Privacy & Security carries two groups and three controls. It is a short screen that does more than its length suggests: two of the three decide what Brief reads at all.

This is the screen, not the posture. For how Brief encrypts and isolates your data and which models see what, read Privacy and security.
Unknown Senders
One toggle: Hide emails from people I've never interacted with.
What it does is narrower than "hide", and the card is precise about it: "Emails from senders you have never written to or met with stay stored and searchable, but are left out of your briefings."
So nothing is deleted or ignored. A cold outreach email is still in Brief and still turns up in search — it just does not take up room in your morning read. Brief decides "never interacted with" from whether you have written to them or shared a meeting.
Turn it on if your brief keeps leading with people you have never met. Leave it off if unsolicited mail is part of your job — inbound recruiting, founder pitches, press — because then those senders are the work.
Exclude List
The sharper instrument. Excluded emails takes one address or pattern per line, and these are excluded from processing rather than filtered out afterwards.
The syntax is more capable than it looks:
- A full address —
noreply@example.com— excludes that sender. - A wildcard —
*@domain.com— excludes everyone at that domain. - A bare domain —
domain.com— does the same thing. - A local-part wildcard —
notify@*— excludes that mailbox name at every domain, which is the one that catches the same robot across a dozen vendors.
The best use is machine traffic: build notifications, monitoring alerts, receipts, calendar spam. Anything that arrives constantly, is never a commitment, and is never a decision.
Take care with a bare domain that also carries real correspondence. Excluding bigcustomer.com to silence their ticketing robot also excludes the person who signs the renewal.
Sessions
Every signed-in device, the current one carrying a This device tag, and two ways out.
Log out ends the session you are using. Log out everywhere ends every other one and leaves you signed in here. Both confirm first, and the confirmation is what spells out which is which — "Log out this session?" against "Log out of all other devices?"
The second is what you want after losing a laptop or phone, or signing in on a machine that was not yours. It is also the right move if you ever suspect your Google or Microsoft account was compromised — end the Brief sessions, then fix the account at the provider, since that is where Brief's sign-in actually lives.
If a session simply looks unfamiliar, check it against how you use Brief before assuming the worst: a phone browser, a work laptop, and a home desktop are three sessions from one person.