BrandKnown — Privacy Policy
Last updated: 1 September 2026 Effective date: 1 September 2026
This Privacy Policy explains what personal data BrandKnown ("BrandKnown", "we", "us") collects when you use the BrandKnown website and service at brandknown.help (the "Service"), why we collect it, who we share it with, how long we keep it, and the rights you have over it.
We are the controller of the personal data described here. Our contact point for privacy matters is privacy@brandknown.help.
1. Summary
- Anonymous scans are not stored on our servers. The result lives in your browser for that session and is gone when you clear it.
- Signed-in scans are stored so you can compare runs over time, protected by database-level row-level security that restricts every row to its owner. Other customers cannot read your scans.
- We do not sell personal data, and we do not share it for cross-context behavioural advertising.
- We do not train AI models on your data. Where a model is used at all, it is to draft copy from text already public on the site you submitted, and that text is passed as data, truncated, and never used as training material by us.
- We do not receive your card number. Stripe handles payments.
- Scanning fetches public pages of the site you submit. That is the only thing our crawler touches.
2. Data we collect
2.1 Data you give us
| Data | When | Why |
|---|---|---|
| Email address, password (hashed by our auth provider) or SSO identifier | Registration | Create and secure your account |
| Display name, if supplied by an SSO provider | Registration via Google | Personalise the account |
| Brand name, domain, website URL, aliases, industry | When you save a brand | Run and organise scans |
| URLs you submit for scanning, including competitor URLs | Each scan | Perform the scan you requested |
HTML and robots.txt you paste into the manual fallback | When automated fetching fails | Run the scan on content you provide |
| Support correspondence | When you contact us | Answer you and keep a record |
2.2 Data generated by your use
| Data | Notes |
|---|---|
| Scan results — health score, findings, extracted page data, generated artifacts | Stored only for signed-in users who save a brand |
| Usage events — one record per scan, per AI draft, per tool run, with a timestamp | Enforces plan quotas and per-user daily caps |
| Subscription record — plan, status, current period, Stripe customer and subscription identifiers | Billing and entitlements |
| Rate-limiting state — a truncated request key derived from your IP address, held in server memory | Abuse prevention; not written to our database and lost on instance restart |
| Server and platform logs — IP address, user agent, timestamp, path, status code | Security, debugging, and fraud prevention; retained by our hosting provider |
2.3 Data from third parties
- Your identity provider (for example Google, if you use SSO): your email address, name, and provider account identifier.
- Stripe: payment status, subscription lifecycle events, the last four digits and brand of your card, and billing country. We never receive your full card number, CVC, or bank credentials.
2.4 Data about websites you scan
When you submit a URL, we retrieve a small number of publicly accessible resources from
that site — typically the homepage, /robots.txt, /llms.txt, and an About page — and
parse them. Retrieved content is capped in size and truncated.
That content is normally organisational rather than personal, but a public homepage or About page can contain personal data such as staff names, photographs, professional biographies, and business contact details. Where it does, we process it as a processor or joint controller acting on your instruction for the purpose of producing your report. You are responsible for having a lawful basis to submit that URL (see Section 3 of the Terms of Service).
If you believe a scan stored on this Service contains your personal data and you are not the account holder, contact privacy@brandknown.help and we will locate it and act on your request.
3. Why we process your data, and our legal bases
For users in the EEA and UK, we rely on the following Article 6 GDPR bases:
| Purpose | Legal basis |
|---|---|
| Providing the Service, running scans, storing your brands and history | Performance of a contract (Art. 6(1)(b)) |
| Creating and authenticating your account | Performance of a contract |
| Taking payment, handling renewals and refunds | Performance of a contract; legal obligation for tax and accounting records (Art. 6(1)(c)) |
| Rate limiting, quota enforcement, abuse and fraud prevention, security logging | Legitimate interests in protecting the Service and third-party servers (Art. 6(1)(f)) |
| Service emails — receipts, security notices, material changes to terms | Performance of a contract; legal obligation |
| Product improvement using aggregated and de-identified statistics | Legitimate interests |
| Marketing email, if we send any | Consent (Art. 6(1)(a)), withdrawable at any time |
| Responding to legal requests, establishing or defending legal claims | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights; you may object as described in Section 8, and you may request our balancing assessment.
4. AI processing
4.1 On plans that include them, we send text already retrieved from the public site you
submitted to a third-party AI provider to draft a brand description or an llms.txt
summary. The text is truncated before it is sent, and it is passed to the model as data,
never as instructions.
4.2 The AI visibility checker sends a question about your brand or category — not your account data — to one or more AI assistants and records what comes back. On plans with live-web checks, the assistant may itself browse the public web to answer.
4.3 The providers we may use, depending on which are configured for the deployment, are OpenAI, Anthropic, Perplexity, and Google. We rely on their API terms, under which submitted content is not used to train their models by default.
4.4 We do not use your data, your scans, or the sites you submit to train our own or anyone else's models.
4.5 There is no automated decision-making producing legal or similarly significant effects about you under Article 22 GDPR. Scores and AI reports are informational and involve no profiling of individuals.
5. Cookies and similar technologies
Most of what we set is strictly necessary. Google Analytics is not, and is listed as such:
| Name / kind | Purpose | Strictly necessary | Duration |
|---|---|---|---|
| Supabase authentication cookies | Keep you signed in; CSRF protection | Yes | Session and refresh token lifetime |
| Cloudflare Turnstile | Anti-bot check on the sign-in form | Yes | Per challenge |
| Theme preference | Remember light/dark selection | Yes | Persistent, local |
Anonymous scan result (localStorage) | Show your one free scan without an account | Yes | Until you clear browser storage |
Free-scan counter (localStorage) | Enforce the anonymous free-scan limit | Yes | Until you clear browser storage |
Design assignment (bk_design_v1) | Keep the same design during a website experiment; does not identify your account | No | 90 days |
| Experiment conversion markers (browser storage) | Avoid counting the same sign-in or recent signup repeatedly; disabled with analytics opt-out | No | Session for sign-ins; until browser storage is cleared for signup markers |
Google Analytics (_ga, _ga_*) | Count visits and see which pages are read | No | Up to 2 years |
We do not use advertising cookies or cross-site advertising pixels, and we do not sell or share personal information for cross-context behavioural advertising.
Turning analytics off. Analytics are on by default and you can switch them off at any time. Use the control in the cookie notice at the bottom of any page, or send a Global Privacy Control signal from your browser — we honour GPC automatically, without your having to find the button. Either one stops collection at source: it sets the flag Google Analytics itself reads, rather than merely hiding the result from you.
6. Who we share data with
We do not sell personal data. We disclose it only to the following categories of recipients, each of which is bound by contract to protect it:
| Recipient | Role | Data | Location |
|---|---|---|---|
| Vercel Inc. | Hosting, edge network, function execution, logs | Request data, IP addresses, application logs | USA / global edge |
| Supabase Inc. | Authentication, Postgres database, storage | Account, brands, scans, usage, subscription records | West US (Oregon) |
| Stripe, Inc. | Payment processing and subscription management | Name, email, billing details, payment method metadata | USA / EU |
| OpenAI, Anthropic, Perplexity, Google (as configured) | AI drafting and visibility checks | Truncated public page text; category and brand questions | USA |
| Supabase Inc. | Transactional email | Email address, message content | USA |
| Google LLC (Google Analytics) | Visit measurement | IP address (truncated by Google), page URLs, device and browser type | USA |
| Professional advisers, auditors | Legal and accounting | As necessary | USA |
We may also disclose data where required by law, to enforce our Terms, to protect the rights and safety of users or the public, or in connection with a merger, acquisition, or asset sale — in which case we will notify you before your data becomes subject to a different privacy policy.
Sub-processor changes. The table above is the current list, published on this page at brandknown.help/privacy, and we will give notice of additions before they begin processing.
7. International transfers
We are established in the United States. Some recipients above are in the United States or elsewhere outside the EEA and UK. Where we transfer personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, on an applicable adequacy decision, or on the EU-US Data Privacy Framework where the recipient is certified. Copies of the relevant safeguards are available on request to privacy@brandknown.help.
8. Retention
| Data | Retention |
|---|---|
| Anonymous scan results | Never stored on our servers |
| Saved scans and history | For as long as your plan's history window allows — approximately 30 days on the mid tier and 12 months on the top tier — and in any event no longer than 30 days after you delete the brand or close your account |
| Account and profile record | Life of the account, then deleted within 30 days of account closure |
| Usage and quota events | 13 months, then deleted or aggregated |
| Subscription and billing records | Life of the account plus the period required by tax and accounting law in the United States, typically 6–10 years |
| Server and security logs | Per our hosting provider's retention, typically up to 30 days |
| Support correspondence | 24 months from last contact |
| Backups | Overwritten on a rolling cycle, typically within 30 days |
Deletion from live systems is immediate on request; residual copies in backups are erased on the normal backup cycle, during which they are not used for any other purpose.
9. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten");
- restrict or object to processing, including processing based on legitimate interests and any direct marketing;
- port data you gave us to another controller in a machine-readable format;
- withdraw consent at any time, without affecting processing already carried out;
- not be discriminated against for exercising these rights.
How to exercise them. Most data is available directly in the product: you can edit your profile, delete a saved brand and its scans, and delete your account from account settings. For anything else, email privacy@brandknown.help. We will respond within 30 days (or 45 days for CCPA requests, extendable once with notice). We may ask you to verify your identity, and we will not charge a fee unless a request is manifestly unfounded or excessive.
Complaints. EEA and UK residents may complain to a supervisory authority — in the UK, the Information Commissioner's Office; in the EEA, your local data protection authority. We would appreciate the chance to address it first.
9.1 California residents
Under the CCPA/CPRA, in the past 12 months we have collected the categories of personal information described in Section 2: identifiers, commercial information, internet activity information, and inferences limited to the scan report itself. We collect it for the business purposes in Section 3 and disclose it to the service providers in Section 6.
We have not sold personal information and have not shared it for cross-context behavioural advertising, including for consumers we know to be under 16. You have the rights to know, delete, correct, and opt out (there is nothing to opt out of), and to limit use of sensitive personal information — we do not collect sensitive personal information as defined by the CPRA. You may use an authorised agent; we will require proof of authorisation.
9.2 Other US state laws
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other states with comprehensive privacy laws have broadly equivalent rights of access, correction, deletion, portability, and opt-out, plus a right to appeal a refused request. To appeal, reply to our decision at privacy@brandknown.help with "Appeal" in the subject line; we will respond within 45 days and, if we deny the appeal, tell you how to contact your state Attorney General.
10. Security
Measures we apply include: TLS in transit and encryption at rest through our providers; Postgres row-level security enforcing owner-only access at the database layer rather than in application code; password hashing handled by our authentication provider; service-role credentials held server-side only and never exposed to the browser; signed and idempotency-checked payment webhooks; SSRF protections on the fetcher that re-validate every resolved address at connect time and on each redirect, blocking private, loopback, and link-local ranges; per-IP rate limits, concurrency caps, and per-user daily caps; and size, redirect, and timeout limits on every outbound fetch.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours where required and notify you without undue delay where the breach is likely to result in a high risk to your rights.
11. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact privacy@brandknown.help and we will delete it.
12. Changes to this policy
We will post any revised policy here with a new "Last updated" date. For material changes — a new purpose, a new category of recipient, or a substantially longer retention period — we will give at least 30 days' notice by email or in-product notice before the change takes effect, and where the law requires it we will ask for your consent.
13. Contact
BrandKnown P.O. Box 537, Denver, CO 80132 Privacy: privacy@brandknown.help · Security: security@brandknown.help · General: support@brandknown.help
