BrandrAI Privacy Policy

Last Updated: May 9, 2026

Effective Date: May 9, 2026

This Privacy Policy describes how BrandrAI, Inc., a Delaware corporation, with offices at 5 Cowboys Way, Suite 300-48, Frisco, Texas 75034 (“BrandrAI,” “we,” “us,” or “our”), collects, uses, shares, and protects personal information when you use our platform, websites (brandrai.com, app.brandrai.com), mobile applications, desktop applications, and related services (collectively, the “Service”).

This Privacy Policy is incorporated by reference into our Terms of Service and User Agreement.

1. Scope

This Privacy Policy applies to:

  • Visitors to our public websites
  • Account holders and authorized users of the Service
  • Persons who submit a Reality Check, contact-form inquiry, or other lead-generation request
  • Job applicants and prospective vendors who contact us

It does not apply to information you provide to third-party sites linked from the Service. For information about how third-party Sub-Processors handle your data, refer to our Sub-Processor List.

2. Information We Collect

2.1 Information You Provide

  • Account information: name, email address, business name, job title, phone number, billing address
  • Payment information: payment-card details collected and tokenized by Stripe (BrandrAI does not store full payment-card numbers; we receive only a Stripe customer ID, the last four digits, and card brand)
  • Customer Content: images, videos, brand-guide entries, product data, and other content you upload to the Service
  • Reality Check / Pro Audit inputs: brand name, domain, business identifiers, and any optional identity-verification fields you provide
  • Communications: messages, support tickets, feedback, and survey responses

2.2 Information Collected Automatically

  • Usage data: pages viewed, features used, asset uploads, API calls, dwell time, click paths
  • Device and connection data: IP address, browser type, OS, device identifiers, time-zone, referring URL
  • Cookies and similar technologies: session cookies, preference cookies, and (only with consent where required) analytics and marketing cookies — see Section 8
  • Authentication and security logs: login timestamps, MFA events, password-reset events, failed login attempts

2.3 Information from Third Parties

  • Identity-resolution and KYB providers (e.g., OpenCorporates) used during Pro Audit: registered-business records, ownership/officer disclosures, jurisdictional registration data — only when you have requested a Pro Audit involving such lookups
  • Authentication providers when you sign in via SSO (Google, Microsoft): the basic profile information necessary to create and authenticate your account
  • Public web sources used by Reality Check to assess brand presence (publicly indexed websites, social-media public pages, AI-search-engine outputs)

3. How We Use Information

PurposeCategories used
Provide and operate the ServiceAccount information, Customer Content, Usage data, Device data, Authentication logs
Process payments and prevent fraudPayment information, Account information, IP address, transaction history
Deliver Reality Check / Pro Audit resultsBrand identifiers, Public web sources, Identity-resolution provider lookups
Customer support and communicationsAccount information, Communications, Usage data
Improve the Service and develop new featuresDe-identified usage data; aggregated, de-identified Customer Content metadata
Security, abuse-prevention, and auditAuthentication logs, IP address, Device data
Marketing communications (with opt-in/out as required)Account information, Communications, Usage data
Legal compliance and enforcementAny of the above as legally required

4. Legal Bases for Processing (EU/UK Customers)

For users in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR / UK-GDPR:

  • Performance of a contract: for account provisioning, billing, and Service delivery
  • Legitimate interests: for Service improvement, fraud prevention, security, and direct marketing of similar services to existing customers
  • Consent: for non-essential cookies, marketing emails to non-customers, and optional features such as Multi-Model Gallery, Premium Download, Marketplace, and Curated Collections (User Agreement §18)
  • Legal obligation: for tax, accounting, and compliance with court orders or regulatory requirements

5. AI and Verification Processing

BrandrAI uses third-party AI providers (currently Anthropic, OpenAI, and selected Sub-Processors listed at brandrai.com/sub-processor-list) to power features such as Reality Check brand-presence analysis, image-authenticity classification, AI-search-engine monitoring, and Pro Audit scoring.

  • BrandrAI does not permit third-party AI providers to retain Customer Content for training their models. Where contractually available, we configure providers to use enterprise/no-train data plans.
  • Verification outputs (authenticity scores, AI-detection signals, brand-presence ratings) are informational tools, not legal/forensic conclusions — see Terms of Service §10.
  • Aggregate, de-identified Verification metadata may be retained by BrandrAI to improve the Verification Stack.

6. How We Share Information

6.1 We do not sell personal information.

BrandrAI does not sell personal information for monetary consideration in the traditional sense. To the extent any data sharing might constitute “selling” or “sharing for cross-context behavioral advertising” under the California Consumer Privacy Act (CCPA/CPRA) or similar laws, see Section 11.

6.2 Service Providers / Sub-Processors

We share information with Sub-Processors who perform services on our behalf, including hosting (Microsoft Azure), CDN, transactional email (Resend), realtime messaging (Pusher), error tracking (Sentry), AI compute (Anthropic, OpenAI), analytics, and payment processing (Stripe). The current list of Sub-Processors is at brandrai.com/sub-processor-list.

6.3 Legal Disclosures

We may disclose information if required by law, subpoena, court order, or governmental request, or to protect the rights, property, or safety of BrandrAI, our customers, or others.

6.4 Business Transfers

If BrandrAI is involved in a merger, acquisition, financing, or sale of all or substantially all of its assets, personal information may be transferred as part of that transaction, subject to standard confidentiality protections.

6.5 With Your Consent

We may share information with third parties when you direct us to do so (for example, sharing a Reality Check report with an advisor, or enabling Marketplace transactions through Stripe Connect).

7. Data Retention

CategoryRetention
Account information (active)Duration of account
Account information (after termination)90 days (export window) + up to 7 years for tax/legal records
Customer Content (active)Duration of subscription
Customer Content (after deletion or termination)Up to 90 days in standard backups; then deleted on rolling-window basis
Reality Check submissions24 months from submission, after which de-identified or deleted
Authentication / security logs13 months
Billing and tax records7 years (per IRS / state-tax requirements)
Marketing-list dataUntil you opt out; suppression list retained indefinitely to honor opt-out

8. Cookies and Similar Technologies

We use cookies and similar technologies for the following purposes:

  • Strictly necessary: session, authentication, security (always active)
  • Functional: preferences and personalization (active by default; user can disable)
  • Analytics: usage measurement, feature analytics (consent required in jurisdictions that mandate it)
  • Marketing: retargeting, conversion measurement (opt-in only in jurisdictions that mandate consent)

You can manage cookie preferences through the cookie banner at first visit, through your browser settings, or by emailing [email protected].

9. International Data Transfers

BrandrAI is based in the United States, and most of our infrastructure is hosted in U.S. data centers (Microsoft Azure regions in the United States). If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States. For transfers from the EEA, UK, and Switzerland, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum) where required. A copy of the SCCs can be requested at [email protected].

10. Your Privacy Rights

10.1 General Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Delete information (subject to legal-retention obligations)
  • Restrict or object to processing
  • Data portability
  • Withdraw consent (where processing is based on consent)
  • Lodge a complaint with a supervisory authority

To exercise these rights, contact [email protected]. We will respond within the time required by applicable law (typically 30–45 days).

10.2 California (CCPA/CPRA)

California residents have the rights to know, delete, correct, opt out of the sale or sharing of personal information, and limit the use of sensitive personal information. BrandrAI does not sell personal information for monetary consideration. We do not knowingly use sensitive personal information for targeted advertising. To submit a request, email [email protected] with the subject line “California Privacy Request.” We do not discriminate against users who exercise these rights.

10.3 Virginia, Colorado, Connecticut, Utah, and other state laws

Residents of states with comprehensive privacy laws (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, and similar) have rights to access, correct, delete, port, and opt out of targeted advertising or profiling that produces legal or similarly significant effects. Submit requests to [email protected].

10.4 EEA, UK, and Switzerland (GDPR)

EEA, UK, and Swiss residents may exercise the rights enumerated in Section 10.1 by contacting [email protected]. You also have the right to lodge a complaint with your local supervisory authority. BrandrAI’s EU representative is available upon request.

10.5 Identity Verification

We may need to verify your identity before fulfilling a privacy request. Verification may include confirming details we already hold (e.g., your account email, billing address) and, in some cases, requiring authentication via the account.

11. Sensitive Personal Information

BrandrAI does not knowingly collect government identifiers (Social Security numbers, driver’s-license numbers, passport numbers), precise geolocation, biometrics, racial/ethnic origin, religious beliefs, union membership, health information, or sexual-orientation data through the Service. If you choose to upload such information into Customer Content, it is subject to standard Customer Content protections. We recommend that you do not upload sensitive personal information into the Service unless required for your business purpose.

12. Children’s Privacy

The Service is not directed to children under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected such information, we will delete it. Parents or guardians who believe their child has provided personal information should contact [email protected].

13. Marketing Communications

BrandrAI may send marketing emails to existing customers about new features, related products, and educational content. You can opt out by clicking “unsubscribe” in any email or contacting [email protected]. Service-related communications (billing notices, security alerts, terms updates) are not subject to marketing opt-out.

14. Security

We maintain administrative, technical, and physical safeguards designed to protect personal information, including:

  • Encryption in transit (TLS 1.2+)
  • Encryption at rest (AES-256)
  • Multi-factor authentication for staff with production access
  • Role-based access controls
  • Routine vulnerability scanning and third-party security assessments
  • Centralized logging and anomaly detection

No security measures are perfect. If you discover or suspect a security vulnerability, please report it to [email protected].

15. Data Breach Notification

In the event of a data breach affecting your personal information, we will notify you and applicable regulators within the time required by applicable law (typically 72 hours for GDPR, “without unreasonable delay” for U.S. state laws). Notice will describe the nature of the breach, the types of information affected, and the steps you can take to protect yourself.

16. Do Not Track

Some browsers transmit a “Do Not Track” (DNT) signal. Because there is no industry-standard interpretation of DNT, BrandrAI does not currently respond to DNT signals. We do honor opt-out preference signals (such as Global Privacy Control / GPC) where required by law in jurisdictions like California.

17. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notice at least 30 days before they take effect. The “Last Updated” date at the top of this Policy reflects the most recent revision. Your continued use of the Service after the effective date constitutes acceptance.

18. Contact

BrandrAI, Inc.
Attn: Privacy Office
5 Cowboys Way, Suite 300-48
Frisco, TX 75034

Privacy / DPA inquiries: [email protected]
Data subject requests: [email protected] (subject line: “Privacy Request – [Jurisdiction]”)
Security disclosure: [email protected]
General legal: [email protected]
Founder direct: [email protected]



The Brand Operations Platform
Brought to you by Curious Monkeys Pressing Buttons LLC
© 2026 BrandrAI.com. All rights reserved.
About User Agreement TOS Blog Privacy Policy