Privacy Policy

BETA

Last Updated: 2026-08-09


1. Who We Are

BranderUX ("BranderUX", "we", "our", or "us") is an AI-UX platform operated by Lev Kaplun from Israel. It lets you build branded, interactive screens that AI agents render at runtime — through our website, our embeddable SDK, and agent connections (our MCP server at mcp.branderux.com).

This policy covers all of those surfaces. For anything privacy-related, contact contact@branderux.com.

2. Information We Collect
  • Account information. When you sign in with Google we receive and store your name, email address, profile picture, and Google account identifier in our database.
  • Security and session data. Sign-in tokens, and the IP address and browser identifier of the device that created them — kept to secure your account and detect abuse.
  • Content you create. Projects, brand settings, screens, custom elements, and API keys (stored hashed) are saved on our servers so the service can operate.
  • Agent connections (MCP). When you connect an AI agent, we store your authorization (the consent you grant) and receive the tool requests the agent sends on your behalf. We do not receive or store your full agent conversations.
  • Usage analytics. We use Google Firebase Analytics to understand aggregate feature usage (for example, page views). We do not use advertising or cross-site tracking.
  • Contact form. Messages sent through our contact form are processed by Formspree and forwarded to our email; we do not store them in our database.

Notice under the Israeli Protection of Privacy Law, 1981: you are under no legal obligation to provide us any information. Providing it is voluntary, but required to operate an account. The information is collected for the purposes and shared with the recipients described in this policy.

3. How We Use Information
  • • Operate, secure, and provide the service and your account
  • • Generate branded UI — your queries, brand settings, and screen configurations are sent to our AI provider (Anthropic) to produce the screens you request
  • • Manage beta access and the waiting list, and contact you about it
  • • Improve the product using aggregate usage analytics
  • • Send service-related communications (not marketing lists)

We do not sell personal information, and we do not use your content to train AI models.

4. Who We Share It With

We share data only with the service providers that run BranderUX, and only to provide the service:

Google (Sign-In, Cloud, Firebase)

Authentication, hosting infrastructure and databases, usage analytics

View privacy policy →
Anthropic

AI processing — generating branded screens and elements from your queries

View privacy policy →
Vercel

Website hosting and delivery

View privacy policy →
Formspree

Contact form processing

View privacy policy →

We may also disclose information where the law requires it. We never sell or rent personal data.

5. Where Data Is Stored & International Transfers

Our infrastructure runs on Google Cloud in the United States, and our providers may process data in other locations where they operate. Transfers of data outside Israel are made in accordance with the Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 2001, including on the basis of your consent given by using the service, and with providers committed to appropriate data protection.

6. How Long We Keep It
  • • Account data and content: for as long as your account exists (deleted on request)
  • • Sign-in refresh tokens: up to 30 days
  • • Agent (MCP) refresh tokens: up to 90 days, and expired authorizations are purged automatically
7. Your Rights

Under the Israeli Protection of Privacy Law, 1981 (including Amendment 13), you may:

  • Access the personal information we hold about you
  • Correct information that is inaccurate or outdated
  • Delete your account and data — email us and we will remove them
  • Withdraw consent at any time by disconnecting agents or closing your account

To exercise any right, email contact@branderux.com. You may also lodge a complaint with the Israeli Privacy Protection Authority.

8. Security

We maintain safeguards in line with the Israeli Privacy Protection (Data Security) Regulations, 2017:

  • • HTTPS/TLS encryption for all connections
  • • Encryption at rest on our cloud infrastructure
  • • API keys stored hashed; agent tokens are short-lived and scoped
  • • Access controls, audited dependencies, and prompt security updates
9. Cookies
  • Essential: authentication cookies that keep you signed in
  • Preferences: theme and interface settings
  • Analytics: Firebase Analytics identifiers (aggregate usage)
  • No advertising cookies and no cross-site tracking
10. Children

BranderUX is a business tool and is not directed at children under 18. If we learn we hold a child's data, we will delete it.

11. Changes & Governing Law

We will post any changes to this policy on this page with an updated date. This policy is governed by the laws of Israel. Questions: contact@branderux.com or our contact form.