Privacy

What Bryeo collects, and what it doesn't

Last updated August 2026. Bryeo is pre-launch; this page describes the product as it is built today and will be updated as it changes.

What Bryeo reads

Only the sources you explicitly connect, and only with read permission:

  • Task status, owners, and deadlines
  • Cells in sheets and files you connect
  • Calendars you connect, for meeting recap
  • Emails you explicitly CC
  • Blockers your team marks

Every integration scope Bryeo requests is read-only. It cannot edit, move, or delete anything in your Google or Microsoft account.

What Bryeo never reads

  • Keystrokes
  • Screens or screenshots
  • Webcams
  • Private messages
  • Browsing history
  • Anything you haven't connected

There is no keystroke logging, screen capture, webcam access, or activity monitoring anywhere in the product.

Where it is stored

Company data is stored in a Postgres database hosted by Supabase in Singapore, with row-level security enabled on every table. Integration access tokens are encrypted at rest with AES-256-GCM before they are written.

Who else processes it

Bryeo relies on the following sub-processors. Each receives only what its function requires:

Supabase
Database and authentication hosting (Singapore).
OpenRouter
Routes MARK requests to a language model. Receives the slice of your company data relevant to the question being asked, scoped to the asker's permissions.
Vercel
Application hosting and request logs.
Resend
Transactional and inbound task email.
Google / Microsoft
Only the sources you connect, read-only.
PostHog
Website analytics on marketing pages only, not inside the product.

AI processing

When someone asks MARK a question, Bryeo assembles the portion of your data that the asker is permitted to see and sends it to a third-party model provider to generate the answer. Bryeo does not train any model on your data. Bryeo does not control the retention or training policies of the model provider, and does not make a claim on their behalf.

How long it is kept

Retention is configurable per organisation. Memory items default to 365 days and meeting recap data to 90 days; past the window, records are hard-deleted rather than flagged. Disconnecting a source stops all further reads immediately.

Deletion

Write to founders@bryeo.com to have your company's data deleted. Nothing you own moves or changes in your own Google or Microsoft account either way — Bryeo never had permission to alter it.

Marketing analytics

These marketing pages record anonymous usage — page views, scroll depth, which calls to action are clicked, and where the visit came from — to work out which parts of the page are doing their job. No product data is involved.

This page describes Bryeo's actual technical behaviour and has not been reviewed by a lawyer. It is not a substitute for a data processing agreement; Enterprise customers receive one.

← Back to home