Privacy Policy
How Brandstash collects, uses, and protects account, project, Google Business, and platform-usage data.
This Policy explains how brandstash Tecnologia Ltda. handles personal data when you visit brandstash.ai, create an account, run the free diagnosis, or use Google Business Autopilot. The current product operates only with Google Business; future capabilities enter this Policy when they are actually released.
TL;DR · In one page
- We collect only the data needed for accounts, projects, diagnosis, authorized Google Business connections, support, security, and billing.
- Google data is used to provide the requested service. We do not sell it, use it for behavioral advertising, or transfer it to data brokers.
- You can disconnect Google Business and request access, correction, or deletion in the app or at privacy@brandstash.ai.
- The free diagnosis is view-only. It uses public data from the confirmed profile and does not change Google Business.
- Project content and briefings remain under your control. Contracted providers may process them only to produce the outputs you request.
Who controls the data
The controller is brandstash Tecnologia Ltda., based in Salvador, Brazil. For privacy matters and rights requests, contact privacy@brandstash.ai.
When a company or agency adds its own clients’ data to a project, it must have appropriate authority and a legal basis. In that situation, Brandstash may act as a processor following the customer account’s instructions.
Data we handle
| Category | Examples | Source |
|---|---|---|
| Account | name, email, protected credentials, language, and preferences | You or your chosen login provider |
| Project | business name, briefing, tone of voice, files, decisions, and content | You and authorized users |
| Diagnosis | search term, Place ID, public profile data, and generated report | You and public Google sources |
| Connected Google Business | identifiers, authorization token, profile data, posts, reviews, and permitted insights | Google, after explicit authorization |
| Usage and security | IP, browser, technical events, logs, consent, and attribution | Collected automatically during use |
| Billing | plan, payment status, and required tax information | You and the payment provider |
| Support | messages, attachments, and context sent to support | You |
Why we use this data
- Account and security: authenticate users, prevent abuse, and protect sessions.
- Diagnosis: locate the correct profile, calculate the baseline, and save the requested result.
- Autopilot: plan the calendar, generate posts and images, organize approvals, publish authorized content, and prepare review replies.
- Insights: show performance data and operating history in the project.
- Support and improvement: fix errors, answer requests, and understand aggregate product use.
- Billing and legal duties: process the plan, maintain tax records, and comply with applicable obligations.
Google Business and API data
Connecting Google Business is optional and requires explicit authorization. We request only permissions needed for the functions shown on the connection screen. Brandstash uses the received data to manage and report on profiles you own or are authorized to manage.
- We do not sell data received from Google APIs.
- We do not use it for personalized advertising, lending, or third-party profiling.
- We do not transfer it to third parties except subprocessors needed to provide or protect the service under confidentiality obligations.
- You can revoke authorization in your Google account and request disconnection inside Brandstash.
- After disconnection, we stop new actions and delete or anonymize data according to your request and applicable retention duties.
Automation and model providers
Briefings, instructions, and necessary portions of a project may be sent to contracted model providers to produce posts, images, and replies. Brandstash configures these services to fulfill the user request and limits sharing to what is necessary.
We do not independently use project content to train a shared public model. Automated outputs may contain errors; the approval history records decisions made within the product.
Legal bases
- Contract and pre-contract steps: account, requested diagnosis, project, support, and plan delivery.
- Consent: optional telemetry, optional communications, and connections that require user authorization.
- Legitimate interests: security, fraud prevention, and technical improvement, assessed against necessity and data-subject rights.
- Legal obligations: tax and accounting records and valid legal requests.
Retention and security
We retain data while the account or project is active and for as long as needed for security, disputes, legal obligations, or rights enforcement. We then securely delete or anonymize it unless retention is required.
We apply technical and organizational measures proportionate to risk, including access controls, credential protection, and monitoring. No system is infallible; material incidents are handled and reported as required by law.
Your rights
Under Brazil’s LGPD, data subjects may request confirmation of processing, access, correction, sharing information, portability where applicable, anonymization, blocking or deletion, withdrawal of consent, and review of automated decisions in cases provided by law.
Send a request to privacy@brandstash.ai. We may request reasonable information to verify identity and protect the account. If the issue is not resolved, data subjects may also contact Brazil’s ANPD and consumer-protection bodies.
Changes to this Policy
We update this page when the product scope, providers, or data practices materially change. The date at the top identifies the current version. Material changes may be communicated by email or inside the app.
Talk to us about your data
To exercise privacy rights or ask a question, email privacy@brandstash.ai.
Send email