Privacy
What Bryeo collects, and what it doesn't
Last updated August 2026. Bryeo is pre-launch; this page describes the product as it is built today and will be updated as it changes.
What Bryeo reads
Only the sources you explicitly connect, and only with read permission:
- Task status, owners, and deadlines
- Cells in sheets and files you connect
- Calendars you connect, for meeting recap
- Audio and transcripts of meetings you send a recap bot to
- Emails you explicitly CC
- Blockers your team marks
Every integration scope Bryeo requests is read-only. It cannot edit, move, or delete anything in your Google or Microsoft account.
Account and usage data
Separately from connected sources, Bryeo stores what it needs to run the account itself:
- Your name, work email, and the company and role you belong to
- Session cookies that keep you signed in
- An audit record of security-relevant actions — who invited or removed someone, who changed a role, who connected or disconnected an integration, and who opened a support session
- Operational logs kept by our hosting provider, including IP address and request metadata
Meeting recap, audio, and transcripts
If you use Recap, a meeting bot joins the calls you point it at and produces a transcript. That means audio and speech from those meetings — including from anyone else present — leaves Bryeo and is processed by third parties: the meeting-bot provider that captures the call, and a model provider that turns speech into text. Transcripts, participant lists, and anything derived from them are then stored in your company's database alongside the rest of your data.
Recording a meeting has consent obligations in many jurisdictions, and they fall on you as the organiser rather than on Bryeo. Recap is off until someone in your company turns it on and sends a bot to a specific meeting.
Email you send to Bryeo
Bryeo has an inbound address you can CC. When you do, the full content of that email — subject, body, sender, and recipients — is received by our email provider, verified as genuine by signature, and parsed into a task. The message content is sent to a model provider to work out what the task is. If you do not CC Bryeo, it never sees the message.
What Bryeo never reads
- Keystrokes
- Screens or screenshots
- Webcams
- Private messages
- Browsing history
- Anything you haven't connected
There is no keystroke logging, screen capture, webcam access, or background activity monitoring anywhere in the product. Bryeo has no agent on anyone's machine and cannot see what someone is doing outside the sources you connect.
What Bryeo works out about people
Being precise about this, because “we don't monitor people” would be too convenient a summary: Bryeo does derive per-person measures from the work you connect. It records how many tasks someone holds, which are late and by how long, how often deadlines move, and how that changes over time, and it uses those measures to suggest who a task should go to and to flag work at risk. It keeps daily snapshots so it can show a trend.
All of that is computed from task and calendar records you already connected — not from observing anyone. It is nonetheless information about identifiable employees, it is visible to managers and executives in your company subject to the permissions you configure, and employees should be told it exists. Where you are the employer, telling them is your responsibility.
Bryeo does not make automated decisions that produce legal or similarly significant effects about anyone. Its output is a recommendation for a person to act on.
Where it is stored
Company data is stored in a Postgres database hosted by Supabase in Singapore, with row-level security enabled on every table so that a query issued for one company cannot return another company's rows. Integration access tokens are encrypted at rest with AES-256-GCM before they are written. Traffic to and from the application is encrypted in transit.
Who else processes it
Bryeo relies on the following sub-processors. Each receives only what its function requires:
- Supabase
- Database and authentication hosting (Singapore).
- OpenRouter
- Routes MARK requests to a language model, and converts meeting and voice audio to text. Receives the slice of your company data relevant to the question being asked, scoped to the asker's permissions.
- Vexa
- Meeting bot for Recap. Joins the calls you send it to and captures the audio and transcript.
- Vercel
- Application hosting and request logs.
- Resend
- Transactional email, and receiving the inbound task email you CC.
- Connected work tools
- Only the sources you connect, read-only. Today that can include Google Workspace, Microsoft 365 and Dynamics, Slack, Zoom, Asana, ClickUp, Monday, Atlassian, GitHub, Zendesk, Zoho and Freshdesk. Nothing is contacted until you connect it.
- PostHog
- Website analytics on marketing pages only, not inside the product.
These providers operate in several countries, so using Bryeo involves transferring data outside the country you are in. This list changes as the product changes; this page is the current version of it.
AI processing
When someone asks MARK a question, Bryeo assembles the portion of your data that the asker is permitted to see and sends it to a third-party model provider to generate the answer. Bryeo does not train any model on your data. Bryeo does not control the retention or training policies of the model provider, and does not make a claim on their behalf.
Who can see your data at Bryeo
Bryeo support staff can open a customer workspace to investigate a problem. This is restricted to staff accounts holding that specific permission, every session is written to the audit record with the staff member and the time, and a banner is displayed in the product for the duration so it is never silent. Aside from that, access to production data is limited to what operating the service requires.
How long it is kept
Retention follows Vision §7.1 layers. Signal skeletons and content are kept for the life of the account (subject to subject erasure). Meeting audio is dropped after 90 days while transcripts remain. Conversation memory rolls at 90 days; extracted facts persist. Processing logs are kept at least one year; consent records at least seven. Disconnecting a source stops further reads immediately. Erasure removes personal content for a named subject while keeping the structural record that aggregates depend on, and completes as PITR backups roll off.
Your rights
Depending on where you are, you may have the right to ask for a copy of the personal data Bryeo holds about you, to have it corrected, to have it deleted, to object to or restrict how it is used, and to complain to a data protection authority. Bryeo honours these requests regardless of whether the law where you live compels it.
Where your employer connected the data, they decide what is collected and Bryeo processes it for them — so a request about your own records is usually fastest through your employer. You can also write to us directly at the address below and we will route it.
If something goes wrong
If a breach affects your data, Bryeo will notify affected customers and the relevant authority without undue delay once the scope is understood, and will say what happened rather than issue a holding statement. Bryeo holds no security certification today and does not claim one.
Deletion and contact
Write to founders@bryeo.com to have your company's data deleted, to exercise any of the rights above, or to raise a privacy concern. The same address reaches the person accountable for privacy questions at Bryeo. Nothing you own moves or changes in your own Google or Microsoft account either way — Bryeo never had permission to alter it.
Cookies and marketing analytics
Inside the product, Bryeo sets only the cookies needed to keep you signed in and to remember which company you are currently viewing. There is no advertising or cross-site tracking cookie anywhere in the product.
These marketing pages record anonymous usage — page views, scroll depth, which calls to action are clicked, and where the visit came from — to work out which parts of the page are doing their job. No product data is involved.
This page describes Bryeo's actual technical behaviour and has not been reviewed by a lawyer. It is not a substitute for a data processing agreement; Enterprise customers receive one.