BrandKnown — Privacy Policy

Last updated: 1 September 2026 Effective date: 1 September 2026

This Privacy Policy explains what personal data BrandKnown ("BrandKnown", "we", "us") collects when you use the BrandKnown website and service at brandknown.help (the "Service"), why we collect it, who we share it with, how long we keep it, and the rights you have over it.

We are the controller of the personal data described here. Our contact point for privacy matters is privacy@brandknown.help.


1. Summary

  • Anonymous scans are not stored on our servers. The result lives in your browser for that session and is gone when you clear it.
  • Signed-in scans are stored so you can compare runs over time, protected by database-level row-level security that restricts every row to its owner. Other customers cannot read your scans.
  • We do not sell personal data, and we do not share it for cross-context behavioural advertising.
  • We do not train AI models on your data. Where a model is used at all, it is to draft copy from text already public on the site you submitted, and that text is passed as data, truncated, and never used as training material by us.
  • We do not receive your card number. Stripe handles payments.
  • Scanning fetches public pages of the site you submit. That is the only thing our crawler touches.

2. Data we collect

2.1 Data you give us

DataWhenWhy
Email address, password (hashed by our auth provider) or SSO identifierRegistrationCreate and secure your account
Display name, if supplied by an SSO providerRegistration via GooglePersonalise the account
Brand name, domain, website URL, aliases, industryWhen you save a brandRun and organise scans
URLs you submit for scanning, including competitor URLsEach scanPerform the scan you requested
HTML and robots.txt you paste into the manual fallbackWhen automated fetching failsRun the scan on content you provide
Support correspondenceWhen you contact usAnswer you and keep a record

2.2 Data generated by your use

DataNotes
Scan results — health score, findings, extracted page data, generated artifactsStored only for signed-in users who save a brand
Usage events — one record per scan, per AI draft, per tool run, with a timestampEnforces plan quotas and per-user daily caps
Subscription record — plan, status, current period, Stripe customer and subscription identifiersBilling and entitlements
Rate-limiting state — a truncated request key derived from your IP address, held in server memoryAbuse prevention; not written to our database and lost on instance restart
Server and platform logs — IP address, user agent, timestamp, path, status codeSecurity, debugging, and fraud prevention; retained by our hosting provider

2.3 Data from third parties

  • Your identity provider (for example Google, if you use SSO): your email address, name, and provider account identifier.
  • Stripe: payment status, subscription lifecycle events, the last four digits and brand of your card, and billing country. We never receive your full card number, CVC, or bank credentials.

2.4 Data about websites you scan

When you submit a URL, we retrieve a small number of publicly accessible resources from that site — typically the homepage, /robots.txt, /llms.txt, and an About page — and parse them. Retrieved content is capped in size and truncated.

That content is normally organisational rather than personal, but a public homepage or About page can contain personal data such as staff names, photographs, professional biographies, and business contact details. Where it does, we process it as a processor or joint controller acting on your instruction for the purpose of producing your report. You are responsible for having a lawful basis to submit that URL (see Section 3 of the Terms of Service).

If you believe a scan stored on this Service contains your personal data and you are not the account holder, contact privacy@brandknown.help and we will locate it and act on your request.

3. Why we process your data, and our legal bases

For users in the EEA and UK, we rely on the following Article 6 GDPR bases:

PurposeLegal basis
Providing the Service, running scans, storing your brands and historyPerformance of a contract (Art. 6(1)(b))
Creating and authenticating your accountPerformance of a contract
Taking payment, handling renewals and refundsPerformance of a contract; legal obligation for tax and accounting records (Art. 6(1)(c))
Rate limiting, quota enforcement, abuse and fraud prevention, security loggingLegitimate interests in protecting the Service and third-party servers (Art. 6(1)(f))
Service emails — receipts, security notices, material changes to termsPerformance of a contract; legal obligation
Product improvement using aggregated and de-identified statisticsLegitimate interests
Marketing email, if we send anyConsent (Art. 6(1)(a)), withdrawable at any time
Responding to legal requests, establishing or defending legal claimsLegal obligation; legitimate interests

Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights; you may object as described in Section 8, and you may request our balancing assessment.

4. AI processing

4.1 On plans that include them, we send text already retrieved from the public site you submitted to a third-party AI provider to draft a brand description or an llms.txt summary. The text is truncated before it is sent, and it is passed to the model as data, never as instructions.

4.2 The AI visibility checker sends a question about your brand or category — not your account data — to one or more AI assistants and records what comes back. On plans with live-web checks, the assistant may itself browse the public web to answer.

4.3 The providers we may use, depending on which are configured for the deployment, are OpenAI, Anthropic, Perplexity, and Google. We rely on their API terms, under which submitted content is not used to train their models by default.

4.4 We do not use your data, your scans, or the sites you submit to train our own or anyone else's models.

4.5 There is no automated decision-making producing legal or similarly significant effects about you under Article 22 GDPR. Scores and AI reports are informational and involve no profiling of individuals.

5. Cookies and similar technologies

Most of what we set is strictly necessary. Google Analytics is not, and is listed as such:

Name / kindPurposeStrictly necessaryDuration
Supabase authentication cookiesKeep you signed in; CSRF protectionYesSession and refresh token lifetime
Cloudflare TurnstileAnti-bot check on the sign-in formYesPer challenge
Theme preferenceRemember light/dark selectionYesPersistent, local
Anonymous scan result (localStorage)Show your one free scan without an accountYesUntil you clear browser storage
Free-scan counter (localStorage)Enforce the anonymous free-scan limitYesUntil you clear browser storage
Design assignment (bk_design_v1)Keep the same design during a website experiment; does not identify your accountNo90 days
Experiment conversion markers (browser storage)Avoid counting the same sign-in or recent signup repeatedly; disabled with analytics opt-outNoSession for sign-ins; until browser storage is cleared for signup markers
Google Analytics (_ga, _ga_*)Count visits and see which pages are readNoUp to 2 years

We do not use advertising cookies or cross-site advertising pixels, and we do not sell or share personal information for cross-context behavioural advertising.

Turning analytics off. Analytics are on by default and you can switch them off at any time. Use the control in the cookie notice at the bottom of any page, or send a Global Privacy Control signal from your browser — we honour GPC automatically, without your having to find the button. Either one stops collection at source: it sets the flag Google Analytics itself reads, rather than merely hiding the result from you.

6. Who we share data with

We do not sell personal data. We disclose it only to the following categories of recipients, each of which is bound by contract to protect it:

RecipientRoleDataLocation
Vercel Inc.Hosting, edge network, function execution, logsRequest data, IP addresses, application logsUSA / global edge
Supabase Inc.Authentication, Postgres database, storageAccount, brands, scans, usage, subscription recordsWest US (Oregon)
Stripe, Inc.Payment processing and subscription managementName, email, billing details, payment method metadataUSA / EU
OpenAI, Anthropic, Perplexity, Google (as configured)AI drafting and visibility checksTruncated public page text; category and brand questionsUSA
Supabase Inc.Transactional emailEmail address, message contentUSA
Google LLC (Google Analytics)Visit measurementIP address (truncated by Google), page URLs, device and browser typeUSA
Professional advisers, auditorsLegal and accountingAs necessaryUSA

We may also disclose data where required by law, to enforce our Terms, to protect the rights and safety of users or the public, or in connection with a merger, acquisition, or asset sale — in which case we will notify you before your data becomes subject to a different privacy policy.

Sub-processor changes. The table above is the current list, published on this page at brandknown.help/privacy, and we will give notice of additions before they begin processing.

7. International transfers

We are established in the United States. Some recipients above are in the United States or elsewhere outside the EEA and UK. Where we transfer personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, on an applicable adequacy decision, or on the EU-US Data Privacy Framework where the recipient is certified. Copies of the relevant safeguards are available on request to privacy@brandknown.help.

8. Retention

DataRetention
Anonymous scan resultsNever stored on our servers
Saved scans and historyFor as long as your plan's history window allows — approximately 30 days on the mid tier and 12 months on the top tier — and in any event no longer than 30 days after you delete the brand or close your account
Account and profile recordLife of the account, then deleted within 30 days of account closure
Usage and quota events13 months, then deleted or aggregated
Subscription and billing recordsLife of the account plus the period required by tax and accounting law in the United States, typically 6–10 years
Server and security logsPer our hosting provider's retention, typically up to 30 days
Support correspondence24 months from last contact
BackupsOverwritten on a rolling cycle, typically within 30 days

Deletion from live systems is immediate on request; residual copies in backups are erased on the normal backup cycle, during which they are not used for any other purpose.

9. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify inaccurate or incomplete data;
  • erase your data ("right to be forgotten");
  • restrict or object to processing, including processing based on legitimate interests and any direct marketing;
  • port data you gave us to another controller in a machine-readable format;
  • withdraw consent at any time, without affecting processing already carried out;
  • not be discriminated against for exercising these rights.

How to exercise them. Most data is available directly in the product: you can edit your profile, delete a saved brand and its scans, and delete your account from account settings. For anything else, email privacy@brandknown.help. We will respond within 30 days (or 45 days for CCPA requests, extendable once with notice). We may ask you to verify your identity, and we will not charge a fee unless a request is manifestly unfounded or excessive.

Complaints. EEA and UK residents may complain to a supervisory authority — in the UK, the Information Commissioner's Office; in the EEA, your local data protection authority. We would appreciate the chance to address it first.

9.1 California residents

Under the CCPA/CPRA, in the past 12 months we have collected the categories of personal information described in Section 2: identifiers, commercial information, internet activity information, and inferences limited to the scan report itself. We collect it for the business purposes in Section 3 and disclose it to the service providers in Section 6.

We have not sold personal information and have not shared it for cross-context behavioural advertising, including for consumers we know to be under 16. You have the rights to know, delete, correct, and opt out (there is nothing to opt out of), and to limit use of sensitive personal information — we do not collect sensitive personal information as defined by the CPRA. You may use an authorised agent; we will require proof of authorisation.

9.2 Other US state laws

Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other states with comprehensive privacy laws have broadly equivalent rights of access, correction, deletion, portability, and opt-out, plus a right to appeal a refused request. To appeal, reply to our decision at privacy@brandknown.help with "Appeal" in the subject line; we will respond within 45 days and, if we deny the appeal, tell you how to contact your state Attorney General.

10. Security

Measures we apply include: TLS in transit and encryption at rest through our providers; Postgres row-level security enforcing owner-only access at the database layer rather than in application code; password hashing handled by our authentication provider; service-role credentials held server-side only and never exposed to the browser; signed and idempotency-checked payment webhooks; SSRF protections on the fetcher that re-validate every resolved address at connect time and on each redirect, blocking private, loopback, and link-local ranges; per-IP rate limits, concurrency caps, and per-user daily caps; and size, redirect, and timeout limits on every outbound fetch.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours where required and notify you without undue delay where the breach is likely to result in a high risk to your rights.

11. Children

The Service is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact privacy@brandknown.help and we will delete it.

12. Changes to this policy

We will post any revised policy here with a new "Last updated" date. For material changes — a new purpose, a new category of recipient, or a substantially longer retention period — we will give at least 30 days' notice by email or in-product notice before the change takes effect, and where the law requires it we will ask for your consent.

13. Contact

BrandKnown P.O. Box 537, Denver, CO 80132 Privacy: privacy@brandknown.help · Security: security@brandknown.help · General: support@brandknown.help