Privacy
What Bryeo collects, and what it doesn't
Last updated August 2026. Bryeo is pre-launch; this page describes the product as it is built today and will be updated as it changes.
What Bryeo reads
Only the sources you explicitly connect, and only with read permission:
- Task status, owners, and deadlines
- Cells in sheets and files you connect
- Calendars you connect, for meeting recap
- Emails you explicitly CC
- Blockers your team marks
Every integration scope Bryeo requests is read-only. It cannot edit, move, or delete anything in your Google or Microsoft account.
What Bryeo never reads
- Keystrokes
- Screens or screenshots
- Webcams
- Private messages
- Browsing history
- Anything you haven't connected
There is no keystroke logging, screen capture, webcam access, or activity monitoring anywhere in the product.
Where it is stored
Company data is stored in a Postgres database hosted by Supabase in Singapore, with row-level security enabled on every table. Integration access tokens are encrypted at rest with AES-256-GCM before they are written.
Who else processes it
Bryeo relies on the following sub-processors. Each receives only what its function requires:
- Supabase
- Database and authentication hosting (Singapore).
- OpenRouter
- Routes MARK requests to a language model. Receives the slice of your company data relevant to the question being asked, scoped to the asker's permissions.
- Vercel
- Application hosting and request logs.
- Resend
- Transactional and inbound task email.
- Google / Microsoft
- Only the sources you connect, read-only.
- PostHog
- Website analytics on marketing pages only, not inside the product.
AI processing
When someone asks MARK a question, Bryeo assembles the portion of your data that the asker is permitted to see and sends it to a third-party model provider to generate the answer. Bryeo does not train any model on your data. Bryeo does not control the retention or training policies of the model provider, and does not make a claim on their behalf.
How long it is kept
Retention is configurable per organisation. Memory items default to 365 days and meeting recap data to 90 days; past the window, records are hard-deleted rather than flagged. Disconnecting a source stops all further reads immediately.
Deletion
Write to founders@bryeo.com to have your company's data deleted. Nothing you own moves or changes in your own Google or Microsoft account either way — Bryeo never had permission to alter it.
Marketing analytics
These marketing pages record anonymous usage — page views, scroll depth, which calls to action are clicked, and where the visit came from — to work out which parts of the page are doing their job. No product data is involved.
This page describes Bryeo's actual technical behaviour and has not been reviewed by a lawyer. It is not a substitute for a data processing agreement; Enterprise customers receive one.