Privacy Policy
Effective Date: March 12, 2026 Last Updated: March 12, 2026
1. Introduction
BrandPen ("we," "us," or "our") is a LinkedIn growth platform operated by an individual based in Quebec, Canada. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our service at brandpen.ai (the "Service").
We are committed to protecting your privacy and complying with Quebec's Law 25 (Act respecting the protection of personal information in the private sector) and the Personal Information Protection and Electronic Documents Act (PIPEDA).
2. Data Controller
The person responsible for the protection of personal information at BrandPen can be reached at:
Email: support@brandpen.ai
3. Information We Collect
Information You Provide
- Account information — Your name, email address, and profile picture when you create an account
- LinkedIn authorization data — OAuth access tokens and refresh tokens when you connect your LinkedIn account, along with your LinkedIn profile information (name, profile URL, profile picture, organization pages you manage)
- Content — Posts, drafts, carousel content, and other content you create or generate within the Service
- AI prompts — Text prompts you provide when using AI content generation features
- Payment information — Billing details processed through Stripe (we do not store your full credit card number)
- Communications — Messages you send to us via email or support channels
Information Collected Automatically
- Usage data — Pages visited, features used, actions taken within the Service, and timestamps
- Device information — Browser type, operating system, screen resolution, and language preference
- Log data — IP address, access times, and referring URLs
- Cookies and similar technologies — See Section 9 below
Information from Third Parties
- LinkedIn — Profile data and post analytics retrieved through the LinkedIn API based on the permissions you granted
- Stripe — Payment status and subscription information
4. How We Use Your Information
We use your personal information to:
- Provide the Service — Publish posts to LinkedIn on your behalf, generate AI content, create carousels, and deliver scheduling features
- Manage your account — Authenticate you, manage your subscription, and process payments
- Improve the Service — Analyze usage patterns to fix bugs, improve features, and develop new functionality
- Communicate with you — Send service-related notifications, respond to support requests, and inform you of important changes
- Ensure security — Detect and prevent fraud, abuse, and unauthorized access
- Comply with legal obligations — Meet our obligations under applicable laws and regulations
We do not sell your personal information to third parties. We do not use your content to train AI models.
5. Legal Basis for Processing
Under Quebec's Law 25 and PIPEDA, we process your personal information based on:
- Consent — You consent to data collection when you create an account and connect your LinkedIn profile
- Contract performance — Processing necessary to provide the Service you subscribed to
- Legitimate interest — Service improvement, security, and fraud prevention
- Legal obligation — Compliance with applicable laws
6. Third-Party Services
We share your information with the following categories of third-party service providers, solely to operate the Service:
| Provider | Purpose | Data Shared | |----------|---------|-------------| | LinkedIn (Microsoft) | Publishing posts, retrieving analytics | OAuth tokens, post content, profile data | | Stripe | Payment processing | Billing information, subscription status | | AI providers | Content generation | Prompts and generated text | | Hosting provider | Infrastructure | All data (encrypted at rest) | | Analytics providers | Usage analytics | Anonymized usage data, device info |
Each third-party provider processes data under their own privacy policies. We encourage you to review their policies:
- LinkedIn: https://www.linkedin.com/legal/privacy-policy
- Stripe: https://stripe.com/privacy
7. Data Retention
We retain your personal information for as long as your account is active and as needed to provide the Service. Specifically:
- Account data — Retained until you delete your account
- Content and drafts — Retained until you delete them or delete your account
- LinkedIn tokens — Retained until you disconnect your LinkedIn account or delete your account; tokens are also deleted if they expire and cannot be refreshed
- Payment records — Retained for 7 years after your last transaction, as required for tax and accounting purposes
- Usage logs — Retained for up to 12 months, then anonymized or deleted
Account Deletion
When you delete your account:
- Your personal data, content, drafts, and LinkedIn tokens are permanently deleted within 30 days
- Anonymized, aggregated data that cannot identify you may be retained for analytics purposes
- Payment records are retained as required by law
To request account deletion, use the account settings page or email support@brandpen.ai.
8. Your Rights
Under Quebec's Law 25 and PIPEDA, you have the right to:
- Access — Request a copy of the personal information we hold about you
- Rectification — Request correction of inaccurate or incomplete information
- Deletion — Request deletion of your personal information, subject to legal retention requirements
- Withdrawal of consent — Withdraw your consent to data processing at any time (this may affect your ability to use the Service)
- Data portability — Receive your data in a structured, commonly used format
- De-indexation — Request that your personal information be de-indexed from search or automated processing where applicable
- File a complaint — Lodge a complaint with the Commission d'accès à l'information du Québec (CAI)
To exercise any of these rights, contact us at support@brandpen.ai. We will respond within 30 days.
9. Cookies and Tracking
We use cookies and similar technologies for the following purposes:
| Type | Purpose | Duration | |------|---------|----------| | Essential cookies | Authentication, session management, security | Session / up to 30 days | | Preference cookies | Language and display preferences | Up to 1 year | | Analytics cookies | Understanding usage patterns and improving the Service | Up to 12 months |
You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent you from using the Service.
We do not use advertising or cross-site tracking cookies.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of data in transit (TLS/HTTPS) and at rest
- Secure storage of LinkedIn OAuth tokens using encryption
- Access controls limiting who can access personal data
- Regular security reviews of our infrastructure
- Use of reputable, security-certified hosting providers
While we take reasonable precautions, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
11. International Data Transfers
Your data may be processed in countries outside of Quebec, Canada, including where our hosting providers and third-party services operate. When data is transferred internationally, we ensure appropriate safeguards are in place as required by applicable privacy laws.
12. Children's Privacy
The Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us at support@brandpen.ai and we will promptly delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify you by email or through the Service
Your continued use of the Service after changes take effect constitutes acceptance of the updated Privacy Policy.
14. Contact
If you have questions or concerns about this Privacy Policy or our data practices, contact us at:
Email: support@brandpen.ai
You also have the right to file a complaint with the Commission d'accès à l'information du Québec (CAI) at https://www.cai.gouv.qc.ca.