Privacy Policy
Last updated: July 21, 2026
1. Information We Collect
BrandKit collects the following information to provide the service:
- Email address for account creation and login
- Brand profiles, project inputs, privately stored source logos, generated asset metadata, and stored ZIP files
- Billing identifiers, product, and subscription status for paid services; payment-card details are handled by LemonSqueezy rather than stored by BrandKit
- Usage, request, device, and technical log data needed for security and service operation
- Checkout email and brief materials submitted for the separately operated Agency validation service
2. How We Use Information
We use collected information for the following purposes:
- Delivering the service and managing accounts
- Processing payments and managing subscriptions
- Sending transactional messages and Agency order follow-up
- Improving the product and developing new features
- Preventing abuse, investigating failures, and protecting tenant data
- Responding to support requests and customer inquiries
3. Service Providers and International Processing
BrandKit uses service providers only as needed to operate the service: Vercel for hosting, logs, private Blob storage, and queued jobs; Neon for authentication and PostgreSQL; Anthropic and FAL.ai for requested AI generation; LemonSqueezy for checkout, billing, and subscription records; SMTP2GO for transactional email; and analytics providers only when the related configuration is enabled.
Project prompts, image inputs, account identifiers, checkout information, email addresses, IP addresses, and technical logs may be processed by the relevant provider for that purpose. Processing locations and provider retention periods may differ by provider.
4. Retention and Deletion
Account and project data is retained while needed to provide the service. Account deletion currently starts with a verified request to support; there is no automated self-service deletion flow. BrandKit must remove project Blob objects before deleting the Auth and database records so that owner mapping is not lost.
Billing, fraud-prevention, security logs, backups, and provider-held records may remain for the period required by applicable law or the provider’s documented retention policy. We will communicate the applicable scope, exceptions, and completion status for a verified request.
5. Disclosure and User Choices
BrandKit may disclose information to the service providers above, when you direct us to do so, or when required by applicable law or a valid legal request.
- Do not submit confidential material to AI generation unless you are authorized to have it processed by the listed AI providers
- You may request access, correction, or deletion through the contact below
- Optional analytics is used only when the deployment has the related configuration enabled
6. Contact
For privacy-related questions, contact support@jadru.com.