Security
Last updated: June 3, 2026
MiniBrief is designed around a simple idea: the safest data is the data nobody keeps. Your mail is read and sorted inside your browser. The features that use AI send a limited amount of it through our AI proxy to Anthropic, which forwards each request without logging it or keeping its contents. Nothing is written to our database. This page explains, in plain terms, how that works and how we protect the limited account data we do keep. It complements our Privacy Policy.
The short version
- Your email content is never stored. Your mail is parsed and pre-sorted in your browser; AI features send a limited amount of it through our proxy to Anthropic, which keeps no copy of it.
- By default we send only a subject line and a preview of about 120 characters. Full message text is sent only for features you turn on yourself, and only for the message you opened.
- We request the minimum access needed (least privilege), and you can revoke it at any time.
- All connections use encryption in transit (HTTPS/TLS); account data is encrypted at rest by our infrastructure providers.
- No analytics, telemetry, or behavioral tracking in the extension.
- We never use your email — or any Google or Microsoft user data — to train AI models.
How your email flows
When you use a feature, here is the exact path your email content takes:
- 1. In your browser — the extension reads the relevant messages directly from Gmail or Outlook in the page you are already signed in to. Parsing and the first sorting pass happen on your device and go no further.
- 2. Through our AI proxy — only the content needed for the feature you triggered leaves your browser: a subject and a short preview for triage, or the body of the message you opened for a draft or a summary. It travels over an encrypted connection to a small service we run, which exists so that our AI key never has to sit inside the extension where anyone could extract it.
- 3. On to Anthropic — the proxy forwards the request and returns the answer. It does not log the request, does not store it, and writes nothing to our database. Anthropic processes it under commercial terms that forbid training on your data.
- 4. Back to you — the generated result is returned to your browser and shown in MiniBrief.
We are precise about this because the distinction matters: your email content does pass through our proxy in transit. What it never does is come to rest there. Nothing is logged, nothing is retained, and no email content is ever written to our database.
What we can and can’t see
We can see: the account details needed to run the product — your account identifier and authentication details, your settings and preferences (such as your VIP list), and your plan or licensing status.
We cannot see: the contents of your emails, your attachments, who you email, what you read, or how you use the extension. The proxy forwards AI requests without logging them, so their contents are not readable by us and are not kept anywhere afterwards. Because the extension contains no tracking and nothing you send is retained, there is nothing on our side to leak, sell, or hand over.
Access and authentication
When you connect a Google or Microsoft account, MiniBrief uses standard OAuth and requests only the scopes needed for the features you use — reading messages, the specific changes needed to apply triage actions, sending the replies you approve, and read-only calendar access for meeting prep. We never ask for more than the product needs, and you can review and revoke access at any time — for Google at myaccount.google.com/permissions, and for Microsoft in your account settings.
How account data is protected
The limited account data described above is stored with our application backend provider (Supabase). It is transmitted over encrypted connections (HTTPS/TLS) and encrypted at rest by the provider. Access is restricted to the systems and personnel required to operate the service. Uninstalling the extension removes its local data from your browser; when you ask us to delete your account, we remove the associated data within 30 days, except where we are legally required to retain it.
Payments
Subscription payments are processed by Stripe, a PCI-DSS Level 1 certified payment provider. Your card details are entered with Stripe directly — we never receive or store your full card number.
Subprocessors
We rely on a small number of vetted providers, each for a narrow purpose: Anthropic (AI processing of the limited content described above), Supabase (account, settings, and licensing data — never email content), Stripe (payments), Resend (waitlist and launch emails), and our hosting provider (serving the website). See our Privacy Policy for details on what each one handles.
Reporting a vulnerability
We welcome reports from the security community. If you believe you have found a security issue, please email security@minibrief.app with enough detail to reproduce it. We ask that you give us a reasonable opportunity to investigate and address the issue before any public disclosure, and that you avoid accessing or modifying other people’s data. We will acknowledge your report and keep you updated as we work on a fix.
This document is written in plain language for transparency. It is not legal advice. Questions? Email privacy@minibrief.app.