Privacy Policy
Last updated: September 11, 2026
This Privacy Policy applies to Today's Brief's Android app and website, including its personalized news, market information, task, audio, and account-sync services. Contact: ppltech26@gmail.com.
Platform Availability
Feature availability and data flows differ by platform. Google Sign-In is not currently available in the Android app or on the website. Other Google-powered services identified in this policy, such as Google Play, Firebase or Google Analytics, Google Maps Platform, and Google Text-to-Speech, are separate and apply only where described. Today's Brief's own task and account-sync features do not require a Google account.
Data We Collect
Depending on how you use the app, we may collect account information such as email or phone number, country and language preferences, saved items, watchlist symbols, reading and listening interactions, task content such as titles, notes, priority, status, due dates, and completion times, custom Today Ideas topics, saved commute place IDs and labels that can represent an exact Home or Work location, account status, subscription entitlement status, authentication and account-security records, diagnostics and crash logs, device and app information, optional city or device-derived approximate location for local features, referral activity, and user-submitted content reports or feedback.
If you grant Android's approximate-location permission and request a local weather, news, or commute feature, the app may send device-provided approximate coordinates to Today's Brief's backend or the relevant weather or mapping provider to return that feature. Manual city or place selection remains available. These functionality requests are separate from the more limited analytics treatment described below.
Daily Mastery And Wellness-Related Learning Data
The dedicated Daily Mastery wellness skills described here are available on the web service and are currently unavailable in the Android app.
Daily Mastery is an optional learning feature, including general education about activity and fitness, nutrition, sleep habits, mindfulness, relaxation, and stress management. Today's Brief is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Consult a qualified healthcare professional for medical advice, diagnosis, or treatment. Do not replace or delay professional care because of a lesson.
When you use Daily Mastery, we process selected skill or topic identifiers, the active lesson, viewed, saved, and completed lessons, quiz results, learning streaks, review schedules, and related dates or timestamps to deliver and personalize lessons, save your place, and synchronize learning progress. Learning state is stored on your device and on our backend, associated with a device identifier when signed out or your account when signed in. Topic choices and lesson activity may reveal wellness interests; they are not medical measurements or clinical assessments. This feature does not automatically measure your activity, nutrition, sleep, or health, or read Health Connect or medical-device data. Free-text features such as tasks and feedback can nevertheless contain health information if you choose to enter it; avoid including sensitive medical details that are not needed for your request.
Lesson content needed for explanations or narration may be processed by Google Gemini or Google Cloud Text-to-Speech under the AI And Content Processing section below. Our backend and hosting providers process learning state to provide the feature. Turning Usage analytics off does not stop this functionality-related processing; optional analytics, essential diagnostics, and service logs follow their separate rules in this policy. You can choose other learning topics or not use Daily Mastery. Learning records follow the retention and deletion rules below; to request deletion of reliably matchable data without deleting your account, use Manage app data.
Invitations And Referral Records
Invitations remain available while Android referral rewards are unavailable. We continue to process referral codes, attribution and event records, and associated identifiers and timestamps to support invitation links and statistics and prevent abuse.
Removing reward offers and progress displays in an Android update does not stop this processing or automatically erase existing records, including any reward-status records. These records remain subject to the retention and deletion terms in this policy. See Android Invitations And Referral Rewards for details about Android reward availability.
Authentication And Account-Security Data
When you create or secure an account, Today's Brief may store a salted, slow password hash (never your plaintext password); short-lived one-time-code, approval-link, recovery, and other authentication-proof hashes together with status and expiry metadata; passkey credential identifiers and public keys (never the private key kept by your authenticator); credential-generation or version metadata; and session, refresh-token, device-link, and security-challenge identifiers or hashes with timestamps and status. We use this data to authenticate you, recover and protect your account, manage signed-in devices, prevent replay or abuse, investigate security events, and comply with applicable obligations. We do not send these authentication records or secrets to Google Analytics, Google Gemini, or Google Cloud Text-to-Speech.
How We Use Data
We use data to provide and personalize daily briefs, localized news, market and watchlist context, saved content, audio playback, account sync, subscription or trial access, support, abuse prevention, diagnostics, and app reliability.
Essential Reliability And Security Telemetry
This essential telemetry is separate from the optional Usage analytics choice below. Production Android releases always enable Google Firebase Crashlytics and the Firebase Sessions component used with Crashlytics. Google Firebase may receive crash stack traces and exception details, crash time, limited app, device, network, and application-state details, Crashlytics or Firebase installation identifiers, a random Firebase session identifier, and the in-app Support ID that we add as a diagnostic key. We use these records to detect and diagnose crashes or non-fatal failures, measure affected installations, secure the service, and maintain operational reliability. The Usage analytics switch does not turn this essential crash, diagnostic, or session collection off.
Firebase's privacy and security documentation Firebase's Android Crashlytics documentation explains that, while Google Analytics collection is enabled, Crashlytics automatically includes recent Analytics screen and custom-event breadcrumbs, including custom-event parameter data, with a crash, non-fatal, or ANR report. Firebase's privacy documentation states that Crashlytics keeps crash traces and associated identifiers, including Crashlytics and Firebase installation identifiers, for 90 days before beginning removal from live and backup systems. A crash record may also contain the random Firebase session identifier and copied Analytics breadcrumbs. These records are not intentionally linked to a Today's Brief account, so deleting an account does not automatically identify or remove a record tied only to an installation or Support ID. You may contact ppltech26@gmail.com with the Support ID shown in Settings and request deletion of reliably matchable crash reports; we may request verification and can act only on records that can be reliably matched. The Android Usage analytics control does not delete earlier Crashlytics records or breadcrumbs already copied into them.
Today's Brief and its hosting or security providers also process essential security and operational request logs needed to deliver, protect, troubleshoot, and prevent abuse of the app and website. These logs may contain the request IP address, user-agent or limited app, device, or network description, requested API route, timestamp, request or security outcome, and a pseudonymous request, session, device, or account correlation identifier when needed. They are not optional product analytics and are not controlled by the Usage analytics switch. Today's Brief keeps its application-level request and security logs for no more than 90 days in the ordinary course; a restricted record may be retained longer only for an active fraud, security, legal, billing, tax, or dispute matter. Infrastructure providers may maintain their own operational logs under their documented service-provider retention schedules.
Today's Brief's application code uses an IP address from this required request path only for delivery and security controls such as rate limiting, session protection, idempotency, abuse prevention, and limited feedback-security context. The required request-IP path does not convert the address into, or persist from it, a country, region, city, coordinates, or other geographic field, and does not pass the address to Google Analytics or Firebase. Optional Analytics uses its own separate network request only when enabled, as described under Usage Analytics And Your Choices.
Required Deidentified Feature-Use Statistics
For restricted service reporting, Today's Brief records one deidentified feature-use row when a supported backend content or audio feature is used. A row contains only the request timestamp, a fixed functionality identifier, language, and, for an applicable news request, bounded publisher or category identifiers and server-supplied labels plus a category-aggregate flag. It contains no account, device, installation, advertising, session, request, event, or Support ID; no IP address, user-agent, city, coordinates, saved place, or other location; and no raw URL, query, request body, content, or error text. We do not send these rows to Google Analytics or Firebase or join them to other records. Every administrator read excludes rows older than the exact rolling 90-day window even if database cleanup is delayed, and the timestamp index is configured with a 90-day database expiry.
Live totals derived from those rows retain only the current UTC date and the preceding 89 dates in bounded day buckets. Existing anonymous theme and news preference-statistics requests separately update counts for strict opaque theme-mode, palette, excluded-category, and excluded-publisher identifiers; each identifier and UTC-date bucket retains only a count and its first and last event times. Malformed, overlong, email-like, URL-like, free-text, and excess-cardinality values are not stored. These snapshots also preserve no more than 90 UTC dates, and deployment of the bounded schema discards any legacy aggregate whose underlying retained event times cannot be proven. Neither statistics path creates an additional client request, contains an account, device, IP, or location identifier, builds a cross-request user history, or supports account-level isolation. Because the records cannot be linked to an account, account deletion cannot identify one person's contribution; automatic pruning applies instead. These required statistics operate even when Usage analytics is off.
Required Aggregate Operational Counters
Separately from the optional Usage analytics described below and from the request and
security logs described above, Today's Brief maintains required first-party daily aggregate
operational counters to monitor the availability and performance of fixed, allowlisted
service features. These include content surfaces and audio, account creation and sign-in,
account and security operations, cloud sync, tasks, subscriptions and trials,
referrals, notifications, feedback, translation, and preference changes. The counters are
created by the server while it processes an existing allowlisted API request. For the Theme
changes and News preferences buckets, the counter reuses the already-existing bounded
anonymous preference-statistics request and does not inspect or copy its body or preference
value. The operational-counter system does not cause the app or website to make an
additional request or create or read tracking storage. Updated clients attach only a fixed
activity-source header to existing first-party API requests. The server
assigns the service day when the request begins. A service day is the calendar date in
Eastern Time (America/New_York), and daily groups follow that zone's
daylight-saving time transitions; a service day can therefore span 23 or 25 hours. When
the request completes or closes, the server immediately folds the coarse result into a
daily aggregate cell; it does not retain an individual counter event. Coalesced cell
increments are written asynchronously.
Each aggregate cell contains only the service day; the selected country edition when it was
already included in the functional API request, or UNKNOWN when it was not; the
existing client family android, web, or unknown; a
fixed allowlisted feature; an activity-source label where available; a coarse outcome category; a coarse latency bucket; the aggregate
count; an optional latest activity time rounded down to the minute; a database-required
deterministic cell key derived only from the service day and those fixed cell dimensions; and technical expiry metadata derived only from the service
day. The latest activity time is the newest recorded request start, stored as one value per
aggregate cell; newer activity replaces it without retaining previous times. The
deterministic key replaces the database's time-bearing default object identifier.
A cell contains no account, device, installation, advertising, session, request, event, or
Support ID; no IP address, raw user-agent, city, coordinates, saved place, or other location
data; no raw URL, query, request body, content, free-text error message, or per-request
timestamp history; and no user journey, sequence, or cross-request history. We do not infer a
missing country edition from an IP address, device location, locale, Google Play Billing
country, or another signal. The selected country edition is a content preference, not a
statement about residence or physical location.
Activity source is a fixed client-reported label carried on the existing request:
user_initiated, foreground_automatic, background,
or unknown. It distinguishes explicit actions from automatic requests for
service-health reporting; it is not proof of a human action or a count of active users.
Historical records, older clients, and unlabelled or invalid values remain Unknown.
The source-aware report applies the 20-request threshold separately per source and daily
cell. A legacy report may combine sources into its previous daily grouping and applies
the same threshold to that grouping. No individual contribution is counted twice.
Comparing exact combined totals with source-specific totals may allow an administrator
to infer a smaller source contribution by subtraction; the threshold is not a guarantee
against that comparison.
These counters operate even when Usage analytics is off. We use them only to measure
aggregate feature availability, coarse outcomes, latency, capacity, and service health. We
do not send them to Google Analytics or Firebase, join them to account, device, session,
analytics, or other records, or use them for advertising, personalization, engagement
profiles, retention cohorts, or cross-request tracking. Restricted operator reporting is
available only to authenticated administrators, suppresses cells with fewer than 20
requests, and returns the exact stored aggregate counter value for each eligible cell.
Where available, its latest activity time is shown in Eastern Time to the minute, with
recent activity first; older cells without a recorded time show it as unavailable. The counter
is best effort and can omit requests when an observation cannot be buffered or a database
write cannot be confirmed. An administrator may restrict the report using only fixed,
server-validated choices. Selected edition, client family, and feature each allow any subset
of their fixed values, including all or none, and default to all values. A row must match
a selected value in every filter. Activity source allows any combination of User initiated, Automatic while app open,
Background, and Unknown, including all four or none.
User initiated and Automatic while app open are selected by default.
Selecting multiple sources does not pool cells to meet the
threshold: each source's daily cell must independently contain at least 20 requests. These
filters only restrict already-defined cells and do not change cell boundaries, lower the
threshold, accept free-form values, or request suppressed cells. The displayed included
cell total is the exact arithmetic sum of the returned stored aggregate counters, not a
count of users or actions; it excludes suppressed cells and may be partial if the response
reaches its fixed row cap. The default Today view may include the current, open Eastern
Time service day as an in-progress report, while the fixed historical presets contain only
completed Eastern Time service days. Last calendar month covers the previous calendar month's
completed days. This year includes the current, open Eastern Time service day and only the
available part of the year within the most recent 90 inclusive days; the actual dates and
any retention clipping are shown explicitly. An administrator may instead select an inclusive
custom calendar-date range of up to 90 days within the available retention window. A
custom range may include the current, open Eastern Time service day and is marked in
progress when it does. Day labels and period boundaries use
America/New_York, not UTC, the administrator's device time zone, or a selected
country edition's time zone. Because the open-day aggregate is still changing, refreshing
Today, This year, or a custom range that includes the current day can show a stored exact counter
increasing by one request or a cell first reaching the reporting threshold. This lets an
administrator observe a one-request change in an
already-reportable aggregate between refreshes, but the report never returns a raw
individual event or identifier. Each aggregate cell is configured to expire 90 days after
its service day and is then removed by the database's asynchronous background expiry
process. Because the cells are not linked to an account or device, an account-deletion
request cannot isolate or subtract one request's contribution from an existing total; the
complete cell remains subject to the same configured expiry.
Usage Analytics And Your Choices
Usage analytics is optional. Before Today's Brief sends a first usage-analytics event, the onboarding analytics notice must have been shown and the platform must have enough current country context to apply the rule below. On Android, before 13 May 2027 at 00:00 Asia/Kolkata (12 May 2027 at 18:30 UTC), base pseudonymous usage analytics may be selected by default for an unknown choice only when your selected country edition, current app or device-locale country, and a fresh live uncached Google Play Billing country all exactly match, and that common country is the United States, Australia, or India. Beginning at that instant, India is no longer eligible for an unknown-choice default; an exact United States or Australia match remains eligible. Missing, invalid, unavailable, stale or cached, or conflicting country evidence is consent-first. The Play Billing country used for each immediate eligibility evaluation is not cached, persisted, logged, used to profile you, or transmitted by Today's Brief. On the website, every unknown analytics choice is consent-first because the website does not currently have an approved trusted country signal: analytics remains off until you affirmatively enable it. This regional rule is a compliance-forward product policy and is not a determination of your residence or a substitute for local legal advice.
You can turn usage analytics on or off at any time. The Android first-run notice includes a Usage analytics switch before collection can begin. It is selected by default only for the exact eligible three-way Android match described above and can be turned off before continuing. In every consent-first, unresolved, or conflicting Android configuration it is unselected and analytics starts only if you affirmatively turn it on. The same control remains available under Settings > Legal & privacy > Usage analytics. On the website, the first-run switch is unselected for every unknown choice, and the control remains under Settings > Privacy > Usage analytics. A saved explicit grant or denial remains authoritative; an explicit Android India grant remains effective after the cutoff unless you turn analytics off. On the website, a recognized Global Privacy Control signal overrides an earlier grant and keeps optional analytics off while that signal is present. Any future website default-on rule would require a separately reviewed trusted-edge country signal, code, and legal release. Extending India's Android unknown-choice default beyond the cutoff would likewise require a later legal review and a deliberately reviewed app release; neither change can be made by editing this policy alone.
When base analytics is active, Today's Brief uses Google Analytics 4 and Google Analytics for Firebase to measure page or screen views, sessions, feature interactions, subscription-funnel steps, performance, and reliability. Google Analytics automatically assigns a pseudonymous browser or app-instance identifier and may automatically collect app lifecycle events and Google Play in-app purchase or subscription metadata, including product ID, product name, and price. Our allowlisted product events may include event time, app version or other limited app and device characteristics, language, and selected country edition. We do not set Google Analytics User-ID or send a Today's Brief account ID, email, phone number, name, saved article text, task text, search text, credentials, purchase token, address, or precise location as an analytics parameter or property. The website sends neither a selected city nor device-derived location as a custom analytics parameter or property.
Google Analytics uses the network or IP address that delivers an enabled event to derive approximate geography and then, according to Google, discards the IP address before analytics data is logged. We configure granular location and device collection off; that prevents collection of city and specified granular device fields, but does not remove country- or region-level network-derived geography. For this reason, our Google Play Data Safety disclosure still identifies Approximate location as optionally collected whenever base analytics is active. Today's Brief does not use this process to collect precise location. Learn more about how Google uses information from sites or apps that use its services.
Android's Device-derived location analytics is a second, separate control under Settings > Legal & privacy and is off by default everywhere. It does not grant location permission and never causes Today's Brief to request or read location for analytics. Only when base usage analytics is active, this separate control is on, Android's approximate-location permission is granted, and a user-requested local news, weather, or commute feature successfully resolves the current location may the app derive an approximately one-degree regional-cell label as part of that live feature operation. Polar locations use a broader bucket. The app may send that label only on the dedicated successful location-feature analytics event; it is never added to general usage events. Analytics does not call a last-known-location API, request a fresh analytics-only fix, persist raw coordinates for this purpose, or send latitude, longitude, address, precise location, or background location to Google Analytics. If a crash, non-fatal error, or ANR is reported after that dedicated event in the same Analytics-enabled session, Firebase may copy the event and its broad regional-cell parameter into the Crashlytics report as an Analytics breadcrumb. The original event follows the configured two-month Analytics retention; a copy included with a Crashlytics report follows Crashlytics' separate 90-day retention before removal begins. Revoking either analytics choice or the Android location permission prevents future regional-cell events, but does not delete a breadcrumb already included in a submitted Crashlytics report. Manual city or saved-place alternatives remain available for the user-facing feature.
Turning usage analytics off stops future analytics collection and clears applicable local Google Analytics cookies or Firebase analytics identifiers. It does not necessarily erase pseudonymous events already processed by Google Analytics or Analytics breadcrumbs already copied into a Crashlytics report. Advertising storage, advertising user data, and ad personalization consent remain denied; Google Ads product links, audience or key-event exports to advertising products, Google Signals use, Android Advertising ID collection, and ad-services attribution identifiers remain disabled.
Sharing
We may disclose data to service providers and APIs that operate the app, including backend hosting, news, market and content APIs, Google Gemini, Google Cloud Text-to-Speech, analytics and crash reporting providers, Google Play Billing, Firebase or Google services, and support tooling. These providers process data for the relevant feature or service. We do not sell personal information.
Google Maps Platform And Saved Places
Commute setup may use Google Maps Platform and Places to show transient address suggestions
and route estimates. Today's Brief stores a saved commute Home or Work destination as an
exact Google place ID plus a user-entered or app-defined label. Even though Android
current-location access is coarse-only and the app does not request
ACCESS_FINE_LOCATION, a saved place ID can represent a physical location within
3 km. We therefore disclose saved commute places as optional, non-ephemeral
Precise location for Google Play Data Safety, used for App functionality and
Personalization. The place ID and label may be sent to Today's Brief's backend and, when
account sync is enabled, synced with account preferences. Google Maps Platform and Places
receive the lookup or selected place ID as needed for address suggestions, place validation,
and route estimates. We do not intentionally store
Google prediction text, formatted addresses, place names, address components, ratings,
reviews, photos, or attribution HTML in app-controlled persistence. You can edit or remove
saved commute locations in the app, and synced records are included in account deletion
subject to the documented exceptions. This saved-place path is separate from
permission-derived current location and is not sent as an analytics parameter.
AI And Content Processing
When you request or enable an AI-assisted summary, insight, briefing, or server-generated narration or audio feature, Today's Brief sends the context needed for that request over HTTPS to its backend and relevant service providers. Depending on the feature, the bounded input may include article and source material; market or watchlist symbols, quote data, and related context; task titles, notes, priority, due-date or status metadata; custom Today Ideas topics; weather, city, or location labels; commute place labels, route, and estimated-time context; and the text selected or generated for narration.
Google Gemini processes the relevant prompt context to produce summaries, insights, or narration scripts. Google Cloud Text-to-Speech processes narration text to synthesize audio. A device's on-device speech engine may instead process eligible text locally. We do not intentionally include passwords, authentication credentials, or other account secrets in AI or speech requests. AI output may be incomplete or incorrect; open original sources for full context and report content issues inside the app.
Market Data
Market information is provided for general informational and educational purposes only and is not financial advice. Market data may be delayed, incomplete, or inaccurate.
Retention And Deletion
We retain data as needed to provide the app, comply with law, prevent abuse, resolve disputes, and maintain records. Short-lived OTP, approval, recovery, passkey-challenge, and similar proof records expire automatically after their configured security window. Active password hashes, passkey public credentials, credential-version metadata, and account-linked session or security records remain while needed to secure the account and are removed or invalidated when replaced, revoked, expired, or covered by account deletion, subject to the limited exceptions below. User-submitted feedback and content-report records are normally deleted 180 days after submission. Application-level request and security logs are normally deleted within 90 days. Deidentified feature-use rows and their rolling aggregate snapshots are limited to the 90-day windows described above. We may delete eligible records earlier with an applicable verified deletion request, or retain a restricted record longer when necessary for an open security, abuse, legal, billing, tax, or dispute matter.
You can request account deletion in the app or at Account Deletion. Account deletion covers account-linked profile and sync data, authentication credentials and passkey public records, tasks, saved items, preferences, watchlists, reading or listening history, device sessions, and Today's Brief's server-side push-token registrations, feedback or content reports, referral attribution, event, and reward records linked to your account or to a device registered to your account, any historical account-linked first-party analytics delivery records, and entitlement, trial, quota, or other usage-governance records, except for limited records we are required or permitted to retain. Removing our server-side push registration is distinct from the Firebase SDK's Firebase Installation ID lifecycle: account deletion does not itself delete or rotate the device-local Firebase Installation ID or erase provider-held crash or session records that already contain it. Clearing app data or uninstalling removes local app state; Firebase-controlled records remain subject to Firebase's documented lifecycle and retention, including the 90-day Crashlytics period described above. Referral-code-only records that cannot be authoritatively linked to the deleting account are not deleted through account deletion and may remain as pseudonymous attribution or reward records. Google Play controls its billing records. We may retain records needed for fraud or security prevention, billing or transaction reconciliation, legal compliance, tax, or dispute resolution, and those records are restricted to those purposes. New first-party analytics delivery records are browser- or installation-pseudonymous, deliberately contain no account ID, and are normally deleted after 90 days. Because they are not account-linked, they ordinarily cannot be identified through an account-deletion request. Any historical records that remain account-linked are included in account deletion.
Google Analytics user-level and event-level data is configured for a two-month retention period with reset-on-new-activity disabled. That retention control does not remove Google's standard aggregated reports. BigQuery export is disabled for this release. Because Today's Brief does not set Google Analytics User-ID or send an account identifier to Google Analytics, Google Analytics events are not intentionally linked to a Today's Brief account and may not be individually identifiable for account deletion. Turning analytics off stops future optional Analytics collection and resets applicable local Analytics identifiers, but previously processed pseudonymous or aggregated measurements remain subject to the configured Analytics retention controls and Google's applicable terms. It does not disable essential Firebase Crashlytics or Sessions collection or delete earlier crash records or Analytics breadcrumbs already copied into them; the separate 90-day Crashlytics retention and Support ID request path described above apply.
The in-app account-deletion control applies to a signed-in account. If you used Today's Brief without an account, there is no account profile to delete and the app does not currently provide an anonymous self-service deletion control. You may email ppltech26@gmail.com with the Support ID shown in Settings and ask support to assess whether any eligible device-linked server records can be reliably matched. Support may request additional verification or an additional identifier; only eligible records that can be reliably matched can be handled.
Children
Today's Brief is not directed to children.
International Availability
The app is intended for availability in the United States, Canada, Australia, India, United Kingdom, Germany, France, and Japan. Data may be processed in countries where we or our service providers operate.
Security
We use HTTPS and reasonable administrative, technical, and organizational measures to protect data. No method of transmission or storage is perfectly secure.
Changes
We may update this policy. When we do, we will update the date at the top of this page.