Privacy Policy
Your data is yours. This page explains what we collect, why, and the control you keep over it.
Last updated: July 17, 2026
This page is being finalized before launch — the wording below is a working draft.
Data controller
The controller within the meaning of the EU General Data Protection Regulation (GDPR) is: Benjamin Thomas Krauß Hindenburgstr. 11 96450 Coburg Germany Email: support@braend.io No data protection officer has been appointed — the legal thresholds that would require one are not met.
What data we process
Account data. When you register, we collect your email address and a password; only a cryptographic hash of the password is stored. If you sign in via Google or GitHub, we receive your email address from them and — where present in your profile — your display name and avatar. We also record which version of the Terms and this Privacy Policy you accepted, and when. Content you create. Your chat histories, generated content, projects and brand data — brand variables, logos, uploaded files — are stored so you can return to them at any time. If you use brand extraction, we process the website address you provide and the content and screenshots derived from it. Payment data. Payments are handled by our payment providers. Your card details never reach us — we store only the status of your subscription or credits and the related customer identifiers. Technical data. To keep the service secure, we process error reports and anonymous performance metrics on our own systems. Email addresses appear in them only as a truncated checksum, and IP addresses are not stored. To prevent abuse we briefly rate-limit requests by IP address; at most a country code is kept.
Why we process it
We process your data to run your account and provide the service, to generate content with AI support and extract brand characteristics from websites at your request, to handle payments, to keep the service secure, stable and free of abuse — and to meet legal obligations, such as tax record-keeping. What we do not do: no ad tracking, no advertising profiles, no selling of your data. And we do not use your content to train AI models.
Legal basis
For the core features — your account, content generation, brand management, billing — the legal basis is the performance of our contract with you (Art. 6(1)(b) GDPR). For security, error diagnosis and abuse prevention, we rely on our legitimate interest in a secure and stable service (Art. 6(1)(f) GDPR) — implemented as sparingly as described above. For retaining billing records, the basis is compliance with legal obligations (Art. 6(1)(c) GDPR). Where we exceptionally ask for your consent (Art. 6(1)(a) GDPR), you can withdraw it at any time with effect for the future.
Service providers
To run Braend we rely on carefully chosen service providers acting as our processors under Art. 28 GDPR: – Hetzner (Germany) — hosting of the application and of our own error and performance systems. That data stays in Germany. – Supabase — database, authentication and file storage. Your data is stored in Frankfurt, Germany. – Zoho Mail (EU data centers) — delivery of account emails such as sign-up confirmations and password resets. – Google (Gemini API) — AI generation of text and images. Your inputs and the relevant brand data are transmitted to Google for generation. – Firecrawl — reading the website you provide during brand extraction. – RevenueCat and Stripe — handling subscriptions, credit purchases and payments. Where providers process data outside the EU, this happens on the basis of the EU Standard Contractual Clauses or the EU-US Data Privacy Framework.
How long we keep it
We keep your account and content data for as long as your account exists. If you delete your account in the settings, your account and content are deleted; any running subscription ends with it. Raw brand-extraction data — scraped website content and screenshots — is deleted automatically after seven days. Billing records are retained for as long as tax and commercial law require, generally up to ten years. Error reports and technical logs are kept only as long as they are needed for diagnosis and security.
Your rights
You have the right to access the data we hold about you (Art. 15 GDPR), to rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20), and the right to object to processing based on legitimate interests (Art. 21). Any consent you have given can be withdrawn at any time. Just write to support@braend.io — we respond within one month at the latest. You can also delete your account, including your content, yourself at any time in the settings. You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA) in Ansbach, Germany.
Contact
For anything about your data, reach us at support@braend.io. A human answers — the one building Braend.