Advancer Inbox Briefingby Advancer Group
← Back to home

Privacy Policy

Last updated: 29 July 2026

Advancer Inbox Briefing reads your recent email and today's calendar so it can email you a short summary each weekday morning. This policy explains exactly what we access, what we do with it, how long we keep it, and how to remove it.

1. Who we are

Advancer Inbox Briefing (“the Service”) is operated by Advancer Group Pty Ltd (“we”, “us”). You can reach us at support@advancer.com.au for any privacy question, access request, or complaint.

2. What we access, and why

When you connect your Microsoft 365 or Google Workspace account, you grant the Service read access to your mailbox and calendar, and permission to send mail as you. We use those permissions only for the purposes below.

Account details we store

  • Your provider account identifier and the email address your provider reports.
  • Your display name — used to address the briefing to you.
  • The address the briefing is delivered to.
  • Your briefing preferences (the free-text instructions you set on your account page).
  • Encrypted OAuth tokens that let us fetch your mail each morning without asking you to sign in again, plus their expiry and your connection status.

Mail and calendar content we read each run

  • Messages received in the previous 24 hours: sender, recipients (including whether you were a direct recipient or copied), subject, timestamp, read state, importance flag, and up to the first 1,500 characters of the message text.
  • Calendar events for the current day: title, start and end time, location, and organiser.

We do not read older mail, folders other than your inbox, attachments, contacts, files, or any other data your provider may expose.

3. How we use it

The content above is assembled into a summary of your morning and emailed to you. That is the entire purpose. Specifically, we do not:

  • sell, rent, or share your data with data brokers;
  • use it for advertising, ad targeting, or profile building;
  • use it to build datasets or products about you or your contacts;
  • allow our staff to read your mail, except in the limited cases in section 6.

4. Automated summarisation

To produce the summary we send the extract described in section 2 to Anthropic’s Claude API, which returns the structured content of your briefing. This happens once per briefing, for your briefing only. Under Anthropic’s commercial API terms, inputs submitted through the API are not used to train their models.

We do not use your mail or calendar data to develop, improve, or train any generalised artificial intelligence or machine learning model, whether our own or a third party’s.

Summaries are generated automatically and can be incomplete or wrong. The briefing is a convenience, not a substitute for reading your own inbox.

5. Storage and retention

  • Account record and preferences — kept in our database until you disconnect, at which point the record is deleted.
  • OAuth tokens — encrypted with AES-GCM before being written to the database, and deleted with your record when you disconnect.
  • Mail and calendar content — never written to our database. It exists only for the few seconds needed to generate and send your briefing.
  • Automation logs — the system that runs the morning job retains execution records, which include the mail extract, for up to 7 days for troubleshooting, after which they are deleted automatically.
  • The briefing email itself — delivered to your mailbox and, where your provider supports it, saved in your Sent items. It is yours; delete it whenever you like.

6. Who else is involved

We use a small number of service providers to run the Service. Each receives only what it needs:

  • Vercel — hosts the web application.
  • Supabase — hosts the database holding your account record and encrypted tokens.
  • n8n — runs the scheduled morning job that fetches your mail and calendar and sends the briefing.
  • Anthropic — generates the briefing content, as described in section 4.
  • Resend — sends service notices, such as an email asking you to reconnect when your authorisation expires.
  • Microsoft and Google — the source of your mail and calendar, and the channel your briefing is sent through.

We may also disclose data where we are legally required to, or where strictly necessary to investigate a security incident or abuse. Our people access mail content only with your explicit permission, or where required by law.

These providers operate outside Australia, principally in the United States, so your data is transferred and processed overseas.

7. Google user data — Limited Use

Our use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, data obtained through Google Workspace APIs is used only to provide and improve the briefing feature you have asked for; is not transferred except as needed to provide that feature, to comply with applicable law, or as part of a merger or acquisition with notice to you; is not used for advertising; is not read by humans except with your permission, for security purposes, or where required by law; and is not used to develop, improve, or train generalised AI or ML models.

8. Security

  • Refresh and access tokens are encrypted at the application layer (AES-GCM) before storage.
  • The automation never holds long-lived credentials; it requests a short-lived access token for each run.
  • All traffic runs over TLS, and internal endpoints require a shared secret.
  • Database credentials are server-side only and never exposed to the browser.

No system is perfectly secure. If we become aware of a breach affecting your data we will notify you and any regulator as required under the Privacy Act 1988 (Cth).

9. Your choices

  • Change what the briefing focuses on — edit your preferences on your account page at any time.
  • Stop the briefings and delete your data — use “Disconnect my inbox” on your account page. This deletes your record, including your stored tokens, and no further briefings are sent.
  • Revoke access directly with your provider — you can also remove the Service from your Google account permissions or your Microsoft account’s app access at any time, independently of us.
  • Access or correct your data — contact us and we will respond within a reasonable period.

10. Eligibility

The Service is intended for working adults using a business or personal mailbox they are authorised to connect. It is not directed at children.

11. Changes

If we change how we handle your data we will update this page and revise the date above. Where the change is significant we will tell you by email before it takes effect.

12. Contact

Advancer — support@advancer.com.au. If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner.