Skip to content
  • How it works
  • What you get
  • Examples
  • Try it free
  • FAQ
  • Privacy
  • Terms
Launch your brand

Home / Privacy Policy

Privacy Policy

This Policy explains how BrandFounder collects, uses, stores and protects information when you use the website, iOS app and related services.

Contact: support@brandfounder.ai
Last updated: 29 September 2026

1. Who we are

BrandFounder is operated by Carter Manahan, trading as BrandFounder, a sole trader based in the United Kingdom, who is the controller of personal data processed for the BrandFounder website, iOS app and related services.

In this Policy, “BrandFounder”, “we”, “us” and “our” refer to the operator named above, trading as BrandFounder. “You” and “your” refer to the person using the services.

2. Scope

This Policy covers personal data collected through:

  • the BrandFounder website;
  • the BrandFounder iOS app;
  • support messages; and
  • account, purchase, generation and storage features operated for BrandFounder.

Apple, Google and other services you choose may also process information as independent controllers under their own notices. This Policy explains BrandFounder’s role and does not replace those notices.

3. Information we collect

3.1 Account and sign-in information

This may include your email address, Firebase user ID, sign-in provider, account timestamps and related identifiers. If you use Google Sign-In, we may receive the name and email information made available by Google. If you use Sign in with Apple, we receive the Apple credential information made available for authentication; Apple may provide a relay email address instead of your personal address.

3.2 Brand, project and user content

This includes brand names, audience and product descriptions, positioning, taglines, keywords, pricing inputs, promotion preferences, launch content, onboarding answers and other text or settings you enter. It also includes photos, logos, visual references and reference images you deliberately select for a request.

3.3 Generated and saved content

This may include generated logos, wordmarks, palettes, typography choices, brand and campaign visuals, generated copy, strategy, market and pricing outputs, launch plans, project records, exported assets and saved brands linked to your account.

3.4 Purchases and entitlements

We receive limited App Store purchase information needed to verify and deliver a Brand Pack, prevent duplicate charging, recover interrupted delivery and restore an eligible purchase. This may include transaction and original transaction identifiers, product identifier, purchase state, entitlement state and related metadata. We do not receive your full payment-card details.

3.5 Support messages

If you contact us, we collect the message and any information or files you choose to include so we can respond and investigate the issue.

When you use the in-app support button, the email is pre-filled with details that help us find your account and purchase: your BrandFounder user ID and sign-in provider, app version, operating-system version, device model, region setting and, where relevant, the identifiers of a Brand Pack purchase and project that have not yet been delivered. You can read and edit these details before sending, and nothing is sent unless you send the email.

3.6 Device, operational and security information

Firebase and our backend may process device and app information, app version, language, time zone, request and error details, installation or device identifiers, authentication state, App Check or device-integrity signals, rate-limit information and related security data needed to deliver requests, diagnose failures and protect the service. Integrity information is operational data and should not be assumed to be anonymous.

3.7 Optional usage analytics

Firebase Analytics is off by default. If you turn on “Share usage analytics” in Settings, it may collect screens viewed, setup steps reached, actions taken (such as creating, exporting or sharing a brand), feature use, purchases, errors, app and device information, and a random identifier that Firebase creates for your installation. It is never linked to your account, email address or user ID, and never includes brand names, ideas, descriptions, prompts or anything you type. Advertising features and the device advertising identifier are turned off. You can turn it off again at any time to stop future collection.

3.8 Crash and error reports

BrandFounder uses Firebase Crashlytics to find and fix problems. If the app crashes, or an important step such as a purchase, brand generation, brand save or upgrade fails, a report may be collected. A report can include the technical details of the crash or error, device model, operating-system and app version, the app’s state at the time, the name of the step that failed, related purchase, project or brand identifiers and a Crashlytics installation identifier. Reports are not linked to your account or BrandFounder user ID.

Crash and error reports are designed to exclude brand names, descriptions, ideas, prompts, images and generated content. Crash reporting is off by default. It starts only if you turn on “Share crash reports” in Settings, and you can turn it off again at any time to stop future reports from that device.

3.9 Optional shared inputs

“Share inputs to improve results” is a separate, off-by-default setting. If enabled, relevant creation inputs and associated generated-pack information may be stored separately to help evaluate and improve result quality. Turning the setting off stops future optional sharing; permanent account deletion removes shared-input records associated with your user ID from BrandFounder’s active systems.

4. How we use information

  • create, authenticate, secure and manage accounts;
  • store, sync, display, edit and retrieve brands, projects and assets;
  • send the inputs needed to generate the AI feature you request;
  • verify purchases, manage entitlements, deliver paid outputs and support eligible retries or restores;
  • respond to support requests and investigate delivery or generation failures;
  • measure product use when you have enabled optional analytics;
  • store optional shared inputs when you have enabled that separate setting;
  • diagnose and fix crashes and failed purchases, generations or deliveries using crash and error reports when you have enabled them;
  • detect errors, fraud, abuse, misuse and security incidents; and
  • meet legal obligations and enforce the Terms of Use.

5. AI processing

Before the first AI request on a device, BrandFounder shows a just-in-time disclosure explaining what is sent and asks you to allow AI processing. If you allow it and request an AI feature, the text, settings, project context and selected reference images needed for that request may be sent securely through BrandFounder’s Firebase-based backend to the OpenAI API.

This processing may support brand summaries, positioning, vocabulary, market and pricing starting points, promotion guidance, launch planning, palettes, logos and other visuals. It is necessary to perform the AI generation you requested. It is separate from the optional “Share inputs to improve results” setting.

OpenAI states that API inputs and outputs are not used to train or improve its models by default unless the API customer explicitly opts in. OpenAI’s default abuse-monitoring logs may contain prompts, responses and related metadata and are generally retained for up to 30 days. OpenAI identifies limited exceptions, including longer retention where required by law or reasonably necessary to protect its services or third parties. BrandFounder does not claim Zero Data Retention. See OpenAI’s API data controls.

BrandFounder may separately store generated outputs and project records so they remain available in your account until you delete the relevant content or account, subject to the exceptions described below.

6. Payments and entitlement verification

Apple processes in-app payments. BrandFounder processes only the purchase and entitlement information needed to confirm access, avoid duplicate charging, recover eligible interrupted deliveries and restore purchases. Apple handles the payment transaction and any payment data it collects under Apple’s own terms and privacy notice.

7. Website technology

The public website is hosted on GitHub Pages. GitHub and its delivery infrastructure may process ordinary web-request and security information, such as an IP address, browser details, requested URL, timestamps and error or abuse signals, to deliver and protect the site.

The website does not include analytics, advertising pixels, fingerprinting, contact forms or non-essential cookies. Instrument Serif, GSAP and the site’s other visual assets are self-hosted, so viewing a page does not require a font or animation request to Google Fonts or jsDelivr.

If you use the theme control, the website stores the selected light or dark theme in your browser’s local storage under brandfounder-theme. This preference remains on your device until you change it, clear browser data or storage is unavailable. It is used only to remember the theme you selected and is not sent to BrandFounder.

8. Legal bases

  • Contract: to create and manage your account, store projects, perform requested AI generation, verify a purchase and deliver the service you ask for.
  • Legitimate interests: to operate, secure, maintain, debug and support BrandFounder, prevent abuse, keep backups and keep proportionate business records, balanced against your rights.
  • Consent: for optional usage analytics, optional crash reporting and optional input sharing. Each is off until you turn it on, and you can withdraw any of these choices in the app. The just-in-time AI choice controls whether a requested feature sends data to OpenAI; once requested, the generation is processed to perform the service.
  • Legal obligation: where processing is required by law, including applicable accounting, tax, consumer or regulatory duties.

9. Recipients and service providers

We do not sell personal data. Depending on the feature you use, relevant information may be processed by:

  • Apple for App Store distribution, in-app purchases, refund handling and Sign in with Apple;
  • Google Sign-In when you choose Google authentication;
  • Firebase / Google for Authentication, Firestore, Storage, Cloud Functions, App Check, optional Crashlytics crash and error reporting, database backups, operational infrastructure and optional Analytics;
  • OpenAI as the API provider for requested AI text and image generation; and
  • GitHub Pages and its delivery infrastructure for hosting and serving the public website.

We may also disclose information where reasonably necessary to comply with law or a binding request, protect rights and safety, investigate fraud or misuse, or enforce our Terms.

10. International transfers

BrandFounder is operated from the United Kingdom, but Apple, Google/Firebase, OpenAI, GitHub and their infrastructure may process information in other countries. The location can depend on the provider, service and configuration in use.

Where UK law requires a transfer mechanism, we will rely on an applicable lawful safeguard made available for the relevant transfer, which may include UK adequacy regulations or approved contractual protections. We do not claim that one particular safeguard applies to every provider or transfer. Contact us if you would like more information about a relevant transfer.

11. Retention

  • Account, brand, project and stored-asset data is generally kept while your account is active and until you delete the content or account.
  • Generated outputs are generally kept while associated with your saved account or projects.
  • Optional shared inputs are kept for the improvement purpose while associated with your account, unless removed through account deletion or no longer reasonably needed.
  • Optional analytics event data is kept by Firebase Analytics for up to 2 months; turning analytics off stops future collection but does not necessarily erase events already processed.
  • Crash and error reports are kept by Firebase Crashlytics for up to 90 days.
  • Temporary generation jobs are deleted automatically about 7 days after they are created, and rate-limit records a short time after the limit period ends.
  • Database backups are kept for up to 7 days for point-in-time recovery and up to 14 weeks for weekly backups, then deleted automatically. Backups are used only to recover from data loss or corruption.
  • Support messages are kept for as long as reasonably needed to resolve the request, maintain support history and handle disputes or legal obligations.
  • Operational and security records are kept for as long as reasonably needed to diagnose failures, prevent abuse and protect the service, taking account of provider retention settings.
  • Purchase and entitlement records are kept while needed to deliver or restore the purchase, prevent fraud, handle disputes and meet accounting or legal duties.
  • OpenAI’s default API abuse-monitoring retention is described in section 5 and is separate from BrandFounder’s storage of projects and outputs.

Where no fixed period is stated, we consider whether the account remains active, whether the record is still needed for the purpose collected, the sensitivity of the data, security and dispute risks, provider controls and applicable legal duties.

12. Your rights

Subject to applicable law and exemptions, you may have the right to:

  • be informed about processing;
  • request access to personal data and a copy of it;
  • request correction of inaccurate or incomplete data;
  • request deletion in certain circumstances;
  • request restriction of processing in certain circumstances;
  • object to processing based on legitimate interests or for direct marketing;
  • receive certain data in a portable format;
  • withdraw consent at any time where processing relies on consent; and
  • ask about safeguards for an applicable international transfer.

BrandFounder does not make solely automated decisions that produce legal or similarly significant effects about you. To exercise a right, email support@brandfounder.ai. We may ask for proportionate information to verify your identity. Withdrawing consent does not affect processing that was lawful before withdrawal.

You can complain to the UK Information Commissioner’s Office. See the ICO’s data-protection complaint guidance.

13. Permanent account deletion

BrandFounder includes permanent in-app account deletion. While you are authenticated, the deletion service removes BrandFounder data associated with your user ID from active first-party systems, including:

  • your user record, saved brands and brand-storage paths;
  • saved projects and stored brand assets;
  • AI jobs and AI usage events;
  • optional shared inputs and onboarding records;
  • BrandFounder purchase-entitlement records; and
  • the Firebase Authentication account.

If Sign in with Apple is linked, the app asks you to confirm that identity so the Apple authorisation can be revoked where applicable. The app also clears local onboarding drafts, cached brand data, optional input-sharing and analytics preferences, and the AI-processing disclosure choice, and resets the device's analytics identifier.

Remote data is deleted before authentication so that a failure leaves the account available for a retry. The app reports success only after the remote operation completes. Contact support if you see an error or believe data remains.

Deletion does not control information Apple, Google or another independent provider must keep under its own responsibilities. Limited information may also remain where required by law, needed for a legal claim, or held temporarily in an isolated backup or provider system until routine expiry. Database backups expire automatically within 14 weeks, and crash and error reports within 90 days.

14. Your app controls

Firebase Analytics is off by default and starts only if you turn on “Share usage analytics”. You can turn it off again to stop future collection. The separate “Share inputs to improve results” setting is also off by default and is not required to use BrandFounder.

“Share crash reports” is also off by default. If you turn it on, crash and error reports help us find and fix crashes and failed purchases or generations. You can turn it off again in Settings at any time.

Turning off AI processing prevents new AI requests until you allow it again. It does not automatically delete projects or outputs already stored; use the in-app deletion controls where you want those removed.

15. Security

We use reasonable technical and organisational measures designed to protect information, including authenticated access controls, encrypted network transmission, Firebase App Check and integrity controls where configured, server-side secret handling, rate limiting, regular database backups with point-in-time recovery, and managed cloud infrastructure.

No online service can guarantee absolute security. Please keep your sign-in method secure and contact us if you suspect unauthorised account access.

16. Children

BrandFounder is not directed at children. We do not knowingly collect a child’s personal data where parental consent would be required. If you believe a child has provided information inappropriately, contact us so we can review it.

17. Third-party links

The app and website may link to Apple, the ICO and other third-party services. A third party controls its own site, terms and privacy practices. Review the relevant notice before providing information directly to that service.

18. Changes to this Policy

We may update this Policy when the product, providers or legal requirements change. We will update the date above and provide appropriate notice where a change materially affects how personal data is used. We will request a new choice where the law requires it.

19. Contact

BrandFounder
4th Floor, Silverstream House, 45 Fitzroy Street, London W1T 6EB, United Kingdom
Email: support@brandfounder.ai

You can also read the BrandFounder Terms of Use.

Back to BrandFounder home
BrandFounder

Turn your idea into a brand you can actually launch.

Download on the App Store
support@brandfounder.ai

© 2026 BrandFounder

PrivacyTermsHome