Privacy notice
Last updated 5 October 2026
Brandmarks is operated by Creative Madness LLC in Maryland, USA. This notice describes information handled when you use brandmarks.dev, join the access waitlist, use the beta API or account portal, or contact us.
Information we collect and why
- Waitlist: your email address, signup time, the form you used, and a country code supplied by our hosting provider. We use this information to manage access requests and contact you about access.
- Beta account: your email, an optional name, access plan and quota settings, and account timestamps. We use these to administer API access.
- Account sign-in: one-time sign-in link hashes, session-token hashes, expiry and revocation timestamps, and a temporary session token in your browser tab's session storage. We use them to verify access and protect account settings. Sign-in links expire after 15 minutes and can be used once; sessions expire after 14 days or when signed out.
- API credentials: key hashes, identifying prefixes, key type, configured allowed domains, and creation or revocation timestamps. Full keys are shown when issued; the key database stores hashes rather than the full keys.
- Usage: request counts by account, UTC day, and endpoint category. We use these to understand usage and operate the service.
- Support: information you include in email or an artwork correction request. We use it to answer questions, verify requests, and resolve issues. Do not send secret API keys or unnecessary personal information.
Hosting and service providers
Cloudflare provides the website and API infrastructure through Workers, D1, and R2. Network requests necessarily provide technical information, such as an IP address and requested URL, to the hosting infrastructure. API Worker invocation logs are persisted to Cloudflare's dashboard at 100% sampling; the request-log view includes request time, method, host and path, status, cache information, IP address, and country. Under our current Workers Free plan, Cloudflare retains Workers Logs for 3 days. Cloudflare D1 Time Travel is always enabled and provides a 7-day restore window, so deleted database records may remain in recovery history during that period. Workers Logs details · D1 Time Travel details.
Google Workspace processes messages sent to or from our support mailbox. Automatic email/chat deletion is disabled for inbox and archived messages. Messages in Trash or Spam are permanently deleted after 30 days unless emptied sooner. Gmail deletion and recovery details.
Resend sends account sign-in emails on our behalf and processes the recipient email address and message needed to deliver the link. Sign-in messages are sent only to email addresses already enabled for beta access. See Resend's privacy policy.
Use secret API keys in Authorization headers on your server, not URL query strings. URLs can appear in infrastructure logs and browser history. Publishable keys are intended for image URLs.
Browser storage
The website uses local storage to remember your catalog background choice (bm-bg), terms acknowledgement (bm-terms-ack), waitlist signup (bm-joined), and when you dismissed the access prompt (bm-join-dismissed). A dismissal suppresses the prompt for 14 days; the stored value itself is not automatically removed after that period. These preferences remain in your browser until cleared or replaced. You can remove them using your browser's site-data controls.
Retention and removal
During beta, account, waitlist, and usage retention is managed manually; these records do not currently have an automatic expiry schedule. To request removal, email brands@brandmarks.dev from the address you used for access and explain what you want removed.
We may need to verify ownership before changing access or removing records. Revoking a key is separate from deleting account or usage records. Active database removal does not immediately erase provider logs, recovery copies, or support correspondence; we will explain the scope of a completed request and any remaining records. Our manual process does not promise a general deletion deadline; this does not limit any deadline or process required by applicable law.
Your questions and requests
Contact brands@brandmarks.dev to ask about your information, request corrections or deletion, or stop access-related email. Privacy rights and obligations depend on the laws that apply to your situation; this notice does not limit rights provided by applicable law.
Public company artwork and brand-owner removal requests follow the separate claim or correct a logo process. Removing an API account does not remove a company's public artwork.
Updates
We will update this notice when the service's data practices change. The date above identifies this version.