Legal
Privacy Policy
Last updated: April 2026 ยท Effective immediately
๐ Short version: We collect only what we need to run this service. We never sell your data. We never share it with advertisers. You can delete your account and all your data at any time.
1. Who we are
Brand Voice is a product created by Finesa Shala ("we", "us", "our"). We provide an AI-powered social media content generation service at brand-voice.space.
For privacy questions: privacy@brand-voice.space
2. What data we collect
- Account data: Your email address and encrypted password when you create an account.
- Brand profile: Business name, niche, product description, target audience, tone of voice, keywords โ saved to your account to personalize your content.
- Content history: The topics and generated content saved to your account for your reference.
- Payment data: Handled entirely by Stripe. We never see or store your card details.
- Analytics data: Anonymous usage data via Google Analytics (only with your consent).
- Technical data: IP address, browser type, device โ collected by our hosting provider for security.
3. How we use your data
- To create and manage your account
- To generate personalized social media content based on your brand profile
- To process your subscription payments via Stripe
- To send transactional emails (account confirmation, password reset, billing)
- To improve the product and understand usage patterns
- To protect against abuse and unauthorized access
- To comply with legal obligations (including German/EU law)
4. Legal basis for processing (GDPR)
- Contract performance: Processing your account and brand data to deliver the service you signed up for.
- Legitimate interests: Security monitoring, fraud prevention, service improvement.
- Consent: Analytics cookies โ you can withdraw at any time via the cookie banner.
- Legal obligation: Retaining certain data as required by German tax and commercial law.
5. Cookies
- Essential cookies: Required for authentication and keeping you signed in. Cannot be disabled.
- Analytics cookies: Google Analytics (GA4) for usage insights. Only activated with your explicit consent via the cookie banner.
6. Third-party services
- Supabase โ authentication and database. Data stored in EU region where available.
- Anthropic โ AI content generation. Your prompts are sent to generate content. Anthropic does not use your prompts to train their models by default.
- Stripe โ payment processing. Stripe handles all payment data directly under their own privacy policy.
- Vercel โ hosting and serverless functions. Data processed under Standard Contractual Clauses.
- Google Analytics โ website analytics. Only activated with your consent.
7. Data retention
- Account data: Retained while your account is active. Deleted within 30 days of account deletion.
- Content history: Retained in your account until you delete it or close your account.
- Analytics data: 14 months (Google Analytics default).
- Server logs: 30 days maximum.
8. Your rights under GDPR
- Right of access โ Request a copy of your personal data.
- Right to rectification โ Correct inaccurate data we hold about you.
- Right to erasure โ Request deletion of your personal data.
- Right to restriction โ Request we limit how we process your data.
- Right to portability โ Receive your data in a machine-readable format.
- Right to object โ Object to processing based on legitimate interests.
- Right to withdraw consent โ Withdraw analytics consent at any time.
To exercise any of these rights, email privacy@brand-voice.space. We respond within 30 days.
You may also lodge a complaint with the German data protection authority: www.bfdi.bund.de
9. Data security
- All data transmitted over HTTPS (TLS encryption)
- Authentication handled by Supabase with JWT tokens
- API keys stored as encrypted environment variables โ never in code
- Rate limiting on all API endpoints to prevent abuse
- No storage of payment card data โ handled entirely by Stripe
10. Children's privacy
Brand Voice is not directed at children under 16. We do not knowingly collect data from anyone under 16. Contact us immediately if you believe a child has provided personal data.
11. Changes to this policy
We will update the "Last updated" date when we make changes. Significant changes will be communicated by email to registered users.
12. Contact
๐ง privacy@brand-voice.space
๐ brand-voice.space