Privacy Policy
Version v1.0-2026-10 · effective 2026-10-01
Draft — pending legal review. This document contains placeholders marked [LEGAL REVIEW] and is not yet binding.
1. Controller
[LEGAL REVIEW] Controller identity and contact.
2. What we process
Account data: e-mail, name, interface language, authentication metadata.
Organization and brand data: legal name, country, optional tax id, website, brand details and markets.
Interview and Brand State data: your answers, the structured Brand State versions, evidence you supply, review decisions.
Strategy and Blueprint data: derived strategy versions, Blueprint versions and their traceability.
Security and operations metadata: request identifiers, timestamps, error codes, usage counters, audit records of operator actions. We do not log the content of your answers or reports.
Payment boundary: orders (product, currency, amounts, status) and payment-provider event identifiers. Card details are handled by Stripe only and never reach us.
3. Why and on what basis
[LEGAL REVIEW] Purposes and legal bases per category (contract performance, legitimate interest, consent where applicable).
4. Processors and recipients
Supabase (database, authentication, e-mail delivery of authentication messages); OpenAI (AI evaluation and strategy synthesis of the content you provide); Stripe (payments); the hosting provider of this application; the transactional e-mail provider used for authentication messages.
[LEGAL REVIEW] Locations, transfer mechanisms and each processor's role.
5. Retention and deletion
You can request deletion of your account, an organization or a project from the Account page. Requests are handled by our team; nothing is deleted automatically, so that purchased results and audit records are not lost by accident.
[LEGAL REVIEW] Retention periods per category and the deletion response window.
6. Your rights
[LEGAL REVIEW] Access, rectification, erasure, restriction, portability, objection, complaint to the supervisory authority.
7. Security
Data is isolated per organization with database-level access rules. Secrets are kept server-side only. Invitation codes are stored only as salted hashes.
Questions: support@aibrandstrategy.ai