brandcurl

Privacy

Effective 2026-08-23

brandcurl reads publicly available web pages you point it at and returns a structured brand profile — logos, colors, typography, and public company metadata. This policy covers the hosted service at brandcurl. If you run brandcurl yourself, you control all data on your own instance and this policy does not apply.

What we collect

  • Domains you submit. The URLs you extract, so we can perform and cache the extraction for faster repeat lookups.
  • Account details (only if you sign up): your username, display name, avatar choice, and a securely hashed password. Passwords are never stored in plain text.
  • API keys you create: shown once at creation, then stored hashed with only a short prefix retained for display.
  • Saved brands you add to your library.
  • On your device only: your theme preference and your collection (pins and keycaps) live in your browser's local storage and are not sent to us.
  • Operational logs: IP address, timestamps, and request IDs, retained briefly for rate-limiting, security, and abuse prevention.
  • Billing records (only if you add a balance): your Stripe customer identifier, subscription state, and an append-only ledger of which endpoints you called, when, and what each cost. We never see or store your card number — card details go directly to Stripe.

What we don't do

We do not sell your data, and we do not run third-party advertising or cross-site tracking.

AI and enrichment providers

Optional features (autonomous research, company enrichment, image enhancement) call third-party providers — such as OpenRouter, Google Gemini, Apollo, Lusha, and Replicate — only when you enable them or supply your own key. When you use these features, the relevant request is sent to that provider and handled under their terms and privacy policies.

Payments

Card payments are processed by Stripe, which acts as our payment processor and handles your card data under its own privacy policy. Stripe receives the information it needs to take the payment; we receive back only the customer identifier, the amount, and the result. Billing records are kept for as long as we are required to keep financial records, which is longer than the rest of your account data.

Extracted content

brandcurl only reads content that is publicly served by the target site. It does not sign in, bypass authentication, or access anything behind a login. Brand assets it surfaces remain the property of their respective owners.

Retention and control

Cached extractions expire on a rolling basis. You can delete saved brands and revoke API keys from your dashboard at any time. To delete your account, email hello@brandcurl.com from your account email.

Changes

We may update this policy; the effective date above reflects the current version.

Questions? Email hello@brandcurl.com. · Terms