BrandShots

Effective June 23, 2026

Privacy Policy

BrandShots is operated by Baruzo Tech. This policy explains what we collect, why, and what your rights are. It covers BrandShots wherever you use it: the web app, the mobile app, and the Shopify app.

How you sign in

  • Web app: you sign in with your Google account or your Apple account via OAuth. From Google we receive your name, email address, and profile picture. From Apple we receive your name (only on first sign-in) and an email address — which may be a private Apple relay address if you choose to hide your real one. We never see or store your Google or Apple password.
  • Mobile app: same as the web app — Google or Apple sign-in, same data. The mobile app is an app wrapper around the same service and collects a few additional things noted under "When you use the mobile app" below.
  • Shopify app: you sign in through Shopify instead of Google or Apple. See "When you use BrandShots through Shopify" below.

In every case we never see or store your password.

What we collect

When you generate creatives, we store the product images you upload, the brand kits you create (logo, palette, voice description), the briefs you submit, and the resulting AI-generated images. We retain these so you can find them in your library later.

We log standard request metadata (timestamp, IP address, user-agent) for security and debugging. Logs are kept for 30 days and then deleted.

We do not track you across other websites, and we do not sell or share your personal data with advertisers.

What we do with it

  • Authenticate you when you sign in.
  • Run the creative generation pipeline (analyzer, image model, copywriter).
  • Store and serve your products, brand kits, and generated creatives back to you.
  • Bill you against your credit balance.
  • Respond to support requests.

We use a small number of subprocessors to make this work:

  • Google Cloud Platform: application hosting, image storage, and the Vertex AI image model.
  • MongoDB Atlas: application database.
  • OpenAI: alternate image model when BrandShots routes through OpenAI.
  • Replicate: background-removal model used during product upload.
  • Dodo Payments: payment processing for paid plans on the web and mobile apps.
  • Slack: internal operational alerts. When you create an account, your name and email are sent to a private Slack channel so our team is notified of the new signup. This is used only for internal operations — never for marketing — and is not shared further.

Each subprocessor processes only what's needed to deliver its part of the service.

How we handle your inputs and AI outputs

The product images and prompts you submit are sent to the AI model providers above to generate outputs. We pass minimum information (the image itself and the composed prompt) and don't include identifying account information in the model request.

We do not use your uploaded images, brand kits, or generated outputs to train AI models, neither ours nor any third party's. The model providers we use (Google Vertex AI, OpenAI on the API tier, Replicate) operate under commercial terms that prohibit training on customer data.

Generated outputs are stored in our infrastructure and served back to you. We retain a non-exclusive license to display generated outputs only within your account so you can see them in your library. We do not display, share, or sell your outputs publicly.

When you use the mobile app

The mobile app uses the same Google or Apple sign-in and handles your products, brand kits, and generated images exactly as the web app does. Because it runs on your device, it also involves a few additional things:

  • Photos you choose: when you upload a product photo, the app accesses only the specific photo or camera image you select. We don't scan, read, or upload your camera roll or photo library; the app receives just the image you pick. The selected image is then handled like any other upload described above.
  • Push notifications: if you opt in, we use a push token (from Apple Push Notification service or Firebase Cloud Messaging) to send notifications such as "your creatives are ready." You can turn notifications off at any time in your device settings, and we delete the token when you do or when you uninstall.
  • Device and diagnostic info: we collect basic device information (device model, operating-system version, app version, and a non-advertising app-instance identifier) and crash/diagnostic logs to keep the app stable and debug problems. This data is not used to advertise to you and is not sold.

The mobile app does not access your contacts, location, microphone, or background camera. We only request the permissions needed for the feature you're using, at the moment you use it.

When you use BrandShots through Shopify

If you install BrandShots from the Shopify App Store, you sign in through Shopify instead of Google or Apple. Shopify handles the authentication and tells us which store is connecting. We never see or store your Shopify password.

What we receive through Shopify's APIs. Once you approve the install, we access your store through Shopify's Admin API to do the job you installed us for. Specifically we read:

  • Your store profile (store name, myshopify domain, primary contact email, plan, and locale) so we can identify and bill the account.
  • Your products and their images (titles, handles, and the product photos you already have) so you can pick a product and send its image to the generator.

When you publish a generated image, we write it back to that product's media through the same API. We only read and write the products and images needed to run the app. We don't read your orders, your customers, or your customers' personal data, and we don't request access to them.

Billing through Shopify. Paid plans for the Shopify app are processed by Shopify's Billing API, not by Dodo Payments. Shopify handles the charge and tells us your plan so we can credit your account. We never see your card details.

Generated content. Images you generate inside the Shopify app are stored in your BrandShots library exactly as described in the sections above, and are handled the same way (no model training, served back only to your account).

Compliance webhooks. Shopify requires every app to honor three privacy webhooks, and we do:

  • customers/data_request — if a store owner forwards a customer's data-access request, we confirm we hold no customer personal data for that store.
  • customers/redact — same: we store no customer personal data, so there is nothing to erase.
  • shop/redact — 48 hours after you uninstall BrandShots, Shopify sends this signal and we permanently delete the store profile, synced product references, brand kits, and generated images associated with that store.

Uninstalling. You can uninstall BrandShots at any time from your Shopify admin. Uninstalling immediately revokes our API access. Your stored data is then deleted on the shop/redact signal as described above, or sooner if you email us.

Where your data is processed

BrandShots is operated by Baruzo Tech. We store and process data on infrastructure located in the United States (Google Cloud Platform and MongoDB Atlas), and our AI subprocessors (Google Vertex AI, OpenAI, Replicate) process the images and prompts you submit in the United States. Our operational-alert subprocessor (Slack) and payment processor (Dodo Payments) also process the limited data described above in the United States. If you are located in the European Economic Area, the United Kingdom, or another region, your data is transferred to and processed in the United States under the standard contractual clauses or equivalent safeguards offered by each subprocessor.

Cookies and analytics

On the web, we use a single first-party cookie (or localStorage entry) to keep you signed in. We do not use third-party advertising cookies. The mobile app uses secure on-device storage to keep you signed in instead of cookies.

We use lightweight first-party analytics to count page views and conversion events. Analytics never identify individual users.

Your rights

You can:

  • See all data we hold for you by signing in and visiting your library, brand kits, and settings.
  • Edit or delete any product, brand kit, or generation at any time.
  • Delete your entire account, instantly and in-app. In the mobile app, go to Profile → Delete account. This immediately and permanently erases your account and everything in it — uploaded product images, brand kits, generated creatives, credits, and subscription/payment records — across our database and file storage. It cannot be undone. You can also request deletion by emailing info@baruzotech.com; we'll complete it within 14 days.
  • Export your generated images as PNGs anytime via the download button.

Note: deleting your BrandShots account does not cancel any subscription billed through Apple or Google. Manage or cancel those in your App Store or Google Play account settings.

If you're in the EU, UK, or California, you have additional statutory rights (access, rectification, erasure, portability, objection). Email us and we'll honor them within the timelines required by GDPR / CCPA.

Children

BrandShots is not intended for users under 16. We don't knowingly collect data from minors. If you believe a minor has created an account, email us and we'll remove it.

Changes to this policy

We'll update this page when material things change and bump the effective date at the top. Substantial changes (e.g., new subprocessors handling personal data) will trigger an email notification to active users.

Contact

Questions, concerns, takedown requests, or rights requests: info@baruzotech.com. We aim to respond within one business day.

Baruzo Tech

626, Laxmi Enclave 2, opp. Gajera School, Katargam, Surat, Gujarat 395004, India