Privacy Policy
Last updated: June 22, 2026
This Privacy Policy describes how Brandex ("we", "us") collects, uses, and shares personal data when you use brandex.app and related services (the "Service").
1. Data we collect
- Account data — email, name, password hash, sign-in provider.
- Content — brand dossiers, prompts, generated assets, comments.
- Connected-provider data — data you authorize us to read from Meta/Facebook, Google, Google Search Console, HubSpot, TikTok, and similar providers (campaign metrics, search performance, page metadata). We never request more scopes than needed.
- Operational telemetry — error logs, request counts, feature usage. Used to keep the Service running.
- Billing data — handled by our payment processor; we store only customer IDs and invoice history.
2. How we use it
To operate the Service, generate the AI outputs you request, surface analytics from your connected channels, send transactional email (sign-in, receipts, notifications), and meet legal obligations. We do not sell personal data. We do not train shared AI models on your private brand content.
3. Legal bases (GDPR/UK)
Contract (to deliver the Service you signed up for), legitimate interest (security, fraud prevention, product analytics), consent (optional integrations, marketing email), and legal obligation (tax, accounting).
4. Sharing
We share data only with subprocessors needed to run the Service: our hosting platform, database, payment processor, email delivery, and AI model providers. A current list is on our Trust page. We do not share your data with advertisers.
5. Retention
Account and content data are retained while your account is active and deleted within 30 days of account deletion. Backups are purged on a ≤ 35-day rotation. Invoices are retained as required by law.
6. Your rights
You can access, correct, export, or delete your data at any time. See User Data Deletion for instructions, or email request@brandex.app. EU/UK users may also lodge a complaint with their supervisory authority.
7. Security
TLS in transit, encryption at rest, row-level tenant isolation, and audit logging for privileged actions. Details on our Trust page.
8. International transfers
Data may be processed in the EU and the US under the European Commission's Standard Contractual Clauses.
9. Children
The Service is not directed to children under 16.
10. Changes
We will post material changes on this page and notify account owners by email.
