Data Processing Agreement
Effective date: February 14, 2026
1. Introduction
This Data Processing Agreement ("Agreement") describes how Brand Manager ("we", "us", "our") collects, uses, stores, and protects your personal data when you use our Service. We are committed to protecting your privacy and handling your data transparently.
2. Data We Collect
We collect the following categories of data:
- Account data: Email address used for authentication
- Brand data: Brand names, descriptions, keywords, and industry information you provide during brand creation
- Generated assets: Logos, color palettes, typography selections, taglines, and other brand materials created through the Service
- Usage data: Token usage, feature interactions, and Service performance metrics
- Payment data: Transaction records processed through our payment provider (Stripe). We do not store credit card numbers.
3. How We Use Your Data
We process your data for the following purposes:
- Providing and maintaining the Service
- Generating brand assets based on your inputs
- Processing payments and managing token balances
- Communicating service updates and important notices
- Improving the Service through aggregated, anonymized analytics
4. Data Storage & Security
Your data is stored securely using Supabase infrastructure with row-level security (RLS) policies ensuring you can only access your own data. Brand assets are stored in encrypted cloud storage. We implement industry-standard security measures including encryption in transit (TLS) and at rest.
5. Third-Party Services
We use the following third-party services to operate the platform:
- Supabase: Database, authentication, and file storage
- OpenAI: AI-powered text generation for brand content
- Ideogram: AI-powered image generation for logos and visual assets
- Stripe: Payment processing
Each third-party service processes data according to their own privacy policies and data processing agreements.
6. Data Retention
We retain your data for as long as your account is active. When you delete your account, we will delete your personal data and brand assets within 30 days, except where we are required to retain data for legal or compliance purposes. Aggregated, anonymized data may be retained indefinitely.
7. Your Rights
Under applicable data protection laws (including GDPR), you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing of your data
- Request data portability
- Withdraw consent at any time
To exercise any of these rights, contact us at hello@brandmanager.dev.
8. Cookies
We use essential cookies for authentication and session management. These cookies are strictly necessary for the Service to function and cannot be disabled. We do not use tracking or advertising cookies.
9. Children's Privacy
The Service is not intended for users under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take steps to delete that data promptly.
10. Changes to This Agreement
We may update this Agreement from time to time. We will notify you of material changes via email or through the Service. Your continued use of the Service after changes constitutes acceptance of the updated Agreement.
11. Contact
If you have questions about this Data Processing Agreement, please contact us at hello@brandmanager.dev.