← Back to homeLEGAL · POLICY

Privacy Policy

How brandstash collects, uses and protects your workspace data, your projects, and the integrations you connect — without the unnecessary legalese.

Last updated May 23, 2026Effective May 23, 2026v1.0

brandstash (operated by brandstash Tecnologia Ltda., registered in Salvador, Brazil) is an operating system for modern marketing. This policy explains what data we collect when you use brandstash.ai, the app at app.brandstash.ai and any connected module (Social Check, GBP Check, Paid Traffic, Assistant, Creatives, Video), why we collect it, and how you stay in control of each piece.

TL;DR · On one page

  • Per-project memory is isolated and encrypted. Nothing leaks across projects. Nothing trains a shared model.
  • Integration tokens are encrypted at rest (AES-256-GCM). Revoke any time — straight in the UI or via the public Data Deletion endpoint.
  • Limited sub-processors: Anthropic (LLM), Meta and Google (integrations you connect), hosting provider. Full list below.
  • You own your data. Export, correct, delete — anytime, no questions.
  • SOC2 Type I complete, Type II in progress. DPA available on request.
01

Who we are and who this applies to

The data controller is brandstash Tecnologia Ltda. This policy applies to anyone who creates an account, uses the app, runs a module, or connects a third-party platform (Meta, Google) through brandstash.

When you run a client brand inside brandstash (typical for agencies and freelancers), you are the controller of your client's data and brandstash is the processor. That relationship is formalised in our DPA (Data Processing Addendum) — available at privacy@brandstash.ai.

02

What we collect

We collect the minimum each module needs to do its job. Nothing is sold. Categories:

CategoryExamplesSource
Accountname, email, password hash, preferred languageYou, at signup
Workspace & projectsworkspace name, project name, briefings, decisions, plans, Assistant chat, uploaded filesYou, using the app
Social integrations (optional)encrypted OAuth tokens, Page / IG Business ID, public counts, post metrics via Instagram Graph APIMeta (with your explicit consent)
Google integrations (optional)Place ID, Google Business Profile data, Performance Max metrics via Google Ads APIGoogle (with your consent)
AI-generated outputaudits, reports, copy drafts, logged decisionsGenerated inside the app from your input
Usage telemetryIP, user-agent, usage events (module opened, job ran), error logsCollected automatically
Billinglegal name, tax ID, address, last 4 digits of cardYou, via payment processor
What we do not collect: precise geolocation, the content of your Instagram/Facebook DMs, contact lists, biometric data, or any information about minors.
03

What we use each piece for

Each piece of data has a specific purpose. No vague "to improve your experience" cover:

  • Account: authenticate you and protect access to the workspace.
  • Workspace & projects: feed the persistent memory every module reads from — literally what makes the product different. We index (RAG) it to return context on demand; we never train a public model on it.
  • Social integrations: run the Social Check audit (metrics, hooks, posting cadence) with the exact permission you approved on Meta's OAuth screen. We list each scope in the next section.
  • Google integrations: run GBP Check (categories, photos, reviews, posts) and — when enabled — operate Pmax campaigns through the Google Ads API.
  • AI output: deliver the report/plan/decision back to you; outputs stay inside the project for history and over-time comparison (e.g. GBP Check regression tracking).
  • Telemetry: keep the service up, detect abuse, debug errors. We aggregate where possible; we never sell.
  • Billing: process payments, issue invoices, meet tax obligations.

Meta scopes we request for Social Check: instagram_basic (public profile and counts), instagram_manage_insights (post/account metrics), pages_show_list (list linked Pages), pages_read_engagement (Page engagement), business_management (operate via Business Portfolio). We only ask for a scope if you actually use the matching module.

05

How we protect it

Per-project memory is the moat of the product — so we treat it like one.

  • Encryption at rest: integration tokens and secrets are encrypted with AES-256-GCM using a managed key (`SETTINGS_ENCRYPTION_KEY`, 64 hex chars, never committed).
  • Encryption in transit: TLS 1.2+ on every public endpoint. HSTS enabled.
  • Project isolation: one project's memory is never exposed to another project, even inside the same workspace.
  • No shared training: no LLM is trained on your data. Conversations with the Assistant are processed live and discarded by Anthropic under the zero-retention agreement we keep contractually.
  • Access control: internal access is role-restricted, MFA-required, and audit-logged.
  • Incident response: we notify affected customers within 72 hours of confirming any material incident involving personal data.
  • Compliance: SOC2 Type I complete; Type II in progress. Summary report available under NDA.
06

Who we share with

We do not sell data. We share only with sub-processors strictly required to operate the service:

VendorRoleRegion
Anthropic, PBCClaude API (powers module output)USA
Meta Platforms, Inc.Instagram Graph API and Facebook Login (only if you connect)USA / EU
Google LLCPlaces API, Google Business Profile API, Google Ads API (only if you connect)USA / EU
Hosting providerCompute, database, and file storageSouth America (primary) / USA (redundancy)
Payments providerBilling and invoicingBrazil
Transactional emailConfirmations, password resets, operational alertsUSA
The current list lives at brandstash.ai/subprocessors (to be published). Material changes are notified to active workspaces 30 days in advance.
07

How long we keep it

  • Active workspace: for as long as your subscription is active.
  • Post-cancellation: data is frozen for 90 days so you can restore; after that it is permanently deleted from production systems.
  • Backups: rotated every 35 days. Once the cycle completes the data is gone from backups too.
  • Usage and security logs: kept for up to 12 months and then aggregated / anonymised.
  • Tax data: kept for the period required by law (5 years in Brazil).
  • Integration tokens: deleted immediately when you disconnect or use the Data Deletion endpoint.
08

Your rights and how to use them

LGPD and GDPR give you rights over your data. You can exercise all of them, free of charge:

  • Access: download a structured copy of everything we hold about you or your workspace.
  • Correction: update incorrect data straight in the UI or by request.
  • Deletion / erasure: delete a workspace, a specific project, an integration, or your entire account.
  • Portability: export in an open format (JSON/CSV) so you can take it elsewhere.
  • Objection and consent withdrawal: turn off integrations or stop marketing communications at any time.
  • Review of automated decisions: no module makes a fully automated decision with legal effect; even so, you can request a human review of any recommendation.

How to ask: write to privacy@brandstash.ai. We respond within 15 days (extendable by 15 more under LGPD art. 19, §1).

Data Deletion for Meta integrations: Meta requires a public endpoint where users can request deletion of the data we collect through Instagram/Facebook. Ours lives at:

POST https://api.brandstash.ai/media-check/meta/data-deletion
It accepts Meta's signed callback and removes the data tied to the user_id within 30 days. You can also request it inside the app at Settings → Integrations → Disconnect.
09

Cookies, analytics and tracking

The landing page (brandstash.ai) uses strictly necessary cookies (session, theme preference, chosen language) and, when you consent, aggregated first-party telemetry to understand what works. No third-party pixel for behavioural advertising.

The app (app.brandstash.ai) uses only authentication and preference cookies. No marketing trackers — you're logged in; you don't need to be profiled.

10

International transfers

Primary operations run on a data centre in South America. Some sub-processors (Anthropic, Meta, Google, transactional email) process data in the USA. For those transfers we rely on the European Commission's Standard Contractual Clauses (SCCs) or an equivalent mechanism accepted by Brazil's ANPD.

11

Children and minors

brandstash is a B2B product and not directed at anyone under 18. We do not knowingly collect data from minors. If you believe a minor has submitted data to us, write to privacy@brandstash.ai and we will delete it immediately.

12

Changes to this policy

We update this page when we ship a new module, swap a material sub-processor, or adjust a security practice. Material changes are announced 30 days in advance by email to workspace admins and via an in-app banner.

Previous versions stay archived and are available on request.

Questions about your data?

Write to our data protection lead at privacy@brandstash.ai, or reach the team at hello@brandstash.ai. We answer personally within 5 business days.

Talk to the team