BETAPro is not billed during beta. Lock in the price and we will honor it at launch.Freeze this price
Draft — this policy has not been approved for production use.

Privacy Policy

Starter template — legal review required before public launch. This document covers the operational disclosures BrandBanta's product requires (data collection, third-party processors, workspace-admin visibility, member self-access). A licensed attorney in your operating jurisdiction must review before publication, particularly around EEA/UK (GDPR), California (CCPA/CPRA), and industry-specific frameworks (HIPAA, GLBA, FERPA) that apply to your customer base.

Effective date: to be filled at publication Last updated: 15 August 2026


Who we are

BrandBanta ("we", "us") provides a software-as-a-service platform for tracking how AI assistants (ChatGPT, Claude, Gemini, Perplexity, and others) describe brands. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the rights you have over it.

The controller responsible for your personal data is Aleksandar Perisic, a sole natural person, Waldspielplatz 3, 82319 Starnberg, Germany (see the Imprint). For workspace content you send through BrandBanta on behalf of your own customers, you are the controller and we act as your processor under the Data Processing Agreement.

If you have any questions, contact us at privacy@brandbanta.com.


Scope

This policy covers:

  • Visitors to brandbanta.com and our documentation site
  • End users of the BrandBanta web application (the people logged into a workspace)
  • Workspace owners and administrators who control a workspace's settings, members, and integrations

A separate Data Processing Agreement (DPA) governs the relationship when you (the workspace owner) are a business processing personal data of your own customers through BrandBanta. See /legal/dpa.


Personal data we collect

Data you provide

  • Account data — name, email, password hash, profile image, and optional two-factor authentication secret.
  • Workspace data — workspace name, slug, billing address, tier selection, member roster.
  • Brand-tracking data — the brand names, queries, and topics you choose to track. We treat the literal text you enter (e.g., the prompt sent to AI assistants) as input data; it is not "personal data" unless you include personal information in it.
  • Payment data — handled by our payment processor (Stripe). We store only a customer ID and tier metadata; full card data never touches BrandBanta servers.
  • API credentials (BYOK) — if you bring your own provider keys (OpenRouter, Anthropic, OpenAI) we encrypt them at rest with AES-256-GCM using the workspace master key (KEYRING_MASTER_KEY) and decrypt only at call time. Plaintext is never logged.

Data generated by your use of the service

  • Scan results — the responses AI assistants returned to your tracked queries, along with structured metadata (mentions, sentiment, sources cited).
  • Usage metadata — timestamps, scan counts, token counts, and inference cost (in micro-dollars) per scan. This metadata powers in-product analytics and is used for billing, capacity planning, and abuse prevention.
  • Activity attribution — when a member of your workspace triggers a scan, we record which member did so (scan_session.userId). This is metadata only; the prompt and response text are stored separately and never shown alongside attribution in admin views.
  • Audit logs — security-relevant events (logins, password changes, key rotations, member invitations) are retained for security incident response.

Data collected automatically

  • Technical data — IP address, browser type, operating system, device identifiers, referrer URL, and pages viewed. Used for security, abuse prevention, and platform optimization.
  • Cookies and similar technologies — session cookies for authentication; preference cookies for color mode and locale. We do not use third-party advertising cookies. Analytics cookies (if configured) are limited to first-party, privacy-respecting providers (Plausible / Umami / PostHog with anonymization on).

How we use your data

We use personal data only for the purposes disclosed below. Each purpose is tied to a legal basis under GDPR Art. 6.

| Purpose | Legal basis | | -------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | | Operating the service (authentication, scan execution, results delivery) | Contract performance (Art. 6(1)(b)) | | Billing and tier enforcement | Contract performance | | Sending transactional email (magic links, verification, alerts, weekly digests) | Contract performance | | Security, abuse prevention, capacity planning | Legitimate interest (Art. 6(1)(f)) | | Aggregate workspace metadata visible to workspace admins (counts, costs, member attribution) | Legitimate interest (workspace owner has a contract with us and a legitimate interest in oversight of their workspace) | | Marketing email (newsletter, product updates) | Consent (Art. 6(1)(a)) — explicit opt-in only | | Legal compliance, responding to lawful requests | Legal obligation (Art. 6(1)(c)) |


Workspace administrator visibility

This section is important. BrandBanta is a workplace tool. Workspace owners and administrators can see:

  • Aggregate workspace metadata — total scan counts, total inference cost, scan-cost breakdown by platform, scan-cost breakdown by member (counts and costs only).
  • Member roster — who is in the workspace and what role they have.
  • Provider credentials (BYOK) — workspace-level API keys are managed by admins only. Regular members never see API key metadata, not even the last four characters.

Workspace administrators cannot see, through the cost dashboard:

  • The text of prompts a member sent
  • The text of AI responses received
  • The brands or topics a member chose to track at the member level (these are workspace-level by design)

Every member can see their own usage on the same /settings/cost page (scoped to their own scans) without filing a request. This satisfies the GDPR Article 15 "right of access" without administrative friction.

When a member leaves a workspace, their attribution on historical scans is preserved as the user identifier with the user record removed (ON DELETE SET NULL). The workspace retains the cost record for billing reconciliation; the member's identity is dissociated.


Third-party processors

We use the following sub-processors. Each processes personal data only on our instructions and under a written data-processing agreement.

| Sub-processor | Purpose | Data shared | Location | | -------------- | -------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------- | ------------------------------- | | Vercel | Hosting (web application, marketing site, documentation) | All web traffic data | US / EU (Vercel's edge network) | | Turso | Database (libSQL/SQLite hosted) | All workspace, scan, and member data | EU / US (configurable) | | OpenRouter | LLM inference routing for scans | Prompt text, model identifiers; no PII unless included in your prompt | US | | Anthropic | Batch insight generation (weekly digest, per-topic narratives) via the Anthropic Batches API | Aggregated scan results; no PII unless included | US | | OpenAI | Embedding generation on scan results | Text snippets from scan results (mention context); no PII unless included | US | | Stripe | Payment processing | Email, name, billing address, card data (handled directly by Stripe) | US / EU | | Resend | Transactional email delivery | Email address and message content | US | | Sentry | Error monitoring | Stack traces, browser/server context, user identifier (no email or PII) | US / EU | | Inngest | Background job orchestration | Job metadata, scan identifiers (no plaintext credentials) | US |

When you bring your own provider credentials (BYOK), the corresponding scans bill to your account at the upstream provider, and the upstream provider becomes your direct data processor for that workload. We facilitate the connection; the contract is between you and the provider.

We do not sell personal data to anyone. We do not share personal data with third parties for advertising.


Data retention and deletion

Drafting note for counsel (remove before publication): this section was rewritten on 2026-07-26 to describe the system's implemented behavior. The previous draft promised scheduled retention windows (24-month scan results, 12-month audit logs) and "deletion within 30 days" that no code enforces — approving those would commit us to processes that do not exist. If the operator prefers the windowed policy, the pruning jobs must be built before this document is approved.

  • Account and workspace data — retained for as long as the account or workspace exists. Deleting your account or workspace is self-service, immediate, and irreversible: the records and their associated data (scan results, stored provider credentials, workspace configuration) are removed at the moment of deletion, not on a delayed schedule. Billing records we are legally required to retain (typically 7 years) survive deletion.
  • Scan results and inference cost metadata — retained for the life of the workspace. We do not currently apply automatic time-based expiry; you remove this data by deleting the workspace, or on request (below).
  • Audit logs — security-relevant events are retained for the life of the account for incident response.
  • Backups — disaster-recovery backups are retained on our database provider's point-in-time-recovery schedule. Backups exist to restore the service after failure, not to restore individually deleted data; deleted data ages out of backups as the recovery window rolls forward.

You can request targeted deletion (less than a full account/workspace) by contacting privacy@brandbanta.com — honored within the statutory response window that applies to you (one month under GDPR, 45 days under CCPA/CPRA).


Security

We apply standard industry security controls:

  • Encryption in transit — TLS 1.3 for all customer-facing endpoints.
  • Encryption at rest — provider credentials and other secrets sealed with AES-256-GCM using the workspace master key (KEYRING_MASTER_KEY); database storage encrypted by our hosting provider.
  • Access control — workspace data scoped per workspace; no cross-workspace access; administrative access to production systems is restricted to authorized personnel and logged.
  • Authentication — passwords are hashed with Argon2id; passkey (WebAuthn) and TOTP two-factor authentication are supported and recommended.
  • Vulnerability response — security reports may be sent to security@brandbanta.com for coordinated disclosure.

No system is perfectly secure. We will notify affected users within 72 hours of confirming a breach that affects their personal data.


Your rights

If you are in the European Economic Area, the United Kingdom, Switzerland, or California, you have specific rights over your personal data:

  • Access — get a copy of the personal data we hold about you. End users can self-serve via /settings/cost (own usage data) and /settings/general (account profile). For everything else, email privacy@brandbanta.com.
  • Rectification — correct inaccurate data. Most fields are self-service in /settings.
  • Erasure ("right to be forgotten") — request deletion of your personal data. Deleting your account or workspace is self-service and takes effect immediately; other requests are honored within the statutory window (one month under GDPR, 45 days under CCPA/CPRA), subject to retention requirements (e.g., billing records).
  • Restriction — request that we limit how we process your data.
  • Portability — receive your data in a machine-readable format.
  • Objection — object to processing based on legitimate interest (we'll re-evaluate the basis and stop unless overriding grounds exist).
  • Withdraw consent — where processing is based on consent (e.g., marketing email), withdraw it at any time via the unsubscribe link or by contacting us.
  • Lodge a complaint — with your local supervisory authority (in the EU/EEA) or the Information Commissioner's Office (in the UK).

For California residents (CCPA/CPRA): you additionally have the right to know what categories of personal information we collect, the right to opt out of any sale or sharing of personal information (we do neither), and the right not to be discriminated against for exercising your rights.


International transfers

Personal data may be transferred to and processed in the United States and other countries outside the EEA/UK. When this happens, we rely on appropriate safeguards, typically the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum. A copy of the relevant SCCs is available on request.


Children

BrandBanta is a B2B service not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact privacy@brandbanta.com and we will delete it promptly.


Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be announced in-product and (for registered users) via email at least 30 days before they take effect.


Contact

  • Privacy questions — privacy@brandbanta.com
  • Security disclosures — security@brandbanta.com
  • Data Protection Officer — to be appointed if EU/UK customer threshold triggers Art. 37
  • EU representative — to be appointed if Art. 27 applies

Postal: Aleksandar Perisic, Waldspielplatz 3, 82319 Starnberg, Germany