Legal · Effective 1 October 2026
Privacy Policy
upbrief turns the work already happening in your team's tools into a morning briefing. To do that it reads data from the tools you connect. This page explains exactly what we collect, why, where it goes, and how you control it.
1. Who we are
upbrief ("upbrief", "we", "us") provides the upbrief website at upbrief.work and the upbrief application at app.upbrief.work (together, the "Service").
When an organisation signs up and connects its tools, that organisation is the controller of the work data it brings into upbrief, and we process that data on its behalf as a processor. For account, billing and website data, we are the controller.
2. What we collect
Account information
- Your name, email address and the team or workspace you belong to.
- Your password, stored only as a salted PBKDF2-SHA256 hash. We never store or see it in plain text.
- If you sign in with Google or your company's single sign-on (SSO), we receive your name, email address and a stable account identifier from that provider (
openid email profile). We do not receive your Google or SSO password.
Content you create or upload
- Documents you upload (for example statements of work or requirement lists), notes, standups, risks, tickets, handbook pages, comments and decisions you record in the Service.
- Credentials your team chooses to store in the Service's vault, which are encrypted at rest.
Billing information
For paid plans, a payment processor handles your card or bank details. We receive only the plan, billing status, and the contact and invoice details needed to bill you. We do not store full card numbers.
Technical information
Our servers record standard request logs (IP address, browser user agent, time and page requested) for security, abuse prevention and debugging. The marketing website does not use third-party analytics or advertising trackers.
3. Data from connected tools
upbrief only reads a tool after a member of your team connects it and grants access. Each connection asks for the narrowest permissions the feature needs:
| Tool | Permission requested | What we use it for |
|---|---|---|
| Jira (Atlassian) | read:jira-work write:jira-work read:jira-user offline_access | Read issues, sprints, statuses and assignees to build the briefing; create or update tickets only when a user approves a draft in upbrief. |
| GitHub | repo | Read pull requests, commits and review activity to show delivery progress, and add a webhook to repositories you choose so updates arrive promptly. We do not modify your code. |
| Slack | channels:history groups:history channels:read channels:join chat:write commands | Read messages in channels you add upbrief to (for standups and blockers), post the briefing and replies, and respond to slash commands. |
| Google Calendar | calendar.events.owned.readonly | Read the events on calendars you own (your primary calendar) for the next 24 hours: each meeting's title, start time, video link and attendee addresses, so upbrief can show what is coming up and give you a Join button. Read-only; we never create, change or delete events, and we do not read your calendar settings, sharing permissions or calendars you only subscribe to. |
| Email mailbox | SMTP/IMAP with an app password you provide | Send requests your team initiates (for example credential requests) and read the replies to those messages. |
You can disconnect any tool at any time from the app, or revoke access from the tool's own settings. After disconnecting, we stop fetching new data from that tool.
4. How we use data
- To provide the Service: compile briefings, show boards and reports, draft tickets and updates, and send the notifications and emails you set up.
- To secure the Service: authenticate users, prevent abuse and investigate incidents.
- To support you: answer questions and fix problems you report.
- To bill paid plans and send service and account messages.
We do not sell personal data, use it for advertising, or share it with data brokers.
5. AI processing
upbrief uses language models to summarise activity, classify requirements and draft text. Your data is processed only to produce results for your own workspace, and AI-generated drafts are shown to a person for review before anything is written back to your tools.
The models are self-hosted. upbrief runs open-weights models on hardware we operate: a text model served with llama.cpp on our own machine, reached only by our servers over an encrypted tunnel, and a small classification model running on our application server. Data, including data received from Google APIs, is processed locally on that infrastructure. It is never sent to an AI model provider or any third-party AI service, and never shared with anyone for training or any other secondary purpose. The model weights were downloaded once and do not report back to their publishers.
We do not use your workspace data or data from connected tools, including Google user data, to create, train or improve any AI or machine-learning model, ours or anyone else's.
Voice. If you speak to upbrief, your recording is sent to upbrief and transcribed by a speech model we host (Whisper), and spoken answers are produced by a voice model we host. Recordings and spoken answers are not stored. Where a workspace has no hosted speech models set up, your browser's built-in speech recognition and voice are used instead, and your browser sends the audio to its maker's service (Google for Chrome, Microsoft for Edge) under their terms; upbrief then receives only the text. The wake word, if you switch it on, listens only while the Briefing is open and shows that it is listening: with our models, only phrases you speak are sent, and only to our server; with the browser's recognition, everything said near your microphone goes to the browser's service while it is on. Your choice of microphone and speaker is kept in your browser only.
6. Google user data
upbrief's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data we receive from Google Calendar is:
- used only to show your upcoming meetings inside your upbrief workspace;
- not transferred to others except as needed to provide that feature, to comply with law, or as part of a merger or acquisition with notice to you;
- not used for advertising, and not used to train generalised AI or machine-learning models;
- not read by humans unless you give us permission, it is needed for security, or it is required by law.
7. Who we share data with
We share data only with service providers that help us run the Service, under contracts that limit their use of it to that purpose:
- hosting and infrastructure providers that run our servers and databases;
- email delivery providers that send account and notification emails;
- payment processors for paid plans.
Data you post to a connected tool through upbrief (for example a Slack message or a Jira ticket) is governed by that tool's own privacy policy. We may also disclose data if required by law, to protect the rights and safety of users or the public, or in connection with a merger or acquisition, in which case this policy will continue to apply.
8. Security
- Traffic to the Service is encrypted in transit with TLS.
- Access tokens for connected tools and vault credentials are encrypted at rest (Fernet / AES).
- Passwords are stored only as salted PBKDF2-SHA256 hashes.
- Session cookies are HTTP-only and marked secure; every credential reveal in the vault is attributed to the person who made it.
- Each team's data is kept separate, and access inside a team follows the roles your admins assign.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you and the relevant authorities as required by law.
9. Retention and deletion
We keep your data for as long as your account or workspace is active. When a workspace is closed, or when you ask us to delete it, we delete its data from our active systems within 30 days and from backups within 90 days, unless we must keep something longer to meet legal, tax or accounting obligations. Server logs are kept for a limited period for security purposes.
To delete your account or workspace, email us at the address below from the account's email address.
10. Cookies
We use only strictly necessary cookies:
upbrief_session: keeps you signed in to the app.- short-lived sign-in cookies (about 10 minutes) that protect Google, SSO and tool-connection sign-ins against forgery.
The app also stores your display preferences, such as light or dark theme, in your browser's local storage. We do not use advertising or cross-site tracking cookies.
11. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, and to complain to a data-protection authority. To exercise these rights, contact us. If your data came into upbrief through your employer's workspace, we may refer your request to that organisation as the controller, and we will help it respond.
12. Children
The Service is a workplace tool and is not directed at children under 16. We do not knowingly collect their personal data.
13. Changes to this policy
We may update this policy as the Service changes. We will post the new version here with a new effective date and, for material changes, notify workspace admins by email or in the app before the changes take effect.
14. Contact
Questions about privacy or requests about your data: allenanand2001@gmail.com.