Privacy Policy
Last updated: 12 July 2026
This policy explains what BrandKnowlaidge (“we”, “us”) collects, why, how we protect it, and the choices you have. It applies to the BrandKnowlaidge marketing site and application. If you have questions, contact us at hello@brandknowlaidge.com.
What we collect
- Account & identity: your name and email, managed through our authentication provider when you sign in or join the waitlist.
- Brand knowledge you bring in: the sources, models, assets, and generated work you create in your workspace. This is your content; we process it to provide the service.
- AI provider credentials: API keys you connect are encrypted at rest in a per-tenant vault and are never returned to the browser or shown to anyone after entry.
- Usage & metering: records of governed actions (calls, tokens, latency, governance outcomes) used for reporting and to run the service.
- Technical data: standard request metadata (e.g. IP address, timestamps) used for security and abuse prevention.
How we use it
To operate and secure the service, provision and isolate your workspace, generate and govern work against your brand, provide usage reporting, respond to support requests, and prevent abuse. We do not sell your data, and we do not use your brand knowledge or generated content to train shared or third-party models.
AI processing & your provider
Generation and evaluation run on the AI accounts you connect (“bring your own”). When you run a task, the relevant brand context and your prompt are sent to your chosen provider under your own account and their terms. We never resell tokens and never route your work through a shared platform key in production.
Cookies
We use only essential and functional cookies: session cookies set by our authentication provider to keep you signed in, and small functional cookies for in-app preferences (such as an operator’s “view as” preview). We do not use advertising or cross-site tracking cookies. Because these cookies are strictly necessary or functional, the app depends on them; disabling them in your browser may break sign-in.
Who we share with (subprocessors)
We rely on a small set of infrastructure providers to run the service: an authentication provider (sign-in), a managed Postgres database, and application hosting. Each processes data only to provide their part of the service. Your connected AI provider processes the content you submit to it, as described above. We disclose data if required by law.
Security & isolation
Every tenant’s data is isolated at the database level with row-level security, so one customer’s workspace cannot read another’s. Connected credentials are encrypted at rest. Access to production data is limited and logged. No system is perfectly secure, but we design for isolation and least privilege by default.
Retention & deletion
We keep your workspace data for as long as your account is active. You can request export or deletion of your data by emailing us; we will remove it within a reasonable period, except where we must retain limited records to meet legal or security obligations.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. To exercise any of these, contact hello@brandknowlaidge.com and we will respond.
Changes
We may update this policy as the product evolves. Material changes will be reflected here with a new “last updated” date, and where appropriate we will notify you.