Privacy Policy
How Brandloop handles account, workspace, brand, billing, provider, and generated-content data.
Operator and legal owner
Brandloop is the product. It is operated by Meritocra LLC, Delaware limited liability company. The mailing address is 8 THE GREEN, STE R, DOVER, DE 19901, United States. Payment, billing, and Stripe account surfaces may identify the company as Meritocra LLC or Meritocra.
Who this policy covers
This policy covers Brandloop users, workspace members, visitors, and people whose business or brand information is provided to Brandloop by a user. Brandloop supports brand intelligence, content planning, generation, approvals, publishing workflows, and usage metering.
Data Brandloop may process
Account, auth, and team data
Brandloop processes names, email addresses, authentication state, account membership, roles, invites, team settings, and audit context needed to operate accounts and workspaces. Account and team access use Supabase and Basejump.
Brand, domain, and uploaded content
Brandloop may process domains, URLs, brand notes, positioning, files, images, source material, social profile references, calendars, approvals, and other workspace data you provide or upload.
Generated content and AI processing
Brandloop may generate drafts, briefs, images, campaign ideas, social posts, analysis, and other AI-assisted outputs from user-provided inputs. Media and automation requests may be routed through configured providers such as fal.ai and Railway-hosted services.
Billing and usage records
Brandloop may process subscription status, invoices, payment method references, usage meters, credit balances, and billing events through Stripe and account-level billing services. Stripe Link may appear where enabled as part of Stripe payment services. The Stripe account and merchant identity may be under Meritocra LLC or Meritocra rather than the Brandloop product name.
Developer, API, and MCP data
Brandloop may process API key metadata, scopes, workspace bindings, idempotency keys, request logs, MCP tool activity, upload-session metadata, rate-limit state, and automation context needed to authenticate requests, operate developer access, prevent abuse, support users, and meter usage.
Social and provider connections
Brandloop may process connected account metadata, channel identifiers, publishing status, and related connection data for services such as Zernio and social networks when those connections are enabled.
Hosting, diagnostics, and security
Brandloop runs on Vercel and may use Railway-hosted services. Diagnostics may include server or edge error, performance, and security data needed to investigate failures. Browser monitoring is treated as optional monitoring and will not run unless that category is enabled.
Support conversations
Brandloop may process authenticated support messages, helpdesk tickets, conversation metadata, support knowledge interactions, and lightweight account context through Intercom when the in-app Messenger or helpdesk features are configured and the relevant optional preference is enabled.
How Brandloop uses data
Brandloop uses data to provide accounts and teams, authenticate users, operate workspaces, generate and store content, support approvals and publishing, provide API and MCP access, measure usage and entitlements, process billing, secure the service, troubleshoot errors, prevent abuse, respond to support requests, and improve the product. Brandloop does not currently load browser analytics or marketing scripts. Server-side lifecycle analytics may be sent to PostHog when configured under Brandloop's analytics controls, and optional Preferences may load Intercom Messenger for authenticated support when configured.
Subprocessors and providers
Brandloop may use subprocessors and service providers to operate the product, including Supabase/Basejump, Stripe including Link, Vercel, Railway, fal.ai, Zernio and connected social network APIs, PostHog for server-side lifecycle analytics when configured, Intercom for optional authenticated support messaging, Sentry, ImprovMX for Brandloop-domain email forwarding. Agno is relevant only when Brandloop uses a hosted Agno or AgentOS service. If Agno runs only as a self-hosted framework on Railway, Railway and the connected model or media providers are the relevant processing providers.
Data deletion, export, and privacy requests
To request access, correction, deletion, export, opt-out, or other privacy handling, contact privacy@brandloop.app. Include your account email, Brandloop account or team name, primary workspace domain, relevant content or asset references, billing or provider connection context, API or MCP context when relevant, and the request type. Do not include passwords, API secrets, payment card details, or private provider tokens in privacy requests.
- You may ask Brandloop to access the personal data Brandloop has about you.
- You may ask Brandloop to correct inaccurate account or workspace information.
- You may ask Brandloop to delete data associated with your account or workspace.
- You may ask Brandloop to export data when technically available.
- You may ask Brandloop to object to or opt out of certain processing where applicable.
Brandloop may need to verify identity and account authority before fulfilling a request. Some data may be retained where required for security, legal, billing, fraud-prevention, or backup reasons.
Brandloop-domain aliases use ImprovMX Free and may forward to the Meritocra legal inbox for handling.
Retention
Brandloop retains account and workspace data while an account is active. After account or workspace deletion, Brandloop will delete or anonymize product data within 30 days where reasonably feasible, except backups retained up to 90 days and records kept for security, fraud prevention, billing, tax, accounting, legal claims, or compliance. Security logs may be retained up to 12 months. Support and legal records may be retained up to 3 years. Billing, tax, and accounting records may be retained up to 7 years, or longer if required by law, investigation, dispute, or legal hold.
Cookies
Brandloop uses necessary cookies or browser storage for core app operation and uses CookieConsent to store cookie preferences locally in the browser. See the Cookie Policy for category details.