Where client data is stored, how it is encrypted, who can read it and how long it is kept. Short on purpose, and each answer names the mechanism behind it.
Sydney, AustraliaDatabase, file storage and server functions
Content encryption
AES-256-GCM, one key per workspaceKeys stay on the server, never in a browser
Briefi staff access
Only through a grant you giveUp to seven days, recorded in your audit log
Breach notice to you
Within 48 hoursA commitment in our Data Processing Agreement
AI model training
Briefi does not train on your contentA provider receives content only to do the task you asked for
Where your data lives
Stored in Sydney. Some tasks use providers overseas.
Client records, briefs, transcripts and recordings are kept in Australia. To draft, transcribe and deliver, Briefi sends the content one task needs to a specialist provider. Several of them are outside Australia, including in the United States.
Stored at restSydney
DatabaseMeetings, briefs, recaps, client records, email threads and your audit log
File storageRecording audio and client documents
Server functionsThe code that reads and writes your data runs in Sydney too
Per task, over HTTPS
Sent for a single task
Drafting
Briefs, recaps, follow-up emails and inbox triage.
Transcription
Recordings, and live captions when you switch them on.
Meeting bot
Joins Zoom, Teams or Google Meet when you send it.
Email and payments
Delivering the email Briefi sends, and billing your subscription.
Transfers outside Australia are covered by APP 8 and, for EU and UK data, the Standard Contractual Clauses.The named list of providers is public, with what each receives and where it is hosted. Read the subprocessors
Encryption
Every workspace has its own key.
Sensitive content is encrypted before it reaches the database, with a key that belongs to your workspace alone. It is decrypted on the server only when a signed-in member with access opens it.
Master keyHeld in the server environment
A 256-bit key that never reaches a browser and is never stored in the database.
Wraps every workspace key
Workspace keyOne per workspace
A random 256-bit key created for your workspace and stored only in wrapped form.
Unwrapped in server memory, briefly
Your contentAES-256-GCM, field by field
One workspace's key cannot open another workspace's records.
Stored as ciphertext in Sydney
Encrypted with your workspace key
Meeting briefs
Recaps
Follow-up drafts
Notetaker transcripts
Client notes
Check-in answers
Email and calendar tokens
Mailbox passwords
CRM keys
What is not field-encrypted
Values the database must search or sort on, such as names, email addresses, dates and statuses. The access rules below protect them. Every connection is HTTPS only, and the browser is told to insist on it (HSTS).
Who can see what
Three boundaries, each enforced separately.
Between practices, between colleagues, and between your practice and us.
1Between workspaces
Another practice cannot reach your records.
Row-level security is on for every table, and a build check fails if a new table ships without it.
Stored credentials cannot be read from a browser at all, even inside their own workspace.
Our server checks membership before it acts, and a record in another workspace answers as if it does not exist.
2Inside your workspace
Colleagues see what their role allows.
Meetings can be visible to the workspace, one team, or the owner alone. Personal mailboxes stay private unless shared.
Four roles, from owner and admin to member and read-only viewer. Privileged actions go to an audit log.
3Briefi staff
We do not look inside your workspace.
Unless an owner or admin grants access, for up to seven days, at a level they choose. They can revoke it at any time.
Read-only by default. Hands-on access never covers sending, spending, billing, members or deletion. Each visit is recorded in your audit log.
Two-step sign-in
Codes from an authenticator app, available to every user.
Connected accounts
Google, Microsoft and CRMs connect by OAuth, asking only for the access the features you turn on need. Their tokens are encrypted, and you can revoke them from the provider.
Briefi's use of information received from Google Workspace APIs, including any raw or derived data, adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use, transfer or sell Google user data to create, train or improve any generalised or foundational AI or ML model.
Retention
How long each thing is kept.
Your records stay while your workspace is active, with these exceptions.
Record
How long
Recording audio
Deleted after 7 days by default. Set anywhere from 1 to 90 days in workspace settings.
Meetings and transcripts
Kept, encrypted, until you delete them or the workspace.
A deleted account
Recoverable for 90 days, then permanently removed.
A paused workspace
Kept for 90 days, then deleted. If you had a trial or a plan, we email the workspace owner first.
Questions
What compliance officers ask first.
Can I get a Data Processing Agreement (DPA)?
Yes. Our DPA is published and covers the Privacy Act, GDPR and the UK Addendum. If your practice needs a signed copy, email us and we will prepare one for you.
The current list, with what each receives and where it is hosted, is public. Workspace owners get at least 30 days of notice before a new subprocessor handles customer data.
It is stored in Sydney. To draft, transcribe and send, Briefi passes the content one task needs to a specialist provider, and several are outside Australia. Those transfers are covered by APP 8 and, for EU and UK data, the Standard Contractual Clauses.
Is our clients’ information used to train AI models?
Briefi does not train AI models on your content, and we do not sell it or share it with advertising networks. Content goes to a provider only to complete the task you asked for. The providers and what each receives are on the subprocessor list.
Can Briefi staff read our client files?
Only if an owner or admin grants support access, for up to seven days. It is read-only unless you allow more, every visit is recorded in your audit log, and you can end it at any time.
What happens if there is a breach?
We notify the workspace owner within 48 hours of becoming aware of it, with what is known about its scope and what we are doing. That leaves you time for your own assessment under the Notifiable Data Breaches scheme.
Can we take our data with us?
An owner or admin can download any client’s full record as one file from their contact page, which is also how you answer an access request. Plans with API access can pull meetings, contacts, deals and threads through the API. For the whole workspace, email us and we will export it for you.
We do not run a bug bounty, but every security report is read personally and we reply as soon as we can. Please give us a fair chance to fix an issue before you disclose it.
Security reports
security@briefi.sh
DPA, subprocessor questions and privacy requests
privacy@briefi.sh
Privacy requests are answered within 5 business days.
Bring your compliance questions to the demo.
A 30-minute walkthrough, with time to go through your own checklist.