)
Briefo accesses Connected Data using read-only authorization and cannot create, modify, send, or delete content in a connected source.
- Google Drive: access via a Google service account to folders the Customer explicitly shares with Briefo (read-only). No mailbox-wide or account-wide access.
- Gmail: read-only access to email.
- Google Calendar: read-only access to calendar events.
- Microsoft Outlook mail: read-only access to email.
- Microsoft Outlook calendar: read-only access to calendar events.
Authorization is granted through the provider's standard consent flow, and can be revoked at any time by the account holder through their Google or Microsoft account settings, or by asking Briefo to disconnect the source.
4. How we use information
We use information to:
- provide, operate, and maintain the Service — ingesting Connected Data, extracting text, building search indexes, retrieving relevant content, and generating cited answers to Customer queries;
- authenticate users and enforce per-customer data isolation and access controls;
- provide support, troubleshoot, secure, and improve the Service;
- comply with legal obligations and enforce our agreements.
We do not:
- use Connected Data for advertising or to build advertising profiles;
- sell or rent Connected Data or personal data;
- use Connected Data to train, fine-tune, or improve generalized AI/ML models, whether our own or a third party's;
- allow humans to read Connected Data except (i) as necessary to operate, secure, or support the Service and troubleshoot issues, (ii) with the Customer's or user's consent, (iii) where required for security or to comply with law, or (iv) in aggregated/de-identified form.
4.1 AI processing
Answers are generated by large language models accessed through Amazon Bedrock within Amazon Web Services. Content sent to these models for retrieval and answer-generation is processed to produce responses and is not used by the model providers to train their foundation models.
5. Google API Services / Microsoft — Limited Use
Briefo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data is used only to provide or improve user-facing features that are prominent in the Service; is not sold; is not used for advertising; and is not transferred to third parties except as necessary to provide or improve the Service, for security, or to comply with law, or with the user's consent. Human access to Google user data occurs only in the limited circumstances described in Section 4.
Briefo's access to Microsoft 365 / Microsoft Graph data is likewise limited to providing the Service and is subject to Microsoft's applicable terms and to this Policy.
6. Storage, sub-processors, and international transfers
Connected Data and derived data are hosted on Amazon Web Services (AWS) in the United States.
We rely on the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting, storage, and AI processing (Amazon Bedrock) | United States |
| Google LLC | Source data access (Drive, Gmail, Calendar) via authorized APIs | United States |
| Microsoft Corporation | Source data access (Outlook mail/calendar) via Microsoft Graph | United States |
| Stripe, Inc. | Payment processing (subscription and setup fees) | United States |
A current sub-processor list is maintained in our Terms (Schedule 2) at briefo.io/terms and in the DPA. If you are located outside the United States, your information will be transferred to and processed in the United States; where required, transfers of personal data from the EEA/UK/Switzerland are made under appropriate safeguards, specifically the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable).
7. Data retention and deletion
- Connected Data and derived data are retained for as long as the connected source remains active and the Customer's account is in effect, and are deleted or de-identified within 30 days of (a) disconnection of the source, (b) termination of the Customer's account, or (c) a valid deletion request, except where retention is required by law.
- Revoking provider authorization stops further ingestion; previously ingested data is deleted according to the period above.
- Backups are cycled out within 35 days.
8. Security
We implement technical and organizational measures appropriate to the sensitivity of the data, including: per-tenant logical isolation so one Customer's data cannot be returned to another; a single enforced, tenant-scoped data-access layer; database-level access controls; encryption in transit and at rest; least-privilege access to credentials (secrets stored in a managed secrets service); and access logging. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. Disclosure of information
We disclose information only:
- to sub-processors under contract, for the purposes above;
- to the Customer that authorized the connection (data is returned only to that Customer's authorized users);
- as required by law, legal process, or governmental request, or to protect rights, safety, and security;
- in connection with a merger, acquisition, or asset sale, subject to this Policy; and
- with consent.
We do not sell personal data.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, port, or restrict the processing of your personal data, and to object or withdraw consent (GDPR, UK GDPR, CCPA/CPRA, PIPEDA/Quebec Law 25, and similar laws).
- Where Briefo is a processor, individuals should direct requests to the Customer (controller); Briefo will assist the Customer in responding.
- Where Briefo is a controller (e.g., account data), contact us at admin@briefo.io.
We do not discriminate against you for exercising these rights.
11. Children
The Service is not directed to individuals under 16, and we do not knowingly collect their personal data.
12. Changes to this Policy
We may update this Policy. Material changes will be notified via the Service or by email, and the "Last updated" date will change. Continued use after changes take effect constitutes acknowledgment.
13. Contact
Noah Consulting Services (operating as Briefo) Province of Quebec, Canada Email: admin@briefo.io