Data we process
We process account email and name, workspace membership, task configuration, public-page research results, reports, usage, and billing status. Stripe processes card data directly; we do not store full card numbers.
Purpose and providers
We use data for authentication, research execution, usage accounting, billing, email notifications, security review, and product improvement. Necessary providers may include Cloudflare, Google, Resend, Stripe, Browserbase, and model providers.
Evidence and retention
Public-page evidence is retained according to the selected plan and may contain product information that was publicly accessible when captured. Verification codes, session tokens, payment secrets, and customer exports are not written to application logs.
Your rights
Authenticated users can request a data export or account deletion from Settings. Export files use the same workspace authorization boundary and expire after seven days. Deletion requests are verified before execution; a sole workspace owner must transfer ownership or explicitly request deletion of a workspace with no other members.
Deletion and required retention
Application content is removed or anonymized according to the approved request. Billing, refund, anti-abuse, and security projections that must be retained remain separated from active product data and are summarized in a non-PII deletion receipt. They are removed after the applicable obligation ends.
Contact
For access problems or questions about a request, contact privacy@brandbestseller.com. The address and operating-entity details must be verified before public launch.