Brylee Privacy Policy
Version: v0.6
Effective date: October 6, 2026
Operated by: Brisco Communications, Inc., a Georgia corporation. Brylee is a service of Brisco Communications, Inc. 6595 Roswell Rd, Suite G2280, Atlanta, GA 30328. Email support@bryleeai.com. Phone 1-888-230-1090.
1. Who we are and what this covers
Brylee is an automation and business phone platform for businesses and individuals. It is a service of Brisco Communications, Inc., a Georgia corporation ("we," "us," "Brisco"). This policy explains what information we collect, how we use and protect it, and the choices and rights you have. It covers bryleeai.com, app.bryleeai.com, the Brylee API, Brylee phone and messaging features, and related services (the "Service").
2. Whose data is it: three situations
It helps to separate three situations:
- Data about you and your account (your name, email, billing status, how you use Brylee). For this data, we decide how it's handled, and this policy is the rulebook. This is true for every user, business or individual.
- Data you put into Brylee for yourself. If you use Brylee as an individual (your own tables, forms, automations, files and messages), there is no company in between: we are directly responsible to you for that personal information under privacy law, and this policy is the rulebook for all of it. Your rights in Section 13 apply to everything you've put in, not just your account details.
- Data a business puts into Brylee that belongs to other people (for example, data its forms collect from its customers, or calls and texts with its customers). That data is the business's responsibility. We process it only on the business's instructions, to run the Service. If you run a business on Brylee, you are responsible for having the right to collect that data and for telling your own customers how you use it. If one of your customers asks us directly about their data, we will point them to you, because the relationship is yours, not ours.
3. What we collect
You give us:
- Account and workspace data: name, email, workspace details, and your role in each workspace.
- Sign-in data: you sign in with a 6-digit code we email to you, with a password, or with your Google, Microsoft or GitHub account. When you use Google, Microsoft or GitHub to sign in, we ask only for your basic identity and email address (the "openid" and "email" permissions), nothing else. Passwords are stored hashed, never in plain text. You can turn on two-factor authentication for extra protection.
- Billing data: handled by our payment processor, Stripe. We store a customer and subscription reference and its status. We never see or store your full card number, and our staff never type card numbers for you. Phone service is not yet available. When offered, if you add phone service, we ask for a payment card before phone service starts, including during a free trial, and that card is charged automatically when a phone trial ends (Terms of Service, Section 4). We use your account email to send you a reminder 2 days before that first charge.
- Content you create: Tasks and their configuration, tables, forms, dashboards, files, and the data your automations process and store.
- Ask brylee conversations: your chat messages with the assistant.
- Phone service data (if you use our phone features): see Section 7.
- Support messages: what you send us when you ask for help.
You authorize us to hold (connected accounts and keys):
- When you connect a third-party app (like Google or Slack), you grant Brylee specific permissions ("scopes"). We access only what's needed to run the features you use, and we request the minimum scopes necessary.
- OAuth tokens and API keys are stored encrypted in a credential vault that we run ourselves, with no third-party credential broker. Credentials are used only to perform the actions your automations and requests call for, and are never shown back to you or written to logs. When you disconnect an app, its credential is removed from the vault.
We collect automatically:
- Usage and diagnostics: log data, run history, error traces, IP address, and device and browser information, used to operate, secure, debug and improve the Service.
- Cookies: one sign-in session cookie, shared across
bryleeai.comsubdomains so you stay signed in as you move between them. That is the only cookie Brylee itself sets. We run no analytics, advertising or session-recording tools in Brylee, so there is nothing to consent to and nothing to opt out of. A blocking check in our build pipeline fails if any third-party tracking script is ever added, so this stays true rather than relying on memory. - Bot check: our sign-up page and public forms use Cloudflare Turnstile to tell people from bots. Turnstile looks at signals from your browser (such as your IP address and browser type) to do that check, only to detect and block bots, and does not use them for advertising or to profile you. See Cloudflare's Turnstile Privacy Addendum at https://www.cloudflare.com/turnstile-privacy-policy/.
4. How we use information
- Provide the Service: run the Tasks you build, including reading and writing your connected-account data exactly as your automations specify, and run your phone and messaging features.
- AI features: see Section 6.
- Billing: manage subscriptions and usage charges through Stripe, and calculate taxes and telecom fees.
- Communications: transactional email (sign-in codes, verification, receipts, alerts, run notifications, and notices about your phone account) sent from
notify.bryleeai.comthrough Mailgun; product updates you can opt out of. - Security and abuse prevention: detect fraud, enforce limits, and protect customers from each other.
- Emergency calls: use the 911 location you give us to route emergency calls, and send the 911 call alerts you set up (Section 7).
- Improvement: diagnose issues and improve reliability and features.
We do not sell your personal information. We do not use your data for advertising. We do not train AI models on your data.
5. Google user data: Limited Use disclosure
Brylee's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What we ask Google for, and why. We only ask for a Google permission when you turn on a feature that needs it, and you see Google's own consent screen before anything is shared:
- Sign in with Google (openid, email): to confirm who you are and get your email address.
- Google Sheets: to read and write the spreadsheets your automations use.
- Google Calendar events: to read, create and change calendar events your automations work with.
- Google Docs and Google Slides: to create and fill in documents and presentations your automations produce.
- Google Tasks: to read and create tasks your automations work with.
- Google Contacts: to read and update contacts your automations use.
- Google Drive, only files you pick or Brylee creates (drive.file), and Drive file names and details, not contents (drive.metadata.readonly): so you can choose files for your automations.
- Gmail, send (gmail.send): to send email from your own Gmail address when your automation says to. This permission lets Brylee send mail. It does not let Brylee read your inbox.
- Gmail, read: Gmail inbox reading is not currently offered. Brylee does not currently request a Gmail read permission.
How we use Google data, including Gmail data. Data we get through Google APIs, including any Gmail data:
- is used only to provide the user-facing features you turned on and can see in Brylee, such as the automations you build that read or write your Google data;
- is not transferred to anyone else except (a) as needed to provide or improve those features (for example, to our hosting providers, or to Amazon Bedrock when you ask an AI feature to work with that data, under terms that stop them keeping or training on it), (b) for security, such as investigating abuse, (c) to comply with the law, or (d) as part of a merger, acquisition or sale of assets, with notice to you;
- is not used for advertising of any kind, including personalized, retargeted or interest-based ads, and is never sold;
- is not used to decide whether you qualify for credit or a loan;
- is not read by any person at Brylee, except (a) when you ask us to, for example to troubleshoot a problem, and give us permission, (b) when needed for security, such as investigating abuse or a bug that affects your account, (c) when the law requires it, or (d) when the data has been combined and made anonymous for internal operations, in line with the law;
- is never used to develop, improve or train AI or machine-learning models, whether generalized models or any other kind. This includes our own models and any third party's.
You can review and remove Brylee's access to your Google Account at any time at myaccount.google.com/permissions, and you can disconnect any connected app from within Brylee. When you disconnect, we delete the Google credential right away. Google data your automations already copied into Brylee (for example, rows in a Brylee table) stays in your workspace until you delete it or your workspace is deleted.
6. AI processing
- When an AI feature runs (an automation step that uses AI, an AI-assisted build, the Ask brylee assistant, or, when offered, the AI receptionist deciding what to say), the data needed for that request is sent to Amazon Bedrock, AWS's AI service, for processing. Today we use Anthropic's Claude models through Bedrock. We may also use other models that Bedrock hosts (for example, OpenAI models), always inside Bedrock and under the same rules. Bedrock is a sub-processor under our AWS agreement, and Bedrock does not keep your prompts or results.
- Cloudflare Workers AI, on Cloudflare's network, is used for voicemail transcription. The AI receptionist is not yet available, and its speech engine has not been finalized. Before it is offered, this policy will name every provider that handles callers' audio or transcripts and describe their retention and training terms. Cloudflare states that it does not use this content to train any AI model or to improve its or anyone else's services.
- We do not train AI models on your data, and your inputs and outputs are not used to improve third-party AI models.
- Ask brylee chat history is kept for roughly 90 days, then deleted. If you delete a chat, it is permanently removed within 30 days.
- AI output can be wrong. Review what your automations produce (see the Terms of Service, Section 6).
7. Phone, texting and voicemail
Phone service and the AI receptionist are not yet available. This section applies when phone features are offered and you use them: business phone numbers, calls, text messages, voicemail, or the AI receptionist.
What we collect:
- Call records: who called whom, when, for how long, and how the call was routed.
- Text messages: the content of texts sent and received on your Brylee numbers, and their delivery records.
- Voicemail: the audio and a written transcript. We keep a cached copy of voicemail audio for up to 30 days, then delete it. The transcript is kept for as long as the voicemail itself exists: when you or anyone in your workspace deletes the voicemail, its transcript is deleted too, and you can delete just the transcript at any time.
- Call recordings: only if you turn recording on. Recording is off by default.
- AI receptionist conversations: what the caller says and what the receptionist says back, turned into text so the receptionist can answer, and a summary so you can see what happened.
- 911 location: the address you register for each phone line and device, and the people you choose to alert when 911 is called.
Customer proprietary network information (CPNI). As a provider of phone service, we are subject to the Federal Communications Commission's CPNI rules. CPNI is information about your phone service: who you call, when, how often, and what services you use. We commit to the following:
- We use CPNI only to provide and bill your phone service, to protect against fraud and abuse, and as the law otherwise allows. We do not use or share it to market other services to you without your permission, and we do not sell it.
- Before we discuss call details with anyone by phone, they must give the account's CPNI passcode, or we send the information only to your address of record or call you back at your phone number of record. Online access to call details requires signing in to your Brylee account.
- When your passcode, your online account, your address of record, or the backup way you confirm your identity is created or changed, we notify you right away at your existing contact details, without revealing the new information.
- If CPNI or other personal information about your phone account is accessed without permission, we notify the FCC and federal law enforcement and then notify you, within the times the rules set.
- An officer of Brisco certifies our compliance to the FCC every year.
Call recording is your responsibility. Some states require every person on a call to agree before it is recorded. If you turn recording on, you are responsible for following the recording-consent laws that apply to you and the people you talk to, such as playing a notice at the start of calls.
911. We use your registered 911 location to send emergency calls to the right emergency center and give responders your address. Keep that address current. When someone dials 911, we also alert the people you chose for that location, by email and, if you set it up, by text or automated call. The Terms of Service, Section 10, explains the limits of 911 on internet phone service.
Who handles phone data for us: our phone system servers run on Oracle Cloud (OCI) in Ashburn, Virginia; our telecom carrier, Telnyx, connects calls and texts to the phone network; Cloudflare Workers AI transcribes voicemail; Amazon Bedrock will decide what the AI receptionist says when it is offered; its speech providers will be disclosed before launch; and Cloudflare stores the cached copy of voicemail audio. See Section 8.
Your customers' calls. When your customers call or text your business, their information is your business's data (Section 2, situation 3).
8. Who we share data with (sub-processors)
We share data only with the service providers below, which we use to operate Brylee, and only as far as needed for their role. We don't have data-sharing side deals.
| Provider | What they do for Brylee | Where |
|---|---|---|
| Cloudflare | Application hosting and compute (Workers), file storage (R2), operational data stores (D1, KV, Durable Objects), background jobs (Queues), voicemail transcription (Workers AI), AI receptionist speech providers to be disclosed before launch, bot checks (Turnstile), network security | Global network |
| PlanetScale | Main database (PlanetScale Postgres, hosted for PlanetScale by a major US cloud provider) | United States |
| Amazon Web Services (AWS) | AI processing (Amazon Bedrock) for automations, Ask brylee and, when offered, the AI receptionist | United States |
| Stripe | Payment processing and subscription billing | United States (global processor) |
| CereTax (coming soon) | Sales tax and telecom tax calculation, using your billing address and what you bought | United States |
| Mailgun | Transactional email delivery (notify.bryleeai.com) | United States |
| Oracle Cloud (OCI) | Hosts our phone system servers | United States (Ashburn, Virginia) |
| Telnyx | Our telecom carrier: connects your calls and texts to the phone network | United States |
| Pulsetic | Uptime monitoring for our public status page (status.bryleeai.com). It checks whether the Service is up and receives only technical metadata, never your data | External monitoring |
| The apps you connect | Receive and provide data only as your automations direct (for example, Brylee sends the email or writes the row you configured) | Per that provider |
We may also disclose information when required to comply with law, to enforce our terms, to protect rights and safety, or as part of a merger or acquisition (with notice to you). We will update this table when providers change, including when we add telecom carriers, and we will announce material changes.
9. Where your data lives
- Our main data store is PlanetScale Postgres, hosted in the United States.
- Some data is stored and processed on Cloudflare's global network (which is what makes the app fast wherever you are). That means some operational and application data may be processed outside the United States in the course of serving requests.
- Our phone system servers run on Oracle Cloud in Ashburn, Virginia, United States.
- We do not currently offer a guaranteed single-country data-residency option. If you need strict data residency, ask us before relying on Brylee for that data.
10. How we protect it: the honest version
- Encryption. Data is encrypted in transit (TLS) and at rest. Sensitive values (OAuth tokens, API keys, and designated sensitive fields) are also encrypted inside our application before they are stored.
- Workspace isolation. Each workspace's data is kept separate from every other customer's. In our main database, the database itself enforces that separation (PostgreSQL row-level security), not only our application code. Our other data stores go through a single access layer that always scopes data to one workspace, and an automated check blocks any code change that tries to get around it.
- Sign-in protection. Email codes, optional two-factor authentication, and bot checks on sign-up.
- Access. Least-privilege access controls and audit logging.
- Backups. Our main database's stated backup retention is currently 2 days, pending a custom schedule; our other data stores have provider recovery windows of up to 30 days; some copies, such as automation run logs, are kept in write-once storage that cannot be changed or deleted for 30 days.
- What we don't have yet, stated plainly: we are not SOC 2 certified (a future goal, not a present fact), we are not HIPAA compliant, and we do not sign Business Associate Agreements. Do not put protected health information (PHI) into Brylee.
- No method of transmission or storage is 100% secure. If we learn of a breach that affects your data, we will notify you without undue delay, consistent with applicable law, and tell you what we know, what we're doing, and what you can do.
11. How long we keep data
| Data | How long |
|---|---|
| Account and workspace content | While your account or workspace is active |
| Items you delete (Tasks, tables, rows, dashboards) | Kept in trash for 30 days so you can restore them, then permanently deleted |
| Ask brylee chat history | About 90 days; a chat you delete is removed within 30 days |
| Accounts whose email was never verified | Deleted after 7 days |
| Data export files | Download link and file expire after 7 days |
| Voicemail audio (cached copy) | Up to 30 days |
| Voicemail transcripts | As long as the voicemail exists; deleted with it, or sooner if you delete the transcript |
| Connected credentials (OAuth tokens, API keys) | Until you disconnect the app or the workspace is deleted |
| Audit logs | Depends on your plan: Free 7 days, Starter 90 days, Pro 1 year, Business 2 years, Scale and Enterprise 7 years |
| After you delete a workspace | 30-day grace period (you can change your mind or export), then erased from every data store, with a record that each store was checked |
| Backups | Deleted data ages out of backups within 30 days |
| Billing, tax and phone call-billing (toll) records | At least 18 months, as federal telecom rules require, and longer where tax law requires |
| CPNI breach records | At least 2 years, as federal telecom rules require |
Deletion and backups: our commitment. When data is deleted (by you, at your request, or on the schedule above), we remove it from all active systems within the stated window. Copies stay in backups only until those backups expire on their fixed schedule (within 30 days), and some copies are kept in write-once storage that cannot be changed before it expires. We do not use backups to repopulate deleted data. If we ever restore from a backup (for example, to recover from a failure), we delete again anything that had already been deleted, so a restore never brings back data or an account that asked to be deleted.
12. Your controls in the product
- Export. You can export your data yourself, free, on every plan, from inside Brylee. You get a machine-readable file, and the download link expires after 7 days (you can always make a new one). If you need help, email us and a person will help.
- Correction and deletion. You can edit or delete your content in the product. Deleting a workspace starts the 30-day grace period in Section 11.
- Disconnect. You can disconnect any connected app at any time.
- Two-factor authentication. You can turn it on in your account settings.
- Call recording. Off unless you turn it on.
- Voicemail transcripts. You can delete a transcript, or the whole voicemail, at any time.
- Marketing. Product-update emails have an opt-out. Transactional emails (sign-in codes, receipts, security alerts, phone account notices) are part of the Service.
- Privacy rights. The law where you live may give you rights over your personal information. Section 13 spells them out and explains exactly how to use them.
- Other people's data a business collected. If someone's data is in Brylee because a business collected it (for example, through that business's form, or by calling that business), we will direct that person to the business. We process that data on the business's instructions (Section 2).
13. Your privacy rights
Several US state privacy laws (California's CCPA and CPRA, and similar laws in Virginia, Colorado, Connecticut and a growing list of other states) give you specific rights over your personal information. This section is written to satisfy those laws, but we handle requests the same way for everyone: you do not have to prove which state you live in before we will help you.
What we collect, why, and who handles it
In the categories those laws use:
| Category | What that is in Brylee | Why we have it | Who handles it for us |
|---|---|---|---|
| Identifiers | Name, email, phone numbers, IP address | Your account, sign-in, phone service, security | Hosting and infrastructure providers (Cloudflare, PlanetScale, Oracle Cloud) |
| Commercial information | Plan, subscription status, payment and usage history | Billing | Payment processor (Stripe); tax calculation (CereTax, coming soon) |
| Internet activity | Usage logs, run history, device and browser info | Operating, securing and debugging the Service | Hosting and infrastructure providers; Cloudflare Turnstile bot check |
| Phone service information | Call records, texts, voicemail and transcripts, recordings if you turn them on, AI receptionist conversations, 911 location | Providing your phone service and routing emergency calls | Oracle Cloud, Telnyx, Cloudflare, Cloudflare Workers AI, Amazon Bedrock (AI receptionist) |
| Content you provide | Tables, forms, files, automations, chat and support messages | It's the product: we store and process it for you | Hosting and infrastructure providers; AI processing (Amazon Bedrock) when an AI feature runs; email delivery (Mailgun) for transactional email |
| Sensitive information | Credentials for accounts you connect (stored encrypted); the content of email you send through Gmail and, when offered, text messages | Sign-in; running the automations and features you turn on | Held in our own encrypted vault and data stores; never given to a credential broker |
Section 8 names every provider. We collect nothing beyond this: no location tracking beyond what an IP address or your registered 911 address reveals, no biometrics, and no browsing history from other sites.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Nobody pays us for your data, and no advertising network receives it. We do not use your sensitive information for anything beyond providing the Service. Because we don't sell or share personal information, there is nothing to opt out of.
The rights
- Know and access. Ask what personal information we have about you and get a copy of it.
- Delete. Ask us to delete your personal information. Deletion follows the schedule and backup rules in Section 11, and we never restore deleted data from backups. Some records we are required to keep (for example, billing and phone toll records kept for tax and telecom law). If something can't be deleted, we will tell you what and why.
- Correct. Ask us to fix inaccurate personal information. You can also edit most of your own data directly in the product.
- Port. Get your data in a machine-readable format you can take somewhere else. The self-service export in Section 12 does this. (Moving your phone numbers to another provider is covered in the Terms of Service, Section 10.)
- No retaliation. We will never charge you more, cut you off, degrade the Service, or treat you differently because you used a privacy right.
How to use a right
- Email support@bryleeai.com from the email address on your account and say what you want: "send me a copy of my data," "delete my data," "fix this." No form or legal language needed. You can also call 1-888-230-1090.
- How we verify it's you. We confirm the request comes from the email address on your account. For deletion, we may also ask you to confirm from inside the app while signed in, because deletion is permanent. Requests for phone call details also follow the CPNI identity checks in Section 7.
- Authorized agents. Someone else can submit a request for you if they provide written proof that you authorized them. We may still confirm directly with you before acting.
- Timeline. We respond within 45 days. If a request is unusually complex, the law allows one extension of another 45 days. If we need it, we will tell you before the first 45 days are up and explain why.
If we say no
If we refuse a request, we will tell you why. You can appeal by replying to our decision or emailing support@bryleeai.com with "Appeal" in the subject line, and we will answer the appeal within 45 days. If you are still unsatisfied, you can contact your state's Attorney General, and our appeal response will include how to do that.
14. International use
We are a US company, and Brylee is a US-based service operated from the United States (with processing on Cloudflare's global network as described in Section 9). If you use Brylee from outside the US, you are transferring your data to the US. We do not currently offer a standard Data Processing Agreement (DPA) or EU-specific transfer mechanisms. If your business needs a DPA, contact us, tell us what you need, and we will respond honestly about what we can offer.
15. Children
Brylee is for adults: you must be at least 18 to use it (Terms of Service, Section 1). Brylee is not directed to children, and we do not knowingly collect personal information from anyone under 18. If we learn that an account belongs to someone under 18, we will close it and delete its data on the schedule in Section 11. If you believe a child is using Brylee, tell us at support@bryleeai.com. Data a business collects through its own forms or phone lines is that business's responsibility (Section 2).
16. Changes to this policy
We may update this policy as the product changes. We will post the new version here with an updated date, and for material changes we will notify you by email or in the product before they take effect.
17. Contact
Brisco Communications, Inc. (Brylee)
6595 Roswell Rd, Suite G2280, Atlanta, GA 30328
Email: support@bryleeai.com
Phone: 1-888-230-1090