Skip to content
Legal

Privacy policy

Last updated: August 2026

The short version: your organization's data belongs to your organization, creators own their connections, we only collect from sources we are allowed to, and nothing is deleted just because a subscription lapsed.

Who we are

Brandora is a creator and brand intelligence platform. This policy explains what personal data we process when you use the Brandora website and product, why we process it, and the rights you have over it.

We process personal data in line with the applicable data protection laws in the markets we serve.

Data we collect

Account data: name, email address, password hash, and organization membership when you register or are invited to an organization.

Product data: the campaigns, briefs, rosters, notes, submissions, comments, and reports your organization creates in the product. This data belongs to your organization.

Creator data: profiles in your private roster, publicly available creator information from compliant sources, and, where a creator has connected their own accounts, first-party analytics the creator has explicitly authorized an organization to see.

Usage and billing data: plan, entitlements, metered usage such as discovery and AI requests, and billing state from our payment provider. We never store full card numbers or mobile money PINs.

How we use data

We use data to operate the product: authenticating you, enforcing organization boundaries, running campaigns and approvals, computing metrics with recorded provenance, sending notifications you have chosen over email, SMS, or WhatsApp, and billing your subscription.

We do not sell personal data. We do not use your organization data to train AI models. AI features operate inside your authenticated organization context on your own data.

Creator ownership and authorization

Social connections made through Creator Connect belong to the creator, not to any client organization. Connections are read-only by default.

An organization can only see a creator’s connected-account data when the creator has granted an explicit authorization, and creators can revoke that authorization at any time. Provider access tokens are encrypted and are never exposed to organizations or included in logs.

Data sources and retention

Public mention and listening data comes only from sources whose terms allow collection, such as licensed APIs, RSS feeds, and manually imported URLs. We do not scrape platforms that prohibit it, and we retain provider data only as their contracts allow.

We keep audit logs of security-relevant events. Customer data is never deleted merely because a trial or subscription expired; paid write features may pause, but your data stays intact and exportable.

Your rights

You may request access to, export of, correction of, or erasure of your personal data. Erasure requests anonymize personal identifiers while preserving records we must keep for legal, billing, or audit integrity reasons.

To exercise any right, email privacy@brandora.io. We respond within the timelines required by applicable law, and you may lodge a complaint with your local data protection authority.

Security

All traffic is encrypted in transit. Provider tokens and sensitive secrets are encrypted at rest. Access to production systems is restricted and audited. Credentials, tokens, and authorization headers are never written to logs.

Changes to this policy

When this policy changes materially we will update the date above and notify account owners by email before the change takes effect.

Questions about this document? Reach us via the contact page.

Run your next campaign on proof

Discover creators, plan the brief, collect approvals, and prove fulfillment. All in one place.