Skip to main content
Last updated: October 10, 2026
Brew Emails Inc. (“we,” “us,” “our,” or “Brew”) offers enterprises the tools they need to create, send, and optimize high-performing email campaigns and automations.
We want you to be familiar with how we collect, use, and disclose personal information. This Privacy Policy describes how we handle personal information that we collect through our websites, social media pages, APIs, online communications, and any other sites or services that link to this Privacy Policy (collectively, the “Services”).
Personal information that we handle on behalf of our customers in our role as a service provider / data processor is governed by our Data Processing Agreement.

1. Personal Information We Collect

Here’s how we collect personal information in providing our Services. 1.1. Personal information we receive from you 1.2. Personal information collected automatically through your use of our Services 1.3. We use the following tools for automatic data collection 1.4. Other sources from which we collect personal information

2. How We Use Personal Information

Here’s an overview of how we use personal information in providing our Services.

3. How We Disclose Personal Information

Here are the types of entities to which we may disclose personal information in providing the Services.

4. Security

We seek to use reasonable organizational, technical, and administrative measures to protect personal information within our organization. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure, please notify us immediately.

5. Marketing Choices

You have choices regarding marketing-related communications. If you no longer want to receive marketing-related communications from us on a going-forward basis, you may opt-out by following the unsubscribe instructions in any such message or by contacting us by email at legal@brew.new. We will try to comply with your request(s) as soon as reasonably practicable. Please note that if you opt out of receiving marketing from us, we may still send you important administrative messages, from which you cannot opt out.

6. Privacy Rights Requests

We offer you choices that affect how we handle the personal information that we control. Depending on your location and the nature of your interactions with our Services, you may request the following in relation to your personal information:
  • Information about how we have collected, used, and disclosed personal information. We have made this information available to you without having to request it by including it in this Privacy Policy.
  • Access to a copy of the personal information that we have collected about you. Where applicable, we will provide the information in a portable, machine-readable, readily usable format.
  • Correction of personal information that is inaccurate or out of date.
  • Deletion of personal information that we no longer need to provide the Services or for other lawful purposes.
To make a request, please contact us in accordance with the “Contacting Us” section below. We will respond to your request consistent with applicable law. You have the right to be free from unlawful discrimination for exercising your rights under applicable law. In your request, please make clear what personal information you would like to have changed, whether you would like to have your personal information suppressed from our database or otherwise let us know what limitations you would like to put on our use of your personal information. For your protection, we may need to verify your identity before implementing your request. We will try to comply with your request as soon as reasonably practicable. To the extent available under applicable law, if we refuse to take action on your request, you may appeal this refusal within a reasonable period after you have received notice of the refusal. You may file an appeal by contacting us as described in the “Contacting Us” section below. If you would like another person (an “agent”) to make a request on your behalf as permitted by applicable law, the agent may use the submission methods noted above. As part of our verification process, we may request that the agent provide proof of their authorization by you to submit the request. Please note that we may need to retain certain information for recordkeeping purposes and/or to complete any transactions that you began prior to requesting a change or deletion (e.g., when you make a purchase, you may not be able to change or delete the personal information provided until after the completion of such purchase). Further, certain personal information may be exempt from requests pursuant to applicable data protection laws or other laws and regulations.

Brew Connectors and MCP Tools

When you connect Brew to an AI assistant using the Model Context Protocol (MCP), the assistant sends Brew the arguments of the tools it calls. Brew authenticates the connection and restricts access to the connected organization or brand and your permissions. Our MCP tool catalog describes the available actions and their inputs and results.

Data Collected and Purposes

Brew’s tools do not request the full conversation history. Free-text tool fields are for the content or change you request, or the feedback or technical report you ask to submit. The assistant receives the selected records, summaries, previews, status, pagination information and any scoped upload or download links needed for the action. That assistant’s handling of the tool results is governed by its provider’s terms and your settings there.

Recipients and Storage

Application records are stored in Brew’s application databases and file storage. Authentication, caching, search, hosting and monitoring providers process the data needed for their services. The subprocessor list identifies these providers, including Vercel, Convex, MongoDB Atlas, Upstash, Turbopuffer, Clerk, Datadog and Braintrust. Monitoring and AI evaluation services may receive generation inputs and outputs where content recording is enabled, as well as account attribution and operational metadata, to diagnose failures and evaluate generation quality. Content recording is disabled on some routes; it is not a uniform exclusion across all tools. Generation requests can send your requested content, brand guidance, selected designs, referenced assets and source material to model providers, generally through Vercel AI Gateway. The subprocessor list identifies generation, embedding and media providers. Source URL and rendering requests can also disclose the selected content or URL to crawling, browsing and rendering services. Provider retention and training controls depend on the provider, route and applicable service configuration; this policy does not promise zero retention or that all routes use identical settings. Email delivery services receive the sender, recipients and rendered email needed to send an email; recipients receive that email. Address validation services receive the addresses being checked. Inbox-placement and rendering tests send the selected test content to the applicable testing services, and an automation test with a recipient sends a real email. Connected export providers receive the selected design and destination information when you request an export. These connected integrations act under your agreement with the provider. When you request submit_feedback, Brew sends only the redacted message, optional title, issue type and a deduplication key to Notra’s Brew feedback inbox. report_tool_issue stores the requested technical report in Brew’s support records. Neither workflow automatically attaches the conversation history. Authorized support personnel may access these records to respond or investigate. Public design images and other public assets are hosted through Brew’s content delivery storage, including cdn.brew.new. Anyone with a public asset URL can retrieve that file. Treat public asset links accordingly. Scoped upload and download links grant access to the indicated file for their validity period; avoid sharing them beyond the intended task.

Retention and User Controls

You can disconnect Brew from your assistant or revoke the relevant connection or API key to stop future access. Disconnecting does not delete existing Brew records, delivered emails, provider-held records or results already returned to your assistant. You can correct or remove supported records in Brew, unsubscribe recipients, and cancel pending sends or workflows where their status permits it. Delivered email cannot be recalled. For access, correction, account or file deletion, feedback removal, or details of provider-held records and backups, contact legal@brew.new. We verify the request and assess the applicable records, recipients and legal obligations. Deletion from the active application does not establish immediate deletion from every provider or backup, and public assets require separate handling. We do not promise an unverified automatic erasure timeline.

7. Retention Period

We retain personal information for as long as needed or permitted in light of the purposes for which it was obtained as outlined in this Privacy Policy unless a longer retention period is required or permitted by applicable law. The criteria used to determine our retention periods include:
  • The length of time we have an ongoing relationship with you (for example, for as long as you keep using our Services);
  • Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records or communications for a certain period before we can delete them); or
  • Whether retention is advisable considering our legal position (such as in regard to applicable statutes of limitations, litigation, or regulatory investigations).

8. Third-Party Services

This Privacy Policy does not address, and we are not responsible for, the privacy, information, or other practices of any third parties. This includes any third party operating any website or service to which our Services link. The inclusion of a link on our Services does not imply endorsement of the linked site or service by us or by our affiliates.

9. Third-Party Payment Service

The Services may provide functionality allowing you to make payments to us using third-party payment services. When you use such a service to make a payment, your personal information will be collected by such third party and not by us, and will be subject to the third party’s privacy policy, rather than this Privacy Policy. We have no control over, and are not responsible for, this third party’s collection, use, and disclosure of your personal information.

10. Use of the Services by Minors

The Services are not directed to individuals under the age of 18, and we do not knowingly collect personal information from individuals under 18. If you have reason to believe that a child under the age of 18 has provided personal information to us through the Services, please contact us.

11. Cross-Border Transfer

Your personal information may be stored and processed in any country or region where we have facilities or engage service providers. By using the Services, you understand that your personal information may be transferred to countries outside of your country or region of residence, which may have data protection rules that are different from those of your country or region. In certain circumstances, courts, law enforcement agencies, regulatory agencies or security authorities in those other countries or regions may be entitled to access your personal information. Where applicable, we have put in place adequate measures, such as the standard contractual clauses adopted by the relevant authority, to protect your personal information. You may obtain a copy of these measures by contacting us in accordance with the “Contacting Us” section below.

12. Updates to This Privacy Policy

The “Last Updated” legend at the top of this Privacy Policy indicates when this Privacy Policy was last revised. Any changes will become effective when we post the revised Privacy Policy on the Services.

13. Contacting Us

Brew is the company responsible for collection, use, and disclosure of your personal information under this Privacy Policy. If you have any questions about this Privacy Policy, please contact us. You can reach us at legal@brew.new or by mail at: Brew Emails Inc.
2248 Broadway 1933
New York, NY 10024