Early Access: 50% off Your 1st Year MembershipUse code EARLY50Claim it
Privacy

Privacy Policy

What we handle, why, who else sees it, and how to have it deleted. Written to be read, not to be survived.

Last updated 2026-08-08

The short version

  • We never sell your personal data, and there is no advertising network or third-party tracking in this product.
  • We do not use your content to train our own AI models, or to improve the service for anyone else.
  • Nothing is published to a connected account without an instruction from you or from automation your organisation switched on.
  • No facial recognition runs on your photographs. The capability is deliberately absent from the product, not merely switched off.

Who we are

BrandSphere AI is a multi-tenant brand content platform. Organisations use it to create, approve and publish social media and blog content across the accounts they connect.

This policy explains what personal data we handle, why, and what you can require of us. It applies to the BrandSphere AI website and application.

In most cases your employer or client organisation is the data controller and BrandSphere AI is the processor acting on its instructions. Where we decide the purpose ourselves — running and securing the service — we are the controller.

What we collect

We collect only what the product needs to do its job. There is no advertising network in this product, no tracking pixel from a third party, and we do not sell personal data to anyone, ever.

  • Account details — your name, email address and the organisation you belong to, supplied when you sign up or are invited.
  • Content you create — posts, captions, briefs, uploaded photographs and videos, brand logos, templates and the writing samples you provide to train your brand voice.
  • Connected account details — for each social or blog account you connect, the account identifier, its display name and an access token, which is encrypted at rest.
  • Publishing and engagement records — what was published, where, when, whether it succeeded, and the public metrics the platform reports back, such as likes and reposts.
  • Guest and contact records — if you photograph a business card, the printed details on it are read into a contact record. Only what is printed on the card is read; nothing is inferred, enriched or looked up elsewhere.
  • Operational records — audit entries recording who changed what and when, and standard security and error logs.

Voice recordings and photographs

Dictation runs in your own browser. When you press the microphone, your browser's built-in speech recognition produces the text — the audio is not sent to our servers, is not stored, and no transcription vendor receives it. The text appears in a field you can edit before anything is created from it.

Recordings you deliberately save — a meeting recording or a studio video — are stored as files in your organisation's library and are subject to your organisation's retention setting.

Photographs of identifiable people are personal data, and under Saudi PDPL biometric data is sensitive personal data. We run no automatic facial recognition on your photographs — not to tag people, not to match a face between images, not to build a faceprint. This is an architectural exclusion, not a setting: the capability is deliberately absent from the product. Where a photograph is cropped for a layout, only the geometry of a detected face region is used so that a crop does not cut through someone's head; no identity is derived, stored or compared.

Why we use it

Your content is used to operate the service you asked for: to generate drafts you request, to route them through your organisation's approval process, and to publish them to the accounts you connected.

We do not use your content to train our own AI models, and we do not use it to improve the service for other customers.

Our staff see operational metadata — counts, statuses, error codes — not your content. Reading tenant content requires a time-boxed, logged support grant that your organisation consents to and can revoke.

Facebook, Instagram and other connected platforms

When you connect a Facebook Page, an Instagram Business account, a LinkedIn profile, a Bluesky account or a WordPress site, you grant BrandSphere AI permission to act on that account on your behalf. This section states exactly what that means.

  • We request only the permissions needed to publish and to read back the performance of what we published. We do not request access to your friends, your private messages, or content posted by anyone else.
  • Nothing is ever posted without an instruction. A post is published when a person with publishing authority in your organisation presses publish, or when an automation your organisation configured and enabled runs. Automated publishing additionally requires your organisation to have switched it on.
  • Access tokens are encrypted at rest and are bound cryptographically to the organisation that created them, so a token cannot be used on behalf of a different organisation.
  • We store the metrics the platform makes available for our own posts — such as likes, comments counts and reposts — so your organisation can see how its content performed. We do not collect the profiles of the people who engaged.
  • You can disconnect an account at any time from the Channels screen. Disconnecting deletes the stored access token immediately, and BrandSphere AI can no longer act on that account. You can also revoke our access from the platform's own settings — on Facebook, under Settings → Business Integrations.
  • Posts already published to a platform remain on that platform after you disconnect. They belong to your account there, and deleting them is done on the platform.

Who else sees your data

We share personal data only with the sub-processors listed below, and only for the purpose stated beside each one. We do not sell personal data, and we do not share it for advertising.

We may disclose data where a law that binds us requires it. Where we are permitted to tell you, we will.

WhoWhat they do with it
ClerkAuthentication and organisation membership only. Clerk holds your name, email address and sign-in activity. It never receives your content.
ConvexThe database and application runtime. All tenant content is stored here, in the region chosen at deployment.
VercelWebsite hosting. Serves the interface and holds standard web request logs. Content is fetched by your browser from Convex, not stored by Vercel.
ResendTransactional email delivery only — approval requests, failure alerts and invitations. Marketing email is not sent through it.
Anthropic, OpenAI, Google, DeepSeekOptional — you can use BrandSphere AI without thisText and image generation, when you use an AI feature. Only the brief and grounding material for that request are sent. Your organisation can restrict which of these vendors may be used, or supply its own API key so requests run on your own vendor account.
LinkedIn, Meta (Facebook and Instagram), Bluesky, WordPressOptional — you can use BrandSphere AI without thisPublishing destinations you connect yourself. Content is sent to a platform only when you or your organisation's automation instructs it, and only to the accounts you connected.

How long we keep it

Content retention is your organisation's setting, not ours to decide. Voice and video recordings carry their own shorter default because they are higher-risk personal data.

Audit records are kept for the life of the account and are not editable, including by us — an audit trail that can be rewritten is not an audit trail.

When an account is closed, content is deleted on the schedule set out in your organisation's agreement with us. Backups age out on their own cycle, so deletion from backups is not instantaneous.

Your rights

Under the Saudi Personal Data Protection Law, and under comparable laws elsewhere, you may ask to see the personal data we hold about you, to have it corrected, to have it deleted, and to receive a copy of it.

Where your data sits inside an organisation's workspace, that organisation controls it. We will route your request to them and support them in answering it. Where we are the controller, we answer you directly.

Write to us at the address below. We aim to respond within thirty days. If you are not satisfied with our answer, you may complain to your data protection authority — in Saudi Arabia, the Saudi Data and Artificial Intelligence Authority (SDAIA).

Deleting your data

To have your personal data deleted, email us from the address on the account and say what you want removed. If you signed in through Facebook and want the data associated with that connection removed, the same request covers it.

You can also remove most of it yourself: disconnect a channel to delete its stored token, delete a contact record, or ask your organisation's administrator to remove your membership, which ends your access and your association with that workspace.

We will confirm in writing when deletion is complete, and tell you plainly about anything we are required to keep, such as audit and billing records.

How we protect it

Every organisation's data is isolated at the database level, and that isolation is enforced by automated checks that block a change from being merged if it would weaken them.

Uploaded files are verified by inspecting their actual contents, not the name or type the uploader claims, and a file that fails is quarantined rather than served. Media is delivered through an authenticated proxy that checks ownership on every request — storage links are never handed to a browser.

Access tokens and API keys are encrypted at rest. BrandSphere AI does not currently hold SOC 2 or ISO 27001 certification; the controls described here are implemented and tested but not independently audited, and we say so rather than imply otherwise.

Where your data is held

Data is held in the region selected when your deployment was created, and that choice is fixed once data exists. Our hosted database has no Middle East region, so data stored on our hosted infrastructure sits outside the Kingdom. An organisation that requires in-Kingdom residency needs a self-hosted deployment, and we will say so rather than imply otherwise.

Where a transfer crosses a border, it is made under the safeguards the applicable law requires.

Children

BrandSphere AI is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child's data has reached us, write to us and we will delete it.

Cookies

We use the cookies the product needs to work: keeping you signed in, and remembering your interface choices such as language, theme and whether you asked for the desktop layout on a phone. There is no advertising cookie and no third-party tracking pixel on this site.

Changes to this policy

If we change this policy in a way that affects you, we will update the date at the top and, for a material change, notify account administrators by email before it takes effect.

Contact us about privacy

For a data-subject request, a deletion request, a retention question or any privacy enquiry, write to our privacy desk. We aim to respond within thirty days.

privacy@brandsphere.nttgroups.com

The contracting legal entity is being finalised and will be named here once registration completes. This does not affect any right described above or our answer to any request.