Privacy Policy
Draft — pending legal review.
Effective date: [Effective date]
Bref (bref.ing) is an internal email “brefing” (digest) tool. Bref is operated by [Leash legal entity name] (“Leash,” “we,” “us”), the company behind leash.build. This policy explains what information Bref processes, why, who we share it with to run the service, and the choices and rights you have. It applies to the Bref application and website.
What we collect and why
Bref is designed to collect only what it needs to let a team compose brefings and send them to colleagues. Specifically:
- Account users.Your work email, display name, and your organization’s name and email domain. Bref uses passwordless magic-link authentication, so we do not collect or store account passwords.
- Recipients. The email addresses and names of colleagues that an organization administrator adds to sending lists.
- Content. The brefings your organization composes within the product.
- Sending & engagement metadata. Records of the messages that were sent, and open/read tracking used to report who engaged with a brefing.
- Session cookies. Strictly necessary cookies that keep you signed in.
We use this information to authenticate you, to compose and deliver brefings, to report engagement back to the sending organization, to operate and secure the service, and to respond to support requests.
Subprocessors
To run Bref, we rely on a small set of trusted third-party service providers (“subprocessors”) that process data on our behalf:
- Supabase — database, authentication, and storage.
- Amazon Web Services (AWS SES) — email delivery.
- Google Cloud Platform — application hosting.
- Resend — delivery of login-link (magic-link) emails.
If your organization chooses to connect its own AI assistant to Bref via MCP, that assistant runs under your organization’s own third-party account and is not a Bref subprocessor; data handled through that connection is governed by that provider’s terms, not this policy.
International data transfers
Bref’s infrastructure and subprocessors are located in the United States. If you access Bref from outside the United States, your information will be transferred to, stored in, and processed in the United States, where data-protection laws may differ from those in your country.
How we protect your data
We apply security measures appropriate to the service, including encryption of data in transit (TLS), tenant isolation enforced through database row-level security so one organization cannot access another’s data, least-privilege access controls, and secrets held in managed secret stores.
Data retention
We retain your data for as long as your account is active. When you request deletion or close your account, we delete the associated data, subject to any limited retention required to comply with legal obligations or to resolve disputes.
Your rights
You may request to access, correct, export, or delete the personal data Bref holds about you. To exercise any of these rights, contact us at privacy@leash.build. If your data was provided to Bref by your organization (for example, as a recipient on a list), we may direct your request to that organization, which controls that data.
Cookies
Bref uses only strictly necessary cookies for session and authentication — the cookies that keep you signed in after you follow a magic link. We do not use advertising or third-party tracking cookies.
Children
Bref is a workplace tool intended for business use. It is not directed at children, and we do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify account users.
Contact
Questions about this policy or how Bref handles your data? Email us at privacy@leash.build.