Privacy Policy
Last updated: 22 June 2026
BrandHum turns your product photos into store-ready copy and ad images. This policy explains what we collect, why, who we share it with, and the choices you have. We keep it short and plain on purpose.
1. Who we are
BrandHum (“BrandHum”, “we”, “us”) provides the service available at this site and at the studio. For any privacy question, or to exercise your rights, email hello@brandhum.io. We are the data controller for the personal data described below.
2. What we collect
- Account data - your email address and the one-time login codes used to sign you in. We do not store passwords.
- Content you submit - product photos you upload, any details, notes, or homepage URLs you provide, and the brand voices you save.
- Generated output - the copy and images we produce for you, kept in your history so you can return to them.
- Usage and billing data - credit balance, generations made, and records of credit purchases.
- Technical data - IP address, browser type, and basic event logs used to keep the service running and secure.
3. How we use it
- To sign you in and run the generations you ask for.
- To keep your history, credit balance, and saved voices available to you.
- To process credit purchases and prevent abuse or fraud.
- To operate, debug, and improve the service.
Our legal bases (where the EU GDPR applies) are performance of a contract (running the service you signed up for), legitimate interest (security, abuse prevention, improving the product), and consent where required.
4. AI processing of your content
To generate copy and images, the content you submit (photos, details, voice inputs) is sent to AI model providers acting as our processors. We instruct these providers to process your content only to return a result to you, and not to train their models on it. We do not sell your content, and we do not use it to train models of our own.
5. Who we share data with
We share data only with service providers who help us run BrandHum:
- Anthropic - generating product copy.
- Google (Gemini) - generating ad images.
- OpenAI - used as an alternative copy provider in some configurations.
- Resend - sending login codes by email.
- Langfuse - diagnostic tracing of generations to debug and improve quality.
- Umami - privacy-friendly, cookieless traffic analytics (aggregate only; does not identify you).
- Meta (Facebook) - advertising measurement, only if you accept marketing cookies. We share event data plus a hashed version of your email and your IP address so Meta can measure how our ads perform.
- Our hosting provider - storing the database and generated media.
Some of these providers operate outside the EU/EEA. Where that happens, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses. We may also disclose data where required by law.
6. Cookies
We use a small number of strictly necessary cookies: a session cookie to keep you signed in, and a locale cookie to remember your language. These need no consent.
For traffic analytics we use Umami, which is cookieless and does not identify you. If you accept marketing cookies in our banner, we also load the Meta pixel, which sets advertising cookies to measure how our ads perform. These load only after you accept, and you can decline. You can change your choice at any time by clearing the consent cookie in your browser.
7. How long we keep it
We keep your account data, content, and generated output for as long as your account is active. If you ask us to delete your account, we remove your personal data and content within 30 days, except where we must keep limited records (for example, purchase records) to meet legal or accounting obligations.
8. Your rights
If you are in the EU/EEA or UK, you can request access to your data, correction, deletion, a portable copy, or restriction of processing, and you can object to processing based on legitimate interest. To exercise any of these, email hello@brandhum.io. You also have the right to complain to your local data protection authority.
9. Security
We use industry-standard measures to protect your data, including encrypted connections and access controls. No system is perfectly secure, but we work to keep your data safe and to notify you of any breach that affects you, as required by law.
10. Children
BrandHum is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.
11. Changes
We may update this policy from time to time. We will revise the date above and, for significant changes, let you know in the app or by email.
12. Contact
Questions about this policy or your data? Email hello@brandhum.io.