Privacy Policy
Last updated 31 August 2026
Morning Brief reads your Google Calendar once a day and sends you a short summary of what is coming up. This page explains exactly what it touches, what it keeps, and how to make it stop.
The short version. Morning Brief requests read-only calendar access. It cannot create, edit, or delete anything in your calendar. Your data is never sold, never used for advertising, and never shared with anyone. It is used for one purpose: producing your own morning summary and sending it to you.
Who runs this
Morning Brief is operated by Chris Bass. Questions, deletion requests, or anything else: cbassav@gmail.com.
What Morning Brief accesses
When you sign in with Google, you are asked to grant four things:
-
Your calendar, read-only
(
calendar.readonly) — used to list the calendars on your account and read the events on the current day so the summary can be written. -
Your email address (
userinfo.email) — identifies your account. -
Your basic profile (
userinfo.profile) — your name and profile picture, shown at the top of the app so you can see which account is connected. - Sign-in (
openid) — the standard Google sign-in.
Nothing else is requested. Morning Brief has no access to your email, files, contacts, photos, or any other Google service.
What is stored, and where
Data is held in Google Cloud Firestore, in a project controlled solely by the operator. Each account holds:
- Your Google account ID, email address, name, and profile picture URL.
- A Google refresh token — the credential that lets the morning job read your calendar while you are asleep. Without it the app would have to wake you up to ask permission every day.
- Your settings: timezone, delivery time, and whether delivery is switched on.
- Your push notification subscriptions — the anonymous endpoint your browser issues so a notification can reach your device.
- Your most recent brief. This is a cached copy of the summary and does contain event titles and times from that day. It is overwritten each time a new brief is generated, so only the latest one is ever held.
- The date of the last delivery, so you are not sent the same brief twice.
Calendar events are otherwise fetched fresh from Google each time and are not archived, copied into a separate store, or retained beyond that cached latest brief.
What Morning Brief does not do
- No advertising, and no data sold or rented to anyone, ever.
- No third-party analytics, trackers, or advertising pixels.
- No sharing with other users or with any third party.
- No use of your data to train, fine-tune, or improve any machine learning or AI model.
- No writing to your calendar. The access granted makes this technically impossible.
Google API Limited Use
Morning Brief's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is used only to provide and improve the user-facing features described above. It is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition — and it is never used for advertising, for creditworthiness or lending decisions, or sold.
Service providers
The app runs on Google Cloud Platform (Cloud Run, Firestore, Cloud Scheduler, Secret Manager), so Google processes and stores the data listed above as infrastructure provider. Push notifications are delivered through the push service your own browser vendor operates — Apple, Google, or Mozilla, depending on your device. Those services receive the notification text needed to display it on your screen. No other third party is involved.
Cookies
One cookie, mb_session, keeps you signed in. It is signed, HTTP-only, and
limited to this site. A second short-lived cookie is used during sign-in to protect
against request forgery and is deleted immediately afterwards. There are no tracking or
advertising cookies.
Security
All traffic is served over HTTPS. The Google client secret and notification signing keys are held in Google Secret Manager rather than in the application code. Access to the underlying database is restricted to the application's own service account.
Retention and deletion
You can remove your data at any time, in either of two ways:
- Delete your account in the app. Open Morning Brief, sign in, and use Delete account. This permanently removes your record — refresh token, settings, push subscriptions, and cached brief — immediately and in full.
- Revoke access at Google. Visit your Google account permissions and remove Morning Brief. The stored token stops working at once and no further calendar access is possible.
Doing both is the belt-and-braces option: revoking at Google kills the access, deleting in the app clears the record. Data is retained only for as long as your account exists. Deletion is not reversible.
Children
Morning Brief is not directed at children under 13 and should not be used by them.
Changes
If this policy changes in a way that affects how your data is handled, the date at the top of this page is updated and, where the change is material, you will be notified by email at the address on your account.