Skip to content

THE DETAILS

Privacy policy

Brayer is built so that we hold as little about you as possible. The editor runs in your browser; your screenshots and designs stay on your machine unless you choose otherwise. This page says exactly what we do hold, why, and what you can do about it.

Effective 21 September 2026

1.Who is responsible

The data controller is Álex Coca (AppHarbor), c/ La Sierra, 4C, 14014 Córdoba, Spain, Spain. For anything about your data, write to support@usebrayer.com.

2.What stays in your browser, and never reaches us

The screenshots you paste, the designs you build, your brand kit and your export settings are stored in your browser (IndexedDB and local storage). Rendering and export happen on your own machine. None of it is sent to us or to anyone else. Clearing your browser storage deletes it, and we cannot recover it, because we never had it.

A shared preview link carries the design inside the link itself. Whoever you send it to can open it; we do not keep a copy.

3.What we hold if you create an account

You only need an account to hold a Pro plan. If you create one, we hold:

  • your email address, used to sign you in and to reach you about your plan. If you sign in with Google, we also receive the name and profile picture Google shares with us;
  • your plan and its status (free or Pro, and the renewal date), so the editor knows which features to unlock;
  • a Stripe customer identifier that connects your account to your payments. Card details never reach us; Stripe holds them.

You can sign in with an emailed link or with your Google account. If you choose Google, Google handles that login under its own privacy policy and tells us only who you are; we never see your Google password, and we do not read anything else in your Google account.

The legal basis is the contract between us (we cannot run a paid plan without knowing whose it is), and our legitimate interest in preventing fraud and abuse.

4.What we hold if you turn on cloud sync

Cloud sync is a Pro feature and it is off until you switch it on. When it is on, the designs you choose to sync, including the screenshots inside them, are uploaded to storage we run on Supabase in the European Union, so you can open them on another device. Only your account can read them; this is enforced at the database, not merely in the app.

The legal basis is your consent, which you give by turning sync on and withdraw by turning it off. Turning it off deletes the synced copies from our storage within 30 days; deleting your account deletes them at once.

5.Payments

Payments are handled by Stripe. When you pay, Stripe collects your card details, billing address and, for VAT, your country and sometimes a tax identifier. Stripe is an independent controller of that information and its own privacy policy applies to it. We receive from Stripe what we need to run your plan: that a payment happened, for which plan, and the invoice record the tax authorities require us to keep.

6.Who processes data for us

We use these providers. Each acts on our instructions under a data processing agreement.

SupabaseAccount sign-in, plan status, and cloud sync when you enable itEuropean Union (Ireland, eu-west-1)
StripePayments, invoices, and VAT calculationEuropean Union and United States
VercelServing the website and cookie-free page-view countsGlobal edge network (Vercel Inc., United States)
ResendSending sign-in links and account emailUnited States
ImprovMXForwarding email you send to our support addressEuropean Union

Where a provider processes data outside the European Economic Area (Stripe, Vercel and Resend do, in the United States), the transfer is covered by the European Commission’s standard contractual clauses and, where the provider is certified, the EU-US Data Privacy Framework.

7.Cookies and local storage

We do not use advertising or tracking cookies, and we do not run analytics that profile you. To know which pages are visited we use Vercel Web Analytics, which counts page views without cookies and without a persistent identifier: it derives a short-lived hash from your connection that is discarded within a day, and it cannot follow you across sites or sessions. The site uses local storage for things that are yours: your theme choice, your export settings, the last-known plan so the editor does not flicker, and the session token that keeps you signed in. None of that leaves your browser except the session token, which is sent to our sign-in service to prove it is you.

8.How long we keep things

  • Account details and plan status: for as long as the account exists, then deleted.
  • Synced designs: until you turn sync off or delete the account (see clause 4).
  • Invoices and payment records: for the applicable accounting and tax retention periods, including after the account is closed.
  • Support email: for as long as the conversation is open, and up to two years afterwards so we can pick it up again if you come back.

9.Your rights

You can ask to see what we hold about you, to correct it, to have it deleted, to receive it in a portable form, to restrict or object to how we use it, and to withdraw consent you have given. Write to support@usebrayer.com and we will answer within a month. You can also delete your account yourself from the account page.

If you think we have handled your data badly, you can complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (aepd.es), or to the authority in the country where you live.

10.Changes

When this policy changes in a way that matters, we tell account holders by email before it takes effect, and the date at the top of this page changes. The previous version is available on request.

See also the terms of service and the refund policy.

Brayer is operated by Álex Coca (AppHarbor), c/ La Sierra, 4C, 14014 Córdoba, Spain, Spain.