Legal · Privacy
Privacy policy.
Plain-English explanation of what we collect, where it lives, and how you can take it back. No dark patterns, no surprises.
Last updated · 18 August 2026
01·Section
Information we collect
When you create an account, we collect your email address and workspace name. When you add brands, we analyze publicly available website data. We collect usage analytics to improve the product.
02·Section
How we use your data
Your data is used to provide the Brandlism service — brand analysis, demand signal detection, lead generation, and AI-powered recommendations. We do not sell your data to third parties.
03·Section
Data storage & security
Data is stored on Supabase (PostgreSQL) with row-level security. API keys and OAuth tokens are encrypted at rest. All connections use TLS 1.3.
04·Section
Third-party services
We use: Supabase (database and authentication), Vercel (hosting), Stripe (payments), AgentMail (email delivery), and DataForSEO (search and ranking data). AI processing may be routed to any of Anthropic, OpenAI, Google, xAI, DeepSeek, Perplexity, Groq, Together AI, Cohere or Abacus, depending on the task and which providers are reachable. Each has their own privacy policy.
05·Section
Data retention
Your data is retained while your account is active. Upon deletion, we remove all personal data within 30 days. Aggregated, anonymized analytics may be retained.
06·Section
Your rights
You can export your data, request deletion, or update your information at any time from Settings. Contact support@brandlism.com for any privacy requests.
07·Section
Cookies
We use essential cookies for authentication and session management. Optional analytics cookies are used only with your consent.
08·Section
Data processing
What goes to AI providers: When you use AI features, your prompts and the relevant brand context are sent to an AI provider for processing. Which provider depends on the task and on which are reachable at the time — Anthropic handles most analysis, with OpenAI, Google, xAI, DeepSeek, Perplexity, Groq, Together AI, Cohere and Abacus used for specific tasks or as fallbacks. We use API tiers whose terms exclude training on submitted data. No personal account data is included in AI requests.
What stays in Supabase: Your account data, brand analyses, leads, and workspace content are stored in Supabase PostgreSQL with AES-256 encryption at rest, row-level security policies, and TLS 1.3 in transit. Backups are encrypted and retained for disaster recovery only.
09·Section
Your controls
- Export — Download all your brand data, analyses, and leads from Settings at any time in standard formats.
- Delete — Request full account and data deletion from Settings or by emailing support@brandlism.com. Completed within 30 days.
- Opt out of analytics — Disable optional analytics cookies from the cookie banner or Settings. Essential auth cookies cannot be disabled.
10·Section
Changes
We may update this policy. Significant changes will be communicated via email.