Privacy notice
Choose the boundary before the context moves.
Local Brief works without an account. Team sync is explicit, and raw repository source is not part of the default cloud contract.
Data Brief processes
- Account data: email address, profile name, authentication identifiers, workspace membership, and role.
- Derived repo data: repo name, branch or commit, file paths, hashes, map nodes, summaries, test references, and freshness.
- Workflow data: task descriptions, context packets, review findings, validation records, handoff notes, learning proposals, and audit events.
- Operational data: connector prefix and scopes, timestamps, usage counters, and request failure details. Connector secrets are stored only as hashes.
Privacy modes
Local-only keeps repo-derived context and receipts on the machine running the connector.
Cloud sync, derived sends derived metadata and proof records so the workspace can show repo freshness, team guidance, reviews, and handoffs. Raw source excerpts and extracted skill or rule bodies are withheld by default.
Team cloud is an explicit opt-in for richer team-managed content. Customers should enable it only after choosing source, visibility, retention, and access policies.
How data is used
Brief uses workspace data to authenticate users, target the right repo, return relevant context, recommend reuse and tests, enforce team guidance, review changes, show proof history, and operate the service. Brief does not sell customer data. The web app currently uses no third-party advertising or behavioral analytics tracker.
Connected clients and service providers
When you connect Brief to Claude, ChatGPT, Codex, Cursor, or another MCP client, Brief returns the approved derived context requested by that client under your current workspace membership. The connected client processes that response under its own terms and privacy policy. Brief does not put OAuth access tokens, connector secrets, raw repository source, or uncommitted diffs in hosted tool results.
Brief uses Supabase for authentication and hosted Postgres data, Render for the web service, npm for the public connector package, and Stripe for billing infrastructure. Those providers process data according to their own service terms and security controls. If a workspace owner starts a paid plan in the future, Brief may send Stripe the billing identity and member quantity, never repository source.
Your choices
Owners and admins can export workspace data. Owners can delete a cloud workspace from Settings. Local files remain under the customer's filesystem controls. See Data controlsfor exact scope and deletion behavior. For a privacy question, use Brief's private request form.