Privacy Policy

Effective date: January 1, 2025

BrandShot (“we,” “us,” or “our”) operates BrandShot(the “Service”). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use the Service.

1. Information We Collect

We collect the following categories of information:

  • Account information: Email address and password (stored as a hashed credential by Supabase Auth). If you sign in with Google OAuth, we receive your email address and public profile from Google.
  • Brand kit content: Logo files, brand color values, and team/product photos you upload to the Service.
  • Generation history: Prompts you submit and the AI-generated images produced from them.
  • Payment information: We use Stripe to process payments. We never store your card number or bank details. Stripe may share limited billing information (last-four card digits, billing country) for display purposes.
  • Usage data: Credit balance, number of images generated, and timestamps of service activity.
  • Log data: IP addresses, browser type, pages visited, and error reports collected automatically when you use the Service.

2. How We Use Your Information

We use collected information to:

  • Provide, operate, and improve the Service.
  • Pass brand kit data and prompts to third-party AI model providers (Replicate) in order to generate your images. Only the data necessary for generation is transmitted.
  • Process payments and maintain your credit balance via Stripe.
  • Send transactional emails (account confirmation, payment receipts).
  • Detect and prevent fraud or abuse of the Service.
  • Comply with legal obligations.

We do not sell your personal data or User Content to third parties, use your generated images to train AI models, or send unsolicited marketing emails without your consent.

3. Data Storage

All user data is stored in Supabase, a cloud database and storage platform. Files (logos, photos, generated images) are stored in Supabase Storage (backed by AWS S3 infrastructure). Your data is stored in the region selected for your Supabase project. Data is encrypted at rest and in transit.

4. Third-Party Services

We share your data with the following third-party providers as necessary to operate the Service:

5. Cookies and Tracking

The Service uses cookies and local storage to maintain your authentication session (set by Supabase). We do not use third-party advertising cookies or tracking pixels. You can disable cookies in your browser, but this will prevent you from staying signed in.

6. Data Retention

We retain your account data and generated images for as long as your account is active. Generated images are kept to populate your generation history. You may request deletion of your account and associated data at any time by contacting us at hello@brandshot.app. We will process deletion requests within 30 days.

7. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, port, or delete your personal data, and to object to or restrict certain processing. To exercise any of these rights, please contact us at hello@brandshot.app.

If you are located in the European Economic Area, you have rights under the GDPR. If you are a California resident, you have rights under the CCPA.

8. Children's Privacy

The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

9. Security

We implement industry-standard security measures including HTTPS encryption, row-level security on all database tables, and hashed credential storage. However, no method of transmission over the internet is 100% secure and we cannot guarantee absolute security.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a notice in the Service. Your continued use of the Service after any changes constitutes acceptance of the revised policy.

11. Contact Us

If you have questions or concerns about this Privacy Policy, please contact us at hello@brandshot.app. You can also review our Terms of Service.