Privacy policy

Last updated: 4 October 2026

1. Who we are and what this policy covers

Brand AI is an operating system for content creators. It brings a creator's identity, content, calendar, metrics and documents into one place, and includes an AI agent that works alongside them.

Miguel Ornelas, resident in Spain, is the controller of the data described in this policy. You can contact us at privacy@getbrandai.app.

We serve people in Spain, Mexico and Latin America, so this policy is written to comply at once with the European Union's General Data Protection Regulation (Regulation (EU) 2016/679) and with Mexico's Federal Law on Protection of Personal Data Held by Private Parties. Where the two regimes name the same right differently, we describe both.

This policy explains what we collect from two groups of people:

It covers our website at getbrandai.app, our applications at app.getbrandai.app and agency.getbrandai.app, our messaging channel, and the LinkedIn, YouTube, TikTok, X and Google Calendar integrations described below.

It does not cover the external services themselves. When you connect LinkedIn, YouTube, TikTok, X or Google Calendar, those services continue to process your data under their own policies, which we do not control.

2. Information you give us directly

Account information. Your name, email address and sign-in credentials. If you sign in with Google, we receive your name, email and profile photo from Google.

Brand identity. The answers you give during onboarding and every later edit: who you are, how you speak, who you speak to, your content pillars, your strategy, the words you avoid, your example scripts and your audience profile. This is the material the agent uses to write in your voice, and it is the most important data we hold about you.

Content you create or upload. Scripts, drafts, documents, notes, titles, descriptions, tasks, calendar entries, workspace files and audio you record for transcription.

Knowledge base material. Documents you upload for the agent to learn from, such as writing frameworks or course notes.

Conversations with the agent. Everything you write to the agent, inside the application and from the messaging channel, together with its replies and a running summary of your history with it. That history is persistent by design: the product's value depends on the agent remembering the work you have done together.

Payment information. Processed by Stripe, Inc. We do not store card numbers. Stripe processes payment data under its own agreement and privacy policy, and we receive only the subscription status and the identifiers needed to manage your account.

Support communications. Everything you send us when you contact us.

3. LinkedIn data

This integration is not available yet. This section describes how we will handle that data once it is live.

If you connect a LinkedIn account, and only for the permissions you grant on the authorisation screen:

What we use it for. To publish and schedule the content you have approved, and to show you its performance inside Brand AI.

LinkedIn does not make member-to-member messages available to applications at any access level, so we never access your LinkedIn inbox.

You can revoke our access at any time from your LinkedIn account settings.

4. YouTube data

This integration is not available yet. This section describes how we will handle that data once it is live.

Brand AI's use of YouTube data is governed by the YouTube Terms of Service and the Google Privacy Policy. You can revoke our access at any time from the Google security settings page.

If you connect a YouTube channel, and only for the permissions you grant:

What we use it for. To show you your performance inside Brand AI, to let the agent answer questions about your content and explain what worked, to upload and schedule the videos you have approved, and to manage comments at your instruction.

What we do not do. We do not sell this data. We do not use it for advertising. We do not share one creator's YouTube data with another creator.

5. TikTok data

This integration is not available yet. This section describes how we will handle that data once it is live.

If you connect a TikTok account through Login Kit, and only for the permissions you grant:

What we use it for. To show you your performance inside Brand AI, to let the agent reason about your content, and to publish at your instruction.

TikTok does not make comments or direct messages available to applications, so we never access them.

You can revoke our access at any time from your TikTok account settings.

6. X data

This integration is not available yet. This section describes how we will handle that data once it is live.

If you connect an X account, and only for the permissions you grant:

What we use it for. To publish and schedule the content you have approved, to show you its performance, and to manage replies and messages at your instruction.

Automated direct messages are only sent to people who have given explicit, recorded consent to be contacted. Someone following your account does not count as consent, and we do not treat it as such. Every automated message honours an opt-out request immediately.

You can revoke our access at any time from your X account settings.

7. Google Calendar data

If you connect your Google Calendar, and only for the permissions you grant:

What we use it for. So that what you plan in Brand AI appears in the calendar you already use every day.

What we do not do. We do not read or store the content of your other events. We do not import anything from your personal schedule into Brand AI. Synchronisation runs in one direction only, from Brand AI to Google, and Google never modifies your dates in Brand AI. We watch the events we created only to detect whether they have been deleted or altered, and to put them back in order.

Google Calendar data is not sent to the AI models, is not sold, is not used for advertising and is not shared with third parties. If you delete your Brand AI account, we do the same as when you disconnect.

What we store. The connection to your account, the calendar you chose, and the mapping between each event and the Brand AI item it belongs to. Access credentials are stored encrypted.

On disconnection. We remove from your calendar the events Brand AI created, revoke our access and delete the credentials. Your planning inside Brand AI is left untouched.

Brand AI's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke our access at any time from the Google security settings page.

8. Messaging channel and information collected automatically

Telegram

You can use the agent outside the application through Telegram. If you link that account, we store your chat identifier, the messages you send the agent including voice notes, and the agent's replies. Voice notes are transcribed and the transcript is stored alongside the rest of your content.

It is a transport channel: the conversations you hold there are part of the same history as those in the application.

Information collected automatically

When you use Brand AI we record:

We do not collect precise location data.

9. What we use your personal data for

To operate the service. To run your account, store your content, show your metrics, publish and schedule what you approve, and manage comments and messages at your instruction.

For AI processing. This is the core of the product and deserves to be stated plainly.

The agent uses language models to help you plan, write and analyse your content, and to answer questions about your operation. To do that we send the models what they need for the task: your brand identity, the relevant parts of your content, your conversation history with the agent, and the metrics you are looking at.

To improve the service. We analyse how features are used so we can make them better. Where we publish or share findings, the data is aggregated and anonymised first.

To communicate with you. Service messages about your account.

To meet legal obligations and to establish, exercise or defend legal claims.

10. Who we share your data with

We do not sell personal data, and we do not share it for advertising.

We use the following processors, each under a contract that limits them to providing the service to us:

ProcessorWhat it processesWhere
AnthropicContent sent to the agent: brand identity, scripts, conversation history, metrics in viewUnited States
OpenAIOnly the audio files sent for transcriptionUnited States
Google Cloud and FirebaseHosting, database, authentication, file storageDatabase and storage in Europe, server functions in the United States
VercelHosting of the web applicationsUnited States
StripePayment processingUnited States and European Union
ResendThe recipient's email, and for invitations the creator's and the agency's nameUnited States
LoopsEmail, name and source of anyone who joins the waiting listUnited States
TelegramThe messages exchanged with the agent, if you link that channelInternational

Neither Anthropic nor OpenAI uses your content to train their models. Both are contractually bound to process it only to provide the service we have requested.

Agencies. If you connect your creator workspace to an agency, that agency can see the parts of your workspace you have shared with them. Your private space is never shared, and you can disconnect at any time: from that moment the agency loses access and you keep everything.

Others. Professional advisers under confidentiality; authorities where the law requires it; and a successor if the business is transferred, in which case we will tell you.

11. How long we keep it

While your account is active, we keep your content, your brand identity, the agent's memory and the data from connected platforms so the product works. The agent's usefulness depends on that history, and that is the purpose of the product, not a side effect.

If you cancel your subscription but do not delete your account, we keep your account and your data so you can pick up where you left off. We do not use it for anything else, and you can request its deletion at any time from your profile or by writing to privacy@getbrandai.app.

When you delete your account, we delete it as described in section 13.

When you disconnect a platform, we stop collecting new data from it.

Technical logs. The technical logs held by our hosting providers (IP address, browser, date and time of each request) are kept according to those providers' configuration: 30 days on Google Cloud and a maximum of one hour on Vercel. To protect the service against abuse we also store a hashed fingerprint of your email or IP address, which cannot be reversed to recover them.

Billing records are kept for as long as the applicable tax and commercial law requires, even after the account is deleted.

12. Legal basis and your rights

Why we are allowed to process your data

What we doLegal basis
Run your account and provide the servicePerformance of our contract with you
Connect your social accounts and process that dataPerformance of the contract, plus your explicit consent on each platform's screen
Improve and secure the serviceOur legitimate interests
Marketing communicationsYour consent, withdrawable at any time
Keep billing recordsLegal obligation

Your rights

Whichever law gives you these rights, we honour them the same way. They are named differently depending on where you live:

RightSpain and the European Union (GDPR)Mexico (LFPDPPP)
Know what data we hold about youAccessAccess
Correct anything inaccurateRectificationRectification
Have your data deletedErasureCancellation
Stop us using it in certain waysRestriction and objectionObjection
Take your data to another servicePortabilityNot expressly provided for, we offer it anyway
Withdraw your consentYesYes

In Mexico these rights are known collectively as ARCO rights.

To exercise any of them, write to privacy@getbrandai.app. We will respond within one month in the European Union and within twenty business days in Mexico. We may ask you to verify your identity first.

You can also revoke each integration directly, at any time and without contacting us: from your LinkedIn, TikTok or X settings, or from the Google security settings page for YouTube and Google Calendar.

Where to complain

13. How to delete your data

To delete everything: go to your profile inside Brand AI and choose to delete your account, or write to privacy@getbrandai.app.

What is deleted. Deletion cascades across the whole system and removes:

What is not deleted.

Content already published on LinkedIn, YouTube, TikTok or X stays on those platforms. We cannot remove it once published, and deleting your Brand AI account does not touch it.

How long it takes. Within a maximum of 30 days from your request. In practice the deletion runs immediately.

14. Security, children, transfers and changes

Security. We use access controls so that each account can only reach its own data, encryption in transit, and we store integration credentials encrypted, with the keys held in a managed secrets service. No system is perfectly secure, and we cannot guarantee absolute security.

Children. Brand AI is not directed at anyone under 16 and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.

International transfers. Some of the processors listed in section 10 are in the United States. Those transfers rely on the safeguards provided for by applicable law. You can request a copy of the safeguards applied by writing to privacy@getbrandai.app.

Changes. We may update this policy. When we make a material change we will update the date above and notify you inside the application. Any new platform integration is added to this policy before it goes live, not after.

Contact. Miguel Ornelas, Spain. privacy@getbrandai.app