Privacy Policy
Last updated July 18, 2026
BrytIO is a product of Gulf Stream Tech Group, LLC (“BrytIO,” “we,” or “us”). This policy explains what personal information we collect, how we use it, who we share it with, and the choices you have. It covers information for which we act as the controller: visitors to brytio.com, people who contact us, and the people who sign up for and administer a BrytIO workspace.
A note on your CRM data. The customer, deal, invoice, and shipping records you put into BrytIO (“Customer Content”) are handled by us as a processor, on your behalf and on your instructions. How we store, secure, and delete that data is described in our Data Processing & Security Policy. For that data, you are the controller.
Information we collect
- Account and profile: name, work email, password (managed by our authentication provider), workspace name, role, and settings.
- Billing: billing contact, plan, and subscription status. Card and bank details are collected and stored by Stripe; we do not store full payment card numbers.
- Support and communications: messages and support requests you send us.
- Integrations you connect: if you connect Microsoft 365, QuickBooks Online, or similar services, we receive the access tokens and the data those connections are scoped to. These are optional and can be disconnected anytime.
- Usage and diagnostics: pages viewed, features used, IP address, device and browser type, timestamps, and error/performance data to keep the product reliable.
- Cookies: essential cookies for sign-in and security. We do not use third-party advertising trackers.
How we use information
We use your information only to run the product and support you: to provide, secure, and maintain BrytIO; authenticate you and prevent fraud; process billing; provide support; send service messages; debug and improve the product; and comply with law. We do not sell your personal information, and we do not use your data, or your Customer Content, to train AI models.
How we share information with sub-processors
We share personal information with vetted service providers who process it on our behalf, under contract, only to provide these services. We do not sell personal information.
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Clerk | Authentication and identity | Name, email, authentication metadata |
| Stripe | Subscription billing and payments (incl. Stripe Connect) | Billing contact, transaction data; card details held by Stripe |
| Anthropic (Claude) | AI assistant features | Content and context you submit to AI features, at the time of the request |
| Resend | Outbound and inbound email | Email content and metadata routed through the product |
| Microsoft | Microsoft 365 mail and calendar sync (optional) | Mailbox messages, calendar events, and contacts you authorize |
| Intuit (QuickBooks Online) | Accounting sync (optional) | Invoices, customers, and payments you sync |
| Cloudflare | Content delivery, edge security, and file storage | Uploaded files and request metadata |
| Sentry | Error monitoring and diagnostics | Diagnostic and technical data |
| DigitalOcean | Cloud hosting and infrastructure | Hosted data at rest |
We may also disclose information to comply with law, respond to lawful requests, protect our rights and users’ safety, or in connection with a merger, acquisition, or sale of assets (with notice where required).
AI features and your data
Some BrytIO features use AI (our assistant, drafting help, and quote suggestions), powered by Anthropic (Claude). When you use these features, we send the relevant content and context to Anthropic solely to generate the response you asked for. Your data is not used to train AI models, and inputs and outputs are not retained by the model provider for training. AI features are only available on plans that include them, and only run when you invoke them.
Security
We protect information with encryption in transit (TLS), encryption of sensitive credentials and integration tokens at rest, strict per-workspace data isolation, role-based access controls, and optional two-factor authentication. No method of transmission or storage is 100% secure, but we work to protect your information and continually improve our safeguards.
Retention
We keep personal information for as long as your account is active and as needed to provide the service, then delete or de-identify it within a reasonable period after account closure, except where we must retain it to meet legal, tax, accounting, or security obligations.
Your rights and choices
Your data is yours. You can:
- Access and correct most information in your account settings
- Export your data at any time
- Delete your workspace, which removes your data as described above
- Opt out of non-essential communications
We do not sell or share your personal information for targeted advertising. To make a request, contact us at privacy@brytio.com.
Data location
BrytIO is operated from and processes information in the United States.
Children
BrytIO is a business product not directed to children, and we do not knowingly collect personal information from anyone under 18.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you and update the date above.
Contact us
Questions or requests: privacy@brytio.com. You can also get in touch.