Breef.
So funktioniert’sPreiseDatenschutz
Anmelden

Diese Seite gibt es nur auf Englisch.

Last updated 7 October 2026

Privacy Policy

In short:

  • Breef reads the email in the inboxes you connect, with read-only access, to find the messages that need you and turn them into tasks.
  • What an email says is kept for 30 days. After that it’s removed; tasks keep only the email’s subject, sender, and date.
  • Your email is never sold, used for advertising, or used by Breef to train AI models.
  • You can disconnect an inbox or delete your account at any time, and the data goes with it.

Who is responsible

Breef is run by G. Rizzo, an individual based in Italy, who is the data controller for the personal data described here (“Breef”, “we”, “us”). For anything about your data, write to privacy@breef.app.

This policy applies to breef.app and the Breef service. It is written to meet the EU General Data Protection Regulation (GDPR).

What we collect

Your account

Your email address, and, if you use Google or Microsoft to access Breef, the name and profile picture they share with us. We also keep your settings (for example, how tasks are created).

Your connected inboxes

When you connect Gmail or Outlook, you allow Breef to read your email. Breef asks for read-only access and cannot send, change, or delete email. For each inbox we store:

  • its address and provider, and the access tokens that let Breef read it, encrypted;
  • for the emails in your inbox from up to 30 days before you connect (7, 14, or 30 days, depending on your plan), and each new email after that: the sender, recipients, subject, date, and text (we don’t store attachments);
  • what Breef decided about each email, and the tasks it made: a title, a due date when the email gives one, and a one-line reason.

Technical data

Like most web services, our hosting providers keep short-lived technical logs (such as IP addresses) to run and secure the service. When something goes wrong in Breef, we keep a report of the error to fix it, with email addresses, tokens, and links’ parameters removed before it’s stored; reports are deleted 30 days after the error last happened. We measure visits with privacy-friendly analytics that don’t use cookies or identify you.

How we use it

We use your data only to provide Breef to you:

  • to decide which new emails ask something of you, and to write tasks for them;
  • to show you your tasks, your activity, and search across them;
  • to send you access links and messages about your account;
  • to keep the service secure, prevent abuse, and fix problems.

We don’t sell your data, use it for advertising, or use it to train AI models. No person at Breef reads your email, except when you ask us to (for example, to help with a problem you report), when it’s needed for security, or when the law requires it.

Deciding which emails become tasks is automated. These decisions don’t have legal or similarly significant effects on you, and you can always review, finish, or dismiss any task.

Google and Microsoft data

Breef’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We use Gmail and Microsoft Outlook data only to provide and improve the features you see in Breef. We don’t transfer it to others except as needed to provide those features (see the service providers below), to comply with the law, or as part of a merger or sale with your notice, and we never use it for advertising.

We don’t use data from Gmail or Outlook to develop, improve, or train AI or machine-learning models, ours or anyone else’s. The AI providers listed below process an email only to return their answer to Breef, and don’t use it to train their models.

Legal basis

  • Contract (Art. 6(1)(b) GDPR): processing your account and email is necessary to provide the service you asked for.
  • Legitimate interests (Art. 6(1)(f)): keeping Breef secure, preventing abuse, and understanding how the site is used in aggregate.
  • Legal obligation (Art. 6(1)(c)): when the law requires us to keep or disclose data.

Who helps run Breef

We use a small number of service providers who process data on our behalf, only on our instructions and under contracts that protect it:

ProviderWhat they do
ConvexDatabase and backend: stores your account, inbox connections, emails, and tasks (hosted in the EU, Ireland).
VercelHosts the website and provides privacy-friendly visit analytics.
ResendSends access links and account emails.
AnthropicAn AI model that reads an email to write its task title, due date, and reason.
CloudflareAn AI service (Workers AI) that reads an email to judge whether it asks something of you.
Google, MicrosoftYour email providers, which Breef reads from with your permission, and optional ways to access Breef.

Some of these providers process data outside the European Economic Area, mainly in the United States. Where they do, the transfer is protected by the European Commission’s Standard Contractual Clauses or the EU-US Data Privacy Framework.

How long we keep it

  • What an email says (its text and preview) is kept for 30 days. After that it’s removed. Emails that didn’t become a task are deleted entirely, along with Breef’s decision about them.
  • Tasks, with the subject, sender, and date of the email they came from, are kept until you delete them with your account.
  • Inbox connections are kept until you disconnect the inbox, which also deletes its emails and tasks.
  • Your account is kept until you delete it in Settings. Deletion removes your data from Breef straight away; copies in our providers’ backups expire on their own schedule. We keep only a one-way fingerprint of your email address and the date your free trial ended, so a new account with the same address can’t start another trial. The fingerprint can’t be turned back into your address.
  • Access links expire after 15 minutes.

How we protect it

Connections are encrypted in transit. The tokens that let Breef read your inboxes are encrypted at rest, and Breef only ever asks for read-only access. Access to the systems that hold your data is limited to what running the service requires.

Cookies

Breef uses only the cookies it needs to keep you signed in to your account; they last up to 30 days. Your light or dark theme is remembered in your browser. We don’t use advertising or tracking cookies.

Your rights

Under the GDPR you can:

  • access the personal data we hold about you, and get a copy in a portable format;
  • correct it, or have it deleted (you can delete your account yourself in Settings);
  • restrict or object to how we use it;
  • withdraw Breef’s access to your email at any time, by disconnecting the inbox in Settings or removing Breef in your Google or Microsoft account.

To use any of these rights, write to privacy@breef.app. We’ll answer within one month. You also have the right to complain to a data protection authority; in Italy that’s the Garante per la protezione dei dati personali.

Children

Breef isn’t meant for anyone under 16, and we don’t knowingly collect their data.

Changes

If we change this policy, we’ll update the date at the top. If the change is significant, we’ll tell you by email or in Breef before it takes effect. See also the Terms of Service.

Breef.

Breef liest deinen Posteingang und macht aus den E-Mails, die etwas von dir wollen, Aufgaben.

Produkt

So funktioniert’sPreiseAnmelden

Rechtliches

DatenschutzerklärungNutzungsbedingungen

Kontakt

privacy@breef.app

© 2026 Breef

EnglishItalianoEspañolFrançaisDeutsch