Privacy
Your appointment story is not our business model.
Last updated August 7, 2026
Your encrypted care workspace
Appointment preparation, check-ins, follow-up plans, and visit history sync to your PeriBrief account so they remain available after browser clearing and on another device. PeriBrief encrypts this workspace at the application layer before storing it in the production database. The database holds a bounded encrypted vault and technical envelope metadata, not readable health content.
The PeriBrief service holds the encryption secret needed to return this workspace after an authenticated sign-in, so this is encrypted account storage - not zero-knowledge storage. Access is limited to the service path that restores your workspace. Readable contents are not sent to Stripe, reminder emails, feedback, analytics, PeriBrief application logs, or Good Guys Labs operations. You can erase the local copy without deleting the account vault, or delete the account and vault from Settings.
Optional AI-assisted recap drafting
When this optional feature is available and you choose “Create an editable draft,” PeriBrief sends your appointment date and the recap text you reviewed to OpenAI's API. It also sends a pseudonymous safety identifier used for abuse prevention and rate limiting. PeriBrief does not send your name or email as account fields, although your recap may contain any details you choose to type. Avoid including names or other identifying details that are not needed to organize your plan.
OpenAI is used only to organize your own words into an editable draft, not to diagnose, recommend treatment, interpret results, or invent instructions. The request uses store: false, and Good Guys Labs does not opt these requests into model training. Under OpenAI's default API data controls, prompts and responses may be retained in abuse-monitoring logs for up to 30 days, with limited exceptions described in OpenAI's data controls. Read OpenAI's API data controls.
PeriBrief does not log the recap or OpenAI's draft. Nothing from this step is saved to your PeriBrief workspace until you review it and choose Save follow-up plan. Once saved, it follows the encrypted workspace and deletion rules described on this page. Account deletion cannot shorten OpenAI's separate abuse-monitoring retention window for a request that has already been processed.
Public website and account access
Cloudflare processes ordinary security and delivery logs when you visit the site. When you create an account, Good Guys Labs LLC stores your first name, normalized email address, a random account identifier, a salted one-way password hash, password-reset token hashes, and session-token hashes. Email-verification and password-reset links expire after 30 minutes, and sessions expire after 30 days. PeriBrief never stores your readable password. Password attempts are protected by Cloudflare Turnstile and rate-limited using hashed email and network-address signals.
If you choose Sign in with Apple or Sign in with Google, that provider confirms a provider-specific account identifier, your verified email address, and, when available, your first name. PeriBrief stores the provider name, provider-specific identifier, verified email, and the dates the connection was created and last used. Neither Apple nor Google receives your appointment preparation, visit history, follow-up plan, or encrypted workspace through the sign-in process. You can connect an existing PeriBrief account from Settings rather than having accounts merged automatically by email alone.
Subscriptions and billing
Stripe processes checkout, payment methods, invoices, and subscription management. PeriBrief stores Stripe customer and subscription identifiers, the selected price identifier, subscription status, renewal timing, cancellation state, and any applied promotion. PeriBrief does not receive or store complete card numbers.
Complimentary tester access
For invited testers, Good Guys Labs LLC stores the invited email address, who granted access, and the grant, expiration, revocation, and update times. These records determine product access without creating a Stripe customer or collecting a payment method. Expired or revoked tester grants are deleted after 90 days, and account deletion removes the grant for that email.
A one-time founder access code can activate a complimentary account without creating a Stripe customer or payment method. PeriBrief stores only a one-way hash of that code, the member identifier that redeemed it, and the redemption or revocation time. The readable code is not stored.
Optional reminders
Email reminders are off until you enable them. If enabled, PeriBrief stores your account identifier, reminder type, send time, delivery status, and a provider message identifier. Reminder emails are generic: they contain no symptoms, medications, clinician names, appointment notes, treatment details, or generated brief. You can disable reminders in Settings or from any reminder email.
Product feedback
The member workspace accepts ratings, fixed feedback categories, and an optional product comment of up to 800 characters. Please do not include symptoms, medications, clinician information, appointment details, or other medical information. Your email is retained with a feedback record only when you explicitly permit follow-up. Feedback, including an optional comment, is deleted after 90 days by a daily cleanup. A daily-changing pseudonymous hash of your authenticated account or preview identity enforces a limit of five submissions per day; PeriBrief does not use your IP address for this limit, and the hash expires shortly afterward. A privacy-minimal email may notify the PeriBrief team that a new record is ready in the private inbox. A weekly owner digest groups counts by feedback category and affected page; it does not include member identities or written comments. Follow-up is tracked only when you explicitly permit contact; the optional comment and appointment or workspace content are not copied into that email. Recoverable database copies may continue to exist until Cloudflare’s D1 Time Travel recovery window expires.
Retention and deletion
Expired authentication challenges, rate-limit records, and sessions are deleted automatically. Completed or cancelled reminder records are retained for no more than 90 days for duplicate prevention and delivery investigation. Minimal weekly feedback-digest delivery receipts are retained for no more than 365 days to prevent duplicate sends. Minimal Stripe webhook event receipts are retained for no more than 365 days for replay prevention and billing investigation. Account deletion removes the PeriBrief account, encrypted vault, sessions, preferences, and reminders from the production database after an active subscription is cancelled. If an account used a partner route, PeriBrief retains an opaque partner-attribution record, related Stripe object identifiers, and append-only commission entries as commercial records for payment, tax, fraud-prevention, dispute, and legal obligations. Those retained records do not contain the member's name, email, health information, appointment content, or workspace content and are not shown to partners. Browser clearing does not request account deletion. Stripe may retain billing records as required for payment, tax, fraud-prevention, and legal obligations.
Contact
Privacy or support questions: support@peribrief.com. Product suggestions can also be submitted through the private “Help us improve” form inside your workspace. Please do not email medical details.
PeriBrief is operated by Good Guys Labs LLC.