ParentBrief
Privacy Policy
Last updated 19 July 2026
This policy explains how David Diviny, a sole trader based in Victoria, Australia, handles personal information for the ParentBrief service under the Australian Privacy Principles. It covers our website, apps, waitlist, email and WhatsApp forwarding, Gmail connection and related services.
1. Who we are and how to contact us
ParentBrief is the name of the service. It is operated by David Diviny, a sole trader based in Victoria, Australia. Our privacy contact is [email protected].
In this policy, personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable. Some school or activity communications may contain sensitive information, such as health, disability, religious or cultural information.
2. Personal information we collect
Account and contact information: your name, email address, sign-in details, Google account identifiers, waitlist status and communications with us.
Family and school information: a child’s name, school, year level, class, activities and other household context you choose to add. We may also receive information about teachers, other parents, children and community members contained in communications you import or forward.
Content and connection information: forwarded email and WhatsApp content, sender and recipient details, message dates, links, media and imported Gmail messages; Gmail connection tokens and import rules; extracted events, tasks, reminders, summaries and brief content; and content you submit for a household or class.
Settings and delivery information: time zone, brief time, writing preferences, notification preferences, device push token, linked WhatsApp number and private forwarding address.
Technical and usage information: device and browser type, app version, IP address, approximate location derived from an IP address, pages and features used, referral information, diagnostics, security events, cookies or similar local storage and analytics identifiers. We do not use this information for targeted advertising.
Payment and subscription information: when you make a purchase, our payment provider or the relevant app store may collect your payment-card, bank or wallet details under its own privacy policy. We generally receive a payment token, billing contact details and records of purchases, subscriptions, renewals, cancellations, refunds and payment status rather than your full payment-card details. We use those records to provide paid features, administer billing, prevent fraud, respond to payment questions and meet legal and accounting obligations.
3. How we collect information
We collect information directly from you when you join the waitlist, create an account, add family details, adjust settings, contact us, forward a message or submit content.
With your direction, we collect information from connected services such as Google Gmail, WhatsApp and notification providers. We also collect technical and usage information automatically when you use ParentBrief.
We may collect information about other people from a parent, carer, class organiser, school communication or activity provider. Please provide another person’s information only when you are authorised to do so and the information is reasonably necessary for the feature you are using.
You may browse public ParentBrief pages without identifying yourself. An account and contact details are needed for features that must connect information to your household. If we receive unsolicited personal information that we could not lawfully have collected, we will delete or de-identify it where required and lawful.
If we ask for information and you do not provide it, you may be unable to create an account, connect an inbox, receive notifications, personalise a brief or use the relevant feature. Optional fields are identified where practical.
4. Why we collect, hold, use and disclose it
We use personal information to create and secure accounts; import, organise and display communications; match content to a child, school or activity; extract dates and actions; create briefs and reminders; deliver email, app and push notifications; and provide household and class-sharing features you choose to use.
We also use it to provide support, communicate service and waitlist updates, prevent fraud and misuse, diagnose faults, measure and improve the service, comply with legal obligations and protect people, ParentBrief and the public.
We may use de-identified or aggregated information for product analysis and service improvement where it is no longer reasonably capable of identifying an individual.
We do not sell personal information, use school communications for targeted advertising, or allow data brokers to use it. We will ask for consent where the law requires it, including before using sensitive information for a purpose not reasonably expected from the feature you requested.
5. Product analytics and service monitoring
ParentBrief uses PostHog to understand whether important parts of the app work, such as account setup, Gmail connection, and viewing or sharing a brief. These records may include your ParentBrief account identifier, email address, display name, app environment, device and app information, and the name of the action or screen. ParentBrief disables location enrichment and removes private record identifiers and authentication details before sending app events.
ParentBrief also records limited technical information about automated brief generation and email processing, such as the workflow, model, duration, token counts, and estimated cost. Privacy mode is enabled for this monitoring, so prompts, email text, generated brief text and model responses are not sent to PostHog.
ParentBrief does not intentionally send passwords, authentication tokens, Google authorisation codes, Gmail message contents, children’s names, class names or brief contents to PostHog.
6. Gmail and Google user data
If you connect Gmail, ParentBrief requests read-only Gmail access for the account you choose. The first scan checks up to the 200 most recent messages from the previous 120 days, excluding trash, spam, sent mail, and drafts. After that, ParentBrief checks new and changed messages.
ParentBrief examines those messages only to identify likely school communications. It stores messages that match your school-email import rules and does not store messages that do not match. You can narrow those rules by sender or Gmail label.
ParentBrief uses matched messages only to show your private inbox, extract school details, and build your briefs and reminders. It does not send email from your Gmail account or change your Gmail mailbox contents.
ParentBrief does not use Google user data for advertising, does not sell Google user data, and does not transfer Google user data to data brokers or information resellers.
ParentBrief uses Google user data only to provide or improve user-facing features inside ParentBrief. Raw school emails stay private to the parent account that imported them unless a parent deliberately creates shared content from them. Google user data is not permitted to train general-purpose AI or machine-learning models.
Human access to Google user data is prohibited except when you give explicit permission for support involving specific data, access is necessary to investigate security or abuse, access is required by law, or the data has been aggregated and anonymised for internal operations.
The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
You can control senders and Gmail labels, disconnect Gmail in Settings, revoke access through your Google account, or use manual forwarding instead. Disconnecting Gmail stops new checks but does not delete messages already imported into ParentBrief; you can delete those messages or your ParentBrief account separately.
7. AI-assisted processing
ParentBrief uses specialised service providers to extract information from communications, fetch pages you ask us to process and generate summaries, briefs and reminders. Relevant message content, links and family context may be sent to those providers solely to provide the requested feature and maintain its safety and quality.
ParentBrief uses OpenRouter to route AI requests to a selected model provider. Requests containing school-email content require zero data retention. Those providers are not permitted to retain the content or use it to train general-purpose AI or machine-learning models.
AI-generated output can be incomplete or inaccurate. ParentBrief does not use AI to make legal or similarly significant decisions about a child or parent. Check important details against the original communication.
8. Children and other people
ParentBrief accounts are for adults who are parents, carers or otherwise authorised to manage the relevant communications. We collect children’s information to provide the family organisation features requested by that adult, not to market to children.
We aim to minimise children’s information, keep imported content private by default and consider a child’s best interests when designing the service. Do not include sensitive or unnecessary information about a child or another person. If you believe information has been provided without authority, contact us so we can investigate, restrict or remove it.
9. When we disclose personal information
We disclose information to providers that support hosting, databases, authentication, cloud delivery, email and WhatsApp forwarding, Google connectivity, analytics, customer support, page retrieval, AI-assisted extraction and generation, and push notifications. This includes PostHog for the limited analytics and service monitoring described above. Providers may process only the information reasonably needed for their role and are subject to contractual, technical or policy safeguards.
We may also disclose information to professional advisers; to regulators, courts, law-enforcement or emergency services where required or reasonably necessary; and in connection with a proposed business sale or restructure, subject to confidentiality and privacy safeguards.
Household content remains private to your account unless you deliberately invite another household member or publish or share content to a class feature. Before sharing, the app identifies the intended audience. You are responsible for ensuring shared content is appropriate and that you have authority to share it.
10. Overseas disclosures
Some providers and their support teams store or process information outside Australia. Depending on the feature and provider configuration, likely locations include the United States, the United Kingdom and countries in the European Economic Area. Global network providers may process traffic in other countries closest to the user or service endpoint.
Before disclosing personal information overseas, we take reasonable steps required by the Privacy Act. These may include due diligence, contractual privacy and security terms, access controls, encryption and limiting the data disclosed. Contact us for current information about providers and locations relevant to your account.
11. Direct marketing and service messages
If you join the waitlist, we use your email to manage your place and send availability or product-launch updates. Where required, we send marketing only with consent or where otherwise permitted by law. You can unsubscribe using the message link or by contacting us.
We may still send non-marketing messages needed to operate your account, such as security alerts, requested briefs, connection errors, policy notices and responses to support requests. We do not use Google user data for marketing.
12. Security
We use reasonable administrative, technical and physical safeguards appropriate to the information we hold. These include access controls, encrypted connections, protected service credentials, separation and encryption of Gmail connection tokens, monitoring and restricted provider access.
No online service is risk-free. Keep your account secure, use a unique password, disconnect integrations you no longer use and contact us promptly if you suspect unauthorised access. If an eligible data breach occurs, we will assess it and notify affected people and the Office of the Australian Information Commissioner as required by law.
13. Retention, deletion and de-identification
We keep account information and imported content while your account is active and for as long as needed to provide the service. Different records have different retention periods based on their purpose, legal requirements, security needs and backup cycles.
ParentBrief stores imported emails, extracted details and brief content so they can appear in your account across devices. Gmail OAuth tokens are stored separately and encrypted. An imported email remains until you delete it from your ParentBrief inbox or delete your account. Details and briefs derived from it may remain after the email is deleted; deleting your account removes that derived content as well.
You can delete individual imported messages and can request or initiate account deletion in Settings. We then delete or de-identify personal information from active systems when it is no longer required, subject to reasonable processing time. Limited information may remain temporarily in protected backups or be retained where required for legal, fraud-prevention, security, dispute or transaction-record purposes. Providers may also retain limited records under their lawful retention schedules.
Disconnecting Gmail stops new checks. Unlinking WhatsApp stops ParentBrief from associating or storing subsequent messages with your account; however, our messaging provider and service may still receive a later message to determine that the number is no longer linked. Do not send further messages to the ParentBrief WhatsApp number after unlinking. Disconnecting either service does not by itself delete content already imported. Contact us if you want help with a broader deletion request.
14. Access and correction
You may ask to access or correct personal information we hold about you or a child for whom you are responsible. Many details can be reviewed or changed in Settings. For other requests, email [email protected] and describe the information concerned.
We may verify identity and authority before acting. We aim to respond within 30 days. We do not charge for making a request, although the Privacy Act may permit a reasonable access charge in some circumstances. If we refuse access or correction, we will give written reasons and explain how to complain, unless the law allows otherwise.
15. Privacy complaints
Send a privacy complaint to [email protected] with your contact details and enough information for us to investigate. We will acknowledge it, investigate fairly and aim to provide an outcome within 30 days.
If you are not satisfied, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au. You may also have rights to contact another relevant regulator or consumer protection body.
16. Changes to this policy
We may update this policy when the service, providers or law changes. We will publish the new date here and, where a change is material, give reasonable notice in the app, by email or on our website before it takes effect where practicable. We will seek consent if a new use requires it by law.