Briefly Wealth LLC ("Brieflywealth," "we," "us," or "our") offers the Briefly platform to financial advisory firms through two surfaces: (1) a hosted, browser-based application (the "Web App"), and (2) a connector that a firm installs locally to use Briefly inside Anthropic's Claude application (the "Connector"). This Privacy Policy describes how we collect, use, disclose, and protect information across both surfaces, collectively the "Service." Where a practice differs between the two, the relevant section says so and labels the Web App and the Connector separately.
By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our practices, please do not use the Service.
Quick take. Briefly does not sell or share Personal Information as those terms are defined under the California Consumer Privacy Act (Cal. Civ. Code § 1798.140(ad), (ah)). We do not engage in cross-context behavioral advertising. We honor Global Privacy Control (GPC) signals from California, Colorado, Connecticut, and other states that recognize universal opt-out preference signals. The Service is intended for use by customers and end clients located in the United States. For Connector Customers specifically: client files stay on the customer's own computer, and Briefly does not receive or store client documents or data through the Connector.
Information We Collect
What Briefly collects depends on which surface of the Service you use. Subsection (a) covers the Web App. Subsection (b) covers the Connector.
(a) Web App Customers
This subsection applies to firms and users who access the hosted Briefly application through a web browser ("Web App Customers").
Account Information. When you create an account, we collect your name, email address, company or firm name, job title, and other registration details you provide.
Client Documents and Data. The Web App allows you to upload, transmit, or otherwise provide documents and data related to your clients, including but not limited to financial statements, account summaries, portfolio data, email correspondence, meeting notes, and CRM records ("Client Data"). Client Data may contain nonpublic personal information ("NPI") as defined under the Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.). You are responsible for ensuring you have the necessary rights, consents, and permissions to provide this Client Data to us for processing, including compliance with any applicable client agreements, advisory contracts, or regulatory obligations.
Usage Data. We automatically collect information about how you interact with the Web App, including pages viewed, features used, session duration, browser type, operating system, device identifiers, IP address, and referring URLs.
Cookies and Tracking Technologies. We use cookies, pixels, and similar technologies to maintain sessions, remember preferences, and analyze usage patterns. You may control cookie settings through your browser, though some features of the Web App may not function properly without them.
Communications. When you contact us for support, provide feedback, or otherwise communicate with us, we collect the contents of those communications along with any associated metadata.
Biometric Information. The Service does not collect, capture, or otherwise obtain biometric identifiers or biometric information as defined under the Illinois Biometric Information Privacy Act (740 ILCS 14/1 et seq.) ("BIPA"). We do not use facial recognition, voiceprint analysis, fingerprint scanning, or any other biometric technology in the operation of the Service. This applies to both the Web App and the Connector.
Categories of Personal Information (Web App). The following table summarizes the categories of Personal Information we process for Web App Customers, the sources, the purposes, and whether the category constitutes Sensitive Personal Information ("SPI") under the California Privacy Rights Act.
| Category | Examples | Source | Used for | SPI under CPRA? |
|---|---|---|---|---|
| Identifiers | Name, email, account ID | From Customer, end-client documents | Service delivery, support | No |
| Customer Records (Cal. Civ. Code § 1798.80(e)) | Contact info, address | From Customer documents | Service delivery | No |
| Commercial Information | Subscription plan, billing records | From Customer | Service delivery, billing | No |
| Internet / Network Activity | IP, device, browser, session logs | From your use of the Web App | Security, support, debugging | No |
| Geolocation | Approximate (city / region from IP) | Derived | Security, fraud detection | No |
| Professional Information | Advisor employer, role, RIA firm CRD | From Customer | Service delivery | No |
| Inferences | Model-generated brief content from Client Data | Derived | Service delivery | No |
| Sensitive Personal Information | End-client financial account information, account values, holdings, transactions, beneficiary details | From Customer-uploaded documents | Service delivery only | Yes |
Sensitive Personal Information. Financial account information about your end clients constitutes Sensitive Personal Information under CCPA § 1798.140(ae)(2)(B). We use SPI only for the purposes permitted under § 1798.121(a) and the implementing regulations, namely to provide the Web App the Customer requested. We do not use SPI to infer characteristics about a consumer. This SPI table applies to Web App Customers only; see subsection (b) for what Briefly holds on Connector Customers.
(b) Connector Customers
This subsection applies to firms and users who use Briefly through the locally installed Connector inside Claude ("Connector Customers").
What the Connector does not send us. The Connector reads client files from a folder on the customer's own computer. Those files, and any Client Data within them, are not uploaded to or stored by Briefly. Briefly's servers do not receive client documents, financial account information, holdings, transactions, or any other Client Data through the Connector.
Account and sign-in information. To provision and authenticate a Connector Customer's account, Briefly's servers receive and store the same category of account information described in subsection (a): name, email address, firm name, job title, and related registration details, processed through Amazon Cognito.
Seat and entitlement records. We store records of which seats, features, and entitlements are assigned to a Connector Customer's account, used to license and meter the Connector.
De-identified preference rules. As a Connector Customer uses the Service, Briefly's servers may receive and store de-identified, tokenized preference rules, small pieces of learned formatting or workflow preference that are stripped of client names, account numbers, and other identifying detail before they leave the customer's computer.
Usage telemetry. When a Connector Customer uses a Briefly tool inside Claude, the Connector sends Briefly's servers a usage event record describing the call: the tool invoked, the event type (query, capture, injection, or artifact), the outcome (for example success or error), seat and firm identifiers, an internal compute-cost figure, and timestamps. These records do not include the contents of the customer's files, prompts, or Outputs. We use them to license and meter seats, monitor reliability, and understand feature usage.
Categories of Personal Information (Connector). The following table summarizes what Briefly processes for Connector Customers. No row in this table includes client documents, financial account information, or other Client Data, because Briefly does not receive it through the Connector.
| Category | Examples | Source | Used for | SPI under CPRA? |
|---|---|---|---|---|
| Identifiers | Name, email, account ID | From Customer at sign-up | Account provisioning, authentication | No |
| Commercial Information | Seat count, plan tier, entitlement records | From Customer, Briefly billing systems | Licensing, billing | No |
| Internet / Network Activity | Sign-in logs, IP address at authentication | From the Connector's sign-in flow | Security, fraud detection | No |
| Usage Telemetry | Tool-call event records: tool name, event type, outcome, seat and firm identifiers, timestamps (no file contents, prompts, or Outputs) | From the Connector's tool calls | Seat licensing and metering, reliability, feature usage | No |
| Inferences | De-identified, tokenized preference rules (formatting and workflow preferences only) | Derived on Customer's computer, transmitted de-identified | Personalizing the Connector | No |
See the engineering-confirmation flag above regarding the de-identification guarantee behind the Inferences row.
How We Use Your Information
For Web App Customers, we use the information we collect for the following purposes:
- To provide, operate, and maintain the Web App, including processing Client Data through artificial intelligence models to generate meeting preparation briefs and related outputs.
- To create and manage your account and authenticate your identity.
- To improve, personalize, and develop new features for the Service.
- To communicate with you, including sending service-related notices, updates, and promotional materials (with your consent where required by law).
- To monitor and analyze usage trends and the effectiveness of the Service.
- To detect, prevent, and address technical issues, fraud, and security concerns.
- To comply with legal obligations and enforce our agreements.
For Connector Customers, we use the account-layer information described in § 01(b) only to provision and authenticate accounts, license and meter seats and entitlements, personalize the Connector using de-identified preference rules, communicate with you about the Service, detect and address technical issues, fraud, and security concerns affecting the account layer, and comply with legal obligations. We do not use this information to process, analyze, or generate outputs from your Client Data, because we do not receive your Client Data.
Artificial Intelligence Processing
Web App Customers
How we use AI. Briefly uses third-party large language models to extract information from Customer-uploaded documents and to generate briefs, agendas, and follow-up notes. AI processing happens only on data the Customer has authority to provide.
No training on Client Data. We route Client Data only to AI sub-processors that contractually prohibit the use of inputs and outputs for training general-purpose models. As of the date above, our sole AI sub-processor is Anthropic, PBC, operating under its Commercial Terms (§ B.1). A current list of AI sub-processors is maintained at brieflywealth.com/subprocessors.
No automated decision-making about consumers. Outputs are decision-support materials only. Briefly does not make significant decisions about end consumers (as defined in CCPA Regs § 7200(a)) and does not engage in profiling that produces legal or similarly significant effects. The Customer (the RIA firm) remains the human decision-maker for all client recommendations.
Connector Customers
The Connector reads client files locally and passes relevant content into the customer's own Claude conversation. That AI processing runs on the customer's own Claude or Anthropic plan, under the customer's own agreement with Anthropic, not through a Briefly-operated AI pipeline. Briefly does not transmit client data to Anthropic on the customer's behalf.
The Claude boundary. Content a Connector Customer passes into a Claude conversation is handled by Anthropic under the customer's own agreement with Anthropic and Anthropic's own privacy documentation, not under this Policy. Briefly does not control, and is not responsible for, Anthropic's retention or use of that content. Anthropic offers plan types that differ in how customer content is retained and used; selecting a plan appropriate to the customer's regulatory obligations is the customer's responsibility.
How We Share Your Information
We share Personal Information only with sub-processors that perform Service functions on our behalf under written agreements requiring them to protect Personal Information consistent with this Policy. We do not sell or share Personal Information for cross-context behavioral advertising.
Sub-processors. We engage the sub-processors below to deliver the Service. What each sub-processor can access differs between Web App Customers and Connector Customers; see the "Applies to" column. We provide at least thirty (30) days' advance notice via the linked page before adding or replacing a sub-processor that processes Client Data. The current canonical list, including non-data-processing and marketing-site sub-processors, is at brieflywealth.com/subprocessors.
| Sub-processor | Purpose | Data categories | Applies to | Location |
|---|---|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting (compute, storage, database, Cognito authentication) | Account Information, Usage Data, and, for Web App Customers, Client Data | Web app (all customer data categories); Connector (account and entitlement data only) | United States (us-east-2, Ohio) |
| Anthropic, PBC | LLM inference for document extraction and brief generation | Client Data passed in prompts; Outputs | Web app (client data passed in prompts). Not a Briefly sub-processor for Connector Customers; the customer's own Anthropic plan governs. | United States |
| Stripe, Inc. | Payment processing (merchant of record) for seat and subscription purchases | Purchaser name, work email, payment card, and billing records (Commercial Information) | Both surfaces (seat purchase and subscription billing only; not Client Data) | United States |
We may disclose Personal Information if required by law, court order, or governmental request, or where we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, or to investigate fraud or respond to a government request.
Data Security
We implement commercially reasonable technical and organizational measures designed to protect the information we collect and store, consistent with the administrative, technical, and physical safeguards contemplated under 15 U.S.C. § 6801(b) of the Gramm-Leach-Bliley Act. These measures include encryption of data in transit and at rest, role-based access controls, regular security assessments, and audit logging. For Connector Customers, this program protects the account-layer data described in § 01(b), which is what Briefly holds for that surface.
Our information security program is informed by industry-recognized frameworks, including the SOC 2 Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy). Formal certification is on our roadmap, not yet in audit. In the interim, we apply commercially reasonable safeguards aligned with SOC 2 principles and evaluate our critical service providers based on their own security certifications and practices.
However, no method of transmission over the Internet or electronic storage is completely secure, and we cannot guarantee absolute security. In the event of a data breach involving your information, we will notify you in accordance with applicable state and federal data breach notification laws.
Incident notification. If we discover unauthorized access to or acquisition of Web App Client Data, we will notify the affected customer (the RIA firm) without unreasonable delay and in no event later than seventy-two (72) hours after confirmation, providing sufficient detail to enable the customer to meet its own SEC Regulation S-P (17 CFR § 248.30) 30-day client-notification obligation. We will also comply with applicable state breach notification laws, including 815 ILCS 530/10 for Illinois residents and Cal. Civ. Code § 1798.82 for California residents. For Connector Customers, because Briefly does not hold Client Data, this commitment applies to incidents involving the account-layer data described in § 01(b), under the same 72-hour standard.
Data Retention
Web App Customers
We retain Personal Information according to the following schedule:
- Account information. Duration of account plus seven (7) years (SEC books-and-records analog).
- Client Data. Duration of Customer subscription plus a 30-day export window plus 90-day backup expiration; secure deletion within 30 days thereafter.
- AI prompt and output logs at AI sub-processors. 30 days at our AI sub-processor (Anthropic); no extended retention by Briefly.
- Usage and analytics data. 14 months (industry-standard default).
- Support communications. Three (3) years from last interaction.
- Backups. Rolling 90 days.
Connector Customers
Because Briefly does not receive or store Connector Customers' Client Data, this schedule does not apply to Client Data for that surface; there is no Client Data at Briefly to retain or delete. Retention applies only to the account-layer data described in § 01(b):
- Account information. Duration of account plus seven (7) years (SEC books-and-records analog), consistent with the Web App schedule.
- Seat and entitlement records. Duration of account plus seven (7) years.
- De-identified preference rules. Retention period to be confirmed.
- Backups. Rolling 90 days.
If a longer retention period is required by law, regulation, or legitimate business purpose (for example, defense of legal claims), we will retain the relevant data only as long as necessary for that purpose.
Your Rights and Choices
Your rights
Depending on your state of residence, you may have the following rights under applicable privacy law:
- Know / Access. Request confirmation of whether we process Personal Information about you and obtain a copy.
- Correct. Request correction of inaccurate Personal Information.
- Delete. Request deletion of Personal Information.
- Portability. Receive a copy of Personal Information in a portable, machine-readable format.
- Opt out of sale or sharing. Direct us not to sell or share Personal Information (we already do not).
- Limit the use of Sensitive Personal Information. Direct us to limit our use of SPI to permitted purposes (we already do).
- Opt out of profiling. Opt out of profiling in furtherance of decisions that produce legal or similarly significant effects (we do not engage in such profiling).
- Non-discrimination. We will not discriminate against you for exercising any of these rights.
Opt-out preference signals. We recognize and honor browser-based universal opt-out preference signals, including Global Privacy Control (GPC), as valid opt-out requests in states that require them. Because we do not sell Personal Information or share it for cross-context behavioral advertising, a GPC signal does not change how we handle your data; it is honored as confirmation of a practice that is already our default.
How to submit a request
Submit requests to contact@brieflywealth.com. We will acknowledge within ten (10) business days and respond within forty-five (45) calendar days, extendable once by an additional forty-five (45) days with written notice. We verify requests by matching the account email plus one additional identifier. If we deny your request, you may appeal by replying to our denial. We will respond to appeals within sixty (60) days. Authorized agents may submit requests on your behalf with written authorization. We will contact you to verify the agent's authority.
Service-provider routing. Where Briefly processes Client Data on behalf of an RIA Customer, we will route end-client requests to the Customer (the controller) within ten (10) business days, and the Customer is responsible for substantive response.
For Connector Customers, the Personal Information within scope of the rights above is limited to the account-layer data described in § 01(b), since Briefly does not receive or store your Client Data through the Connector.
Illinois-Specific Disclosures
For users and clients located in Illinois, we provide the following additional disclosures:
Biometric Information. As stated in Section 1, the Service does not collect biometric identifiers or biometric information as defined under the Illinois Biometric Information Privacy Act (740 ILCS 14/1 et seq.). If this practice changes in the future, we will update this Privacy Policy and obtain all required consents before any collection of biometric data occurs.
Personal Information Protection. We comply with the Illinois Personal Information Protection Act (815 ILCS 530/1 et seq.) with respect to notification obligations in the event of a data breach involving personal information of Illinois residents.
Third-Party Links and Services
The Service may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.
Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information.
Changes to This Privacy Policy
For material changes to this Policy, we will provide at least thirty (30) days' advance notice via email to account administrators and through the Service before the change takes effect. Non-material changes will be reflected by updating the "Last updated" date at the top of this Policy. Continued use of the Service after a material change becomes effective constitutes acceptance of the updated Policy.
Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at: