Privacy Policy
Effective date: August 21, 2026
Brixa Studio ("we", "us") is a design service by BRIXA that you use through your AI
assistant and through our website at brixastudio.com. This policy explains what data we
collect, why, where it lives, and what your rights are. We keep it short because the
truth is short: we collect what the service needs to work, and nothing else.
1. What we collect
- Account data — your email address and, if you sign in with Google or
GitHub, the name and email those providers share. Passwords are handled and stored by our
authentication provider (Supabase); we never see or store them ourselves.
- Your content — the brand assets (logos, colors, texts), photos,
templates and generated images you create or upload while using the service. It is yours;
we store it so the service can show it back to you and render your designs.
- Technical data — standard server logs (IP address, timestamps,
request paths) used for security and troubleshooting.
- Webhook secrets — if you connect a live-data source, we generate a
secret that authenticates deliveries from your system. It is shown to you once, stored
on our side to verify incoming data, and you can rotate it at any time (the old one
stops working immediately).
1b. What you can choose to make public
- Published pieces — publishing a piece is opt-in and gives it a
permanent public URL: anyone with the link can view that image. You can unpublish at
any time (a CDN copy may persist for about a minute).
- Community templates — sharing a template publishes only its
SKELETON (layout and declared slots). Before publishing, we block private library
assets and ask you to review every example text that would travel with it. Your
generated pieces and their contents never travel.
2. What we do NOT do
- We do not sell your data. To anyone. Ever.
- We do not show ads or share your data with advertisers.
- We do not use your designs or brand assets to train AI models.
- We do not read your conversations with your AI assistant — see section 4.
3. Where your data lives (subprocessors)
- Supabase — database, authentication and file storage.
- Fly.io — application hosting.
- Resend — transactional email (account verification, password reset).
We never send marketing email without your consent.
- Google / GitHub — only if you choose to sign in with them.
4. About AI assistants
You use Brixa Studio by talking to an AI assistant (such as Claude or ChatGPT). Your
conversation happens on that platform, under that platform's own privacy policy — we only
receive the specific requests the assistant sends to our service (for example "save this
template" or "generate this image"), authenticated with your account.
5. Retention and deletion
We keep your data while your account is active. If you want your account and its content
deleted, email us at support@brixa.ai and we will delete it.
6. Security
All traffic is encrypted (HTTPS). Access to your content is enforced per-account at the
database level (row-level security): each account can only see its own projects.
7. Your rights
You can ask us to access, correct, export or delete your personal data at any time by
writing to support@brixa.ai. If you are in the EU/EEA, these
rights are guaranteed by the GDPR and you may also lodge a complaint with your local data
protection authority.
8. Changes
If this policy changes, we will update this page and its effective date. Material changes
will be announced by email.