BriefDesk App LLC
Privacy Policy
Last updated August 14, 2026
This Privacy Policy explains how BriefDesk App LLC, a Virginia limited liability company (“BriefDesk,” “we,” “us,” or “our”), handles information when you use the BriefDesk website, application, support channels, and related services (collectively, the “Service”).
1. Information we collect
- Account information: name, email address, authentication identifiers, account settings, and security events. Our authentication provider stores password credentials; BriefDesk does not receive your plaintext password.
- Academic workspace information: semesters, courses, schedules, class meetings, readings, assignments, cases, exams, study plans, notes, outlines, task status, and the links and metadata used to organize materials.
- Syllabus and note processing: when you import a syllabus, BriefDesk keeps a private temporary review copy so you can compare extracted details with the original after a reload. The copy is removed when you import or discard the draft and otherwise expires after 24 hours. We retain the file name, type, size, cryptographic hash, import status, and the extracted proposal you approve. Handwritten-note originals are saved to your Google Drive when you use that feature; transcription drafts and review status may be stored in BriefDesk and in a Google Doc you control.
- Connected-service information: if you connect Google, we store an encrypted Google authorization credential and file or calendar metadata needed to provide features you request. If you subscribe, Stripe provides customer, subscription, invoice, status, and limited payment-method metadata; BriefDesk does not store complete card numbers.
- Communications: your name, email address, subject, message, and our correspondence when you contact us.
- Technical and usage information: IP address, browser and device information, request identifiers, pages or features used, error reports, rate-limit records, and security logs.
2. How we use information
We use information to provide and secure the Service; create and maintain your workspace; process syllabi and notes at your request; connect Google Drive and Calendar; administer subscriptions; provide support; diagnose errors; prevent fraud and abuse; improve usability; comply with law; and enforce our Terms of Service. We do not sell personal information or use academic content for targeted advertising.
3. AI processing
When you choose an AI-assisted feature, the relevant syllabus, image, PDF, text, or prompt is sent to OpenAI through its business API to produce the requested extraction or transcription. BriefDesk requests that responses not be stored by the model endpoint and deletes staged API files after processing. OpenAI states that API data is not used to train its models by default and that abuse-monitoring data may ordinarily be retained for up to 30 days, subject to its terms, legal obligations, and available data controls. Always review AI-produced information before relying on it.
4. When we disclose information
We disclose information only as needed to operate the Service, complete a transaction you request, protect users and the Service, or comply with law. Categories of recipients include:
- Supabase for database, authentication, and related infrastructure.
- Vercel for application hosting and delivery.
- OpenAI for AI processing you initiate.
- Google for Drive, Docs, and Calendar features you connect.
- Stripe for checkout, subscription billing, invoices, and payment support.
- Resend for delivery of messages submitted through our contact form.
- Professional advisers, authorities, or transaction parties when reasonably necessary for legal compliance, safety, claims, financing, merger, acquisition, or sale of assets, subject to appropriate protections.
5. Google data
BriefDesk requests Google permissions only for features you choose. Google Picker performs Drive browsing and searching inside Google's interface; BriefDesk does not receive a listing of your Drive. We receive only files you deliberately select, plus files and folders BriefDesk creates for you. The limited drive.file permission lets BriefDesk open or update those specific files and write to Google Docs it may access; we do not request a separate all-Docs permission. The calendar.events.owned permission is used to create, update, and remove BriefDesk-managed class events on calendars you own; BriefDesk does not import or display your other calendar events.
You may disconnect Google from Settings at any time. BriefDesk attempts to revoke the Google credential and removes it from BriefDesk, but disconnecting does not delete files, folders, Docs, or calendar events already created in your Google account.
6. Retention and deletion
We retain account and workspace information while your account is active and as needed to provide the Service. Temporary syllabus review files are removed at import or discard and expire after 24 hours if a draft is abandoned. You may export your account data and permanently delete your account from Settings. Account deletion initiates deletion of BriefDesk account records and stored connection credentials; files in your Google Drive remain under your control. Service providers may retain limited backups, security records, billing records, or API data for their documented retention periods, and we may retain information when required for fraud prevention, dispute resolution, tax, accounting, or other legal obligations.
7. Your choices and privacy rights
You can review and correct workspace information in the Service, download a private JSON export, disconnect Google, or delete your account in Settings. You may also email contact@briefdeskapp.com to request access, correction, deletion, portability, or another privacy right available where you live. We may verify your identity before acting.
Where the Virginia Consumer Data Protection Act or a similar law applies, you may also request to opt out of qualifying sale, targeted advertising, or profiling. BriefDesk does not currently sell personal data or use it for targeted advertising. If we decline a request, you may appeal by replying to our decision with the subject “Privacy Appeal.” We will respond within the period required by applicable law.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information, including encrypted transport, provider encryption at rest, row-level access controls, encrypted Google credentials, scoped authorizations, authenticated data access, upload validation, rate limiting, and restricted administrative access. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
9. Cookies and similar technologies
BriefDesk uses cookies and local storage necessary for authentication, security, preferences, and core product operation. If we introduce non-essential analytics or advertising technologies, we will update this notice and provide any consent controls required by law.
10. Children
The Service is intended for users who are at least 18 years old and is not directed to children. If you believe a child provided personal information, contact us so we can investigate and delete it as appropriate.
11. Changes and contact
We may update this policy as the Service or law changes. We will post the revised policy with a new effective date and provide additional notice when required.
Privacy questions and requests may be sent to contact@briefdeskapp.com. The data controller is BriefDesk App LLC, a Virginia limited liability company.
