Privacy Policy
Effective Date: July 18, 2026
SMS / Mobile Information Sharing (CTIA / A2P 10DLC Disclosure):
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Mobile opt-in data and consent will not be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
1. Introduction
AI Life Briefing ("we," "us," or "our") operates the AI Life Briefing service at https://ailifebriefing.com (the "Service"). This Privacy Policy describes what information we collect, how we use it, with whom we share it, and the choices you have. It applies to all users of the Service, including visitors to our public site and subscribers who enable email, web, push, or SMS delivery, and to the AI Life Briefing mobile app.
2. Information We Collect
We collect the following categories of information:
2.1 Account Information
- Name
- Email address
- Mobile phone number (optional, only if you enable SMS delivery)
- Institutional / organization (if provided during sign-up)
2.2 Microsoft 365 Data (with your explicit consent)
- Calendar events (titles, times, attendees, locations)
- Tasks / to-dos (Microsoft To Do and Planner: titles, due dates, completion status)
- Email metadata and, for the inbox folder only, email body contents used to generate your briefing and classify messages
- Email attachments: attachment names and metadata; if you enable attachment archiving, attachment files are copied into an "/ALB Archive" folder in your own OneDrive — the Service stores the resulting links, not the file contents
- OneDrive and SharePoint file metadata (filenames, folders, links) when you use file-related features; file contents are fetched transiently only when you open or attach a file and are not stored on our servers
- Microsoft Teams messages and channel/chat metadata, when you use the Teams features
- Contacts / people you correspond with (names, addresses, and interaction-derived rankings used to prioritize your briefing)
2.3 Usage & Diagnostic Data
- Interaction events within the web app (emails opened, actions taken, preferences changed)
- Device and session information (browser, operating system, approximate time zone)
- Error and crash reports (in-app JavaScript errors; on the iOS app, MetricKit crash diagnostics) used solely to fix defects
- Web-push subscription endpoints, if you enable push notifications
- SMS delivery status (delivered / failed / STOP received) from Twilio
2.4 SMS Opt-In Data
- The phone number you submit for SMS
- The timestamp, IP address, and user-agent captured at the moment you ticked the SMS consent checkbox
- The exact consent language displayed at the time of opt-in
2.5 Google Data (with your explicit consent)
If you connect a Google account, we access the following via Google APIs, using only the scopes you approve at the Google consent screen (the complete scope list is in Section 4.5):
- Gmail message metadata (sender, recipients, subject, date, labels, thread identifiers) and, for messages in your inbox, message body contents — used to generate your briefing, score and classify messages, and let you act on them (mark read, archive, label, send/reply) from within the Service
- Gmail labels (your label names and which labels are applied to a message) — used to reflect and update message state when you triage from the app
- Gmail settings, limited to mail filters — used only to create or remove a filter when you block or unblock a sender from within the app
- Google Calendar events (titles, times, attendees, locations) when you use calendar features
- Google Drive file metadata (filenames, folders, links) to show your files in the app's Files view; file contents are not stored on our servers
- Your Google account email address (from the userinfo scope) — used solely to identify which Google mailbox a briefing item came from
If you enable the optional mailbox bridge integration (used to connect an institutional mailbox through your own Google Drive), the Service reads and writes its transport files in dedicated /ALB-UC-* folders in your own Google Drive: mailbox-mirror files written there by your own automation are read by the Service, and command/journal files are written by the Service. Bridge housekeeping moves processed files to your Drive's trash, where they remain recoverable by you for 30 days under Google's standard trash behavior. These folders live in your Drive, under your control, at all times.
Gmail message content used to generate summaries and classifications is processed by our AI provider (Microsoft Azure OpenAI Service) on the same terms described for all other content in Sections 3, 4.1, and 6 — inside our own Azure environment, and never used to train models.
3. How We Use Your Information
We use the information we collect to:
- Generate and deliver your personalized daily briefing via email, the web app, push notifications, and (if you opted in) SMS
- Send time-sensitive task and calendar reminders
- Enable two-way conversational interactions with your AI assistant when you reply via SMS, email, or the web app
- Improve the Service's classification, ranking, and summarization behavior using your own interaction history (your data is never used to train models shared with other users)
- Operate, maintain, and secure the Service
- Respond to your requests and provide customer support
- Comply with legal obligations and enforce our Terms of Service
SMS / Mobile Information Disclosure (A2P 10DLC):
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Mobile opt-in data and consent will not be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support of our Services, such as SMS originator / message-delivery platforms (Twilio), is permitted for the sole purpose of delivering the messages you asked us to send. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
4. How We Share Your Information
We do not sell, rent, or trade your personal information. We share information only in the limited circumstances described below. All the categories of information described below exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
4.1 Service Providers (Subprocessors)
- Twilio — processes your mobile number solely to deliver SMS messages on our behalf. Twilio's privacy practices are available at https://www.twilio.com/legal/privacy.
- Microsoft — the Service connects to your Microsoft 365 account via the Microsoft Graph with scopes you approve. Microsoft's privacy practices are available at https://privacy.microsoft.com.
- Google LLC — if you connect a Google account, the Service connects to your Gmail, Google Calendar, and Google Drive via Google APIs with the scopes you approve at the Google consent screen. We use Google's APIs only to read, classify, and (with your authorization) act on your own messages, events, and files on your behalf. Google's privacy practices are available at https://policies.google.com/privacy.
- Cloud hosting & database (Microsoft Azure) — hosts the Service and stores your account record, preferences, interaction history, and per-user briefing data.
- AI processing (Microsoft Azure OpenAI Service) — briefing text and email content are processed by OpenAI models running on the Azure OpenAI Service within our own Azure subscription; content is not sent to OpenAI, L.L.C. Under Microsoft's Azure OpenAI terms, your content is not used to train models and is not shared with other customers. Microsoft's standard abuse-monitoring for the Azure OpenAI Service may retain prompts and completions for up to 30 days for abuse detection, which can include review by authorized Microsoft personnel; we are pursuing Microsoft's modified abuse-monitoring configuration (no logging, no human review) and will update this policy when it is in effect. Microsoft's Azure OpenAI data-privacy documentation is available at https://learn.microsoft.com/en-us/legal/cognitive-services/openai/data-privacy.
4.2 Legal Requirements
We may disclose information when required by law, subpoena, court order, or to protect the rights, safety, or property of AI Life Briefing, our users, or the public.
4.3 Business Transfers
If AI Life Briefing is involved in a merger, acquisition, or sale of assets, personal information may be transferred to the successor entity; you will be notified before your information is subject to a different privacy policy.
4.4 What We Never Share (CTIA / A2P 10DLC)
All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. Mobile information and opt-in consent will not be shared with third parties or affiliates for marketing or promotional purposes. We never share, sell, rent, license, or otherwise disclose your mobile phone number, SMS opt-in status, SMS consent metadata, or the content of SMS messages to third parties or affiliates for marketing or promotional purposes. This category is excluded from any data sharing described elsewhere in this policy.
4.5 Google API Services — Limited Use
AI Life Briefing's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the user-facing features of the Service for which you granted access — generating your daily briefing, scoring and classifying your messages, letting you read, archive, label, mark as read, block senders, and send or reply to your own Gmail messages, showing your Google Calendar events, and listing and linking your Google Drive files.
- We do not transfer Google user data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or asset sale (with notice to you, as described in Section 4.3).
- We do not use Google user data for serving advertisements of any kind, and we do not sell Google user data.
- We do not allow humans to read your Google user data unless (i) we first obtain your affirmative consent for specific messages, (ii) it is necessary for security purposes such as investigating abuse, (iii) it is required to comply with applicable law, or (iv) the data is aggregated and anonymized and used for internal operations. Briefing summaries and classifications are generated by automated AI processing (the Azure OpenAI Service, as described in Section 4.1).
- We do not retain user data obtained through Workspace APIs to develop, improve, or train non-personalized AI and/or ML models.
The complete set of Google scopes the Service may request at the consent screen, and what each is used for:
| Scope | Used for |
gmail.modify (restricted) | Reading your messages to build your briefing and message views; in-app triage actions on your own messages (archive, move, trash, mark read, label); and sending or replying to messages you compose in the app |
gmail.settings.basic (restricted) | Creating or removing a mail filter only when you block or unblock a sender |
calendar.readonly | Reading your events for the briefing and calendar views |
tasks | Reading your Google Tasks lists for the Tasks view, and completing, adding, editing, or deleting a Google task only when you do so in the app |
userinfo.email | Identifying which Google account is connected |
drive.readonly (restricted) | Listing your Drive files in the Files view, and reading the bridge's mailbox-mirror files from your own Drive (Section 2.5) |
drive.file | Writing the Service's own bridge command/journal files into your Drive (only files the Service itself creates) |
The scopes marked "restricted" are restricted scopes under the Google API Services User Data Policy. You may grant or decline scopes at the Google consent screen, and you may revoke them at any time (see Section 8). Signing in with Google (as a login method) uses only the basic OpenID scopes (openid, email, profile) and grants no mailbox, calendar, or file access.
5. SMS / Text Messaging Program
5.1 Program Description
If you opt in, AI Life Briefing will send recurring automated text messages including: (a) your daily briefing summary, (b) time-sensitive calendar and task reminders, and (c) two-way assistant replies when you message us first.
5.2 How You Opt In
SMS is optional. You opt in by (i) providing your mobile number on the public sign-up form at https://ailifebriefing.com, (ii) ticking an initially unchecked consent checkbox, and (iii) submitting the form. The consent language is reproduced in full at the point of sign-up. A separate in-app confirmation step is available in Settings at https://ailifebriefing.com/app.
5.3 Message Frequency
Message frequency varies by your settings. Typical usage is 1–3 messages per day; the cap is 10 messages per day.
5.4 Costs
Message and data rates may apply according to your mobile carrier plan. AI Life Briefing does not charge a fee for SMS delivery.
5.5 How to Opt Out
Reply STOP to any message at any time to immediately cancel SMS delivery. Other accepted opt-out keywords: OPTOUT, CANCEL, END, QUIT, UNSUBSCRIBE, REVOKE, STOPALL. You may also disable SMS at any time in the web app under Settings → Notifications. Opting out of SMS does not terminate your AI Life Briefing account; email and web delivery continue.
5.6 Help
Reply HELP or INFO to receive contact information. You may also email support@ailifebriefing.com.
5.7 Carriers
Supported carriers include AT&T, Verizon, T-Mobile, Sprint, Boost, Cricket, MetroPCS, U.S. Cellular, Google Fi, and most other U.S. mobile carriers. Carriers are not liable for delayed or undelivered messages.
6. Data Retention and Deletion
- Account information is retained for as long as your account is active. When you delete your account (Section 8), your account record is removed immediately along with your data, as described below.
- Microsoft 365 data (calendar, tasks, email metadata, inbox bodies, file and Teams metadata) is cached on secured servers for the operational life of your account to produce briefings instantly. Email bodies are removed when the source message is archived, deleted, or moved out of the inbox; a short preview snippet is retained with the email metadata.
- Google / Gmail data (Gmail message metadata, labels, inbox bodies, Google Calendar events, and Drive file metadata) is cached on secured servers for the operational life of your account to produce briefings instantly. Gmail message bodies are removed when the message is archived, trashed, or no longer carries the inbox label; a short preview snippet is retained with the message metadata.
- On Google disconnect (Settings → disconnect, or revoking access at https://myaccount.google.com/permissions): your stored Google OAuth tokens are disabled immediately, and the cached Google data — Gmail message rows, Drive file listings, Google sync state, and the link between your Google identity and your account — is deleted at disconnect time.
- On account deletion (Settings → Account → Delete Account, or by emailed request): all data the Service stores for you — cached Microsoft 365 and Google content, preferences, interaction history, AI conversation history, push subscriptions, and your account record — is deleted immediately as part of the deletion request, and provider access tokens are disabled or revoked. Encrypted database backups that include your data age out automatically within 30 days. Operational server logs are short-lived and rotate automatically.
- Attachment archives and bridge files live in your own storage — files the Service copied into your OneDrive "/ALB Archive" folder or bridge files in your Google Drive
/ALB-UC-* folders are yours, in your own accounts, and are unaffected by deleting your AI Life Briefing account; remove them from your OneDrive/Drive whenever you wish.
- AI processing content — content processed by the Azure OpenAI Service within our Azure subscription is never used for model training; Microsoft's standard abuse-monitoring may retain prompts and completions for up to 30 days (see Section 4.1; we are pursuing the no-logging configuration).
- SMS opt-in records (timestamp, IP, user-agent, exact consent language) are retained for at least 4 years after opt-out, as required by A2P 10DLC / CTIA record-keeping guidance.
- SMS message content and delivery logs are retained per Twilio's standard retention (approximately 13 months) for delivery troubleshooting and regulatory purposes.
7. Data Security
We use TLS 1.2+ for all data in transit, per-user encryption for sensitive at-rest fields, JWT-based authentication, and role-based access controls. OAuth refresh tokens for connected Microsoft and Google accounts are stored encrypted at rest in Azure Key Vault. Only authorized personnel may access production systems. No system is perfectly secure; we commit to notifying affected users in the event of a data breach as required by applicable law.
8. Your Rights and Choices
- Data Export: Download a complete copy of the data the Service stores for you at any time, in the app under Settings → Account → Download My Data (a JSON file).
- Account Deletion: Delete your account and all associated data directly in the app under Settings → Account → Delete Account — no email or support contact required. Deletion takes effect immediately as described in Section 6. You may also email support@ailifebriefing.com to request deletion, correction of inaccuracies, or a copy of your data.
- SMS Opt-Out: Reply STOP to any SMS (see Section 5.5), or toggle SMS off in Settings.
- Microsoft 365 Consent Revocation: Revoke at any time via your Microsoft account (https://account.microsoft.com/privacy → Apps and services). Instructions are available in the web app under Settings.
- Google Consent Revocation: Revoke the Service's access to your Gmail, Google Calendar, and Google Drive at any time at https://myaccount.google.com/permissions, or disconnect from within the web app under Settings. Revoking access stops all future data access; cached data is deleted as described in Section 6.
- California Residents (CCPA/CPRA): You have the right to know, delete, correct, and opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined.
- EEA / UK Residents (GDPR): You have rights of access, rectification, erasure, restriction, portability, and objection. Contact us to exercise these rights. You may lodge a complaint with your local data-protection authority.
9. Children's Privacy
The Service is not directed to children under 18. We do not knowingly collect personal information from children under 18. If you believe a child has provided us information, contact us and we will delete it.
10. International Data Transfers
The Service is operated from the United States. If you access the Service from outside the U.S., your information will be transferred to, stored, and processed in the U.S. By using the Service, you consent to this transfer.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The "Effective Date" at the top reflects the latest revision. For material changes we will notify you via the email address associated with your account and post a prominent notice in the web app.
12. Contact Us
Questions or requests? Contact us at:
AI Life Briefing
Email: support@ailifebriefing.com
Web: https://ailifebriefing.com