Brandid — Privacy Policy
Brandid keeps nothing. Here's the paperwork proving it.
The short version
Brandid runs entirely in your browser. Every logo, photo, brand board, colour, PDF and export is processed on your own computer. Nothing you put into it ever reaches us. We have never seen your work and we never will.
No accounts, no logins, no uploads, no analytics, no tracking pixels, no cookies set by Brandid, no "phone home" of any kind. The tool would work on an aeroplane with the Wi-Fi off after it has loaded once.
Wherever you live — UK, EU, USA (including California), Australia, or anywhere else — you have privacy rights, and they apply to us. In practice there is almost never anything for us to exercise them on, because we hold almost nothing. This policy explains that in full.
1. Who publishes Brandid
Brandid is published by Modern Media Mastery, a business based in Sydney, New South Wales, Australia. "We", "us", and "our" in this policy refer to Modern Media Mastery in that capacity.
For the purposes of the UK GDPR and EU GDPR, we are the data controller for any personal information Brandid touches. For the purposes of the Australian Privacy Act 1988, we are the APP entity.
2. What Brandid does — and what it never does
Brandid is a single HTML file. Everything it does — extracting a colour palette from your brand board, rendering fifteen social-media sizes from your logo, watermarking your product photos, stamping PDFs, tracing SVGs, building the ZIP you download — happens inside your browser tab, on your own device.
In practical terms, Brandid does not:
- Upload your logos, photos, brand boards, PDFs, colours, exports or any other content to any server
- Have accounts, sign-ins or a database — there is nothing to sign into
- Include analytics, telemetry, error reporting or session-recording of any kind
- Set cookies
- Store fingerprints, IDs, or anything else in your browser that could identify you
- Load advertising scripts, tags, pixels or third-party trackers
- Send anything anywhere once the page has loaded
The technical consequence is straightforward: we could not disclose or delete your Brandid work if we wanted to. We have never seen it. You are its only custodian, and it exists only on the device you created it on until you export it.
3. What loading the Brandid page does touch
If you use Brandid at brandidnetwork.com, loading that page produces the same ordinary web-server records that visiting any website produces. Specifically:
- Server logs
- Your IP address, browser user-agent, page requested, timestamp, and referring page — automatically logged by our web host to keep the site running securely and to diagnose problems. Retained for up to 30 days, then deleted or aggregated.
- CDN requests for tool libraries
- Brandid uses three open-source libraries — pdf-lib (PDF generation), JSZip (ZIP creation), and PDF.js (PDF reading) — served from a public content delivery network (currently cdnjs.cloudflare.com). Your browser fetches them from the CDN the first time you load Brandid, and the CDN sees only your IP address and the file it is serving. It does not see any of your Brandid content, because your content only ever exists inside your browser tab.
That is the complete list of what a page load touches. We do not use: analytics, tag managers, ad networks, session recorders, third-party trackers, fingerprinting scripts, embedded video players, or A/B-testing tools.
4. Cookies and browser storage
Brandid does not set cookies. Full stop. There is no cookie banner because there is nothing to consent to.
Brandid also does not currently write to localStorage, sessionStorage, IndexedDB, or any other browser storage — every piece of state lives only in the memory of the current tab. Close the tab and it is gone. If we ever add opt-in local persistence (for example: "remember my accent colours between sessions"), it will be plainly labelled, off by default, and never sent anywhere.
5. Third-party libraries
Brandid depends on the following open-source libraries, loaded once from a CDN when you open the tool:
- pdf-lib — used to generate the Brandid Guide PDF and stamp your own PDFs. Runs entirely in your browser.
- JSZip — used to build the Download ZIP and read logo ZIPs you drop in. Runs entirely in your browser.
- PDF.js — used to read PDFs you drop in as brand boards. Runs entirely in your browser.
- Google Fonts (Montserrat) — the tool's default typeface, loaded from Google's CDN. Google sees your IP address on that one request; it never sees Brandid content.
None of these providers receive anything about how you use Brandid or what you create in it. Each is chosen because it processes on your device rather than theirs.
6. Running Brandid offline or from a download
Brandid is a single HTML file. If you save it to your computer and open it from disk — or drop it on a USB stick and open it there — you skip the web-server visit entirely. In that mode, the only network activity is the initial fetch of the CDN libraries the first time your browser needs them; after they cache, Brandid runs fully offline.
If you host Brandid on your own site or intranet, none of your users' activity reaches us either. This policy still describes accurately what Brandid the tool does with data (nothing), but the "page load" section above will then be a matter for whoever operates the server you are hosting it on.
7. Your rights — by jurisdiction
Wherever you live, if we hold personal information about you, you can ask us to see it, correct it, or delete it by writing to us (see contact). Almost every time you ask, the answer will be that we hold none — because Brandid was built specifically to avoid holding any. Below is a jurisdiction-specific summary of what the law entitles you to regardless.
United Kingdom & European Union — UK GDPR / EU GDPR
You have the right to:
- Access any personal information we hold about you.
- Rectification — correct inaccuracies.
- Erasure ("right to be forgotten") — ask us to delete your data, where the law allows.
- Restriction — pause our processing while a query is resolved.
- Portability — receive your data in a common, machine-readable format.
- Objection — object to processing based on legitimate interests, including any direct marketing.
- Withdraw consent at any time where processing is based on consent, without affecting past lawful processing.
- Not to be subject to automated decision-making with legal effect — we do not do this.
- Complain to a supervisory authority:
- UK — the Information Commissioner's Office (ICO), ico.org.uk
- EU — the data protection authority in your member state (list at edpb.europa.eu)
Lawful basis for the little we do process: the 30-day server logs and CDN request records described above are processed on the basis of our legitimate interest in running and securing the tool. There is no other processing to have a lawful basis for.
We respond to rights requests within one month.
California — CCPA / CPRA
If you are a California resident, you have the right to:
- Know what categories of personal information we have collected, the sources, the purposes, and the categories of third parties we have shared with.
- Delete personal information we have collected, subject to legal exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of your personal information — we do neither, so there is nothing to opt out of. If that ever changes we will provide a "Do Not Sell or Share My Personal Information" link at the top of every page, as CPRA requires.
- Limit use of sensitive personal information — we do not collect sensitive PI.
- Non-discrimination — we will not punish you (denial of service, worse pricing, degraded features) for exercising these rights.
What we collect that could count as personal information under CCPA: internet activity in the form of the server logs and CDN request records described above — that is, your IP address and browser user-agent during a page visit. We collect no other categories. Purpose: to run and secure the tool. Retention: 30 days. Sold or shared for cross-context behavioural advertising: no, and never.
To exercise these rights, email us — see contact. We verify requests using at least two data points before acting.
Other US states — VCDPA (VA), CPA (CO), CTDPA (CT), UCPA (UT), and similar
Residents of Virginia, Colorado, Connecticut, Utah, and states with comparable comprehensive privacy laws generally have the right to:
- Confirm whether we are processing your personal data, and access it
- Correct inaccuracies
- Delete personal data provided by or obtained about you
- Obtain a portable copy of your data
- Opt out of targeted advertising, sale, or profiling with legal effect — we do not do any of these
To exercise these rights, email us — see contact. We respond within 45 days.
Australia — Privacy Act 1988 & the Australian Privacy Principles
Under the APPs you can:
- Access the personal information we hold about you (APP 12).
- Correct it if it is inaccurate, out-of-date, incomplete, irrelevant, or misleading (APP 13).
- Deal with us anonymously or by pseudonym where practicable (APP 2) — this is Brandid's default.
- Be notified of collection and of the reasons why (APP 5) — this policy is that notice.
- Complain to us first; if unresolved, to the Office of the Australian Information Commissioner (OAIC), oaic.gov.au.
We respond to APP requests within 30 days.
Everywhere else
If your local law gives you privacy rights not listed above, write to us and we will do our best to honour them.
8. Security
The tool is served over HTTPS with modern TLS. The CDN and hosting providers we rely on have their own security controls. Nonetheless — no online service can promise absolute security. If a breach ever occurs that could affect your rights (which, given the almost-nothing we hold, would in practice mean the server logs), we will notify you and the relevant regulator within the timeframes required by the law that applies to you — 72 hours under UK/EU GDPR; as soon as practicable under the Australian Notifiable Data Breaches scheme.
Your Brandid content is protected simply by never leaving your device. The strongest security posture is not collecting the data in the first place.
9. Children
Brandid is not directed at children. We do not knowingly collect personal information from anyone under 16 (or under 13 for US residents, in line with COPPA). If you believe a child has provided us information, please contact us and we will delete it.
10. Changes to this policy
If we make material changes, we will update the "Last updated" date at the top of this page. Continued use of Brandid after a change means you accept the updated policy. Previous versions are available on request.
11. Contact us
For anything privacy-related — a rights request, a question, a concern — write to us:
Modern Media Mastery
Sydney, New South Wales, Australia
Email: privacy@brandidnetwork.com