~ Brief

Privacy Policy

Last updated: 29 September 2026

The short version

Who we are

Brief is made by Runbear Inc. (“Runbear”, “we”, “us”). This policy covers the Brief macOS application (the “App”) and the website at dobrief.app (the “Site”). It does not cover Runbear’s other products, which have their own policies.

Brief has no sign-up, no login and no user accounts. We do not know who you are, and there is nothing we hold about you by name.

What Brief reads, and when

When you press the hotkey (⌃X by default), Brief uses the macOS Accessibility API to read text out of the window that is in front at that moment, and then summarises it. It reads:

Brief also reads the window’s title, and the name and icon of the app it belongs to, so the panel can say where a brief came from.

Brief does not read anything at any other time. There is no background capture, no screen recording, no keystroke logging and no clipboard monitoring. The Accessibility permission macOS asks you to grant is broad by design; Brief uses it on the hotkey and at no other moment.

Where the captured text goes

Brief sends the captured text to the engine you selected in the ~ menu, and nowhere else. There is no silent fallback: if the engine you chose cannot run, Brief tells you why rather than quietly sending your text somewhere else.

EngineWhere the text goes
Haiku 4.5 (API)Posted from your Mac to Anthropic’s Messages API, authenticated with your own API key. If your machine is configured to use a gateway (see Credentials below), it goes to that host instead, and the panel footer names the host on every brief.
Sonnet / Opus via Claude CodePassed on standard input to the claude program already installed on your Mac, which sends it to Anthropic under your own Claude subscription.
Apple Intelligence (on-device)Nowhere. Summarised locally by Apple’s on-device model. No network request is made.
ExtractiveNowhere. No model is used at all; sentences are selected locally.

In every case the request goes from your Mac to the destination. It does not pass through Runbear. We operate no proxy, relay or log of your briefs.

What Anthropic — or your gateway operator — does with text you send them is governed by their terms and privacy policy, not ours. See Anthropic’s privacy policy.

Credentials

To reach an API engine, Brief looks for a credential on your machine, in this order: a key you entered in the app (stored in your user defaults), the ANTHROPIC_API_KEY environment variable, then the env block of ~/.claude/settings.json. That last source is frequently a company gateway rather than Anthropic — which is why the panel footer names the destination host on every brief. Your key is sent only to the engine host, as the request’s authentication, and never to us.

What stays on your Mac

These files are yours. They are never uploaded, and you can delete any of them at any time.

FileWhat it holds
~/Library/Application Support/Brief/history.jsonBriefs you have already read: the brief text, the window title, the footer, and a SHA-256 hash of the captured text. The captured text itself is not stored — the hash only serves to recognise a repeat request. Written owner-only (0600).
~/.brief-debug.logA rolling diagnostic log of the capture path: window titles, which app, which scope was chosen, and short previews of the answer. Capped at 512 KB and truncated, not rotated. It exists because capture problems depend entirely on which app you were in, and that is not knowable from a bug report. Delete it freely; Brief will start a new one.
User defaults (sh.brief.Brief)Your settings: engine, style, language, hotkey, always-on-top, whether analytics is on, and an API key if you entered one.

Nothing in this section is transmitted anywhere. If you send us a bug report and choose to attach the debug log, you are sending us its contents deliberately — read it first.

Anonymous usage counts

Brief sends anonymous product analytics to PostHog. This is the only thing the App sends that you did not ask for, so it is deliberately narrow: enums and numbers only. No captured text, no brief text, no window title, no app name, no file path and no error message may ever be a property — error types only, because a message can quote the request.

The events, in full:

EventProperties
app_launchedengine setting, whether the hotkey registered, whether Accessibility is granted, whether the app is running from a disk image
briefengine, style, language, whether it was a re-read, the outcome (an enum such as ok, cancelled, engine_blocked), and elapsed milliseconds
onboardingwhich first-run stage was reached

Every event also carries the app version, build and macOS version. Events are keyed to a random UUID generated on first launch and derived from nothing about your machine, so it counts an install without identifying one. PostHog is configured to build no person profile, and to discard IP addresses server-side. A failed send is dropped, never queued to disk.

Switching it off: ~ menu → Share anonymous usage. Nothing is sent from that moment on.

Update checks

Brief checks for new versions using Sparkle, which fetches https://dobrief.app/appcast.xml. That request carries only what any HTTP request carries — your IP address, the time, and a user agent that includes the Brief version. The feed is a static file on GitHub Pages; we do not analyse its access logs, and GitHub’s own handling is governed by GitHub’s privacy statement.

This website

The Site is a static page served by GitHub Pages. The home page sends anonymous page analytics to PostHog, in the same project and US region as the App’s usage counts: that the page was viewed, how far it was scrolled, which links and buttons were clicked, the referring page, and your browser, operating system and screen size. It sets no cookies and stores nothing in your browser, so a later visit cannot be linked to an earlier one. As with the App, IP addresses are discarded server-side, no person profile is built, and nothing is recorded as a replay.

If you email us, we hold your address and what you wrote for as long as we need it to answer you.

What we do not do

Children

Brief is not intended for children under thirteen (or the minimum age of digital consent where you live), and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.

Security

Brief is signed with a Developer ID certificate and notarized by Apple, so macOS can verify it has not been tampered with, and updates are signature-checked before they install. Requests to engines and to the update feed use TLS. Files Brief writes in your home folder are protected by macOS file permissions; history.json is written owner-only.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Your rights

Depending on where you live you may have rights to access, correct, delete, port or restrict the processing of your personal information, to object to processing, and to withdraw consent. Two practical notes for Brief specifically:

EEA and UK residents: our lawful bases are performance of a contract (running the App you asked to run), our legitimate interests in keeping Brief working and understanding aggregate usage, and your consent where we ask for it. You may lodge a complaint with your local supervisory authority.

California residents: you have the right to know, delete, correct, and opt out of the sale or sharing of personal information, and not to be discriminated against for exercising those rights. We do not sell or share personal information. Under California’s “Shine the Light” law (Civil Code § 1798.83) you may request information about personal information shared with third parties for their direct marketing purposes; we share none.

To exercise any right, email contact@runbear.io.

International transfers

Runbear is in the United States, and the PostHog cloud region Brief uses is hosted in the United States. Where required, transfers rely on appropriate safeguards such as the European Commission’s standard contractual clauses.

Changes to this policy

We may update this policy. When we do, we publish the new version here with a new date at the top. If a change is material — in particular, any change to what Brief sends and where — we will say so prominently on this page and in the App’s release notes.

How to contact us

Runbear Inc. — contact@runbear.io