Legal & Privacy
Privacy Policy for BrandForge OS
Comprehensive disclosures on how BrandForge OS collects, uses, stores, shares, and protects your personal data, creative work, and Google user data.
Privacy Policy for BrandForge OS
Last Updated: September 21, 2026 • Effective Date: September 21, 2026
BrandForge OS (“we,” “our,” or “us”), a software product operated by TANATEQ Innovations LTD, provides an intelligent brand operating system and creative workflow platform via the website https://brand-forge.xyz (the “Service”). This Privacy Policy explains our commitment to transparency, detailing how we access, collect, process, store, disclose, and protect your information when you access or use BrandForge OS, including our Google Workspace integrations and third-party tools.
1. Information We Collect
We collect personal information and operational data necessary to create and manage your account, deliver our branding tools, and fulfill our contractual commitments:
- Account & Registration Information: Your full name, email address, company or agency name, profile avatar, and account login credentials provided during sign-up or profile setup.
- User Content & Brand Projects: Creative briefs, brand questionnaire responses, logos, vector marks, design sketches, color palettes, typography selections, stylescapes, and exported brand guidelines created by you or uploaded into your workspaces.
- Billing & Payment Details: When you subscribe to paid tiers, payments are processed by PCI-DSS compliant third-party payment gateways (such as Stripe). BrandForge OS does not store or process raw credit card numbers or sensitive banking credentials on its servers.
- Device & Diagnostic Data: IP addresses, browser types, operating systems, referring URLs, access timestamps, and usage events collected automatically through server logs, analytics, and session telemetry.
- Communications & Customer Support: Messages, feedback, and support inquiries sent to our support desk or through in-app channels.
2. Google API Services & OAuth Scopes
BrandForge OS provides optional Google Workspace integrations allowing seamless single sign-on, automated asset export to Google Drive, presentation generation in Google Slides, and consultation scheduling via Google Calendar. When you connect your Google Account, we access only the specific Google user data needed to deliver these requested features.
2.1 Specific Scopes Requested & Functional Purpose
Basic Profile & Authentication (openid, userinfo.email, userinfo.profile)
Used to authenticate your identity, create or log into your BrandForge OS account, verify your email address, and display your name and profile picture within your workspace.
Google Drive File Creation (https://www.googleapis.com/auth/drive.file)
Used solely to create project folders, export brand manuals, copy briefs, styleguides, and upload master deliverable ZIP archives directly to your personal or organizational Google Drive. BrandForge OS only accesses, modifies, or deletes files that were created by BrandForge OS or explicitly selected by you. We do not inspect, read, or catalog your personal Google Drive files.
Google Slides Export (https://www.googleapis.com/auth/presentations)
Used exclusively to generate, format, and export interactive brand strategy presentation decks directly to Google Slides at your explicit request.
Google Calendar Scheduling (https://www.googleapis.com/auth/calendar.events)
Used solely to create and sync discovery consultation appointments and brand review milestones on your Google Calendar, complete with meeting details and Google Meet video links when initiated by you.
2.2 Compliance with the Google API Services User Data Policy
Google Limited Use Commitment: BrandForge OS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
2.3 Strict Protection of Google User Data
- No Advertising or Commercial Sale: We do NOT sell, rent, trade, or transfer Google user data to any third party, data broker, or advertising platform. Google user data is NEVER used for serving advertisements, including personalized, targeted, or retargeted advertising.
- Prohibition on AI Model Training: Google user data received through Google APIs is NOT used to train, retrain, or fine-tune generalized artificial intelligence (AI) or machine learning (ML) models.
- Prohibition on Human Access: We strictly prohibit human access to Google user data, unless: (1) you have granted affirmative consent for specific technical support or troubleshooting; (2) it is necessary for internal security purposes (such as investigating system compromise or abuse); (3) it is required by applicable law or a valid court order; or (4) the data is aggregated and anonymized for internal operational metrics.
3. Third-Party Design & Creative Tool Integrations
To provide an end-to-end creative workflow, BrandForge OS connects with industry-standard design tools and visual platforms. When you choose to use these integrations, the following practices apply:
Canva Integration
BrandForge OS supports optional Canva account authorization via secure OAuth. This connection is used solely to export generated brand guidelines, color palettes, typography styles, and logo assets directly into editable Canva templates in your Canva workspace. BrandForge OS does not inspect, modify, or delete your existing Canva designs, personal files, or private projects. You can disconnect your Canva integration at any time from your BrandForge OS Workspace Settings or directly within your Canva account settings.
Pinterest & Visual Inspiration Services
BrandForge OS enables users to curate visual stylescapes, explore aesthetic precedents, and perform visual heuristic evaluations during strategic logo audits. We interact only with public Pinterest boards and search queries explicitly entered by you. We do not access, collect, or store private Pinterest profile data, personal pins, or account credentials.
Figma & Vector Design Tooling
When you export design tokens, stylescapes, or vector assets to Figma, data is transmitted strictly to populate your destination files. BrandForge OS does not harvest, store, or monitor external Figma files or private team libraries.
Artificial Intelligence & Large Language Models
BrandForge OS uses advanced Google Gemini and vision model APIs to assist with creative brief synthesis, brand positioning models, audience persona development, and logo auditing heuristics. All inputs provided to AI endpoints are processed in secure, isolated API sessions. Your brand data, proprietary business strategies, and Google user data are NEVER used to train, retrain, or fine-tune public foundation AI models.
4. Legal Bases for Processing (GDPR & UK GDPR)
Under international privacy regulations, including the EU and UK General Data Protection Regulation (GDPR), we process your data under the following lawful bases:
- Contractual Performance: Processing required to provide the core BrandForge OS services, process transactions, authenticate logins, and generate brand deliverables.
- Legitimate Interests: Improving platform reliability, securing our systems against fraud or unauthorized access, and communicating essential system notifications.
- Consent: Where you explicitly grant permission to connect third-party accounts (such as Google OAuth) or opt into non-essential cookies.
- Legal Obligation: Retaining records where mandatory under tax, corporate governance, or regulatory laws.
5. Data Storage, Token Handling & Security Protections
We deploy robust organizational and technical safeguards designed to protect personal data from unauthorized access, loss, or alteration:
- Encryption in Transit: All data transmitted between your browser and our platform or third-party APIs uses modern Transport Layer Security (TLS 1.3 / HTTPS).
- Encryption at Rest: Account data and stored credentials are encrypted using industry-standard AES-256 encryption within secure cloud databases hosted by Google Cloud Platform / Firebase.
- Ephemeral Token Storage: Google and Canva OAuth tokens are short-lived and cached securely in client-side memory or session storage. Tokens are not written to unencrypted public storage.
- Restricted Access: Production environments enforce strict least-privilege role-based access control (RBAC), multi-factor authentication, and continuous automated vulnerability monitoring.
6. Data Retention, Account Deletion & Access Revocation
- Data Retention: We retain personal and project data only as long as your BrandForge OS account is active or as required to deliver our services. Google and third-party OAuth tokens are stored ephemerally and expire automatically.
- Account Deletion Request: You may request complete account and data deletion at any time by emailing support@brand-forge.xyz. Upon receiving your request, all personal data, workspace assets, and stored tokens will be permanently deleted from active production servers within thirty (30) days, except where legal retention obligations apply.
- How to Revoke Google Permissions: You can revoke BrandForge OS's access to your Google account at any time directly through Google Security Settings by visiting the Google Account Third-Party Permissions Page. Revoking access terminates all active Google Drive, Slides, and Calendar connections immediately.
7. Third-Party Subprocessors & Data Sharing
We do not sell, rent, or monetize your personal data. We share data only with trusted third-party service providers bound by strict data processing and confidentiality agreements:
- Hosting & Database Infrastructure: Google Cloud Platform & Firebase (secure hosting, authentication, and database services).
- Payment Gateways: Stripe (secure payment processing; PCI-DSS compliant).
- Analytics & Error Monitoring: Internal diagnostic logging and performance telemetry used strictly to identify bugs and improve platform responsiveness.
- Legal & Business Transfers: If required by a valid legal process, or in connection with a corporate reorganization, merger, or asset sale involving TANATEQ Innovations LTD.
8. Cookies, Local Storage & Tracking Technologies
BrandForge OS uses cookies and local browser storage to provide core platform functions:
- Essential Cookies: Required for user login, session integrity, authentication, and security validation.
- Functional Cookies: Retaining user interface preferences, active workspace selections, and layout configurations.
- Performance & Analytics: Aggregated, anonymized interaction counts to help us measure platform speed and error rates.
You can manage or modify your cookie consent preferences at any time by opening the in-app cookie settings via the footer link or configuring your browser to block cookies.
9. Your Global Privacy Rights (GDPR, CCPA/CPRA & Others)
Depending on your geographic location, you may have specific statutory privacy rights:
- Right to Know & Access: You can request a summary of the personal data we hold about you and receive a portable copy.
- Right to Rectification: You can correct incomplete or inaccurate personal data directly in your account or by contacting us.
- Right to Erasure (“Right to be Forgotten”): You can request the permanent deletion of your personal information.
- Right to Restrict or Object: You can object to certain data processing activities or request restrictions on how your data is used.
- Right to Non-Discrimination: We will never deny you service, charge different prices, or provide a lower quality of service for exercising your statutory privacy rights.
To exercise any of these rights, contact our privacy desk at support@brand-forge.xyz.
10. International Cross-Border Data Transfers
BrandForge OS operates globally. Data may be stored or processed in data centers located in the United States, Europe, or other regions where our cloud infrastructure providers operate. Where personal data is transferred across international borders, we ensure that appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by relevant authorities, are in place to safeguard your data.
11. Children's Privacy (COPPA Compliance)
BrandForge OS is a business-to-business and professional creative application designed for designers, strategists, and enterprises. It is not intended for or directed to individuals under thirteen (13) years of age (or under 16 where required by local law). We do not knowingly collect personal data from children. If we discover that a child has provided us with personal information, we will immediately delete it.
12. Changes to This Privacy Policy
We may periodically update this Privacy Policy to reflect platform enhancements, operational modifications, or regulatory requirements. If material changes are made, we will provide notice through a prominent banner on our website or via email before the changes take effect.
13. Data Controller & Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our privacy desk:
TANATEQ Innovations LTD
Product: BrandForge OS
Website: https://brand-forge.xyz
Support & Privacy Contact: support@brand-forge.xyz
© 2026 BrandForge OS. A product of TANATEQ Innovations LTD. All rights reserved.