Brekfuz connects to an organisation’s Gmail, Google Calendar and Slack, indexes that content, and answers questions grounded in it. This policy explains what that means for the data.
LAST UPDATED 19 AUGUST 2026
Brekfuz is an enterprise knowledge platform. It connects to an organisation’s Gmail, Google Calendar and Slack, indexes that content, and allows authorised users to query it and receive answers grounded in their own organisational records.
This policy explains what we access, what we store, who else touches it, and what you can ask us to do about it.
When a company uses Brekfuz, that company is the data controller and Brekfuz is the data processor. We handle their data only to run the service, and only on their instructions.
If you are employed by an organisation that uses Brekfuz and have questions about why it was deployed, direct them to your employer. The employer determines which sources are connected and who may access them.
Brekfuz never acts as you. Gmail and Google Calendar are connected with read-only permissions: Brekfuz cannot send, reply to, forward, edit, move or delete anything in your mailbox or calendar, and no message or invitation is ever sent from your address or on your behalf.
Slack is the one exception, and only in one direction. Brekfuz is installed as an app with its own identity, and it can post replies and reactions in channels it has been added to — always visibly as Brekfuz, never as you, and never as a direct message from your account. It cannot edit or delete anyone’s messages.
| Source | What we read |
|---|---|
| Gmail | Subject and message body, sender and recipients (To, Cc, Bcc), labels, and attachment names, types and sizes. We do not download or store attachment files themselves. |
| Google Calendar | Event titles, descriptions, locations, times, organiser and attendees. |
| Workspace Directory | Names and email addresses of people in your organisation. |
| Slack | Messages in channels the Brekfuz application has been granted access to, plus channel names and member names. Brekfuz can post replies and reactions in those channels under its own app identity. |
Optional connectors — GitHub, Jira, Linear and Fireflies — are enabled only at the customer’s election.
Messages in Spam, Trash and the Promotions category are excluded from processing.
When you first connect a source, we read a window of history:
Thereafter the platform processes new activity incrementally.
We use your content to:
We do not use your data for advertising. We do not sell it. We do not use it to train AI models — ours or anyone else’s.
Brekfuz’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
Brekfuz uses a small number of vendors to run the service. Each one is bound by contract to protect your data and use it only to provide their service to us.
The current list is on our subprocessor page. We give customers at least 30 days’ notice before adding a new one.
Brekfuz is hosted in the United States. Our application and primary database run in Amazon Web Services (US East, Ohio). Our search index runs in Google Cloud (US Central). Our other vendors are US-based.
If your organisation is in the UK or EU, this means your data is transferred to the United States. Our Data Processing Agreement includes the European Commission’s Standard Contractual Clauses to cover that transfer.
We do not currently offer EU or UK data residency.
Customer content is retained for the duration of the active subscription. There is no automatic expiry today — content stays indexed until you ask us to remove it or you close your account.
Content is deleted on request. On termination, customer content is removed from Brekfuz systems.
Backup copies are held for disaster recovery and are overwritten on their normal cycle. Deleted content can persist in a backup until that cycle completes.
Depending on where you live, you have the right to ask for a copy of your data, correct it, delete it, restrict how it’s used, object to how it’s used, or receive it in a portable format.
If you’re an employee at a customer company, send your request to your employer. They control the data, and we act on their instruction.
If you’re a Brekfuz customer, contact us at support@brekfuz.com. We respond within 30 days.
You can disconnect any source at any time from your Brekfuz settings. You can also revoke Brekfuz’s access directly in your Google Account or Slack settings.
If you’re in the UK or EU and you’re not satisfied with how we’ve handled a request, you can complain to your local data protection authority.
The long version is our Security Overview.
Emails and calendar invites naturally contain people outside your company — customers, partners, suppliers. When we index that content, we store their names and email addresses as they appear, and we may record what they were involved in.
If you’re one of those people and want your details removed, contact the Brekfuz customer whose account holds them, or write to us at support@brekfuz.com and we’ll pass it on.
Customers using Brekfuz should reflect this in their own privacy notice.
Brekfuz is a workplace product and is not intended for anyone under 16.
If we make a material change, we’ll notify customers by email and update the date at the top of this page.
Questions about this policy, or a request about your data?
Ask us anything Back to the site FOUND SOMETHING WE GOT WRONG? SUPPORT@BREKFUZ.COM · WE ANSWER FAST