Privacy policy

Effective 12 August 2026. Applies to brandbake.app and the BrandBake Shopify app.

The short version

BrandBake plans and designs email campaigns and social posts for your store. To do that it reads your product catalog, inventory, and order totals from Shopify, and your past campaign results from your email platform. It never imports your customers' personal data — no names, no email addresses, no shipping addresses. Orders are stored as anonymous financial facts. We don't run ads, we don't use tracking cookies, and we never sell data.

What we collect

Your account. Your name, email address, company name, and a password we store only as a salted hash. Signing in sets a session cookie.

Your store, from Shopify. Products, variants, inventory levels, and orders as anonymous financial records — dates, totals, discounts, refunds, and line items. We request read-only access and deliberately exclude customer fields. Order history informs campaign planning (bestsellers, seasonality); it is never used to target or contact individual buyers.

Your marketing, from your email platform. If you connect Klaviyo or Omnisend: campaign names, subjects, audiences, and performance metrics (opens, clicks, revenue). BrandBake creates draft campaigns there; it never sends email itself.

What you make in BrandBake. Your brand kit (colors, type, voice), campaign plans, generated emails, social posts, and images, plus an audit log of actions taken in your workspace.

Public web content. If you run brand research, BrandBake reads publicly available pages about your brand and stores a written report with its sources.

If you bake a preview. The homepage brand-kit preview asks for your name, email, and website address. We fetch your public homepage once to compose the preview, keep those details so we can invite you in, and never share or sell them. Email support@brandbake.app to have them deleted.

What we never collect

Customer personal data from your store: names, emails, phone numbers, addresses, payment details. Our Shopify sync strips orders down to anonymous financials before anything is stored. Because we hold no customer personal data, a "customer data request" from your store has a one-line answer: there is nothing held.

AI processing

BrandBake generates content using Anthropic's Claude models (planning and writing) and OpenAI's image models (imagery). What gets sent: your brand kit, product catalog details, aggregate performance signals, and the content being worked on. What never gets sent: customer personal data — we don't hold any. Both providers are used through their business APIs, which do not permit training their models on our requests.

Who touches the data (subprocessors)

Fly.io hosts the application and database. Anthropic and OpenAI process content generation as described above. Shopify, Klaviyo, Omnisend, and SocialKit are platforms you connect yourself — data flows to each only when you connect it and only to do the job you connected it for. We share nothing with anyone else, and we never sell data.

Cookies and analytics

Cookies are strictly functional: a session cookie to keep you signed in, a cookie remembering which brand you're viewing, and short-lived encrypted cookies used during Shopify's connect flow. No analytics cookies, no advertising cookies, no third-party trackers.

We count visits to our own public pages ourselves, without cookies: each visit is recorded with an anonymous identifier that changes every day and can't be traced back to you — your IP address and browser details are used to compute it and are never stored. Browsers that send Do Not Track or Global Privacy Control are not counted at all. Nothing about this leaves our server.

Security

Everything travels over TLS. API keys and access tokens are encrypted at rest (AES-256-GCM) and never shown in the interface or logs. Passwords are salted and hashed (scrypt). Every write to an external platform goes through an idempotency ledger and an audit trail.

Retention and deletion

Uninstalling the Shopify app: when Shopify sends the uninstall and redaction notices, we purge everything sourced from your store — products, inventory, and order records — and delete the stored access token, within 48 hours of the redaction notice.

Deleting your account: email support@brandbake.app and we'll delete your workspace — account details, brand kits, and generated content — within 30 days, except records we must keep for legal or security reasons.

Your rights

Wherever you are, we honor access, correction, deletion, and portability requests for your data — email support@brandbake.app and we'll respond within 30 days. If you're in the EEA/UK, this is how we meet GDPR; processing rests on performing our contract with you and our legitimate interest in operating the service.

Children

BrandBake is a business tool and not directed at anyone under 16.

Changes

If this policy changes in a way that matters, we'll say so on this page and update the effective date. Questions: support@brandbake.app.

BrandBake © 2026 · brandbake.app