Privacy Policy
Last updated: 3 October 2026 — Applies to the Brandzy web app, public creator pages, and this website.
1. Who we are
Brandzy is managed by Tharun Tech Solutions, a sole proprietorship based at 3-4-696/1, Om Sai Colony, Hanamkonda, Warangal – 506001, Telangana, India ("Brandzy", "we", "us", "our"). This policy explains what information we collect, why, where it is stored, and the choices you have. For any privacy question or request, email info@brandzy.app.
2. Information we collect
From creators (account holders):
- Account details — your email address and a password (stored in hashed form by our authentication provider; we never see it in plain text).
- Profile and media kit — name, username, bio, niche, location, contact email, rate card, audience details, and the social platform handles and statistics you enter or connect.
- Business records — the deals, deliverables, invoices, clients, notifications, and storefront products you create, including any brand contact names, emails, and phone numbers you add.
- Subscription records — your plan and billing status. Card, UPI, and bank details are collected and stored by our payment processors, not by Brandzy.
From brands and fans who use a creator's public page:
- Brand inquiries — brand name, contact name, email, budget range, and message submitted through a creator's media kit form.
- Store orders and bookings — buyer name, email, the product ordered, amount, and any session time chosen.
This information is shared with the creator whose page it was submitted on, so they can respond and fulfil the request.
3. Information stored in your browser
The Brandzy web app stores your sign-in session in your browser's local storage so you stay signed in after a reload. The interactive demo on our homepage stores its sample data only in your browser's local storage; it is never sent to us. This marketing website (brandzy.app, but not the Brandzy web app, checkout or creators' public pages) uses Google Analytics to count visits and see which pages are useful; it sets first-party analytics cookies and receives your IP address, browser and device details and the pages you view. We do not use advertising cookies, and we do not use Google Analytics data for advertising. You can block it with your browser's cookie or tracker settings or the Google Analytics opt-out add-on.
4. How we use information
- To provide the Service — storing your records, showing your public page, and delivering inquiries and orders to you;
- To manage your subscription and billing;
- To respond to support requests and send essential service emails (such as account and billing notices);
- To keep the Service secure and prevent abuse.
We do not sell your personal information, and we do not use it for advertising.
5. What is public
Information you choose to show on your published media kit or storefront — such as your name, username, bio, contact email, rates, audience details, social statistics, and active products — is visible to anyone with the link. You can unpublish your page or hide individual sections from within the app.
6. Instagram Auto DM
Auto DM is an optional feature. It works only after a creator connects their Instagram professional account through Instagram's own login screen and approves the permissions. When connected:
- What we receive and store: the creator's Instagram account ID and username, and an access token that Instagram issues. The token is stored on our servers only, is never sent to a browser, and is renewed automatically while the connection is active.
- Comments and messages: Instagram notifies us when someone comments on the creator's posts or reels, or sends the creator a direct message. We check the text against the keywords the creator has set up. If a keyword matches, we send the creator's pre-written reply (and, if set, a public reply to the comment). We do not store the text of comments or messages, or the profiles of the people who wrote them.
- Records we keep: to avoid replying twice to the same comment or message, we keep the Instagram ID of each comment or message we replied to, which rule replied, and when. We also keep a count of replies sent per rule so the creator can see it in the app.
- What we never do: we do not post to the creator's feed, read their other messages, sell Instagram data, use it for advertising, or share it with anyone other than Instagram (Meta) to send the replies.
- Disconnecting: a creator can disconnect Instagram at any time in the app (Store → Auto DM → Disconnect), or remove Brandzy in Instagram under Settings → Website permissions → Apps and websites. Disconnecting deletes the stored access token, Instagram account ID, and username straight away.
Instructions for deleting Instagram data are on our Data deletion page. Use of Instagram data follows the Meta Platform Terms.
7. Connected accounts for automatic stats
Creators can connect YouTube, Instagram or TikTok so the follower, reach and engagement numbers on their media kit are pulled from the platform instead of typed in. This is optional and works only after the creator signs in on the platform's own screen and approves read-only access. When connected:
- What we read: YouTube (Google): the channel's ID, handle, subscriber count, and total views, likes and comments over the last 30 days (YouTube Data API and YouTube Analytics API, read-only). Instagram: the account's username, follower count, accounts reached over the last 30 days, and like and comment counts on recent posts. TikTok: the account's username, display name, follower count, and view, like, comment and share counts on recent videos.
- What we store: the platform account ID and username, the totals we calculate from them (followers, 30-day reach, engagement rate), and the access and refresh tokens the platform issues. Tokens are kept on our servers only and are never sent to a browser. We do not store videos, posts, captions, comments, or anyone else's profile.
- How we use it: only to show those totals in the creator's dashboard and, if the creator publishes it, on their public media kit marked "Verified". We refresh them about once a day and when the creator taps Sync now.
- What we never do: we do not post, upload, comment or change anything on the creator's accounts, sell this data, use it for advertising, or share it with anyone. Brandzy's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Disconnecting: a creator can disconnect any platform at any time in the app (Settings → Connected Social Platforms). Disconnecting deletes the stored tokens straight away; the last numbers stay on the creator's page as ordinary, editable stats until they delete them. Access can also be removed from the platform side: Google Account → Security → Third-party connections, TikTok → Settings → Security → Manage app permissions, or Instagram → Settings → Website permissions.
8. Service providers we use
- Supabase — database and authentication. Your data is stored on servers in Mumbai, India.
- GitHub Pages — hosting for this website and the web app. The host may log IP addresses and browser details for security and operations.
- Google Fonts — font delivery. Your browser requests font files from Google's servers when pages load.
- Google Analytics — visit statistics for this marketing website only, as described in section 3.
- Resend — delivery of account emails and of the emails creators send to their subscribers.
- Meta (Instagram) — only for creators who connect Instagram, to receive comment and message notifications, send Auto DM replies, and read the account statistics described above.
- Google (YouTube) and TikTok — only for creators who connect those accounts, to read the account statistics described above.
- Cashfree Payments — subscription payments for creators in India. We send Cashfree your name, email and mobile number for the payment, and it processes your card, UPI or bank details under its own privacy policy. Brandzy never sees or stores your full card or bank details.
We share only the information each provider needs to perform its service. We may also disclose information where required by law.
9. Data security
Data is transmitted over encrypted connections (HTTPS). Access to each creator's private records is restricted at the database level so that only the signed-in owner can read or change them. No system is completely secure, so please use a strong, unique password.
10. Data retention and deletion
We keep your account data for as long as your account is active. You can delete individual deals, clients, invoices, products, and other entries in the app at any time. To delete your entire account and its data, email info@brandzy.app from your account email address (or see our Data deletion page); we will delete it within 30 days, including any connected Instagram data, except for any records we must keep by law (for example, billing records for tax purposes).
11. Your rights
Subject to applicable law, including India's Digital Personal Data Protection Act, 2023, you can ask to access, correct, or erase your personal data, or withdraw consent where processing relies on it. Brands and fans who submitted an inquiry or order can contact the creator directly, or email us and we will pass the request on. To make a request or raise a grievance, email info@brandzy.app.
12. Children's privacy
Brandzy accounts are for people aged 18 or over. We do not knowingly collect personal information from children.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be shown by an updated "Last updated" date above and, where appropriate, communicated by email.
14. Contact
Questions or requests about this Privacy Policy can be sent to info@brandzy.app or +91 63009 67265.