BrandStyleKit
  • Features
  • How It Works
  • Pricing
  • FAQ
Sign InGet Started
  • Features
  • How It Works
  • Pricing
  • FAQ
Sign InGet Started
BrandStyleKit

AI-powered design tokens.
Made for makers.

Product

  • Features
  • Pricing
  • FAQ

Resources

  • Documentation
  • Blog
  • Changelog

Legal

  • Privacy Policy
  • Terms of Service
  • Imprint

© 2026 BrandStyleKit. All rights reserved.

Privacy Policy

Data protection information in accordance with the EU General Data Protection Regulation (GDPR)

1. Controller

The controller responsible for data processing on this website is:

[Full Name of Owner]
[Company Name]
[Street Address]
[Postal Code] Salzburg, Austria
Email: [email@example.com]

2. Overview of Data Processing

We process personal data only to the extent necessary to provide a functional website and our services. The processing of personal data takes place only with your consent or when processing is permitted by law.

3. Your Rights

Under GDPR, you have the following rights:

  • Right of access (Art. 15 GDPR) — You can request information about your stored personal data.
  • Right to rectification (Art. 16 GDPR) — You can request correction of inaccurate data.
  • Right to erasure (Art. 17 GDPR) — You can request deletion of your personal data.
  • Right to restriction (Art. 18 GDPR) — You can request restriction of processing.
  • Right to data portability (Art. 20 GDPR) — You can request your data in a structured, machine-readable format.
  • Right to object (Art. 21 GDPR) — You can object to data processing at any time.
  • Right to lodge a complaint — You may lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna.

4. Hosting

This website is hosted on Vercel Inc., 440 N Baxter St, Suite 4060, Coppell, TX 75019, USA. When you visit our website, Vercel may process your IP address and technical browser data to deliver the website. Processing is based on our legitimate interest in a stable and secure website presentation (Art. 6(1)(f) GDPR). We have entered into a data processing agreement with Vercel.

5. User Authentication

We use Supabase (Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992) for user authentication and database services. When you register or log in, Supabase processes your email address and authentication data. This is necessary for the performance of our services (Art. 6(1)(b) GDPR).

Data stored: email address, hashed password, account creation date, last sign-in date, user role, and credit balance.

6. Payment Processing

Payments are processed through Stripe Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA. When you make a purchase, Stripe processes your payment information (credit card details, billing address) directly. We do not store your full payment details on our servers. Processing is based on the performance of our contract with you (Art. 6(1)(b) GDPR).

Stripe's privacy policy: https://stripe.com/privacy

7. AI Processing Services

To generate design tokens, we use AI language models provided by:

  • Anthropic PBC (Claude API) — San Francisco, CA, USA
  • Google LLC (Gemini API) — Mountain View, CA, USA

When you generate a brand kit, your briefing data (industry, colors, fonts, style preferences) is sent to these services for processing. No personal identification data is included in AI requests. Processing is based on the performance of our services (Art. 6(1)(b) GDPR).

8. Google Fonts

We use Google Fonts provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Font files are loaded through our server-side proxy to minimize data transfer to Google. However, the Google Fonts API may receive your IP address. Processing is based on our legitimate interest in a consistent presentation (Art. 6(1)(f) GDPR).


9. Cookies

This website uses cookies. Cookies are small text files that are stored on your device. We use the following types:

  • Essential cookies: Required for website functionality (authentication session, CSRF protection). These cookies are set without consent as they are strictly necessary (Art. 6(1)(f) GDPR).
  • Preference cookies: Store your preferences such as cookie consent choice and theme preferences. Set based on your consent (Art. 6(1)(a) GDPR).

You can manage your cookie preferences at any time through your browser settings or our cookie consent banner.

10. Data Retention

We retain your personal data only for as long as necessary for the purposes stated in this policy or as required by law. Specifically:

  • Account data: Until you delete your account.
  • Generated brand kits: Until you delete them or your account is removed.
  • Payment records: 7 years (Austrian tax law — BAO § 132).
  • Server logs: 30 days.

11. International Data Transfers

Some of our service providers are based in the USA. Data transfers to the USA are covered by the EU-U.S. Data Privacy Framework or Standard Contractual Clauses (SCCs) in accordance with Art. 46 GDPR.

12. Changes to This Policy

We may update this privacy policy from time to time. The current version is always available on this page. We encourage you to review this policy periodically.

Last updated: March 2026


If you have questions about data protection, please contact us at [email@example.com].

Also see our Imprint and Terms of Service.