← Back

Privacy Policy

Last updated August 8, 2026

The short version

You bring your own AI provider keys, and your briefs are generated using them, not ours. We encrypt those keys before we store them. Your uploaded recording, its audio, and the frames we sample are deleted from our storage once processing finishes. We do not sell your recordings, transcripts, keys, contact details, or workflow content, and we do not use your workflows for research.

1. Who we are

Telos Brief is operated by Telos Intelligence. We are finalising our registered legal-entity name and address and will publish them here; until then, the fastest way to reach a person is email. Questions, requests, or complaints: support@telosintel.com.

2. What we collect

You give us: your email address, your name if you provide one, and a password, which we store only as a bcrypt hash — we never store or see your actual password. Your screen recording, or the text of your chat interview if you use that mode. Your AI provider API keys, if you add them. Any feedback you send us.

We generate: the transcript of your recording, the brief itself, and the configuration files we produce for you. We also record our own estimate of what your brief cost in provider tokens, for internal planning — we never bill you for it.

We record automatically: which pages you visit and when, and events such as signing up, logging in, and starting or completing a brief. These records contain no transcript text, no recording, no API key, and no content from your workflow. Our hosting providers also keep standard server logs, which include IP addresses; those logs are kept under each provider's own default retention, which we have not yet published here.

3. Why we use it, and for how long

We use what we collect to run your account, produce your briefs, keep the service working, and understand how it is used. How long each thing lasts:

We would rather tell you that some of this is currently kept indefinitely than publish a retention schedule we have not built. A defined schedule with automatic deletion is planned; this page will change when it exists, not before.

4. Your API keys

You bring your own Anthropic and OpenAI keys, and every brief runs on them. We encrypt each key with AES-256-GCM before writing it to our database, and we store a four-character hint so you can tell your keys apart. Your key is never sent back to your browser or shown to you again.

A key is decrypted only inside the job that runs your own request. We hold the encryption key, so this is protection against a database compromise — it is not a claim that we technically cannot read your key. We think you should know the difference.

You can delete any key at any time in Settings, and the record is removed immediately rather than flagged as deleted. Charges for your provider usage are billed to you by that provider, never by us.

5. Where your data lives

Our database is hosted on Neon. Neon keeps backups for point-in-time recovery, which means a deleted row can remain recoverable from a backup for some period after we delete it; we are confirming that window and will state it here rather than guess at it.

Files are stored in Amazon S3 in the us-east-2 region, with server-side encryption (SSE-S3) applied by the bucket, all public access blocked, and object versioning disabled — so when we delete an object it is gone, not hidden behind a delete marker.

Our job queue runs on Upstash Redis and holds only job identifiers, never your content. The application runs on Vercel and the processing worker on Railway.

6. Who we share it with

We do not sell your data. We share it only with the services needed to run the product:

The Telos team can see your account email and your usage counts. We cannot see the contents of your briefs unless you explicitly share one with us when leaving feedback.

7. Research

We do not currently use your workflows for research. If that changes, we will ask you separately and explicitly, and you will be able to decline. Accepting our Terms does not grant research permission and will not be treated as if it did.

8. Your choices

In Settings you can add and remove your provider API keys, and you can download your generated files at any time from your brief.

There is no self-service export or account deletion yet. To request a copy of your data or ask us to delete your account, email support@telosintel.com and a person will handle it. We are not going to promise a response time we have not staffed; we will acknowledge your request and tell you when it is done.

9. Security

Provider keys are encrypted at rest with AES-256-GCM. Passwords are hashed with bcrypt. Access to your briefs and files is checked against your account on every request. Download links are pre-signed and expire after one hour. Uploaded media lives in a bucket with public access blocked and server-side encryption enabled, and is deleted once processing finishes.

We are a small team building an early product. We do not hold SOC 2, ISO 27001, or any other security certification, and we are not going to imply one. If you need a specific control or assurance before you can use Telos Brief at work, email support@telosintel.com and we will tell you honestly whether we have it.

10. Children

Telos Brief is not intended for anyone under 18, consistent with our Terms.

11. Changes

If we make material changes to this policy we will update the date above and take reasonable steps to tell you.

12. Contact

support@telosintel.com.

See also our Terms of Use. This document describes what the product actually does today and is not legal advice.