1. Information we collect
We collect the following categories of information:
- Account information — name, email address, password (stored hashed), country selected at signup, email verification status, and authentication identifiers where you sign in with a third-party provider such as Google.
- Business information — business name, industry, location, brand voice, target audience, services, contact details and similar information you enter during onboarding or when managing businesses in the app.
- Brand assets and uploads — logos, brand colours and images you upload, including images used for Image-to-Post generation. These are stored in our hosted file storage so they can be applied to your content.
- Generated content — captions, post plans, Premium Posts, Premium Stories, images and other outputs created under your account, together with the settings used to produce them.
- Credit and billing records — your Free and Premium Credit balances, credit charges, restorations and ledger history, purchase records, invoices and Stripe customer/payment identifiers.
- Social connection information — where you choose to connect Meta accounts: connected Facebook Page details, Instagram Professional account details, account names and IDs, the Meta user identifier associated with the authorisation, the permissions granted, and the OAuth access tokens themselves (stored encrypted).
- Publishing information — content you queue for publishing, scheduled publish times, publishing status, platform post identifiers and any errors returned by the platform.
- Usage and product analytics — pages and features used, generation activity, funnel events, device and browser information, IP address and approximate location derived from it, and referral/attribution data about how you found us.
- Cookies and similar technologies — see our Cookie Policy.
- Support and feedback — messages you send us by email or through in-app feedback.
2. How and why we use it
- To create and secure your account, verify your email address and authenticate you.
- To generate the content you request, using the business information and assets you provide as context.
- To operate Premium Credits: charging credits for Premium work, granting included redesigns and automatically restoring credits when a generation fails.
- To process credit pack purchases and issue receipts and invoices.
- To list the Facebook Pages and Instagram Professional accounts you manage and to publish or schedule content at your request.
- To send transactional emails (verification, billing, security, publishing and product notices).
- To send product updates and marketing emails where permitted, always with an unsubscribe link.
- To measure and improve the product, detect abuse and fraud, and diagnose errors.
- To comply with legal obligations and respond to lawful requests.
3. Legal bases (UK GDPR)
- Performance of a contract — to provide the Service, process purchases and publish content you request.
- Legitimate interests — to secure, measure, support and improve the Service and prevent abuse.
- Consent — for non-essential cookies and analytics where required, and for direct marketing where required.
- Legal obligation — to comply with tax, accounting and law-enforcement requirements.
4. Service providers and processors
We share data only with providers who help us run the Service. Our current categories and providers are:
- Hosting, database and file storage — our cloud infrastructure provider hosts the application, database and uploaded assets.
- Stripe — payment processing for Premium Credit packs. Stripe collects your card details directly; we receive only limited metadata such as card brand, last four digits, payment status and invoice history. We never see or store your full card number or security code.
- AI model providers — the business context and prompts needed to produce your requested content are sent to our AI providers on a per-request basis.
- Meta (Facebook / Instagram) APIs — where you connect a social account, we exchange data with Meta to list your eligible accounts and publish the content you request.
- Email delivery — our email provider sends transactional and product emails and records delivery, open and click events.
- Analytics — Google Analytics 4, Microsoft Clarity, the Meta Pixel and the TikTok Pixel on our public website, plus our own in-house product analytics inside the app. See the Cookie Policy for details.
We do not sell your personal data. We do not use your private business information to train third-party AI models.
5. Facebook and Instagram connections, and Meta data deletion
Connecting a social account is optional. Connections are authorised through Meta's official OAuth flow — BrandZilla never asks for or receives your Facebook or Instagram password. We request only the permissions needed to identify the Pages and Instagram Professional accounts you manage and to publish or schedule the content you ask us to publish.
- Access tokens are encrypted before being stored and are used only to perform actions you initiate. Tokens are never sent to your browser and are never written to our logs.
- We store basic account identifiers and names so you can choose a destination, plus publishing status and platform post IDs so you can see what happened.
- We keep limited technical diagnostics about the connection process (such as step names, success or failure status, error messages and account identifiers) to troubleshoot failed connections. These diagnostics are automatically deleted after 30 days, are deleted when you remove your last Facebook or Instagram connection, and are deleted with your account.
- You can disconnect any account at any time from Social Accounts in the app. When you disconnect, we ask Meta to revoke the authorisation, delete the stored token and connection record, and cancel pending scheduled publishes for that destination. If Meta's revocation endpoint is temporarily unavailable, the local token and connection record are still deleted and you can also remove BrandZilla from your Facebook settings.
- If you remove BrandZilla from your Facebook settings, Meta notifies our deauthorization callback and we revoke the corresponding connections automatically.
- You can request deletion of the Meta data we hold either through Facebook's app removal / data deletion flow, which calls our data deletion endpoint and returns a confirmation code and status page, or by emailing us.
- When a Meta data deletion request completes, we retain a small confirmation record (a confirmation code, the request status, the date and the number of connections removed) so that the deletion can be verified. This record does not contain tokens or the content of your Meta accounts.
To request deletion of Meta-related data directly, email support@brandzilla.ai with the subject "Meta data deletion". We will remove the stored connection records and tokens for your account and confirm once complete.
6. Data retention
We retain account, business, asset and generated-content data while your account remains active and for a reasonable period afterwards to support reactivation, legal obligations and dispute resolution. Credit ledger and billing records are retained for up to seven (7) years for tax and accounting purposes. Social connection tokens are deleted or invalidated when you disconnect an account, when Meta notifies us of deauthorization, or on a data deletion request. Connection diagnostics are retained for a maximum of 30 days. A minimal deletion-confirmation record is retained after a Meta data deletion request as evidence that the request was fulfilled.
7. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your account and associated personal data.
- Restrict or object to certain processing.
- Withdraw consent at any time (where processing is based on consent).
- Data portability — request your data in a machine-readable format.
- Lodge a complaint with the UK Information Commissioner's Office (ICO) or your local supervisory authority.
To exercise any of these rights, or to close your account, email support@brandzilla.ai. We respond within 30 days.
8. Marketing communications
We may send product updates, tips and offers by email where permitted. Every marketing email includes an unsubscribe link, and unsubscribing is honoured for all marketing messages. We will still send essential transactional emails relating to your account, purchases, security and publishing activity.
9. International transfers
BrandZilla is operated from the United Kingdom and may be accessed worldwide. Some of our providers process data outside the UK or EEA. Where personal data is transferred internationally, we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses with our processors.
10. Security
We use industry-standard measures to protect your data, including encryption in transit (TLS), encryption of sensitive credentials such as social access tokens, row-level database access controls, role-based administrative access, audit logging and regular security reviews. No system is 100% secure; you are responsible for using a strong, unique password and notifying us of any suspected compromise.
11. Children
The Service is not directed at children under 18 and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notice. The "Last updated" date above always reflects the current version.
13. Contact
For privacy questions or data requests, contact support@brandzilla.ai.
Need help or have a legal request? Email support@brandzilla.ai. We aim to reply within 2 business days.
