Privacy Policy
Last updated: March 13, 2026
1. Introduction
This Privacy Policy describes how Rob van Baaren ("Company", "we", "us", or "our"), operating brag.fast from Oldenzaal, Netherlands, collects, uses, and protects your personal data when you use our Service.
By using the Service, you agree to the collection and use of information in accordance with this policy.
2. Data We Collect
Personal Data
When you create an account, we collect:
- Email address
- Name (if provided)
- Authentication provider information (e.g. Google account)
- Hashed password (if using email/password authentication)
Usage Data
We automatically collect:
- IP address (used for signup rate limiting)
- Browser type and version
- Pages visited and time spent
- Device identifiers
- API usage data (requests, credits consumed, timestamps)
Content You Provide
When using the Service, you may submit:
- Brand assets (logos, colors, website URL, font preferences)
- Template configurations (layout, styling, image references)
- Release content (text, image URLs, metadata strings)
- Webhook URLs for delivery notifications
This content is processed solely to generate your images and operate the Service.
3. Legal Basis for Processing (GDPR Art. 6)
We process your personal data on the following legal bases:
- Contract performance — to provide the Service, manage your account, process payments, and generate images (Art. 6(1)(b))
- Legitimate interest — to prevent abuse, enforce rate limits, maintain security, and improve the Service (Art. 6(1)(f))
- Legal obligation — to retain billing records and comply with tax and accounting requirements (Art. 6(1)(c))
4. How We Use Your Data
We use your personal data to:
- Provide, maintain, and improve the Service
- Manage your account and subscription
- Process payments via Stripe
- Authenticate your identity and API requests
- Send service-related communications (billing, usage alerts, outages)
- Enforce rate limits and prevent abuse (including IP-based signup rate limiting)
- Deliver webhook notifications to URLs you provide
- Comply with legal obligations
We do not sell your personal data. We do not use your data for advertising purposes.
5. Cookies and Tracking
We use essential cookies only, to maintain your session and authentication state. These cookies are strictly necessary for the Service to function and do not require consent under the ePrivacy Directive.
We do not currently use analytics cookies or third-party tracking. If this changes, we will update this policy and obtain your consent where required.
6. Third-Party Service Providers
We share data with the following third-party processors to operate the Service:
- Convex — database and backend services. Stores your account data, brands, templates, releases, and API key hashes.
- Stripe — payment processing. Stripe collects and processes payment information under their own privacy policy. We share your email and user ID with Stripe to manage your subscription.
- Cloudflare — CDN and image hosting (R2 storage). Generated images and uploaded logos are stored on Cloudflare R2.
- Vercel — application hosting and infrastructure.
These providers process your data only as necessary to perform their services and are contractually obligated to protect it.
7. Webhooks and External Delivery
If you provide a webhook URL when creating a release, we will send a notification to that URL upon completion. The data delivered includes the release ID and status. You are responsible for the security of your webhook endpoints.
8. API Key Security
API keys are stored as SHA-256 hashes. We never store your API key in plaintext after initial generation. The full key is shown to you only once at creation time.
9. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service.
- Account data — deleted within 30 days of account deletion, except where retention is required by law.
- Generated images — stored on Cloudflare R2 and deleted when your account is deleted. CDN caches may persist briefly after deletion.
- Uploaded logos — stored on Cloudflare R2 and deleted when the brand is updated or your account is deleted.
- Billing records — retained for up to 24 months for accounting and compliance purposes.
- Rate limit data — transient; deleted upon account deletion.
10. International Data Transfers
Your data may be processed on servers located outside the European Economic Area, including in the United States (Convex, Cloudflare, Vercel, Stripe). These transfers are protected by:
- EU-U.S. Data Privacy Framework certifications where applicable
- Standard Contractual Clauses (SCCs) approved by the European Commission
11. Your Rights (GDPR)
If you are in the European Economic Area, you have the following rights:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your personal data
- Restriction — request restriction of processing
- Portability — request your data in a machine-readable format
- Object — object to processing based on legitimate interest
- Withdraw consent — where processing is based on consent, withdraw it at any time
To exercise any of these rights, contact us at privacy@brag.fast. We will respond within 30 days.
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
12. Account Deletion
You may delete your account at any time through the Service. Upon deletion, we will:
- Cancel any active Stripe subscriptions immediately
- Delete all releases, templates, brands, and API keys from our database
- Remove all generated images and uploaded logos from Cloudflare R2
- Delete your user profile and rate limit records
Billing records may be retained as described in the Data Retention section.
13. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption in transit (TLS)
- Secure authentication via session tokens
- SHA-256 hashing of API keys
- Access controls and data isolation per user
- Ownership verification on all data queries
However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
14. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Dutch Data Protection Authority within 72 hours of becoming aware. If the breach is likely to result in a high risk to you, we will also notify you directly without undue delay.
15. Children's Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will delete it promptly.
16. Third-Party Links
The Service may contain links to third-party websites. We are not responsible for the privacy practices of these sites. We encourage you to review their privacy policies.
17. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. For significant changes that affect your rights, we will make reasonable efforts to notify you by email.
Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
18. Contact
For privacy-related questions or to exercise your data rights, contact us at:
privacy@brag.fast
Rob van Baaren
Oldenzaal, Netherlands