Spectre AI

Features

Privacy

Privacy Policy

This policy explains what personal data Brandsearch collects, why we collect it, who we share it with, how long we keep it, and the choices you have. It covers the brandsearch.co website, the Brandsearch web application, the Brandsearch Chrome extension, and our API and MCP server.

Effective date: 11 September 2026|Last updated: 11 September 2026

1. Who we are

Brandsearch is an ecommerce and advertising intelligence platform operated by SPECTRE PRYSM S.à r.l.-S, a company registered in Luxembourg. In this policy, “Brandsearch”, “we”, “us” and “our” mean SPECTRE PRYSM S.à r.l.-S.

For the personal data described here, we act as the data controller. That means we decide what data is collected and why. If you have a question about this policy, or want to exercise any of the rights described in section 11, write to contact@brandsearch.co and we will answer.

Data controller

SPECTRE PRYSM S.à r.l.-S

Simplified Limited Liability Company

Registration number: B300832

28, Op der Haart, 9999 Wemperhardt, Luxembourg

Email: contact@brandsearch.co

2. Information we collect

We collect only what we need to run the service. The data falls into six groups, listed below by where it comes from.

a. Account data you give us

When you register, we collect your name, your email address, and a password. Passwords are stored only as a bcrypt hash, so we never hold the password itself. We also store the profile and preference settings you choose, such as your display picture, interface language, theme, notification preferences, and the answers you give during onboarding.

b. Data from Google Sign-In

If you choose to sign in with Google, we receive a limited set of profile fields from your Google account. Section 3 sets out exactly which fields, why we ask for them, and what we do and do not do with them.

c. Billing data

Payments are processed by Stripe. Your card number, expiry date, and security code are entered directly into Stripe and never reach our servers. What we store is the billing information we need to run your subscription: your Stripe customer and subscription identifiers, your plan, your subscription status, renewal dates, and your invoices. If you provide a business name, address, or VAT number for invoicing, we store that too.

d. Product and usage data

As you use Brandsearch we store the content you create and the actions you take, so the product works as you expect between sessions. This includes saved ads, saved brands and products, folders and boards, saved searches and filters, tracked brands, alert settings, exports you generate, and the counters we use to apply your plan limits.

e. Data collected automatically

When you visit our website or use the application, we and our analytics providers collect technical data: your IP address, browser and device type, operating system, referring page, pages viewed, the time and duration of your visit, and the actions you take in the interface. Microsoft Clarity records anonymised session replays and heatmaps on our public website. We use this data to understand how the product is used, to diagnose errors, and to detect abuse. It is not used to build advertising profiles about you.

f. Support and communications

If you contact us by email, through the in-app support widget, or through our Discord community, we keep a record of the conversation and anything you send us in it, so we can follow up and improve our support.

3. Google user data

Brandsearch offers Google Sign-In as one way to create and access an account. This section explains exactly what Google user data we access, how we use it, who we share it with, how we protect it, how long we keep it, and how you can take it back. It applies in addition to everything else in this policy.

What we access, and why

When you sign in with Google, we request the three scopes below and nothing more. We do not request access to Gmail, Google Calendar, Google Contacts, Google Photos, Google Search Console, Google Ads, or any other Google service.

Scope requestedData we receiveWhy we need it
openidA stable, pseudonymous Google account identifier (the “sub” claim) contained in an ID token.To recognise that a returning sign-in belongs to the same Google account, so we can log you back into the correct Brandsearch account.
https://www.googleapis.com/auth/userinfo.emailYour Google account email address and whether Google has verified it.To create your Brandsearch account, to use as the unique identifier for that account, to link a Google sign-in to an existing Brandsearch account with the same address, and to send you service and billing email.
https://www.googleapis.com/auth/userinfo.profileYour Google display name and the URL of your Google profile picture.To pre-fill your Brandsearch profile and to show your own name and picture to you inside the product interface.

These scopes are read-only. They let us confirm who you are. They do not let us read, create, edit, or delete any content in your Google account.

How we use Google user data

Google user data is used for authentication and identity only. Specifically, we use it to:

  • Create your Brandsearch account the first time you sign in with Google.
  • Verify your identity and sign you in on later visits.
  • Link your Google identity to an existing Brandsearch account that uses the same email address, so you do not end up with two accounts.
  • Show your own name and profile picture back to you in the Brandsearch interface.
  • Send you service email about your account, such as billing notices and security alerts.

We do not use Google user data for any other purpose. In particular, we do not use it to serve advertising, to build marketing profiles, or to enrich the brand and advertising datasets that Brandsearch sells access to.

How we store and protect Google user data

Your Google account identifier, email address, display name, and profile picture URL are stored in our PostgreSQL database in the European Union, alongside the rest of your account record. The OAuth tokens issued by Google are held server-side only. They are never sent to your browser, never included in a client-side bundle, and never exposed through our public API. Access to the database is restricted to a small number of engineers who need it to operate the service, and all traffic is encrypted in transit with TLS.

Who we share Google user data with

We do not sell, rent, trade, or transfer Google user data. We do not share it with advertisers, data brokers, or any third party for their own purposes. It is not passed to our analytics or marketing tools. The only circumstances in which Google user data leaves our systems are the hosting and database infrastructure we use to run the service, listed in section 6, and a valid, binding legal order that compels disclosure.

Limited Use disclosure

Brandsearch's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

To state this in plain terms, we affirm that Brandsearch does not:

  • Use Google user data for serving advertisements of any kind, including retargeting, personalised advertising, and interest-based advertising.
  • Sell, licence, or otherwise transfer Google user data to data brokers, information resellers, or any other party.
  • Use Google user data to determine credit-worthiness, or for any lending, insurance, or eligibility purpose.
  • Allow humans to read Google user data, except where you have given us explicit consent for specific messages, where it is necessary for security purposes such as investigating abuse, where it is required to comply with applicable law, or where the data has been aggregated and anonymised for internal operations.
  • Use Google user data to develop, train, improve, or fine-tune any artificial intelligence or machine learning model, including generalised and non-personalised models. Brandsearch offers AI-powered features, and Google user data is excluded from every one of them.

How long we keep it, and how to revoke access

We keep your Google profile data for as long as your Google account stays connected to your Brandsearch account. You can disconnect Brandsearch at any time from your Google account security settings at myaccount.google.com/permissions. Revoking access there stops us from receiving any further data from Google, and invalidates the tokens we hold.

Revoking access does not by itself erase the profile data already stored in your Brandsearch account. To have that deleted, email contact@brandsearch.co and we will delete it within 30 days. If you delete your whole Brandsearch account as described in section 9, all Google user data and tokens associated with it are deleted at the same time.

4. How we use your information

We use personal data for the purposes below. Because we serve users in the European Economic Area, the table also names the legal basis we rely on under the General Data Protection Regulation.

PurposeLegal basis
Creating your account, authenticating you, and providing the features you subscribe toPerformance of a contract
Taking payment, managing subscriptions, invoicing, and handling failed paymentsPerformance of a contract, and legal obligation for invoicing records
Responding to support requests and sending service notices about your accountPerformance of a contract, and our legitimate interest in supporting our users
Measuring how the product is used so we can fix problems and improve featuresOur legitimate interest in operating and improving the service
Detecting fraud, abuse, account sharing, and security incidentsOur legitimate interest in keeping the service secure, and legal obligation
Sending marketing email and product announcements you have opted intoYour consent, which you can withdraw at any time
Keeping accounting and tax recordsLegal obligation under Luxembourg law

Where we rely on your consent, you can withdraw it at any time without affecting anything we did before you withdrew it. Where we rely on legitimate interests, we have weighed those interests against your rights, and you can object as described in section 11.

5. Cookies and similar technologies

We use cookies and similar browser storage for three purposes.

  • Strictly necessary. These keep you signed in, remember your session, protect against cross-site request forgery, and apply rate limits. The service cannot work without them, so they are not optional.
  • Preferences. These remember choices you have made, such as your interface language, your theme, and which panels you have collapsed.
  • Analytics. These let us measure how the website and product are used, through PostHog, Microsoft Clarity, and Google Tag Manager. They tell us which features are used and where people get stuck.

We do not use advertising cookies to build profiles for third parties. You can block or delete cookies in your browser settings, though blocking the strictly necessary ones will stop you from signing in. You can also opt out of Microsoft Clarity and similar session analytics using your browser's “Do Not Track” setting or an ad-blocking extension.

6. How we share information

We do not sell your personal data. We have never sold personal data, and we do not share it with third parties for their own marketing.

We do share personal data with a small set of service providers who process it on our behalf, under contract, and only on our instructions. These are our subprocessors:

ProviderWhat they do for usWhere they process data
VercelApplication hosting and content deliveryEU and US
StripePayment processing, subscriptions, and invoicingEU and US
BrevoTransactional and marketing email deliveryEU
PostHogProduct analytics and feature usage measurementEU
SentryApplication error and crash monitoringEU and US
Microsoft ClaritySession analytics and heatmaps on our websiteUS
Google Tag ManagerLoading and managing our website analytics tagsUS
GleapIn-app support widget and bug reportingEU
Our own infrastructureSelf-hosted PostgreSQL, Elasticsearch, Redis, and media storage that hold your account and saved contentEU

As stated in section 3, Google user data is not shared with any of these analytics or marketing providers. It stays within our hosting and database infrastructure.

Beyond those providers, we disclose personal data only:

  • When you ask us to, or direct us to share it.
  • To comply with a law, a regulation, or a valid and binding order from a court or public authority.
  • To establish, exercise, or defend a legal claim, or to investigate fraud, abuse, or a security incident.
  • In connection with a merger, acquisition, or sale of assets, in which case we will notify you before your data becomes subject to a different privacy policy.

7. International data transfers

We are based in Luxembourg and our primary infrastructure is in the European Union. Some of the providers listed in section 6 process data in the United States. Where personal data is transferred outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies, together with additional technical safeguards such as encryption in transit and at rest. You can ask us for details of the safeguards that apply to a specific transfer by writing to contact@brandsearch.co.

8. How long we keep your data

We keep personal data only as long as we need it for the purpose we collected it, or as long as the law requires. In practice that means:

Type of dataHow long we keep it
Account data (name, email, password hash, preferences)For as long as your account is open, then deleted within 30 days of a deletion request.
Google profile data and Google OAuth tokensFor as long as your Google account stays connected. Deleted when you revoke access at your Google account, or within 30 days of a deletion request.
Saved ads, folders, filters, tracked brands, and other content you createFor as long as your account is open, then deleted with the account.
Invoices and accounting records10 years from the end of the financial year, as required by Luxembourg accounting law.
Product analytics and session analyticsUp to 26 months from collection.
Server and security logsUp to 90 days, unless a log is part of an active security or fraud investigation.
Support email and conversationsUp to 24 months after the conversation is closed.

When a retention period ends, we delete the data or irreversibly anonymise it so that it can no longer be linked to you.

9. Deleting your account and your data

You can ask us to delete your Brandsearch account and the personal data associated with it at any time, for any reason, without giving an explanation.

To do this, email contact@brandsearch.co from the address registered on your account, with the subject line “Delete my account”. We will confirm that the request came from you, and then delete your account and its personal data within 30 days. That includes your profile, your Google profile data and OAuth tokens, your saved ads, folders, filters, tracked brands, and your support history.

Two things survive deletion. We keep invoices and accounting records for the period Luxembourg law requires, because we are not permitted to delete them. And we keep a minimal record that an account with your email address was deleted, and when, so we can demonstrate that we honoured your request.

Deleting your account is separate from cancelling your subscription. Cancelling stops future billing and leaves your data in place. If you want both, say so in your email and we will do both.

10. How we protect your data

We take the security of your data seriously, and we apply measures appropriate to the risk:

  • All traffic between you and Brandsearch is encrypted in transit using TLS.
  • Passwords are never stored in readable form. They are hashed with bcrypt.
  • OAuth tokens, including Google tokens, are held server-side only and are never exposed to the browser or to our public API.
  • Access to production systems and databases is restricted to the engineers who need it, and is protected by individual accounts and multi-factor authentication.
  • We monitor for errors, abuse, and unusual account activity, and we log access to production systems.
  • Our infrastructure providers maintain their own certified physical and organisational security controls.

No system is perfectly secure, and we will not pretend otherwise. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours as required by the GDPR, and we will notify you directly where the law requires it.

11. Your privacy rights

If you are in the European Economic Area or the UK

Under the GDPR you have the right to:

  • Access. Ask whether we hold personal data about you and receive a copy of it.
  • Rectification. Have inaccurate data corrected and incomplete data completed.
  • Erasure. Have your data deleted where we no longer have a lawful reason to keep it. Section 9 explains how.
  • Restriction. Ask us to stop processing your data while a dispute about it is resolved.
  • Objection. Object to processing we carry out on the basis of legitimate interests, and object at any time to direct marketing.
  • Portability. Receive the data you gave us in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible.
  • Withdraw consent. Withdraw any consent you gave us, at any time, without affecting processing carried out before you withdrew it.

To exercise any of these rights, email contact@brandsearch.co. We answer within one month, and we do not charge for it. If you are unhappy with our response, you can complain to the Luxembourg supervisory authority, the Commission Nationale pour la Protection des Données, or to the authority in the country where you live.

If you are in California

Under the California Consumer Privacy Act, as amended by the CPRA, you have the right to know what personal information we collect and how we use it, to request a copy of it, to request its correction or deletion, and to opt out of the sale or sharing of personal information.

Brandsearch does not sell personal information, and does not share it for cross-context behavioural advertising, as those terms are defined in the CCPA. There is therefore nothing to opt out of. We will not discriminate against you for exercising any of your rights. To make a request, email contact@brandsearch.co.

12. Children

Brandsearch is a business tool intended for professional use. It is not directed at children, and you must be at least 18 years old to create an account. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, email contact@brandsearch.co and we will delete it.

13. Data about brands and advertisers

Separately from the data we hold about our own users, Brandsearch indexes publicly available information about ecommerce brands and their advertising. This includes advertising creatives and metadata published in public ad transparency libraries operated by platforms such as Meta and TikTok, publicly accessible storefront and product information, and publicly published social media content.

This information is overwhelmingly commercial rather than personal. Where it does contain personal data, for example the name or image of a person appearing in an advertisement, we process it on the basis of our legitimate interest in providing market and competitive research, balanced against the rights of the people concerned. The data is already published by the advertiser or the platform.

If you appear in content indexed by Brandsearch and want it removed, email contact@brandsearch.co with a link to the content and enough detail for us to find it. We review these requests individually. Copyright holders should use the procedure on our DMCA page instead.

14. The Brandsearch Chrome extension

The Brandsearch Chrome extension reads publicly visible data on the pages where you activate it, so it can show you Brandsearch insights in context and let you save what you find to your account. It sends us the page or advertisement identifier you are looking at, together with your account token so we know the request is yours.

The extension does not read your browsing history, does not run on pages where you have not activated it, does not capture passwords or form input, and does not access your Google account data. It does not bypass authentication or access content that is not publicly visible to you.

15. Changes to this policy

We may update this policy as the product changes or as the law requires. The date at the top of the page always shows when it was last updated, and that version is the one that applies.

If we make a material change, such as collecting a new category of personal data, requesting an additional Google scope, or using your data for a genuinely new purpose, we will tell you before it takes effect, by email or through a notice in the product, and where the law requires it we will ask for your consent.

16. Contact us

For any question about this policy, about how we handle your data, or to exercise any of your rights, contact us at contact@brandsearch.co. We read every message and we answer.

Data controller

SPECTRE PRYSM S.à r.l.-S

Simplified Limited Liability Company

Registration number: B300832

28, Op der Haart, 9999 Wemperhardt, Luxembourg

Email: contact@brandsearch.co

Looking for our terms instead? Read the Terms of Service.