This Privacy Policy explains what information BrandSweets collects, how we use and share it, and the choices you have. It applies to the BrandSweets website, application, APIs, and MCP endpoints (the “Service”). Terms not defined here have the meaning given in our Terms of Service.
1. Information we collect
- Account information — your email and authentication details, workspace and membership information.
- Brand content — the brands, logos, tokens, copy, and other materials you create, upload, extract, or generate (“Your Content”).
- Feedback & design signals — your selections, locked choices, ratings, annotations, and the notes you write about why you prefer one direction over another.
- Provider keys (BYOK) — if you connect your own third-party provider API keys, we store them encrypted at rest and use them only to make the requests you direct.
- Usage & technical data — logs, device and browser information, IP address, and interactions with the Service, collected to operate, secure, and improve it.
- Cookies — used for authentication/session and essential functionality.
2. How we use information
- to provide, maintain, secure, and support the Service;
- to store and serve your brands and generate the exports and endpoints you request;
- to analyze and improve the Service and its systems — including its design-quality checks, skills, reference materials, evaluation sets, and preference/taste models — as described in Section 3;
- to communicate with you about the Service; and
- to comply with law and enforce our Terms.
We do not sell your personal information, and we do not use it to serve third-party advertising.
3. Improving the Service — aggregation & de-identification
The Service gets better through use. We use your Feedback & Design Signals to improve it. Where an improvement benefits users other than you, we use those signals only in aggregated and de-identified form — general craft patterns and learnings that do not identify you, your workspace, or your specific brands.
Your private brands stay private. The specific decisions you make about a private brand, and that brand’s identifying details, are not shared with other users and are not pooled in identifiable form. We do not train third-party foundation models on your data; “improvement” here means refining our own systems, checks, reference materials, and skills.
4. How we share information
- Service providers — vendors who host, secure, and operate the Service (for example, cloud hosting, database, authentication, and email), under confidentiality and data-protection obligations.
- Public brands — if you publish a brand to the gallery, its structured data is made publicly available and served to third-party agents, per your choice.
- Third-party providers you connect — when you use BYOK features, requests (and your key) go to the provider you chose; their handling is governed by their policies.
- Legal & safety — where required by law or to protect rights, safety, and the integrity of the Service.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
5. Your rights & choices
Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can edit or delete your brands and account within the Service, or contact us to exercise these rights.
When you delete content or your account, we delete or de-identify the associated personal information within a reasonable period, except for residual copies in routine backups and information we must retain for legal, security, or fraud-prevention purposes. Aggregated, de-identified learnings already incorporated into the Service’s systems do not identify you and may persist.
6. Data retention
We retain personal information for as long as your account is active or as needed to provide the Service, and thereafter as required to comply with legal obligations, resolve disputes, and enforce agreements.
7. Security
We use administrative, technical, and organizational measures designed to protect information, including encryption of provider keys at rest and access controls. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
8. International transfers
The Service may process and store information in countries other than yours. Where required, we use appropriate safeguards for cross-border transfers.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.
10. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated through the Service or by other reasonable means; the “Last updated” date above reflects the current version.
11. Contact
Questions or requests regarding your privacy: privacy@brandsweets.com.