Privacy

How we handle the data behind every briefing.

Briefwright is built around the morning safety meeting — the brief you draft, the crew that signs in, and the audit record you keep. That means we hold a specific kind of data, and this page explains what we hold, why we hold it, and what you can do about it.

Effective August 16, 2026.

Overview
What this policy covers — and what it does not.

This policy covers the data Briefwright collects when a supervisor signs up, when a worker signs in to a briefing, when a company records its roster, and when the audit trail of any meeting is generated or stored.

It does not cover third-party sites we link out to (for example the Stripe-hosted checkout). Those sites have their own policies.

Data we collect
The classes of record held for every Briefwright account.

Account & authentication

Your name, email, profile image, role, sign-in sessions, and password hash. These are managed by our auth provider and exist so you can sign in and so admins can disable an account that misuses the platform.

Company record

Per-account company details you save in Settings — company name, industry, contact email, timezone, default meeting template, and an optional letterhead logo uploaded to our servers.

Worker & crew roster

Roster rows you enter or import for your own crew: name, employee number, role, email, phone. These rows are scoped to your account — one supervisor’s roster is never visible to another.

Meeting records

Every meeting you run: title, industry, job, location, crew, the brief text and structured brief payload, attendance records, the time-stamped acknowledgement by each attending worker, drawn worker signatures, and the supervisor’s drawn signature and sign-off timestamp.

Supporting audit data

Inspection checklist responses, JSA (job safety analysis) entries and steps, equipment inspection records, incident reports, and any waitlist or contact-form entries from the marketing site.

How we use data
Each class has a narrow purpose — and no other.
  • To draft briefings. When you start a morning briefing, your answers and the chosen template are sent through our AI proxy so the brief can be written. Only the minimum prompt needed to produce the brief leaves the platform.
  • To sign and persist the audit record. Worker signatures, supervisor signatures, acknowledgement timestamps, and the full meeting payload are stored so the PDF the platform exports later in the day is an accurate record of what actually happened.
  • To operate sign-in and billing. Authentication data is used only to log you in and protect per-account data. Payment flows run through Stripe-hosted checkout; no card data ever enters Briefwright.
Storage & retention
Where the records live — and how long we keep them.

Application data is held in a hosted Postgres database managed by the platform. Worker signatures and supervisor signatures are stored as SVG markup alongside the meeting they belong to.

Meeting history, roster records, and supporting audit data are kept for as long as you keep your account. When you delete your account, the meeting records and roster that were scoped to it are removed with it.

Sharing & third parties
The short list of services that touch your data.
  • Auth provider. Used to sign you in and hold sessions.
  • Stripe.Hosted checkout only — card data never reaches Briefwright.
  • AI proxy. Receives only the prompt needed to draft the brief you asked for.
  • Email delivery. Used to send the audit recap email at sign-off and to route contact-form submissions to us.

We do not run advertising networks, sell data to brokers, or share your data with parties outside the operational list above.

Security
The minimum we hold ourselves to.

All requests are served over HTTPS. Every record is scoped to the account that created it — a query that does not filter by the signed-in user is a bug, not a feature.

Passwords are hashed by the auth provider; Briefwright never sees the plaintext. Worker and supervisor signatures are stored as drawn SVG markup rather than biometric data and are bound to the meeting they were drawn for.

Your rights & contact
Access, correction, deletion — one address for all three.

You can access, correct, or delete the data tied to your account from inside Briefwright — a supervisor can drop a row from the roster, archive a meeting, or close the account. If you would rather we receive the request and handle it on your behalf, write to ag-solutions@polsia.app.

Updates to this policy
When we change how we handle data.

If we change what we collect, how we use it, or who we share it with, this page will be updated and the effective date at the top will move forward. Material changes are announced in the in-product changelog and, where appropriate, by email to the address on your account.