Privacy Policy

Last updated: 14 September 2026. Plain English, because that’s the whole product philosophy.

The short version

Your brand content lives in your browser, not on our servers. The free audit keeps nothing you type. The on-device headshot treatments never upload your photo. AI portraits are opt-in: only if you choose to generate them are your selfies sent to our image provider (Google) to create your portraits — they aren’t stored afterwards. Text and images you submit aren’t used to train anything. We run no advertising trackers — only cookieless page counts that tell us which pages are visited, never who visited them.

Two things are kept, and both are your choice. If you become a member, we keep a small record so your access works (your email and your access code). If you ask for a bio page, we keep what that page is built from — you’ll be asked to accept this before anything is saved, and you can delete it at any time.

1. What we collect and why

Content you type — your role, goals, headline, About text, and posts you paste — is sent to our servers only at the moment you request a generation or audit, solely to produce your output. Unless you ask for a bio page (section 2), we do not store this content in a database; it passes through and comes back as your result.

The free audit may ask for the name you’d like your bio page to use. Answering is optional, and the audit works the same either way. Giving a name does not mean we keep it: like the rest of the audit, it is used for that one result and discarded — unless you then choose a bio page and accept that it will be kept.

Your photo — the headshot treatments run entirely on your device using browser image effects; those photos are never uploaded. AI portraits are opt-in and different: if you choose to generate them, the selfies you upload are sent to our image provider (Google) purely to produce your portrait options, and you tick a consent box before this happens. We don’t store your selfies or the generated portraits on our servers — they’re processed in the moment and returned to your browser.

Locally stored data — your strategy, generated assets, audit score history, and access code are saved in your browser’s local storage so your work survives reloads. This data sits on your device; we cannot see it. Clearing your browser storage deletes it.

Membership and payments — payments are handled by Stripe (your checkout and bank statement may show Link, Stripe’s payment service). We never see or store your card details. When you join, we keep a membership record: the email address you paid with, your access code, your plan, its status, and the Stripe customer and subscription references needed to keep your access in step with your subscription. We use your email to send your access code and messages about your membership, and to answer you when you contact us. Those emails are sent through our email provider, Resend.

Technical basics — our hosting provider (Vercel) processes IP addresses and standard request logs to serve and secure the site, and we use IP addresses and access codes transiently to rate-limit the audit and the app. We do not run advertising or cross-site tracking cookies.

Aggregate page analytics — we use Vercel Web Analytics to count page views and see which pages people visit, so we know whether the product is useful. It is cookieless: it sets no cookies, assigns you no persistent identifier, and cannot follow you to other websites. We see counts and trends, never individuals, and it is never joined to anything you type into the app. Separately, when you complete an audit we count it along with the campaign link you arrived from (if any) and a broad score band — never your IP, your words, or anything that tells one person from another.

2. Bio pages — opt-in, and kept because you asked

A bio page is a public page about you at brandstudio.tech/yourname, built to be read by people and by AI assistants. It is being rolled out to founding members first; until it opens to you, nothing described in this section is collected.

A bio page only works if we keep your details, so asking for one means agreeing to that. Before anything is saved you’ll be asked, in a separate step, to accept it. That box is never ticked for you, and running an audit or typing a name is not agreement. We record when you accepted.

What we keep once you accept: the name you chose for your page, the headline and About text you had audited, the audit result, and the email address you use to claim the page. Later, whatever you add or confirm for the page itself.

How it’s used: only to build, show and update your bio page and the positioning in your account. You review it before it is used — nothing from your audit goes onto your page until you confirm it. It is never used to train AI models, never combined with other members’ data, and never sold or shared for marketing.

Public means public. Your bio page is private until you publish it. Once published, what’s on it can be seen, and indexed, by anyone — including search engines and AI assistants. You can unpublish it at any time. We cannot recall copies that others have already made.

If you don’t finish: if you start claiming a page but never confirm your email, what you gave us is deleted after a short period. It is not kept “just in case”.

Deleting it: you can delete your bio page and the details behind it at any time. Delete means deleted, not hidden.

3. AI processing

Text generations and audits are produced by Anthropic’s Claude API. AI portraits are produced by Google’s Gemini API. Content you submit is processed by the relevant provider to return your result, subject to that provider’s commercial API terms, under which API inputs and outputs are not used to train their models. We recommend not submitting sensitive personal information (health, financial details, government identifiers) — a branding tool doesn’t need it.

4. What we don’t do

We don’t sell or share your information for marketing. We don’t access your LinkedIn account — the Service has no connection to LinkedIn; you copy and paste content yourself. We don’t build advertising profiles. We don’t store the content you generate in the app on our servers. The only content we keep is what you ask us to keep for a bio page.

5. Data retention

Content in the app and the audit: not kept beyond transient processing and standard infrastructure logs held by our providers for security purposes. Data on your device is under your control at all times.

Membership records: kept while your membership exists, and afterwards for as long as we need them to handle refunds, disputes and our tax and accounting obligations. Stripe keeps its own payment records under its own policy.

Bio page data: kept until you delete it. Unfinished claims are deleted after a short period, as described in section 2.

6. Overseas disclosure

Our providers — Vercel (hosting), Anthropic (text), Google (AI portraits), Stripe (payments), Resend (email), Upstash (membership records), and Neon (bio page data) — process data in the United States, Australia and other regions where they operate. By using the Service you acknowledge this processing.

7. Your rights

Under the Australian Privacy Act you may request access to or correction of personal information we hold. For most visitors that is nothing beyond transient logs. For members it is your membership record and, if you asked for one, your bio page data. Ask and we’ll show you exactly what exists, and correct or delete it. Complaints can also be directed to the Office of the Australian Information Commissioner (oaic.gov.au).

8. Children

The Service is intended for professionals and is not directed at anyone under 18.

9. Changes

If our data practices change, this policy is updated first — before the change reaches the product — with the changes explained in plain language and a new “last updated” date.

10. Contact

Vestry Technology Pty Ltd (ABN 15699575034) · support@brandstudio.tech

Terms of Service · Home