BREKFUZ INC.

Privacy Policy

Brekfuz connects to an organisation’s Gmail, Google Calendar and Slack, indexes that content, and answers questions grounded in it. This policy explains what that means for the data.

LAST UPDATED 19 AUGUST 2026

Privacy Policy Security Overview Subprocessors Security · The Architecture

Brekfuz is an enterprise knowledge platform. It connects to an organisation’s Gmail, Google Calendar and Slack, indexes that content, and allows authorised users to query it and receive answers grounded in their own organisational records.

This policy explains what we access, what we store, who else touches it, and what you can ask us to do about it.

01

Our role

When a company uses Brekfuz, that company is the data controller and Brekfuz is the data processor. We handle their data only to run the service, and only on their instructions.

If you are employed by an organisation that uses Brekfuz and have questions about why it was deployed, direct them to your employer. The employer determines which sources are connected and who may access them.

02

What we access

Brekfuz never acts as you. Gmail and Google Calendar are connected with read-only permissions: Brekfuz cannot send, reply to, forward, edit, move or delete anything in your mailbox or calendar, and no message or invitation is ever sent from your address or on your behalf.

Slack is the one exception, and only in one direction. Brekfuz is installed as an app with its own identity, and it can post replies and reactions in channels it has been added to — always visibly as Brekfuz, never as you, and never as a direct message from your account. It cannot edit or delete anyone’s messages.

SourceWhat we read
GmailSubject and message body, sender and recipients (To, Cc, Bcc), labels, and attachment names, types and sizes. We do not download or store attachment files themselves.
Google CalendarEvent titles, descriptions, locations, times, organiser and attendees.
Workspace DirectoryNames and email addresses of people in your organisation.
SlackMessages in channels the Brekfuz application has been granted access to, plus channel names and member names. Brekfuz can post replies and reactions in those channels under its own app identity.

Optional connectors — GitHub, Jira, Linear and Fireflies — are enabled only at the customer’s election.

Messages in Spam, Trash and the Promotions category are excluded from processing.

03

How far back we look

When you first connect a source, we read a window of history:

  • Gmail — 365 days by default; 90 days is the minimum
  • Google Calendar — 120 days back, 30 days ahead
  • Slack — up to 365 days, limited by what your Slack plan makes available (Slack’s Free plan only exposes the last 90 days)
  • GitHub, Jira, Linear — 180 days

Thereafter the platform processes new activity incrementally.

04

What we do with it

We use your content to:

  • index it so your team can search and ask questions across it
  • send relevant excerpts to AI model providers so they can generate an answer
  • build a private map of who works on what, so questions get routed to the right person

We do not use your data for advertising. We do not sell it. We do not use it to train AI models — ours or anyone else’s.

05

Google API Limited Use

Brekfuz’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • we use Google data only to provide and improve the features you can see in Brekfuz
  • we do not transfer it to anyone except as needed to run the service, to comply with the law, or as part of a merger or acquisition with prior notice
  • we never use it for advertising
  • we do not let people read it, except with your explicit permission, where necessary for security, to comply with the law, or where the data is aggregated and anonymised
  • we do not use it to develop, improve or train generalised AI or machine learning models
06

Who else touches your data

Brekfuz uses a small number of vendors to run the service. Each one is bound by contract to protect your data and use it only to provide their service to us.

The current list is on our subprocessor page. We give customers at least 30 days’ notice before adding a new one.

07

Where your data is stored

Brekfuz is hosted in the United States. Our application and primary database run in Amazon Web Services (US East, Ohio). Our search index runs in Google Cloud (US Central). Our other vendors are US-based.

If your organisation is in the UK or EU, this means your data is transferred to the United States. Our Data Processing Agreement includes the European Commission’s Standard Contractual Clauses to cover that transfer.

We do not currently offer EU or UK data residency.

08

How long we keep it

Customer content is retained for the duration of the active subscription. There is no automatic expiry today — content stays indexed until you ask us to remove it or you close your account.

Content is deleted on request. On termination, customer content is removed from Brekfuz systems.

Backup copies are held for disaster recovery and are overwritten on their normal cycle. Deleted content can persist in a backup until that cycle completes.

09

Your rights

Depending on where you live, you have the right to ask for a copy of your data, correct it, delete it, restrict how it’s used, object to how it’s used, or receive it in a portable format.

If you’re an employee at a customer company, send your request to your employer. They control the data, and we act on their instruction.

If you’re a Brekfuz customer, contact us at support@brekfuz.com. We respond within 30 days.

You can disconnect any source at any time from your Brekfuz settings. You can also revoke Brekfuz’s access directly in your Google Account or Slack settings.

If you’re in the UK or EU and you’re not satisfied with how we’ve handled a request, you can complain to your local data protection authority.

10

How we protect it

  • All data is encrypted in transit
  • Gmail content and stored credentials are additionally encrypted by Brekfuz using AES-256-GCM with keys held in AWS Key Management Service
  • Every customer’s data is separated at the database level, enforced by the database itself rather than only by application code
  • Access to production systems is limited to staff who need it
  • All personnel are bound by confidentiality and invention-assignment agreements

The long version is our Security Overview.

11

Other people in your data

Emails and calendar invites naturally contain people outside your company — customers, partners, suppliers. When we index that content, we store their names and email addresses as they appear, and we may record what they were involved in.

If you’re one of those people and want your details removed, contact the Brekfuz customer whose account holds them, or write to us at support@brekfuz.com and we’ll pass it on.

Customers using Brekfuz should reflect this in their own privacy notice.

12

Children

Brekfuz is a workplace product and is not intended for anyone under 16.

13

Changes to this policy

If we make a material change, we’ll notify customers by email and update the date at the top of this page.

14

Contact

support@brekfuz.com — privacy and data requests, and security reports.

CONTINUE READING
Security Overview Subprocessors

Questions about this policy, or a request about your data?

Ask us anything Back to the site FOUND SOMETHING WE GOT WRONG? SUPPORT@BREKFUZ.COM · WE ANSWER FAST