Privacy Policy
Last updated: June 19, 2026
Brandlyre ("we", "us", or "our") operates the website and application at brandlyre.com. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights under applicable law including the General Data Protection Regulation (GDPR).
By using Brandlyre you agree to the collection and use of information in accordance with this policy. If you are using Brandlyre on behalf of an organisation, you confirm that you have authority to agree to these terms on its behalf.
1. Who is the data controller?
Brandlyre is a product operated by Andreality S.L. (Tax ID B-10663193), Pasaje Dr. Bartual Moret 8, 46010 Valencia, Spain, which is the data controller for personal data processed through Brandlyre. You can reach us at [email protected].
2. Data we collect
Account and profile data
When you register we collect your name, email address, and a hashed password. If you invite team members we also store their email addresses and role assignments.
Brand profile data
You may provide us with information about your brand including its name, website URL, logo, colour palette, tone-of-voice descriptions, target audiences, and marketing objectives. This information is used solely to power the AI-assisted content planning features.
Social-account OAuth tokens
When you connect a social network (Instagram, Facebook, LinkedIn, TikTok, Threads, X) we store the OAuth access and refresh tokens issued by that platform. These tokens are held encrypted at rest and are used exclusively to publish, schedule or retrieve content on your behalf. We never read your personal inbox or follow/unfollow contacts without your explicit instruction.
TikTok
Account connection. You connect your TikTok account to Brandlyre through TikTok's official
Login Kit (OAuth). We request only the user.info.basic and video.publish scopes. From
user.info.basic we read and store your basic public profile — your TikTok open ID, display name, and
avatar URL — solely to identify the connected account and show it back to you in the app. We do not access your
videos, followers, messages, or any other TikTok data.
Access tokens. The access and refresh tokens issued by TikTok are stored encrypted at rest and are used exclusively to publish the content you create, on your explicit instruction. We never post to your TikTok account without an action you initiate.
Posting settings. Before publishing, we query TikTok's Creator Info endpoint and present you with TikTok's own posting controls — the audience/privacy level (e.g. Public, Friends, or Only me), and the commercial-content disclosure options (Your Brand and/or Branded Content) where applicable. We publish strictly according to the settings you select; the default privacy level is the most restrictive (Only me) until you choose otherwise. All content is published in compliance with TikTok's content-sharing and disclosure requirements.
Disconnect and revoke. You can disconnect your TikTok account at any time from your Brandlyre account settings, which immediately deletes the stored TikTok tokens from our systems. You may also revoke Brandlyre's access directly from your TikTok account under Settings → Security & permissions → Manage app permissions.
Data retention. TikTok tokens are deleted immediately when you disconnect the account or delete your Brandlyre workspace. We do not retain TikTok profile data beyond what is needed to operate the connection, and we do not sell or share TikTok data with any third party.
Account connection. You connect your LinkedIn account and the LinkedIn Company Pages you
administer to Brandlyre through LinkedIn's official OAuth flow, using the Community Management API. We request only
the scopes needed to identify you and to publish and review content on your behalf: openid,
profile and email to identify the connected user; w_member_social to publish
to your own profile where you choose to; and r_organization_admin and w_organization_social
to list and manage the Company Pages you are authorised to administer.
Data we access. From your LinkedIn profile we read your basic profile information (name, LinkedIn member ID, and profile picture) solely to identify the connected account. For Company Pages you administer, we access the Page's identity, the posts you publish through Brandlyre, and the engagement and performance metrics for those posts (such as impressions, reactions, comments, shares, and clicks) so that you can review how your own content performed. We access only Pages you are authorised to administer; we do not access Pages, connections, messages, or member data you do not manage.
How we use it. Personal data (including profile data and activity data) obtained via the LinkedIn Community Management API is used exclusively to provide the Brandlyre features you initiate — creating, scheduling, and managing organic posts, comments, and reactions on your Company Page, and presenting your own Page analytics. We do not use LinkedIn profile or activity data for advertising, sales prospecting, or any purpose other than operating the features you request.
Data isolation. LinkedIn data obtained to manage a specific customer's Page is kept strictly within that customer's own workspace. It is never shared with, sold to, or made accessible to any other Brandlyre customer or any third party.
Access tokens. The access and refresh tokens issued by LinkedIn are stored encrypted at rest and are used exclusively to act on your explicit instruction. We never post to your LinkedIn profile or Company Page without an action you initiate.
Disconnect, deletion, and revocation. You can disconnect LinkedIn at any time from your Brandlyre account settings, which immediately deletes the stored LinkedIn tokens and associated data from our systems. We are able to securely delete all data obtained via LinkedIn's Community Management APIs upon request, including any request from LinkedIn. You may also revoke Brandlyre's access directly from your LinkedIn account under Settings → Data privacy → Permitted services.
Compliance. Our access to and use of LinkedIn data complies with the LinkedIn API Terms of Use and the Additional Terms for the LinkedIn Marketing API Program.
Uploaded media
Images and other media files you upload are stored in our cloud object storage (Cloudflare R2) under a per-brand prefix. Files are accessible only to authenticated members of your brand workspace.
Usage and log data
We collect server access logs (IP address, browser user-agent, page visited, timestamp) for security, debugging, and abuse prevention. Log data is retained for 90 days.
Cookies and analytics
We use first-party session cookies essential for authentication. With your consent (via our cookie-consent banner) we may also load Google Analytics (GA4) to understand aggregate usage patterns. GA4 data is anonymised and no cross-site tracking occurs. You can withdraw consent at any time via the cookie settings link in the footer.
Contact form submissions
If you contact us through our website form we store your name, email, subject, message, IP address, and browser user-agent. This data is used only to respond to your enquiry and is deleted after 24 months.
3. AI processing
Brandlyre uses large-language-model (LLM) APIs to generate copy, image descriptions, and content plans. Your brand profile data (name, tone notes, objectives) and post drafts may be sent to these APIs as part of generating suggestions. We currently use:
- Google Gemini (primary) for text and Google Imagen for image generation — governed by Google's Privacy Policy.
- OpenAI (fallback) — GPT-4o for text and gpt-image-1 for images — governed by OpenAI's Privacy Policy.
We do not use your data to train external AI models. API requests are made over TLS. If you prefer that a specific piece of brand information is not sent to AI providers, you may omit it from the brand profile.
4. Third-party services and sub-processors
We engage the following sub-processors. Each is GDPR-compliant or operates under appropriate transfer safeguards (e.g. EU Standard Contractual Clauses):
- Hetzner Online GmbH — application hosting and database (Germany, EU)
- Cloudflare — object storage (R2), content delivery (CDN), DNS, and bot protection (Turnstile)
- Google — Gemini and Imagen AI (copy and image generation), Google Business Profile publishing, and optional analytics (GA4)
- OpenAI — fallback AI copy and image generation
- Meta (Facebook / Instagram / Threads) — social publishing, OAuth
- LinkedIn — social publishing, OAuth
- TikTok — social publishing, OAuth
- Resend — transactional email delivery
- Sentry — application error monitoring
We do not sell, rent, or share your personal data with any third party for advertising purposes.
5. Legal bases for processing
- Contract performance — processing necessary to deliver the service you subscribed to.
- Legitimate interests — security logging, abuse prevention, and product improvement analytics (aggregated).
- Consent — optional analytics cookies; you can withdraw at any time.
- Legal obligation — retaining records where required by applicable law.
6. Data retention
We retain account data for as long as your account is active plus 60 days after deletion to allow recovery. Social OAuth tokens are deleted immediately when you disconnect a social account. Uploaded media is deleted when you explicitly remove it or when the brand workspace is deleted. Log data is purged after 90 days. Contact-form submissions are deleted after 24 months.
7. Data transfers
Brandlyre's application servers and primary database are hosted in the European Union (Hetzner, Germany). Some sub-processors listed above (e.g. Google, OpenAI, Cloudflare, Meta, TikTok) may process data outside the European Economic Area (EEA). Where required, such transfers are governed by Standard Contractual Clauses approved by the European Commission.
8. Your rights (GDPR)
Under GDPR you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate data.
- Erasure — request deletion of your data ("right to be forgotten").
- Restriction — ask us to restrict processing in certain circumstances.
- Portability — receive your data in a machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — at any time where consent is the legal basis.
To exercise any of these rights email [email protected] with the subject line "Data Rights Request". We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.
9. Security
We implement appropriate technical and organisational measures to protect your data, including TLS in transit, encryption at rest for sensitive tokens, access controls, and regular security reviews. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
10. Children
Brandlyre is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us immediately and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you by email or by a prominent notice within the application when we make material changes. The "Last updated" date at the top of this page will always reflect the most recent revision.
12. Contact
Questions about this policy? Email us at [email protected] or write to us at Andreality S.L., Pasaje Dr. Bartual Moret 8, 46010 Valencia, Spain.