Legal
Privacy Policy
Last Updated: September 6, 2026
Brightney ("Brightney," "we," "us," or "our") respects your privacy and is committed to protecting personal information and business data processed through our services.
This Privacy Policy explains how we collect, access, use, store, share, protect, retain, and delete information when you use Brightney's websites, applications, artificial intelligence features, APIs, integrations, workflows, agents, and related products and services (collectively, the "Services").
This Privacy Policy applies when you:
- visit our website;
- create or use a Brightney account;
- use a Brightney workspace;
- connect third-party applications or data sources;
- interact with Brightney's AI features;
- create workflows or automated actions;
- communicate with us; or
- otherwise use the Services.
By using Brightney, you acknowledge the practices described in this Privacy Policy.
1. Information We Collect
The information we collect depends on how you use Brightney and which features and integrations you enable.
1.1 Account Information
When you create or use a Brightney account, we may collect information such as:
- your name;
- email address;
- profile information;
- organization or company name;
- job title or role;
- account identifiers;
- authentication information;
- workspace membership; and
- account and workspace settings.
If you sign in using a third-party authentication provider, we may receive information that provider makes available to us based on the permissions you authorize.
1.2 Customer Data
You or your organization may provide information directly to Brightney or make information available through connected applications, systems, or data sources.
We refer to this information as "Customer Data."
Customer Data may include:
- documents;
- files and folders;
- emails and communications;
- calendar information;
- meeting information;
- meeting transcripts or recordings where supported and authorized;
- contacts;
- CRM records;
- project and task information;
- notes;
- knowledge-base content;
- database records;
- business information;
- design or collaboration content;
- prompts and instructions;
- workflow information;
- AI conversations;
- generated content;
- uploaded content; and
- other information provided through or connected to the Services.
Customer Data remains owned by you, your organization, or the relevant third party.
Brightney does not obtain ownership of Customer Data simply because it is processed through the Services.
2. Connected Services
Brightney is designed to connect information across the applications, tools, knowledge sources, and systems used by your organization.
You may choose to connect Brightney with third-party applications, platforms, APIs, databases, infrastructure, and other services ("Connected Services").
Connected Services may include:
- email and communication platforms;
- calendars and scheduling systems;
- meeting and video-conferencing platforms;
- cloud storage services;
- file and document-management systems;
- productivity and collaboration tools;
- CRM and sales platforms;
- project and task-management systems;
- design and whiteboarding tools;
- customer-support systems;
- databases and data warehouses;
- developer and source-code platforms;
- enterprise resource planning systems;
- enterprise applications; and
- other business tools and data sources supported by Brightney.
This definition is intended to include both currently supported Connected Services and additional services Brightney may support in the future.
Depending on the integration and permissions you authorize, Brightney may access information from a Connected Service.
Brightney seeks to access only the information and permissions reasonably necessary to provide the functionality you choose to enable.
For example, if you enable a feature that searches your organization's documents, Brightney may need permission to retrieve relevant documents.
If you enable functionality that schedules an event, sends an authorized communication, updates a CRM record, creates a task, or modifies information in another system, Brightney may require permission to perform that action.
The exact information Brightney can access depends on:
- the Connected Service;
- the permissions granted by you or your organization;
- your organization's configuration;
- the functionality you enable; and
- restrictions imposed by the Connected Service.
3. How We Use Connected Service Data
Brightney processes information obtained from Connected Services to provide functionality requested or authorized by you.
Depending on the feature being used, this may include:
- retrieving relevant information;
- searching organizational knowledge;
- indexing information for retrieval;
- generating embeddings or other representations for contextual retrieval;
- understanding relationships between business information;
- answering questions using organizational context;
- summarizing information;
- extracting information from documents or communications;
- identifying relationships and insights;
- preparing meeting context;
- generating recommendations;
- creating or updating records;
- generating or editing documents;
- creating tasks;
- scheduling events;
- preparing or sending authorized communications;
- executing workflows;
- performing authorized AI-agent actions; and
- providing other functionality requested by you.
Brightney does not sell Connected Service Data.
Brightney does not use Connected Service Data for advertising.
4. Third-Party APIs and Provider Requirements
Connected Services may be provided and operated by third parties.
When Brightney accesses information through a third-party API or integration, we process that information according to:
- the permissions you or your organization grant;
- the functionality you choose to enable;
- this Privacy Policy;
- our Terms of Service; and
- applicable requirements imposed by the relevant third-party provider.
Where a third-party provider imposes additional requirements governing information obtained through its APIs, Brightney will process such information in accordance with those applicable requirements.
For information obtained through Google APIs, Brightney's use and transfer of that information will comply with the Google API Services User Data Policy, including applicable Limited Use requirements.
Brightney does not use data obtained from Connected Services to train generalized AI models.
Where supported, you may disconnect an integration or revoke Brightney's access through Brightney or directly through the relevant third-party provider.
5. Authorization Tokens and Integration Credentials
When you connect a third-party account or service, Brightney may receive authorization tokens or similar credentials that allow Brightney to communicate with the Connected Service.
We use these credentials only to maintain the connection and perform functionality you have authorized.
We take reasonable measures designed to protect authorization credentials against unauthorized access.
Where OAuth or a similar authorization mechanism is used, Brightney does not request or store your password for the Connected Service.
If you disconnect a Connected Service or revoke authorization, Brightney will stop using the applicable authorization credentials to make new requests to that service.
Certain technical records may remain temporarily in backups, logs, or security records where reasonably necessary for security, reliability, fraud prevention, or legal compliance.
6. AI Processing
Brightney uses artificial intelligence and related technologies to provide parts of the Services.
These technologies may include:
- large language models;
- machine-learning models;
- retrieval systems;
- embeddings;
- knowledge graphs;
- search systems;
- classification systems; and
- agentic and workflow technologies.
Depending on the functionality you use, Customer Data may be processed to provide:
- enterprise search;
- contextual retrieval;
- question answering;
- summarization;
- information extraction;
- classification;
- recommendations and insights;
- knowledge discovery;
- content generation;
- workflow automation; and
- AI-agent functionality.
Customer Data and Model Training
Brightney does not use Customer Data to train generalized AI models.
Customer Data may be processed by AI systems as necessary to generate responses, retrieve relevant business context, execute workflows, or otherwise provide functionality requested by you.
Where Brightney uses third-party AI, cloud, or infrastructure providers to provide the Services, we seek to use appropriate contractual, privacy, security, and data-protection arrangements for the processing of Customer Data.
7. Business Context and AI Outputs
Brightney is designed to provide AI functionality using business context made available by you or your organization.
Depending on the feature being used, Brightney may retrieve relevant information from authorized:
- documents and files;
- emails and communications;
- calendars;
- meetings;
- CRM records;
- project and task-management systems;
- internal knowledge sources;
- databases;
- business applications; and
- other Connected Services.
When you interact with Brightney's AI features, we may process:
- your prompts;
- your instructions;
- information provided with your request;
- relevant Customer Data;
- contextual information retrieved from Connected Services; and
- generated responses or outputs.
The accuracy, completeness, and relevance of Brightney's output may depend on the Customer Data and context available to the Services.
If connected information is incomplete, inaccurate, outdated, unavailable, or restricted by permissions, Brightney's resulting output may also be incomplete or inaccurate.
AI-generated outputs may be stored in your workspace where necessary to provide conversation history, workflow records, collaboration, auditability, or other product functionality.
8. Automated Actions and AI Agents
Brightney may allow users to configure workflows, automations, and AI agents that interact with Connected Services.
Depending on the permissions and configuration you provide, these features may perform actions such as:
- retrieving information;
- creating or editing documents;
- updating business records;
- creating or updating tasks;
- scheduling events;
- preparing communications;
- sending authorized communications;
- updating information in Connected Services; or
- executing other authorized workflows.
Information is processed for these purposes based on your configuration, permissions, and instructions.
Brightney does not intentionally allow AI agents or workflows to access Connected Services beyond the permissions granted to the relevant account or workspace.
9. Service and Usage Information
When you use Brightney, we may automatically collect technical and usage information such as:
- IP address;
- browser type;
- device type;
- operating system;
- application version;
- pages or features accessed;
- timestamps;
- session information;
- error logs;
- diagnostic information;
- integration status;
- performance information; and
- interactions with the Services.
We may use this information to:
- operate the Services;
- troubleshoot issues;
- improve reliability and performance;
- understand feature usage;
- prevent abuse;
- detect security incidents; and
- improve the user experience.
Where appropriate, we may use aggregated or de-identified information for analytics and product improvement.
10. Cookies and Similar Technologies
Brightney's website and Services may use cookies, local storage, and similar technologies.
These technologies may be used for:
- authentication;
- maintaining sessions;
- remembering preferences;
- security;
- fraud prevention;
- understanding website performance; and
- improving the Services.
Where required by applicable law, we will request consent before using non-essential cookies or similar technologies.
11. Communications
If you contact us, request support, participate in a demo, join a waitlist, or otherwise communicate with Brightney, we may collect:
- your name;
- email address;
- company information;
- the content of your communication; and
- information necessary to respond to your request.
We may use this information to provide support, respond to inquiries, communicate about the Services, and maintain appropriate business records.
12. Payment Information
If you purchase paid Services, payment information may be processed by Brightney or third-party payment providers.
Where a third-party payment provider is used, Brightney may not directly receive or store complete payment-card information.
We may receive information such as:
- payment status;
- subscription plan;
- billing period;
- billing contact information; and
- transaction identifiers.
13. How We Use Information
We may process information to:
- create and manage accounts;
- authenticate users;
- provide the Services;
- connect applications and data sources;
- retrieve and organize business information;
- provide AI functionality;
- execute workflows and authorized actions;
- provide customer support;
- process subscriptions and payments;
- maintain, monitor, and improve the Services;
- diagnose technical problems;
- protect against fraud and abuse;
- maintain security;
- enforce our Terms of Service;
- comply with legal obligations;
- communicate important Service information; and
- protect Brightney, our customers, users, and third parties.
We do not use Customer Data for unrelated advertising purposes.
14. How We Share Information
Brightney does not sell Customer Data.
We may share or transmit information only in circumstances such as those described below.
Service Providers and Subprocessors
We may use third-party providers to help operate Brightney.
These providers may include:
- cloud infrastructure providers;
- database providers;
- AI model providers;
- authentication providers;
- integration infrastructure;
- communications providers;
- analytics providers;
- security providers;
- payment processors; and
- customer-support tools.
These providers may process information only as necessary to provide services to Brightney and are subject to appropriate contractual requirements where applicable.
At Your Direction
We may transmit information when you instruct Brightney to interact with a Connected Service.
For example, if you instruct Brightney to create an event, send an authorized communication, update a record, create a task, or generate or modify a document in another service, information required to perform that action may be transmitted to the relevant Connected Service.
Within Your Organization
If you use Brightney through an organization, information may be accessible to authorized members or administrators according to workspace permissions.
Organization administrators may be able to:
- manage accounts;
- manage integrations;
- control permissions;
- access workspace content;
- review activity;
- configure workspace settings; or
- otherwise administer the organization's Brightney environment.
Legal and Security Reasons
We may disclose information where reasonably necessary to:
- comply with applicable law or valid legal process;
- respond to lawful governmental requests;
- enforce our agreements;
- investigate fraud or abuse;
- protect the security of Brightney;
- protect users or third parties; or
- protect legal rights.
Business Transactions
If Brightney participates in a merger, acquisition, financing, restructuring, sale of assets, or similar corporate transaction, information may be transferred as part of that transaction subject to applicable confidentiality and legal requirements.
15. Human Access to Customer Data
Brightney restricts human access to Customer Data.
Authorized personnel may access Customer Data only where reasonably necessary for purposes such as:
- providing support requested by the customer;
- investigating security incidents;
- diagnosing technical issues;
- preventing fraud or abuse;
- complying with legal obligations; or
- where access has otherwise been authorized by the customer.
Access is limited to personnel or service providers who require such access for an authorized purpose and is subject to appropriate confidentiality and security obligations.
16. Data Retention
We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including:
- providing the Services;
- maintaining your account;
- complying with contractual obligations;
- maintaining security and audit records;
- resolving disputes;
- enforcing agreements; and
- complying with applicable law.
Retention periods may vary depending on:
- the type of information;
- workspace configuration;
- contractual requirements;
- security requirements;
- legal requirements; and
- the functionality being provided.
Customer Data may remain in backups for a limited period after deletion from active systems.
Information retained in backups remains subject to appropriate security protections and will not be used for ordinary product functionality after deletion from active systems.
17. Deleting Your Data
You may be able to delete certain information directly through Brightney.
You may also:
- delete content you have created;
- disconnect Connected Services;
- revoke third-party permissions;
- leave an organization or workspace where permitted; or
- request deletion of your account or personal information.
To request deletion, contact:
When a valid and applicable deletion request is received, we will delete or de-identify relevant information from active systems within a reasonable period, subject to technical limitations and information we are required or permitted to retain for legal, security, fraud-prevention, billing, dispute-resolution, or other legitimate purposes.
If your Brightney account is controlled by an organization, certain deletion requests may need to be handled by your organization's administrator.
Disconnecting an integration prevents Brightney from making new requests to that Connected Service using the disconnected authorization.
Disconnecting an integration does not automatically delete information previously imported, indexed, generated, or stored within Brightney unless that information is separately deleted.
18. Your Privacy Rights
Depending on where you live, you may have legal rights regarding your personal information.
These may include the right to:
- access personal information;
- correct inaccurate information;
- request deletion;
- obtain a copy of certain information;
- restrict certain processing;
- object to certain processing;
- withdraw consent where processing is based on consent; and
- submit a complaint to an applicable data-protection authority.
These rights may be subject to limitations or exceptions under applicable law.
To exercise a privacy right, contact:
We may need to verify your identity before completing certain requests.
If you use Brightney through an organization and your request relates to information controlled by that organization, we may direct your request to the relevant organization.
19. Organization Customers
When Brightney provides Services to an organization, the organization may control Customer Data processed within its workspace.
In those circumstances, Brightney may process personal information on behalf of the organization.
The organization is responsible for determining why and how certain information is processed and for providing necessary notices or obtaining necessary permissions where required by applicable law.
If your personal information is processed through an organization's Brightney workspace, you may need to direct certain privacy requests to that organization.
20. Security
Brightney uses reasonable administrative, organizational, and technical safeguards designed to protect information against:
- unauthorized access;
- unauthorized disclosure;
- alteration;
- destruction;
- loss; and
- misuse.
Security measures may include, where appropriate:
- encryption;
- authentication controls;
- access restrictions;
- infrastructure security;
- logging and monitoring;
- secure software-development practices; and
- security reviews.
No online service or data-transmission method can guarantee absolute security.
If we become aware of a security incident involving personal information, we will respond in accordance with applicable legal and contractual requirements.
If you believe you have discovered a security issue involving Brightney, contact:
21. International Data Transfers
Brightney and its service providers may process information in countries other than the country in which you are located.
Where required by applicable law, we use appropriate safeguards for international transfers of personal information.
The countries in which information is processed may have privacy and data-protection laws that differ from those in your jurisdiction.
22. Third-Party Services
Brightney may contain integrations or links to services operated by third parties.
This Privacy Policy governs Brightney's handling of information and does not govern the independent privacy practices of those third parties.
Your use of a Connected Service may also be subject to that provider's terms, privacy policies, API policies, and other applicable agreements.
We encourage you to review the privacy practices of services you connect to Brightney.
23. Children's Privacy
Brightney is designed for business and professional use and is not intended for children under the age of 18.
We do not knowingly collect personal information directly from children under 18 through the Services.
If you believe a child has provided personal information to Brightney without appropriate authorization, contact us at hello@brightney.ai.
24. Changes to This Privacy Policy
We may update this Privacy Policy as Brightney, our Services, technologies, integrations, and applicable legal requirements evolve.
When we make material changes, we may provide notice through:
- the Brightney website;
- the Services;
- email; or
- another reasonable communication method.
The "Last Updated" date at the top of this Privacy Policy indicates when it was most recently revised.
25. Contact Us
If you have questions about this Privacy Policy, how Brightney handles information, or your privacy rights, please contact us:
Brightney
Website: brightney.ai
Email: hello@brightney.ai
© 2026 Brightney. All rights reserved.