Skip to content
Brandora

Privacy

Last updated 12 August 2026

Brandora is operated by Enigmitic, in the United Arab Emirates. This page says what the product holds about you, who else it passes through, and how to have it back or removed. Questions go to hello@enigmitic.com.

What you give us

An account needs a name, an email address, and either a password or a Google sign-in. Passwords are stored hashed and are never readable by us. If you sign in with Google we receive your name, email address and profile picture, and nothing else from your Google account.

A brand run needs a business name, an industry, a country, a style and whatever brief you write. Those words are sent to the AI models listed below, because that is how the brand gets made.

Everything the product then produces — names, slogans, palettes, fonts, the written brand, website copy, social copy, logo concepts, kit photography, and anything made in Content Studio — is stored against your workspace so you can come back to it.

What we record as you use it

A session cookie, so you stay signed in. It is required; the product cannot work without it.

A ledger of every credit granted and spent, and a record of every model call: which model, how many tokens, what it cost us. This is how billing is checked and how the price of the product is understood.

Product analytics — which steps of a run are reached and where people stop — and error reports when something breaks. Both are used to fix the product, not to build a profile of you.

Messages sent through a published site

When a customer publishes a website with Brandora, its contact form collects a visitor’s name, email address and message. We store that message and email it to the customer who owns the site.

For those messages the customer is responsible for what they do with them, and we are only the means of delivery. If you sent a message through someone’s Brandora site and want it removed, write to us and we will pass it on and delete our copy.

Card details

We never see them. Payments run through Polar, which is the merchant of record: they take the payment, they hold the card, and they collect any tax. What reaches us is the fact that an order succeeded and which plan or credit pack it was for.

Who else processes it

Vercel — hosting, and the traffic analytics on our own marketing pages.

Neon — the PostgreSQL database, hosted on AWS in us-east-1.

Cloudflare R2 — storage for generated images, documents and brand kits.

OpenRouter — the text models that write names, stories, website and social copy.

fal — the image models that draw logo concepts and kit photography.

Polar — payments, subscriptions and invoicing, as merchant of record.

Resend — transactional email: verification codes, password resets, invitations, and contact-form delivery.

Inngest — the queue that runs generations in the background.

Sentry — error reports. PostHog — product analytics.

Google — only if you choose to sign in with it.

How long it is kept

Your account and its work stay until you delete them. Deleting a project removes its generated assets. Closing your account removes the account, its workspaces and their contents.

Two things outlive that, and only in a reduced form: the credit ledger and payment records, which are kept because they are accounting records, and aggregate usage figures that no longer identify anyone.

What you can ask for

A copy of what we hold, a correction, or a deletion. Write to hello@enigmitic.com from the address on the account and we will act within thirty days.

We do not sell personal data, and we do not use your briefs or generated work to train our own models. The providers above process what we send them under their own terms as our processors.

Changes

If this policy changes in a way that matters, the date at the top changes and anyone with an account is told by email before it takes effect.