Privacy Policy
Last updated: September 8, 2026
Introduction
Branduals Inc. ("we," "our," or "Branduals") provides a B2B SaaS platform that stores brand-approved content and enables users to access and use that content through web interfaces and plug-ins for third-party applications such as Canva, Figma, and Adobe Creative Cloud. The Service also lets you import files you choose from your own cloud storage accounts (Google Drive, Microsoft OneDrive, Dropbox). This Privacy Policy describes how we collect, use, share, and protect personal information when you use our Service.
By using the Service, you agree to the collection and use of information in accordance with this policy. This Privacy Policy is incorporated into and subject to our Terms and Conditions.
Information We Collect
Account Information: Email address, name, and password (hashed) used to create and authenticate your account.
Brand Content: Files, metadata, and usage logs associated with the brand assets you upload or access via the Service.
Usage Data: IP address, browser type, device ID, operating system, timestamps, feature usage (e.g., plug-in launches, downloads), and support interactions.
Temporal Data: The Service maintains a complete, immutable history of all content changes, access events, and workflow actions within your brand workspace. This temporal data is a core feature of the platform and is used to provide point-in-time reconstruction, audit trails, and analytics.
Communications: Messages sent to our support team or generated through in-app notifications.
Waitlist and Marketing: If you join our waitlist or subscribe to updates, we collect your email address, IP address, and browser information for anti-abuse purposes.
How We Use Your Information
- To provide, maintain, and improve the Branduals Service, including authentication, content storage, and plug-in functionality.
- To enforce brand owners' access rules and ensure content distribution complies with their policies.
- To power AI-driven features such as brand health scoring, content analysis, usage analytics, and evidence-based recommendations. These features analyze your brand assets and usage patterns to surface insights; they do not generate or modify your content, and your content is never used to train or improve AI or machine-learning models.
- To send service-related communications (e.g., account security notices, service updates) and, with your consent, occasional product-related emails.
- To troubleshoot issues, keep the Service secure, and understand aggregate usage of the Service so we can improve it. Google user data and Meta Platform Data are excluded from this: we use Google user data solely to provide the import feature described in the Google User Data section, and Meta Platform Data solely to provide the campaign publishing features described in the Meta Platform Data section below.
- To maintain the temporal audit trail that enables point-in-time brand reconstruction and compliance reporting.
Data Sharing and Third-Party Services
Brand Owners: We may share your usage data (e.g., which assets you accessed) with the brand that owns the content, solely for compliance with their distribution policies.
Plug-in Partners: When you use our Canva, Figma, or Adobe plug-ins, we transmit the necessary authentication tokens and content references to enable the integration; we do not share your personal email with those platforms beyond what is required for the plug-in to function.
Cloud Import Providers: When you connect a cloud storage account (Google Drive, Microsoft OneDrive, or Dropbox), we access that account on your behalf, in read-only mode, solely to list and copy the files you select for import. Our handling of Google user data is described in the Google User Data section below.
Social Media Platforms (Meta): Workspace administrators — or members granted permission to manage the workspace's settings — can connect a brand's Facebook Pages and Instagram professional accounts to publish the workspace's campaign content and read its performance statistics. What we receive from Meta and how we handle it is described in the Meta Platform Data section below. Meta Platforms processes data on its own services as an independent controller under its own terms and privacy policy.
AI Assistants Your Workspace Connects: Workspace administrators can connect third-party AI assistants to their workspace. A connected assistant can access workspace content according to the permissions the administrator grants it, including reading and downloading files. Branduals never initiates such transfers itself, and access lasts only while the workspace's grant remains active.
Service Providers: We engage trusted third parties to operate the Service, including:
- Microsoft Azure — cloud hosting, storage, and AI services (automatic tagging, search, and previews), operating as our data processor
- Postmark — transactional email delivery
- Microsoft Clarity — website analytics and session recording (marketing site only)
- Google reCAPTCHA Enterprise — anti-abuse protection for public forms
These providers are contractually obligated to protect your data and may only use it to perform their services on our behalf.
Legal Requirements: We may disclose information to comply with valid legal processes, enforce our Terms of Service, or protect the rights, property, or safety of Branduals, its users, or others.
Aggregate and Anonymized Data: We may use anonymized, aggregate data derived from usage patterns across tenants for benchmarking and industry insights. Such data cannot be used to identify any individual user or brand. Participation in cross-tenant intelligence features is always opt-in. Content imported from connected cloud storage accounts (including Google user data) and Platform Data received from Meta are excluded from cross-tenant aggregation.
Data Retention and Deletion
Personal data (email, name, account credentials) is retained as long as your account remains active or as necessary to fulfill legal obligations, resolve disputes, or enforce agreements. Brand content you upload is stored according to the brand owner's retention instructions.
We do not retain brand workspaces indefinitely once they are no longer in active use. Workspaces follow a defined lifecycle:
- Free trials that are not converted. When a trial ends, the workspace becomes read-only. The workspace and its address (for example, your-brand.branduals.com) remain reserved for 90 days from the end of the trial, during which you may export your data or pick a plan to reactivate; after that the workspace is scheduled for deletion and the address may be reassigned to others.
- Cancelled paid subscriptions. When a paid plan is cancelled, the workspace becomes read-only at the end of the billing cycle. The workspace and its address are retained for 12 months, during which you may export your data or reactivate, after which it is scheduled for deletion.
Before a workspace is removed, we send advance reminders to the account owner. Deletion is staged: a workspace is first marked for deletion and can be restored for a short recovery period, after which all associated data, including stored files, member personal data, and the temporal history, is permanently purged. We keep only a minimal record of the deletion (a workspace identifier and the relevant dates, with no personal data) for audit purposes.
The Service's temporal history is maintained as an immutable audit trail for the lifetime of the workspace. This immutability prevents selective tampering with records inside a live workspace; it does not prevent deletion of an entire workspace under the lifecycle described above.
You may export your data at any time before deletion, on any plan. You may also request deletion of your account and all associated personal data at any time by contacting privacy@branduals.com; we will confirm deletion within 30 days.
User Rights and Choices
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion or restriction of processing of your data.
- Obtain a portable copy of your data in a structured, commonly used format.
- Object to direct marketing or withdraw consent where consent is the legal basis for processing.
To exercise these rights, please contact us at privacy@branduals.com with a verifiable request.
Security Measures
We implement industry-standard technical and organizational safeguards, including encryption at rest and in transit, regular security assessments, access controls, and employee training, to protect your personal data against unauthorized access, alteration, or disclosure.
International Transfers
Branduals is based in the United States. If you are located outside the United States, your information will be transferred to and processed in the U.S. We ensure such transfers comply with applicable data protection laws, using mechanisms such as Standard Contractual Clauses where required by the GDPR or similar regulations.
Cookies and Tracking Technologies
Our website and plug-ins may use cookies or similar technologies to remember your preferences, enable authentication, and analyze usage. Specifically:
- Essential cookies — required for authentication and session management.
- Analytics — Microsoft Clarity for understanding how visitors interact with our marketing site (session recordings and heatmaps). Clarity does not collect personally identifiable information.
- Anti-abuse — Google reCAPTCHA Enterprise to protect public forms from automated abuse.
You can manage cookie preferences through your browser settings; however, disabling essential cookies may affect the functionality of the Service.
Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us at privacy@branduals.com and we will promptly delete it.
Google User Data
Branduals offers an optional "Import from cloud storage" feature that lets you connect your own Google Drive account and copy files you select into your Branduals workspace. This section describes how we handle Google user data. Where this section is more restrictive than the rest of this policy, this section prevails for Google user data.
What we access: With your permission, we request read-only access to your Google Drive (Google's drive.readonly permission). We use this access solely to (a) show you your own Drive folders and files inside Branduals so you can choose what to import, and (b) copy the files and folders you select into your workspace. We never modify or delete anything in your Google Drive, and we access your Drive only when you connect the account or run an import you started.
What we store: The files you chose to import are copied into your workspace, where they are treated like any other uploaded file. We also store the email address of your connected Google account (so you can see which account is connected) and an encrypted credential that lets imports you started finish in the background. We never see or store your Google password.
How imported content is processed: Imported files go through the same automated pipeline as directly uploaded files — preview and thumbnail generation, automatic tagging, and search indexing — using Microsoft Azure AI services operating as our data processor. This processing exists solely to power the user-facing features of your workspace (search, organization, previews). Neither Branduals nor its service providers use your Google user data to train or improve artificial-intelligence or machine-learning models.
What we never do with Google user data: We do not sell it. We do not use it for advertising. We do not use it for market research, credit assessment, or any purpose unrelated to the import feature and the workspace features described above. We do not transfer it to third parties except to the service providers listed in Section 4 as needed to operate the Service, or where required by law.
Human access: Our staff do not read the content you import from Google Drive except with your explicit permission (for example, to resolve a support request), where necessary for security or abuse investigation, or where required by law.
AI assistants: If your workspace administrator connects a third-party AI assistant to your workspace (see Section 4), that assistant can access workspace content within the permissions it was granted, which may include files originally imported from Google Drive. Such access is initiated and consented to by your workspace, never by Branduals, and is not used to train AI models.
Disconnecting and deletion: You can disconnect your Google account at any time; disconnecting revokes Branduals' access at Google, and we keep only a minimal audit record of the connection and its revocation. Files already imported remain in your workspace as your workspace's own copies and can be deleted there like any other file. You can also revoke Branduals' access directly at myaccount.google.com/permissions.
Limited Use disclosure: Branduals' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Meta Platform Data
Branduals offers an optional Campaigns feature that lets workspace administrators — or members granted permission to manage the workspace's settings — connect a brand's Facebook Pages and Instagram professional accounts to publish the workspace's campaign content and measure how it performs. This section describes how we handle the data we receive from Meta Platforms ("Platform Data"). Where this section is more restrictive than the rest of this policy, this section prevails for Platform Data.
What we access: Connecting happens through Meta's own login and consent screens — we never see or store your Facebook or Instagram password. With the permissions granted there, we (a) list the Facebook Pages and linked Instagram professional accounts available to connect so the administrator can choose among them, (b) publish, and where the workspace requests it remove, the posts the workspace prepared and, where it runs an approval review, approved, and (c) read performance statistics (such as reach and engagement) for those posts and the connected accounts. We contact Meta only to maintain the connection, to carry out a publication the workspace scheduled, and to collect statistics for the workspace's campaign reports.
What we store: An encrypted access credential for each connected account, the account's identifier and name (so the workspace can see what is connected), the identifier of the Meta account that granted access together with the permissions it granted (so we can honor Meta's notices about that grant and act only within it), records of the publications made through Branduals (post identifiers and links), and the performance statistics we retrieve. Statistics are kept as part of the workspace's campaign reports so that reporting remains available even after Meta's own reporting window has passed.
What we never do with Platform Data: We do not import or back up your Facebook or Instagram content — publishing flows one way, from your workspace to Meta, and the only data flowing back is the status and statistics of what was published, plus the account details above. Platform Data stays within the workspace that connected the account: we do not combine it across customers, use it for benchmarking or any cross-customer dataset, sell it, use it for advertising, or use it to train AI or machine-learning models.
Meta's role: Meta Platforms is an independent controller of the data it processes on its own services; this policy covers only what Branduals receives and stores. Your use of Facebook and Instagram remains governed by Meta's own terms and privacy policy.
Disconnecting: A workspace administrator can disconnect a channel at any time, which permanently deletes the stored access credential and stops all requests to Meta for that account. You can also remove Branduals' access on the Meta side (in your Facebook settings under Business integrations); when Meta notifies us, we check each of that grant's connections with Meta and deactivate the ones Meta reports as no longer authorized.
Deletion requests: When you ask Meta to have your data deleted from Branduals (through Facebook's data-deletion mechanism when removing the app), Meta sends us a verified deletion request. We then permanently erase the stored access credentials, remove your Meta account's and the connected accounts' identifiers and names from our records, and erase the raw responses we received from Meta. The workspace keeps its record of what it published — the post identifiers, their public links, and the statistics — but that record no longer names the connected account or the Meta account that granted access. Each deletion request receives a confirmation code and a status link where you can verify completion. You can also request deletion at any time at privacy@branduals.com.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify users of material changes by posting the updated policy on our website and, where appropriate, by email. Your continued use of the Service after such changes constitutes acceptance of the revised policy.
Contact Information
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
Branduals Inc.
info@branduals.com