Offbrand.ai Privacy Policy
Last Updated: August 26, 2026
This Privacy Policy explains how Offbrand.ai LLC collects, uses, discloses, retains, and protects information when you visit our website, use our platform, interact with our services, or communicate with us.
Offbrand.ai provides an AI-powered brand operations platform for businesses. Our Services help companies monitor, review, analyze, improve, and create customer-facing brand, marketing, sales, and content materials.
This Privacy Policy applies to our website, application, platform, AI agents, dashboards, reports, artifacts, integrations, communications, and related services.
For purposes of this Privacy Policy:
“Offbrand,” “we,” “us,” and “our” mean Offbrand.ai LLC.
“Customer,” “you,” and “your” mean the business entity, agency, reseller, organization, or other customer using the Services.
“Services” means the Offbrand.ai website, application, platform, AI agents, software, dashboards, reports, recommendations, integrations, generated artifacts, scheduled tasks, and related products or services.
“Customer Content” means materials, documents, files, text, images, guidelines, rules, URLs, prompts, data, instructions, feedback, and other information that Customer or its authorized users upload, submit, connect, provide, or make available through the Services.
“Customer Data” means account information, usage information, integration data, metadata, user information, and other information processed by the Services on behalf of Customer.
“AI Outputs” means reports, findings, recommendations, rewritten content, summaries, artifacts, brand observations, compliance observations, risk flags, content suggestions, scoring, drafts, and other AI-assisted outputs generated by the Services.
“Personal Information” means information that identifies, relates to, describes, or can reasonably be linked to an individual.
By using the Services, you acknowledge this Privacy Policy.
1. Business Use Only
Offbrand is designed for business use. The Services are not intended for personal, household, or consumer use.
If you use the Services on behalf of a company, agency, client, or other organization, your organization is responsible for ensuring that it has provided any required notices and obtained any required rights, permissions, consents, or legal bases to provide information to Offbrand.
2. Information We Collect
We collect information in several ways, including information provided directly by users, information uploaded or connected by Customers, information collected automatically, and information received from third-party integrations.
2.1 Account and Contact Information
We may collect:
Name
Business email address
Company name
Job title or role
Phone number
Account login information
User profile information
Billing contact information
Admin and authorized user information
Customer support information
Communications with us
2.2 Customer Content
Customers and authorized users may upload, connect, submit, or make available Customer Content through the Services.
Customer Content may include:
Brand guidelines
Campaign documents
Website URLs
Marketing materials
Social content
Emails
CRM data
Audience personas
Compliance rules
Product information
Customer-facing content
Internal business documents
Sales enablement materials
Operational materials
Other brand, marketing, sales, or business materials
Customer is responsible for ensuring that Customer Content is lawful, authorized, and appropriate for use with the Services.
2.3 Customer Data and Platform Usage Information
We may collect information about how Customers and authorized users interact with the Services, including:
Login activity
Account settings
User permissions
Feature usage
Reports generated
Artifacts created
Scheduled tasks
AI agent activity
Prompts, instructions, and user inputs
Approval, edit, and feedback activity
Error logs
System logs
Performance data
Metadata associated with Customer Content or AI Outputs
2.4 Integration Data
If Customer connects third-party services to Offbrand, we may collect and process information from those connected services as authorized by Customer.
Third-party integrations may include:
Slack
HubSpot
Google Drive
Google Calendar
CRM systems
Websites
Social platforms
Digital asset management systems
Email systems
Analytics tools
Other third-party platforms
The information we access depends on the integration, permissions, account settings, and Customer’s configuration.
Customer is responsible for configuring third-party integrations and permissions appropriately.
2.5 Website, Device, and Technical Information
When you visit our website or use the Services, we may automatically collect:
IP address
Browser type
Device type
Operating system
Referring pages
Pages viewed
Date and time of visit
Session information
Clickstream data
Approximate location derived from IP address
Cookie and tracking information
Usage analytics
Performance and diagnostic information
2.6 Communications and Support Information
If you contact us, request a demo, submit a support request, respond to a survey, join a call, or communicate with us, we may collect:
Contact details
Message content
Support tickets
Call notes
Feedback
Survey responses
Sales communications
Customer success communications
2.7 Payment and Billing Information
We may collect billing-related information, including:
Billing name
Billing email
Company billing details
Subscription plan
Invoice history
Payment status
Tax information
Transaction metadata
Payment card details may be processed by third-party payment processors. We do not intentionally store full payment card numbers on our own systems.
3. Sources of Information
We may collect information from:
Customers
Authorized users
Account administrators
Uploaded documents and files
Connected integrations
Websites submitted for review
Third-party services authorized by Customer
Publicly available sources
Sales and support interactions
Analytics and usage tools
Service providers
4. How We Use Information
We use information to provide, operate, secure, maintain, and improve the Services.
This includes using information to:
Create and manage accounts
Authenticate users
Provide the Services
Generate reports, recommendations, summaries, artifacts, and other AI Outputs
Run AI agents and automated workflows
Build and maintain customer-specific brand memory
Perform brand reviews, content reviews, compliance observations, and risk checks
Process Customer Content and Customer Data as instructed by Customer
Connect and operate integrations
Provide dashboards and scheduled tasks
Respond to support requests
Communicate with Customers
Send administrative notices
Process billing and payments
Monitor usage and performance
Debug errors
Improve reliability and security
Prevent fraud, abuse, misuse, and unauthorized access
Analyze product usage
Improve the Services
Develop new features
Enforce our Terms of Service
Comply with legal obligations
Protect Offbrand, Customers, users, third parties, and the public
5. AI Processing
Offbrand uses AI systems to provide the Services. Customer Content and Customer Data may be processed by AI systems to generate AI Outputs, including reports, recommendations, summaries, rewritten content, artifacts, observations, scores, and suggested actions.
Offbrand may use Customer Content and Customer Data to:
Generate customer-specific AI Outputs
Configure customer-specific AI agents
Build and maintain customer-specific brand memory
Analyze customer-facing content
Identify potential brand or compliance issues
Recommend edits or improvements
Support customer-specific workflows
Improve the customer-specific experience
Offbrand will not use Customer Content, Customer Data, Slack data, or Brand Memory to train third-party foundation models.
Offbrand will not use Customer Content, Customer Data, Slack data, or Brand Memory to train Offbrand’s own general models, systems, or features in a manner that benefits other customers.
Offbrand may use aggregated, anonymized, or de-identified data derived from use of the Services for analytics, benchmarking, security, operational improvement, product development, and business purposes, provided that such data does not identify Customer, Customer’s users, Customer’s clients, or Customer’s confidential information.
5.1 Google Workspace API Data
Offbrand’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs, including Google Calendar and Google Drive, will adhere to the Google User Data Policy, including the Limited Use requirements.
Google Workspace API data is used only to provide and improve the user-facing features the user connected it for. Google Calendar data is read only, is used only to prepare the connecting user for their own upcoming meetings, and is delivered only to that user. Google Drive data is limited to the files the user selects.
When Google Workspace API data is processed by an AI model to provide these features, it is sent to Anthropic’s API under Anthropic’s commercial terms, which do not permit Anthropic to train models on that data. Offbrand does not transfer Google Workspace API data to any AI service that uses it to create, train, or improve generalized machine learning or artificial intelligence models, does not use it for advertising, and does not sell it.
AI Outputs may be inaccurate, incomplete, duplicative, or unsuitable for a particular use. Customers are responsible for reviewing, editing, validating, approving, and legally clearing AI Outputs before publishing, distributing, relying on, or taking action based on them.
6. How We Share Information
We may share information with the categories of recipients described below.
6.1 Service Providers and Subprocessors
We may share information with vendors, service providers, contractors, and subprocessors that help us operate the Services, including providers of:
Cloud hosting
AI processing
Data storage
Analytics
Security
Customer support
Email delivery
Payment processing
Product infrastructure
Logging and monitoring
Error tracking
Sales and customer management
Communication tools
These providers are authorized to use information only as necessary to provide services to us or as otherwise permitted by law or contract.
6.2 Customer-Authorized Integrations
If Customer connects third-party services to Offbrand, information may be shared with or accessed from those services as authorized by Customer.
Third-party integrations are governed by their own terms, privacy policies, data practices, and security practices.
6.3 Within Customer Accounts
Customer administrators and authorized users may access information associated with their organization’s account, including Customer Content, Customer Data, AI Outputs, reports, user activity, and integration information, depending on permissions and account settings.
6.4 Legal, Compliance, and Safety Purposes
We may disclose information if we believe disclosure is necessary or appropriate to:
Comply with applicable law
Respond to legal process
Enforce our Terms of Service
Protect the rights, property, or safety of Offbrand
Protect Customers, users, third parties, or the public
Detect, prevent, or address fraud, security, or technical issues
Investigate misuse or unauthorized activity
Respond to government or regulatory requests
6.5 Business Transfers
We may disclose or transfer information in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar business transaction.
6.6 Professional Advisors
We may share information with lawyers, accountants, auditors, insurers, bankers, and other professional advisors where reasonably necessary.
6.7 Aggregated, Anonymized, or De-Identified Data
We may share aggregated, anonymized, or de-identified data that does not identify Customer, Customer’s users, Customer’s clients, or Customer’s confidential information.
7. Third-Party Services and Integrations
The Services may allow Customer to connect third-party services, including Slack, HubSpot, Google Drive, CRM systems, websites, social platforms, digital asset management systems, email systems, analytics tools, and other platforms.
Customer controls whether to connect third-party services and what permissions to grant.
Offbrand is not responsible for third-party services, including their availability, security, data practices, permissions, settings, outages, errors, or changes to APIs.
Customer should review the privacy policies and terms of any third-party services it connects to Offbrand.
7.1 Google API Services User Data Policy
Offbrand's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Offbrand requests only the narrowest Google scopes its features require:
Google Drive (drive.file): access is limited to the individual files a user explicitly selects through the Google Picker. Offbrand cannot see, list, or open any other file in the user's Drive, and does not request broad Drive access.
Google Calendar (calendar.readonly): read-only access to the connected user's calendar events, used to prepare that user for upcoming meetings. Offbrand does not create, modify, or delete calendar events.
Basic profile email (userinfo.email): used only to identify which account is connected and to show it back to the user.
Google user data obtained through these scopes is used solely to provide and improve the user-facing features that the connecting user requested. Specifically:
We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
We do not sell Google user data, and we do not use it to serve advertising of any kind.
We do not transfer Google user data to others except as necessary to provide or improve the user-facing features the user requested, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to affected users. Where a service provider processes Google user data on our behalf in order to deliver a requested feature, that provider is bound by obligations consistent with the Limited Use requirements.
We do not allow humans to read Google user data unless we have the user's affirmative agreement for specific messages or files, it is necessary for security purposes such as investigating abuse, it is necessary to comply with applicable law, or the data has been aggregated and anonymized for internal operations.
A user may disconnect a Google account at any time from within the Offbrand application, which revokes Offbrand's stored credentials for that account. A user may also revoke Offbrand's access directly at https://myaccount.google.com/permissions.
7.2 Storage and Retention of Google User Data
What Offbrand stores from Google depends on the feature the connecting user enabled. Offbrand does not copy a user's Google Drive or Google Calendar into its own systems.
Google Calendar: Offbrand stores a limited record of upcoming events relevant to preparing the connected user for a meeting, covering when the meeting is and which outside organization it involves. Most events are discarded when read and are never stored, including events the user has not accepted and events the user has marked private. Offbrand does not store participant email addresses and does not store event descriptions. These records cover upcoming events only and are maintained while the calendar remains connected.
Google Drive: when a user selects a file through the Google Picker, Offbrand reads that file and stores information derived from its contents so that it can be reviewed and, if approved by a member of the Customer's team, retained as part of that Customer's brand knowledge. Offbrand does not store a copy of the file itself. Information derived from a selected file belongs to the Customer's account and is retained after the individual user disconnects Google. It may be removed by the Customer at any time, or by a deletion request under Section 9. Where Offbrand reads a Drive file only to answer a question a user has asked, that content is used to produce the answer and is not retained.
Effect of disconnecting: disconnecting a Google account stops all further access to that account, and the meeting records derived from that user's calendar are retired and then deleted or de-identified in accordance with Section 9. Information already derived from Drive files the Customer's team selected remains part of the Customer's brand knowledge and is retained and deleted in accordance with Section 9.
8. Cookies and Similar Technologies
We may use cookies, pixels, local storage, software development kits, and similar technologies to operate, secure, analyze, and improve our website and Services.
These technologies may be used to:
Keep users signed in
Remember preferences
Operate the Services
Measure website and product usage
Understand how visitors interact with our website
Improve performance
Detect errors
Protect against fraud or misuse
Support marketing or sales analytics
You may be able to control cookies through your browser settings. Disabling cookies may affect the functionality of the website or Services.
If we use advertising cookies, retargeting pixels, or similar marketing technologies, we may provide additional notices or choices where required by law.
9. Data Retention
We retain information for as long as reasonably necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, prevent fraud, maintain security, and keep legitimate business records.
Unless otherwise stated in a written agreement, Offbrand will delete or de-identify Customer Content within a commercially reasonable period after the earlier of:
Account cancellation
Subscription expiration
Account termination
Written deletion request from Customer
Sustained account inactivity for 90 days
For purposes of this Privacy Policy, “sustained account inactivity” means no login, active subscription, active integration, active scheduled task, active report generation, active support request, active billing relationship, or other meaningful account activity for 90 consecutive days.
Deletion may not be immediate and may not include:
Backup copies retained for a limited period
Security logs
Billing records
Legal records
Dispute records
Fraud prevention records
Aggregated, anonymized, or de-identified data
Data retained as required by law
Data stored by third-party services or integrations outside Offbrand’s control
Offbrand may, at its discretion, provide Customer with a reasonable opportunity to export certain Customer Content or AI Outputs after cancellation, termination, or expiration where technically feasible and commercially reasonable. Offbrand does not guarantee that data export will be available after account access ends.
10. Data Security
We use commercially reasonable administrative, technical, and organizational measures designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.
These measures may include access controls, authentication, encryption where appropriate, vendor controls, monitoring, logging, and internal policies.
No system, network, software, AI tool, or data transmission is completely secure. We cannot guarantee absolute security.
Customer is responsible for maintaining appropriate security controls for its own systems, accounts, credentials, users, integrations, and devices.
If you believe your account or information has been compromised, contact us at team@offbrand.ai.
11. Sensitive Information
The Services are not designed to process highly sensitive information unless Offbrand expressly agrees in a separate written agreement.
Customers should not upload, submit, connect, or otherwise provide:
Passwords
API keys
Authentication tokens
Private keys
Secrets
Government identification numbers
Social Security numbers
Driver’s license numbers
Passport numbers
Payment card data
Bank account information
Protected health information
Sensitive personal information
Children’s data
Biometric data
Precise geolocation data
Consumer credit information
Regulated financial account data
Data subject to heightened legal or contractual restrictions
Any data requiring a business associate agreement, special security addendum, or similar legal arrangement unless one has been executed
If a specific customer engagement requires sensitive or regulated data, Customer and Offbrand must enter into an appropriate written agreement, such as a data processing agreement, business associate agreement, security addendum, or other required document.
12. Customer Responsibilities for Personal Information
Customer is responsible for ensuring that it has all required rights, notices, permissions, consents, and legal bases to provide Personal Information to Offbrand.
Customer is responsible for:
Determining what information to upload, submit, or connect to the Services
Configuring integrations and permissions
Providing required privacy notices to its users, employees, contractors, clients, prospects, and other individuals
Obtaining required consents or legal bases
Responding to privacy rights requests where Customer is the controller or business
Ensuring that Customer Content and Customer Data comply with applicable law
Avoiding prohibited sensitive information unless separately authorized in writing
Where Offbrand processes Personal Information on behalf of Customer, Customer is generally responsible for determining the purposes and means of processing, and Offbrand processes such information on Customer’s behalf and in accordance with Customer’s instructions, the Terms of Service, this Privacy Policy, and any applicable data processing agreement.
13. Privacy Rights and Requests
Depending on where you are located and the nature of your relationship with Offbrand, you may have certain rights regarding Personal Information, such as the right to:
Access Personal Information
Correct inaccurate Personal Information
Delete Personal Information
Obtain a copy of Personal Information
Opt out of certain processing activities
Restrict or object to certain processing activities
Withdraw consent where processing is based on consent
Appeal a denied request where applicable law provides such a right
To submit a privacy request, contact us at team@offbrand.ai.
Because Offbrand primarily provides B2B services, some Personal Information may be processed on behalf of a Customer. If we process your information on behalf of one of our Customers, we may refer your request to that Customer or ask you to contact the Customer directly.
We may need to verify your identity or authority before fulfilling a request.
We will respond to privacy requests as required by applicable law.
14. State Privacy Notices
Certain U.S. state privacy laws may provide residents with additional rights. These rights may include access, correction, deletion, portability, and opt-out rights.
Where applicable, Offbrand will honor state privacy rights as required by law.
California
If the California Consumer Privacy Act or related California privacy laws apply, California residents may have rights to know, access, correct, delete, and opt out of certain uses or disclosures of Personal Information.
Offbrand does not sell Personal Information in the traditional sense. Offbrand does not use Customer Content, Customer Data, Slack data, or Brand Memory to train third-party foundation models or Offbrand’s general models for the benefit of other customers.
If Offbrand uses cookies or similar technologies that may be considered “sharing” under California law, Offbrand may provide additional notices or choices where required.
Other States
Residents of states such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, New Jersey, Tennessee, and other states may have additional privacy rights if applicable state laws apply to Offbrand.
To exercise privacy rights, contact team@offbrand.ai.
15. International Users
Offbrand is based in the United States. If you access the Services from outside the United States, your information may be transferred to, stored in, or processed in the United States or other jurisdictions where we or our service providers operate.
These jurisdictions may have data protection laws that differ from those in your location.
If Offbrand serves customers in jurisdictions requiring additional data protection terms, such as the European Economic Area, United Kingdom, or Switzerland, Offbrand may enter into appropriate data processing terms, standard contractual clauses, or other required transfer mechanisms as applicable.
16. Children’s Privacy
The Services are not intended for children. We do not knowingly collect Personal Information from children under 13 or from individuals under the age required by applicable law.
Customers may not use the Services to knowingly upload, process, or submit children’s data unless expressly authorized in a separate written agreement.
If we learn that we have collected Personal Information from a child without appropriate authorization, we will take reasonable steps to delete it.
17. Marketing Communications
We may use business contact information to send product updates, newsletters, event invitations, sales communications, and other marketing communications.
You may opt out of marketing emails by using the unsubscribe link in the email or by contacting team@offbrand.ai.
Even if you opt out of marketing communications, we may still send transactional, administrative, billing, legal, security, or service-related messages.
18. Publicity and Customer Logos
As described in our Terms of Service, Offbrand may use Customer’s name, logo, and trademarks in customer lists, websites, pitch decks, marketing materials, sales materials, investor materials, case studies, and other promotional materials to identify Customer as a customer of Offbrand.
Customer may opt out of future public logo use by providing written notice to team@offbrand.ai.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
If we make material changes, we will use commercially reasonable efforts to provide notice, such as by posting the updated Privacy Policy on our website or within the Services, updating the “Last Updated” date, or sending notice by email or in-app notification.
Offbrand will not materially change its data-use or model-training commitments in a way that expands Offbrand’s rights to use Customer Content, Customer Data, Slack data, or Brand Memory without appropriate notice and, where required, Customer consent.
Your continued use of the Services after an updated Privacy Policy becomes effective means you acknowledge the updated Privacy Policy.
20. Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact us at:
Offbrand.ai LLC
Email: team@offbrand.ai