Privacy Policy
Short version: Daily Brief reads your email and calendar — nothing else — to build your morning brief. It can't send, delete, reply to, or change anything. We keep as little as possible: no permanent copies of your messages, a short-lived cache of your actual brief content, and anything you explicitly tell us to remember, which you can see and remove at any time. We don't sell your data. We don't use it for advertising. We don't use it to train AI models.
1. Who we are
Daily Brief is operated by Key True Consulting, LLC ("Daily Brief," "we," or "us"). Daily Brief reads a business owner's connected email and calendar, read-only, and delivers one prioritized daily brief with a checklist.
Questions about this policy? Email us at support@keytrueconsulting.com.
2. What we collect
We collect information in four ways: information you give us directly, information we access from your connected Google account, information you tell Scout (Daily Brief's assistant) to remember, and limited information we receive from service providers that support the service.
For residents of certain U.S. states, including California, this section and Sections 4 and 5 describe the categories of personal information we collect, the categories of sources from which we collect it, the purposes for which we collect, use, and disclose it, and the categories of third parties or other recipients to whom we disclose it, as required by applicable law.
Information you provide directly:
- Account information — your name and email address, collected when you sign up.
- Feedback — if you tell us an item in your brief was wrong (not relevant, already handled, wrong priority, or another reason), along with any note you choose to add.
- Owner-provided context — facts you tell Scout directly, or that Scout notices from patterns in your brief and asks you to confirm (e.g., "sits on the board of X," a recurring commitment) — used to judge what's actually relevant in future briefs. This category is never written anywhere until you've had the chance to keep, edit, or reject it.
Information we access from your connected Google account (read-only):
- With your permission, we connect to your Gmail and Google Calendar using read-only access. We cannot send, reply to, delete, forward, or otherwise modify anything in your account, and we never request write access.
- We read the sender, subject, and body text of your email messages, and the details of your calendar events, to work out what needs your attention. We do not read attachments.
- This connection is brokered through our authentication provider, Clerk, which stores and refreshes the access token on our behalf — we request a short-lived access token from Clerk each time we need one, rather than holding a long-lived credential to your account ourselves.
Information collected automatically:
- Basic usage data (which features you use, how often you sign in).
- Device type and browser.
- Error and crash reports.
Depending on how you use the service, the personal information we collect may include identifiers and contact information, the contents of your email and calendar (processed as described in Section 3, not stored as described there), feedback and context information you provide, and internet or other electronic network activity information. We collect this information from you, from your connected Google account (with your permission), from your device or browser, and from service providers that support the service.
3. What we keep, and for how long
This is the most important section of this policy, because Daily Brief's entire design starts from the idea that we should keep as little as possible. Four different things happen to four different kinds of information:
Never stored. The full text of your emails and calendar events — sender, subject, body — is fetched live from Google each time we need it, used in memory to generate that day's brief, and then discarded. We do not keep a database of your messages. If we need to look at a message again (for example, to re-evaluate an item that's still open), we fetch it fresh from Google rather than from a copy of our own.
Kept indefinitely, but only as an opaque reference. For each email thread or calendar event that's ever been part of your brief, we keep an internal identifier (not the subject or content) plus its checklist status (open, done, snoozed, or dismissed) and timestamps. This is what lets your checklist and history work, without us holding a readable copy of what the item was about.
Kept for roughly 24–48 hours. The actual readable content of your brief — the one-line reasons, priorities, and timing that make up what you see in your inbox and on the dashboard — is generated fresh each morning and held just long enough to power that day's email, web view, and checklist actions. After that window, it's automatically deleted.
Kept until you change it. Context you've confirmed about yourself — the kind of standing fact that helps Scout judge relevance (e.g., a board you sit on) — is stored encrypted, separately from our regular database, and stays until you edit or remove it. A newly noticed candidate fact is held only long enough for you to keep, edit, or reject it; if you reject it, it's deleted immediately and never becomes part of your stored context.
Feedback you leave us. If you tell us an item was wrong, we keep which reason you chose (not relevant, already handled, wrong priority, or other) permanently — it's a fixed category, not content. Any note you write to go with it is kept for roughly 48 hours, the same window as your brief content, and then automatically deleted. You can also ask us to delete specific feedback sooner by contacting us.
Account and usage information — your name, email address, and basic usage/error data — is kept for as long as your account exists, and for as long as reasonably necessary afterward to comply with legal, security, or fraud-prevention obligations.
4. How we use your information
We use your information to:
- Read your connected email and calendar to generate your daily brief.
- Maintain your checklist (done, snoozed, dismissed) and its history.
- Let Scout get better at judging what matters to you specifically, based on context you confirm and feedback you give — never by training a general AI model.
- Deliver your brief by email and show it on the web dashboard.
- Respond to your support requests.
We use AI (via our model provider, Anthropic) to classify your email and calendar items and to write your brief. The relevant text of your messages is sent to Anthropic to produce that result. Anthropic does not use this data to train its models, and retains it under its standard commercial API data-retention terms, currently up to 30 days. Anthropic is a subprocessor for this purpose.
Because Daily Brief's primary data source is Google Workspace data accessed via Google APIs, our use of that data is additionally governed by Google's API Services User Data Policy, including the Limited Use requirements: we use this data only to provide and improve user-facing features of Daily Brief, not to train generalized AI or ML models, and we do not allow humans to read it except (a) with your affirmative consent for a specific item, (b) to secure or maintain compliance with applicable law, or (c) if required to investigate abuse or a security incident.
Who can see your email. You can. Our systems can, automatically, to generate your brief. Nobody on our team reads your email content as a matter of course. We don't currently have a self-service feature for sharing a specific item with support — if we add one, we'll update this policy before it's available.
What we never do. We don't sell your data, use it for advertising, or use it to train AI models.
5. How we share your information
We do not sell your personal information or share it for cross-context behavioral advertising. We do not use personal information for targeted advertising, and we do not share it with advertisers. In the preceding 12 months, we have not sold or shared personal information.
We disclose personal information to the following categories of recipients, for the following business purposes:
- Google — the source of your email and calendar data, accessed read-only with your permission, governed by Google's own terms and the Limited Use restrictions described above.
- Anthropic — our AI model provider, used to classify and prioritize your brief content, as described in Section 4.
- Clerk — our authentication provider, which handles sign-in and securely stores and refreshes your Google access token on our behalf.
- Railway — our infrastructure and database hosting provider.
- Vercel — hosting for the web dashboard.
- Resend — used to deliver your daily brief by email.
- Legal requirements — if required by law, court order, or to protect the rights and safety of our users or the public.
- Business transfer — if Daily Brief is acquired or merges with another company, your information may be transferred as part of that transaction. We will notify you if this happens.
These providers are contractually required to use your data only to provide services to us.
6. How to disconnect and delete your data
You can disconnect your Google account at any time from Settings. Disconnecting stops Daily Brief from accessing your email and calendar going forward.
You can request full deletion of your account and data at any time by emailing support@keytrueconsulting.com. We will delete your account information, your checklist history, your stored context, and any cached brief content within 30 days.
7. Security
We use industry-standard practices to protect your data: encrypted connections (HTTPS), encrypted storage for your access tokens (held by Clerk, not by us directly) and for your confirmed owner-context facts (encrypted separately from our regular database, with the encryption key held only as server configuration, never alongside the data itself), and access controls limiting which of our own systems can reach which data. However, no system is perfectly secure. If you believe your account has been compromised, contact us immediately.
8. Information about other people
Your email and calendar naturally contain information about other people — clients, family members, colleagues, vendors — who have not separately signed up for Daily Brief or agreed to this policy. By connecting your account, you represent that you have the right to have this information processed by Daily Brief as described in this policy, and you're responsible for your own obligations to the people you communicate with (for example, any confidentiality obligations to clients). We process this information only as part of generating your brief, under the same minimization rules described in Section 3 — we don't build profiles of the other people who appear in your inbox, and we don't retain their information separately from yours.
9. Children's privacy
Daily Brief is a business tool, directed at business owners, and is not directed at children. We do not knowingly collect account information from children under 13, and Daily Brief accounts are not intended for use by children.
Your connected email or calendar may incidentally contain information about a minor (for example, a family member's school correspondence). That information is processed only as described in Section 8 above, under the same minimization rules as the rest of your inbox — it is not treated as a separate child's account, and we do not knowingly build any profile of a minor.
10. Your rights
Depending on where you live and subject to applicable law, you may have the right to:
- Access the personal information we hold about you, and where applicable, request information about the categories and specific pieces of personal information we've collected, the categories of sources, the purposes for collecting it, and the categories of third parties it's been disclosed to.
- Correct inaccurate information.
- Request deletion of your account and data.
- Export your data in a portable format.
- Opt out of non-essential email communications and, where applicable, the sale or sharing of your personal information, targeted advertising, and certain profiling, including by withdrawing consent where consent is the basis for processing.
To exercise any of these rights, email support@keytrueconsulting.com. We may need to verify your identity before acting on your request. If permitted by applicable law, you may also use an authorized agent to make a request on your behalf. If we decline to take action on your request, you may appeal that decision by replying to our response or emailing support@keytrueconsulting.com with "Privacy Appeal" in the subject line. We will not discriminate against you for exercising your privacy rights, subject to applicable law. We will respond within 30 days or within a longer period permitted by applicable law if we notify you.
11. Contact us
Key True Consulting, LLC (Daily Brief)
Email: support@keytrueconsulting.com
We may update this policy as the service evolves. We'll notify you of material changes by email or through the app. The effective date at the top of this page is the date this policy was last updated and will always reflect the most recent version.