Legal

Privacy Policy

Version 2026-07.2 · Last updated: July 2026 (rev 2)

1. Overview

Brikly is operated by MiDa Innovations Pty Ltd (ABN 42 665 670 137), Sydney, Australia. Brikly (“we”, “our”, or “us”) is committed to protecting your privacy. This policy explains what personal and financial information we collect, how we use it, and the choices you have regarding that information.

By using Brikly you agree to the practices described in this policy. If you do not agree, please do not use the service.

2. Information we collect

We collect the following categories of information:

  • Account information: email address and authentication credentials (via Google SSO or email/password).
  • Property data: property addresses, purchase prices, current valuations, and property types that you enter.
  • Financial data: loan balances, interest rates, repayment schedules, rental income, expense records, and depreciation entries that you enter or connect. Where the bank-feed feature is offered, transaction data may also be imported automatically from an account you authorise (see section 5).
  • Billing information: your subscription tier, billing interval, and payment status. Card details are collected and stored by our payment processor, Stripe, never by Brikly. We do not see or hold your card number.
  • Usage data: pages visited, features used, and timestamps of activity, collected via server logs and Supabase Analytics. When you accept our Privacy Policy and Terms we also record the acceptance time, policy version, and the IP address and browser user-agent of that request.

3. How we use your information

  • To provide, maintain, and improve the service.
  • To calculate portfolio metrics, cashflow, and yield figures shown in the dashboard.
  • To parse documents you provide (document content is sent to the AI model only for extraction).
  • To send service-related communications (account verification, security alerts).
  • To comply with applicable Australian privacy laws.

4. Data security

We take security seriously and apply the following controls:

  • Encryption at rest: sensitive financial fields are encrypted using AES-256 via pgcrypto before storage.
  • Row-level security: Supabase row-level security policies ensure your data is only accessible to your authenticated account.
  • Encryption in transit: all data is transmitted over HTTPS/TLS.
  • Audit logs: all create, update, and delete operations are recorded with timestamps and user attribution.
  • Security headers: HTTP security headers including Content-Security-Policy, HSTS, and X-Frame-Options are applied to every response.

5. Data sharing

We do not sell your personal data. We share data only in these circumstances:

  • Supabase: database hosting and authentication. Supabase processes data under their own privacy policy and data processing agreement.
  • Anthropic: when you forward or upload a document, its content is sent to Anthropic's API solely for parsing and extraction of financial figures. No chat or assistant data is involved. Anthropic processes this data under their usage policy.
  • Amazon Web Services (AWS): inbound email infrastructure. When you forward property-related email to your unique Brikly forwarding address (an optional, off-by-default feature), AWS (Simple Email Service and Lambda) receives and relays that message to Brikly for processing. See section 10 for the full detail.
  • Resend: transactional and contact email delivery. When we send you service email, or when you message us through the contact form, Resend processes your email address and the content of that message to deliver it.
  • Vercel: application hosting and content delivery (CDN). Vercel processes request metadata and server logs (such as IP address and user-agent) as part of serving the application.
  • Basiq: bank-feed connection via the Consumer Data Right (CDR), where this feature is offered. When you authorise a bank connection, Basiq processes your financial and account data to import transactions. This processing only occurs if you connect an account.
  • Stripe: payment processing. When you subscribe to a paid plan, Stripe collects and processes your payment details under their own privacy policy. Brikly stores only a customer reference, your subscription status, and the billing period, never your card details.
  • Google Places: address autocomplete. When you type into the add-property address field, the text you have typed is sent to Google's Places service to return address suggestions. This happens only when you use that field.

Sharing you initiate: accountant share links

You can generate a read-only share link for your reports (Reports → Share with Accountant). Anyone who has the link can view the shared reports without logging in, including your property addresses, valuations, loan balances, income, expenses, depreciation and tax-report figures. Links use a long random token that is designed to be unguessable, expire automatically 90 days after they are created, and can be revoked by you at any time from the Reports page. Creating a new link revokes the previous one. We record when a share link was last accessed so you can see whether it has been used. Treat a share link like the report itself: only send it to someone you intend to see your figures.

  • Legal requirements: we may disclose information if required to do so by law or in response to valid requests by public authorities.

6. Data retention

We retain your data for as long as your account is active. When you delete your account, we delete your data and cryptographically destroy any encryption keys associated with your account within 30 days.

7. Your rights

Under the Australian Privacy Act 1988, you have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate information.
  • Request deletion of your account and associated data.
  • Withdraw consent for optional data processing.

To exercise these rights, use the account deletion feature in Settings → Privacy & Security, or contact us at the address below.

8. Cookies

We use session cookies managed by Supabase for authentication. We do not use tracking cookies or third-party advertising cookies.

9. Changes to this policy

We may update this policy from time to time. We will notify you of material changes via email or a notice in the app. Continued use after changes constitutes acceptance.

10. Optional email forwarding

Brikly offers an optional, off-by-default email-forwarding feature so the service can extract property-related documents (rental statements, council and water rates notices, insurance policies, strata levies) and route them to the correct property. The feature only activates after you set up forwarding and enable scanning in Settings.

  • How it works: we issue you a unique, private forwarding address. You forward (or set your email provider to auto-forward) property-related email to that address. Brikly never connects to or reads your mailbox; we only ever receive the messages you forward to your Brikly address.
  • What we access: only the messages you forward to your Brikly forwarding address.
  • What we extract: Financial figures only: amounts, dates, document types, and property addresses.
  • What we store: the extracted financial data and the source document you forwarded, attached to the relevant property, together with the sender address and subject line of the forwarded message (used to identify and match the document).
  • Data minimisation: Only the fields required to populate your property records are retained. Nothing is used for advertising, profiling, or training third-party models.
  • Security: AES-256 encryption at rest on sensitive fields. Your forwarding address is an unguessable private token, and Row Level Security is enforced at the database level so no other user can read your data.
  • Turn it off: you can disable scanning at any time from Settings → Email, and stop or remove the forward at your email provider.

11. Contact us

For privacy enquiries, please contact us at hello@brikly.com.au.