Legal

Privacy Policy

Last updated: May 28, 2026 · Effective: May 28, 2026

On this page

About DayBrief

DayBrief ("DayBrief", "we", "us", or "our") is an SMS‑based daily briefing service operated from Ontario, Canada. We integrate with Google Calendar to generate personalised morning briefings and let users manage their calendar via text message. This Privacy Policy describes what we collect, how we use it, who we share it with, how long we keep it, and the rights you have over your information. By signing up for or using DayBrief, you agree to this Policy.

Information we collect

Information you provide

Information we receive from Google

When you connect Google Calendar, we receive an OAuth access token and refresh token from Google, along with the calendar event data we explicitly request. See the dedicated Google user data section below for full details.

Information collected automatically

Information we do not collect

Google user data

Summary: DayBrief reads and (only at your explicit SMS request) writes to your Google Calendar. We never use that data for advertising, never sell it, never share it with third parties for unrelated purposes, and never use it to train machine‑learning models.

Scopes we request

DayBrief requests the following Google OAuth scope during signup, and only this scope:

https://www.googleapis.com/auth/calendar Full read and write access to your Google Calendars. Required because DayBrief reads upcoming events to build briefings and creates, updates, or deletes events on your behalf when you explicitly request a calendar change via SMS (for example: "add gym tomorrow 7am").

We do not request, receive, or store any other Google user data. We do not access Gmail, Drive, Contacts, Photos, Tasks, or any other Google product.

What we do with Google Calendar data

We do not read your free/busy availability outside the primary calendar. We do not read other users' calendars, even if they are shared with you. We do not modify events that you did not ask us to modify.

How long we store Google data

How we protect your Google user data

We treat Google user data — including OAuth access tokens, refresh tokens, and any calendar event content read at request time — as sensitive data, and apply the following specific protection mechanisms:

Limited Use — compliance with Google API Services User Data Policy

DayBrief's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In plain English, this means:

How to revoke DayBrief's access to your Google account

You can revoke DayBrief's access to your Google Calendar at any time. Two ways:

  1. Visit myaccount.google.com/permissions, find DayBrief, and choose "Remove access". This immediately revokes the tokens we hold.
  2. Email info@daybrief.ca or text "delete my account" to your DayBrief number. We will revoke and delete your tokens, and delete your account data within 30 days.

Revoking access does not automatically cancel a paid subscription — please cancel from your dashboard or text "cancel" to your DayBrief number as well.

How we use your information

Sharing and disclosure

We do not sell your personal information. We share data only with the service providers strictly necessary to operate DayBrief, each of which is contractually bound to handle data in accordance with this Policy and applicable law:

We may also disclose information if required by law, regulation, valid legal process, or to protect the rights, safety, or property of DayBrief, our users, or others.

Data retention

Your rights

You have the right to:

To exercise any of these rights, email info@daybrief.ca. We respond within 30 days.

Security — how we protect sensitive data

We treat the following categories as sensitive data and apply specific, named protection mechanisms to each: Google OAuth access and refresh tokens, calendar event content, SMS conversation history, authentication credentials, account identifiers, and payment‑adjacent metadata. The mechanisms below apply across all sensitive data unless noted otherwise.

Encryption

Authentication and access control

Data minimisation and retention

Monitoring, auditing, and incident response

Secure development

Sub‑processor security

Each sub‑processor listed under Sharing and disclosure is contractually required to maintain comparable security controls. Our principal sub‑processors maintain widely recognised security attestations:

No method of transmission or storage is 100% secure, and no security program can guarantee absolute prevention of unauthorised access. We commit to applying the mechanisms above continuously, reviewing them at least annually, and improving them as the threat landscape changes. If you have specific questions about our security posture, contact us at info@daybrief.ca.

Children's privacy

DayBrief is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with information, please contact us and we will delete it.

Changes to this Policy

If we make material changes to this Privacy Policy, we will notify you by SMS, by email, or by prominent notice on this page at least 14 days before the changes take effect. Non‑material changes (clarifications, typos) may be made without notice. The "Last updated" date at the top of this page always reflects the most recent version.

Contact

If you have questions about this Privacy Policy or how we handle your data, contact us:

DayBrief is operated from Ontario, Canada. This Policy is governed by the laws of Ontario. For users in the EU/UK, we comply with GDPR requirements; for users in California, we comply with CCPA/CPRA requirements. For specific regional rights, contact us at the email above.