Privacy Policy
How brandstash collects, uses and protects your workspace data, your projects, and the integrations you connect — without the unnecessary legalese.
brandstash (operated by brandstash Tecnologia Ltda., registered in Salvador, Brazil) is an operating system for modern marketing. This policy explains what data we collect when you use brandstash.ai, the app at app.brandstash.ai and any connected module (Social Check, GBP Check, Paid Traffic, Assistant, Creatives, Video), why we collect it, and how you stay in control of each piece.
TL;DR · On one page
- Per-project memory is isolated and encrypted. Nothing leaks across projects. Nothing trains a shared model.
- Integration tokens are encrypted at rest (AES-256-GCM). Revoke any time — straight in the UI or via the public Data Deletion endpoint.
- Limited sub-processors: Anthropic (LLM), Meta and Google (integrations you connect), hosting provider. Full list below.
- You own your data. Export, correct, delete — anytime, no questions.
- SOC2 Type I complete, Type II in progress. DPA available on request.
Who we are and who this applies to
The data controller is brandstash Tecnologia Ltda. This policy applies to anyone who creates an account, uses the app, runs a module, or connects a third-party platform (Meta, Google) through brandstash.
When you run a client brand inside brandstash (typical for agencies and freelancers), you are the controller of your client's data and brandstash is the processor. That relationship is formalised in our DPA (Data Processing Addendum) — available at privacy@brandstash.ai.
What we collect
We collect the minimum each module needs to do its job. Nothing is sold. Categories:
| Category | Examples | Source |
|---|---|---|
| Account | name, email, password hash, preferred language | You, at signup |
| Workspace & projects | workspace name, project name, briefings, decisions, plans, Assistant chat, uploaded files | You, using the app |
| Social integrations (optional) | encrypted OAuth tokens, Page / IG Business ID, public counts, post metrics via Instagram Graph API | Meta (with your explicit consent) |
| Google integrations (optional) | Place ID, Google Business Profile data, Performance Max metrics via Google Ads API | Google (with your consent) |
| AI-generated output | audits, reports, copy drafts, logged decisions | Generated inside the app from your input |
| Usage telemetry | IP, user-agent, usage events (module opened, job ran), error logs | Collected automatically |
| Billing | legal name, tax ID, address, last 4 digits of card | You, via payment processor |
What we use each piece for
Each piece of data has a specific purpose. No vague "to improve your experience" cover:
- Account: authenticate you and protect access to the workspace.
- Workspace & projects: feed the persistent memory every module reads from — literally what makes the product different. We index (RAG) it to return context on demand; we never train a public model on it.
- Social integrations: run the Social Check audit (metrics, hooks, posting cadence) with the exact permission you approved on Meta's OAuth screen. We list each scope in the next section.
- Google integrations: run GBP Check (categories, photos, reviews, posts) and — when enabled — operate Pmax campaigns through the Google Ads API.
- AI output: deliver the report/plan/decision back to you; outputs stay inside the project for history and over-time comparison (e.g. GBP Check regression tracking).
- Telemetry: keep the service up, detect abuse, debug errors. We aggregate where possible; we never sell.
- Billing: process payments, issue invoices, meet tax obligations.
Meta scopes we request for Social Check: instagram_basic (public profile and counts), instagram_manage_insights (post/account metrics), pages_show_list (list linked Pages), pages_read_engagement (Page engagement), business_management (operate via Business Portfolio). We only ask for a scope if you actually use the matching module.
Legal bases
In Brazil (LGPD) and the European Union (GDPR) we process data under these bases:
- Performance of contract (LGPD art. 7, V / GDPR art. 6(1)(b)): everything strictly needed to deliver the service you signed up for.
- Consent (LGPD art. 7, I / GDPR art. 6(1)(a)): for optional integrations (Meta, Google) and for marketing communications. Revocable at any time.
- Legitimate interest (LGPD art. 7, IX / GDPR art. 6(1)(f)): security, fraud prevention, product improvement from aggregated data.
- Legal obligation (LGPD art. 7, II / GDPR art. 6(1)(c)): invoicing, accounting retention.
How we protect it
Per-project memory is the moat of the product — so we treat it like one.
- Encryption at rest: integration tokens and secrets are encrypted with AES-256-GCM using a managed key (`SETTINGS_ENCRYPTION_KEY`, 64 hex chars, never committed).
- Encryption in transit: TLS 1.2+ on every public endpoint. HSTS enabled.
- Project isolation: one project's memory is never exposed to another project, even inside the same workspace.
- No shared training: no LLM is trained on your data. Conversations with the Assistant are processed live and discarded by Anthropic under the zero-retention agreement we keep contractually.
- Access control: internal access is role-restricted, MFA-required, and audit-logged.
- Incident response: we notify affected customers within 72 hours of confirming any material incident involving personal data.
- Compliance: SOC2 Type I complete; Type II in progress. Summary report available under NDA.
Who we share with
We do not sell data. We share only with sub-processors strictly required to operate the service:
| Vendor | Role | Region |
|---|---|---|
| Anthropic, PBC | Claude API (powers module output) | USA |
| Meta Platforms, Inc. | Instagram Graph API and Facebook Login (only if you connect) | USA / EU |
| Google LLC | Places API, Google Business Profile API, Google Ads API (only if you connect) | USA / EU |
| Hosting provider | Compute, database, and file storage | South America (primary) / USA (redundancy) |
| Payments provider | Billing and invoicing | Brazil |
| Transactional email | Confirmations, password resets, operational alerts | USA |
How long we keep it
- Active workspace: for as long as your subscription is active.
- Post-cancellation: data is frozen for 90 days so you can restore; after that it is permanently deleted from production systems.
- Backups: rotated every 35 days. Once the cycle completes the data is gone from backups too.
- Usage and security logs: kept for up to 12 months and then aggregated / anonymised.
- Tax data: kept for the period required by law (5 years in Brazil).
- Integration tokens: deleted immediately when you disconnect or use the Data Deletion endpoint.
Your rights and how to use them
LGPD and GDPR give you rights over your data. You can exercise all of them, free of charge:
- Access: download a structured copy of everything we hold about you or your workspace.
- Correction: update incorrect data straight in the UI or by request.
- Deletion / erasure: delete a workspace, a specific project, an integration, or your entire account.
- Portability: export in an open format (JSON/CSV) so you can take it elsewhere.
- Objection and consent withdrawal: turn off integrations or stop marketing communications at any time.
- Review of automated decisions: no module makes a fully automated decision with legal effect; even so, you can request a human review of any recommendation.
How to ask: write to privacy@brandstash.ai. We respond within 15 days (extendable by 15 more under LGPD art. 19, §1).
Data Deletion for Meta integrations: Meta requires a public endpoint where users can request deletion of the data we collect through Instagram/Facebook. Ours lives at:
POST https://api.brandstash.ai/media-check/meta/data-deletionIt accepts Meta's signed callback and removes the data tied to the
user_id within 30 days. You can also request it inside the app at Settings → Integrations → Disconnect.International transfers
Primary operations run on a data centre in South America. Some sub-processors (Anthropic, Meta, Google, transactional email) process data in the USA. For those transfers we rely on the European Commission's Standard Contractual Clauses (SCCs) or an equivalent mechanism accepted by Brazil's ANPD.
Children and minors
brandstash is a B2B product and not directed at anyone under 18. We do not knowingly collect data from minors. If you believe a minor has submitted data to us, write to privacy@brandstash.ai and we will delete it immediately.
Changes to this policy
We update this page when we ship a new module, swap a material sub-processor, or adjust a security practice. Material changes are announced 30 days in advance by email to workspace admins and via an in-app banner.
Previous versions stay archived and are available on request.
Questions about your data?
Write to our data protection lead at privacy@brandstash.ai, or reach the team at hello@brandstash.ai. We answer personally within 5 business days.
Talk to the team