Security
What we hold, who can reach it, and what we never do with it — in plain words, and only what's true today.
What we store
Your brand and competitors, the pages we read from public websites, the questions you track, and the answers AI agents gave to them. No customer lists, no visitor analytics from your site, no personal data about your buyers.
We don't train on your data
Your content is sent to AI providers to answer your tracked questions and to draft your actions, and for nothing else. We don't use it to train models, and we don't sell or share it. One provider is an exception: when our self-hosted model is unavailable, analysis runs on DeepSeek, which may use what it receives for training. No other AI provider we use trains on it.
Credentials are hashed or encrypted
Passwords are hashed. Connection tokens for AI agents (MCP) are stored as a hash — we can revoke one, we cannot read it back to you. Card details never reach our servers at all: payment is handled by Stripe on their own pages.
One account can't see another
Every record belongs to a user and a workspace, and every request is scoped to the account making it. An agency's client sees nothing of another client's; a request for someone else's data returns nothing found, not an error that confirms it exists.
Access is small on purpose
Production access at Muplex Technologies Ltd., which operates BrandReco, is limited to the people who run it, and used for support and incidents rather than routine work.
Deleting means deleting
Delete a brand or a tracked question and its history goes with it. Close your account from Settings and everything is removed within 30 days. There is no archive we quietly keep.
Found something?
Email contact@brandreco.com with "security" in the subject, plus what you found and how to reproduce it. We reply to every report, we won't take legal action against good-faith research, and we'll tell you when it's fixed.
See also the privacy policy, AI policy and terms.