Your inbox is personal. We treat it that way.
Privacy Policy. Effective September 18, 2026.
Who operates this service
DailyAiBrief is operated by Daily AI brief. For privacy questions, contact [email protected].
Information we access
With your Google authorization, we access your Gmail email address, message identifiers, senders, subjects, message text, timestamps and labels. We access inbox messages to display email, calculate statistics and support your read/unread and archive actions. We do not download attachments or load remote email images.
We receive OAuth access and refresh tokens to act within your granted permission, including offline access. We never receive your Google password. We use an essential session cookie and a short-lived OAuth security cookie. This application contains no advertising, analytics or tracking cookies.
How we use the information
We use Google data only to provide visible email productivity features: inbox viewing, user-directed label changes, inbox statistics and the optional daily brief. Background AI reading runs only after you enable automatic daily briefs. We do not sell Gmail data, use it for ads, credit decisions or unrelated profiling.
Optional AI processing
AI is disabled by default. If you enable it, message excerpts and sender/subject details are processed by the operator's private self-hosted AI service. Up to 10 recent inbox messages and up to 1,200 text characters per message are included in each brief. The app does not transfer this information to a third-party AI provider. Google user data and derived briefs are not used to train or improve generalized AI or machine-learning models.
AI can be inaccurate or omit details. Its output is a suggestion; it cannot send or alter email. Turning AI off deletes the saved brief and stops future AI jobs. An already-running request may finish processing, but its result is discarded if permission has been withdrawn.
Storage and retention
We encrypt your email address, Google tokens, settings and latest AI brief in the application database using AES-256-GCM. Session identifiers are stored as hashes. Email bodies are processed in memory and are not saved in the app database. They are sent to your browser to display the inbox.
Only the latest brief is retained; generating another replaces it. Account records expire after 30 days without authenticated app activity. Expired records are deleted on the next service database activity or scheduled cleanup. Disconnecting deletes active account data immediately. The app does not create backups; any infrastructure backup retention must be disclosed here before such backups are enabled.
Sharing and human access
The app does not sell data or share it with advertisers or external AI providers. Hosting infrastructure processes data only to operate the service under the operator's control. Human access to Google user data is limited to your explicit consent for specific messages, necessary security investigations, legal obligations, or other uses specifically allowed by Google's Limited Use requirements. Ordinary support does not require reading your inbox.
The deployed service runs on a private VPS controlled by Daily AI brief. Cloudflare provides the public reverse proxy and browser-facing HTTPS connection; the VPS origin uses HTTP under the selected Cloudflare Flexible configuration. These infrastructure services process requests to deliver the app. We do not configure email-content logging or application backups. Contact us for questions about hosting and applicable data rights.
We may disclose information when required by applicable law or to address fraud, abuse or security incidents, subject to Google's user data requirements.
Google API Services Limited Use
DailyAiBrief's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. These restrictions also apply to derived, aggregated and anonymized Google user data.
Your choices and deletion
You can disable AI or daily processing, disconnect Gmail and delete app data in Settings, or revoke access through Google Account connections. Revoking access at Google stops our API access but does not by itself delete locally stored records. Use our data deletion process for local deletion. For access, correction or other privacy requests, contact [email protected].
Children and policy updates
This service is not directed to children under 13 or below the minimum age required by local law. Material changes to data use require an updated policy and any necessary new consent before those changes take effect.