Contracting party#
| Contracting party | Imad Idrissi, trading as Brownbox (eenmanszaak) |
| Trading name | Brownbox |
| Website | https://usebrownbox.com |
| Legal form | Eenmanszaak (Dutch sole proprietorship) |
| Registered office | Makreelstraat 24, 3192 AM Hoogvliet Rotterdam, the Netherlands |
| KvK | 84236361 |
| VAT / BTW | NL003931061B13 |
| Privacy | privacy@usebrownbox.com |
| Abuse | abuse@usebrownbox.com |
| Copyright / IP | copyright@usebrownbox.com |
| Legal | legal@usebrownbox.com |
| Security | security@usebrownbox.com |
| Support | support@usebrownbox.com |
This Privacy Policy explains how we process personal data. It is not the Terms of Service. Commercial rules (plans, Generations, refunds, cancellation) live in the Terms and Refund Policy — not here.
Consent vs contract: Accepting the Terms is acceptance of a contract. Reading this Privacy Policy is transparency, not a blanket GDPR consent. Cookie and marketing consents — when required — are collected separately.
Who we are and our role#
The data controller is Imad Idrissi, trading as Brownbox, a Dutch sole proprietorship (*eenmanszaak*) registered with the Netherlands Chamber of Commerce (KvK) under trade name Brownbox (KvK 84236361, VAT NL003931061B13), with registered office at Makreelstraat 24, 3192 AM Hoogvliet Rotterdam, the Netherlands.
For privacy correspondence: privacy@usebrownbox.com.
Supervisory authority: Autoriteit Persoonsgegevens (AP) is Brownbox's competent supervisory authority in the Netherlands — https://autoriteitpersoonsgegevens.nl. You may also lodge a complaint with your local EU/EEA supervisory authority.
Brownbox's GDPR role depends on who decides the purposes and essential means of processing — not on labels in a contract alone.
| Processing | Typical role | Who is usually the data subject |
|---|---|---|
| Account creation, authentication, Terms acceptance | Controller | The Account holder |
| Billing, subscriptions, credit ledger, tax records | Controller | The Account holder / payer |
| Platform security, abuse prevention, rate limiting | Controller | Account holders and visitors |
| Brownbox legal compliance and dispute handling | Controller | Relevant individuals |
| Hosting and processing Customer Content (prompts, uploads, generated assets, Brand Kit, catalogue data) to deliver the Service at a business customer's direction | Processor | Customer's staff, models, talent, and others depicted in Customer Content |
| Trust & safety review of reported or flagged content | Controller (limited, independent purpose) or Processor (where acting on customer instructions) | Depends on context |
Self-serve and business customers: When you use Brownbox for your own commercial purposes and upload content about other people (models, talent, staff, or people appearing in reference imagery), you are typically the controller for their personal data and Brownbox acts as your processor for that Customer Content. You must have a lawful basis and, where required, provide notices and obtain permissions before uploading such content.
Data Processing Agreement (DPA): Where GDPR Article 28 requires a processor agreement, our standard B2B Terms incorporate a DPA for Customer Content processing. Enterprise customers may request a signed copy at privacy@usebrownbox.com. This does not replace your own obligations toward people whose data you upload.
Scope and data-subject categories#
This Policy covers personal data processed when you:
- visit or use the Brownbox website or application;
- create an Account, join a Workspace, or use generation, Brand Kit, Products, Models, presets, campaigns, settings, or support;
- pay or manage subscriptions or credit packs via Stripe;
- contact us about privacy, security, or support; or
- appear in content uploaded or imported by a Brownbox customer.
Data-subject categories include:
| Category | Description |
|---|---|
| Account Users | People who register or sign in to Brownbox |
| Workspace Users | Account Users invited to a Workspace (owners, editors, viewers) |
| Identifiable persons in Customer Content | Models, talent, staff, or others whose image or personal data appears in uploads, imports, or generated outputs |
| People in scraped or imported material | Individuals whose personal data may appear in publicly accessible website content, screenshots, or catalogue imports you submit |
| Website visitors | People who browse marketing pages or interact with essential site functions |
| Payment contacts | Billing email and details provided to Stripe |
This Policy does not replace privacy notices of third-party services you open directly (e.g. Stripe Checkout, Google sign-in).
Personal data we collect directly (Article 13)#
We collect the following categories from you or your device when you use the Service:
Email address, password hash (managed by our auth provider — we do not store plaintext passwords), display name, optional avatar, authentication identifiers, session tokens, Terms acceptance metadata, Google OAuth identifiers when you choose Google sign-in, and signup anti-bot verification data.
Free-text prompts, mode and quality settings, brief fields, and prompt-enhancement inputs and outputs.
Product references, lifestyle references, logos, and other files you upload, stored in private cloud storage with access controls. Upload flows may record likeness or rights attestations where required.
AI-generated images and related metadata stored in private storage buckets.
Product records you create or import, including names, SKUs, descriptions, gallery images, and external identifiers. Shopify (and similar) connection metadata applies only if you enable the integration.
Brand kit fields, URLs you submit for analysis, and extracted or scraped page content, screenshots, logos, and derived brand settings processed through our import pipelines.
Model or talent images and metadata you add to the Models library, and related attestations where collected.
Membership, roles, invites, shoots, turns, campaigns, saved items, presets, and collaboration activity.
Balance events, plan tier, and entitlement state.
Stripe customer identifier, subscription and invoice references. Card and bank details are processed by Stripe — Brownbox does not store full card numbers.
Messages you send to support or privacy@usebrownbox.com, and transactional email preferences. Marketing or newsletter email is not part of the current product path; if introduced, it will use a separate opt-in.
Application and infrastructure logs, abuse-enforcement state, short-lived IP-based rate-limit signals for public endpoints, and error diagnostics where we operate monitoring for reliability and security.
See Cookie Policy. Current posture: essential-only — no non-essential analytics or marketing cookies unless we introduce a consent mechanism.
Personal data we receive indirectly (Article 14)#
We may receive personal data without collecting it directly from the data subject, including when:
- a customer uploads photos or contact data of models, talent, staff, or other identifiable persons;
- people appear incidentally in reference imagery, product shots, or lifestyle content uploaded by a customer;
- Brand Kit or catalogue import processes publicly accessible website content, screenshots, or third-party catalogue data that contains personal data;
- a Workspace owner invites someone by email address; or
- integrations (e.g. Shopify) sync product or contact data you authorise.
For identifiable persons who did not sign up to Brownbox: When a customer uploads your personal data, that customer is typically the controller and must have a lawful basis under Article 6 (and Article 9 where applicable) and must provide Article 14 transparency where required. Those are separate obligations. Brownbox generally processes such Customer Content as processor under our DPA and relies on the customer for upstream lawfulness and transparency.
If Brownbox later processes the same data for its own controller purposes (for example limited trust & safety or legal compliance), we assess Article 6, Article 14 (including any applicable exceptions), and safeguards separately.
If you believe your personal data was processed through Brownbox without a proper basis, contact privacy@usebrownbox.com or abuse@usebrownbox.com. We aim to respond within one month, subject to identity verification and legal limits.
Sources: The uploading or importing Account holder; publicly accessible websites you submit for import; connected third-party services you authorise; and AI or scrape subprocessors acting on our or your instructions.
Purposes and lawful bases (GDPR Article 6)#
Lawful bases apply per processing activity and data subject. We do not use our contract with a customer as an automatic Article 6(1)(b) basis for processing third persons who are not parties to that contract.
| Purpose | Typical data | Lawful basis |
|---|---|---|
| Create and manage accounts; authenticate; enforce Terms | Account, session | Art. 6(1)(b) — contract with you |
| Provide generation, storage, workspace, Brand Kit, and catalogue features for your own Account | Your prompts, uploads, outputs | Art. 6(1)(b) — contract with you |
| Process payments, subscriptions, credit packs; maintain ledger | Billing, ledger | Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation (tax/accounting) |
| Transactional service email | Email, preferences | Art. 6(1)(b) contract |
| Prevent abuse, fraud, and bot signups | IP (short window), security signals | Art. 6(1)(f) legitimate interests (security and integrity of the Service); Art. 6(1)(b) where necessary to perform the contract safely |
| Respond to privacy, support, and security requests | Correspondence | Art. 6(1)(b) / (c) / (f) as applicable |
| Establish, exercise, or defend legal claims; comply with law | Relevant subsets | Art. 6(1)(c) / (f) |
| Marketing email (if introduced later) | Art. 6(1)(a) consent — separate from Terms | |
| Non-essential cookies or analytics (not used at launch) | Identifiers | Art. 6(1)(a) consent |
Legitimate interests (where used): keeping the platform secure, preventing signup and credit abuse, maintaining service reliability, and communicating about the service you use. You may object under Article 21 — see §12.
When a business customer uploads personal data about models, talent, or other identifiable persons, the customer is typically the controller and must identify its own lawful basis (commonly consent, contract with the model, or legitimate interests with appropriate balancing). Brownbox processes that content as processor under the customer's instructions and our DPA.
Brownbox may additionally act as controller for limited trust & safety, legal-compliance, and abuse-handling processing of such content, typically under Art. 6(1)(f) (security and legal compliance) or Art. 6(1)(c) (legal obligation).
Special-category and biometric data (Article 9)#
Uploading a photograph of a person is not automatically processing of biometric data under GDPR. Biometric data in the GDPR sense arises when specific technical processing enables unique identification or authentication of a natural person.
Brownbox sends reference images and prompts to third-party AI systems for image generation and analysis. Brownbox does not operate a product feature that creates, stores, or matches persistent facial templates or biometric identifiers for identifying or authenticating natural persons.
Certain quality or fidelity checks may compute short-lived image embeddings (vector representations of an image) to compare a generated result against a customer-supplied product reference. Those embeddings are used for quality control of the generation job, are not used as a facial recognition or identity-matching database, and are not retained as reusable biometric templates for later identification of people.
Customer Content may incidentally reveal special-category information (e.g. health, ethnicity, religion, sexual orientation) visible in images or text. Customers must not upload special-category data unless they have an Article 9 condition and our written agreement where required. See Likeness & Model Policy.
Third-party AI providers may apply their own safety or abuse systems to content we send them; those systems are governed by the provider's terms and our Subprocessors disclosures.
- We treat model/talent images as personal data and apply access controls, deletion workflows, and subprocessors agreements.
- We do not intentionally collect biometric templates.
- If we introduce features involving biometric identification or systematic special-category inference, we will update this Policy, perform required assessments, and obtain an Article 9 condition where required before launch.
AI processing and providers#
To generate images or analyse brand and product inputs, we send relevant prompts, recipes, and (where the selected path supports it) reference images to third-party AI providers. Active and conditional providers are listed in our Subprocessors register.
Brownbox does not use your prompts, reference images, or generated assets to train Brownbox-owned foundation models. Any future optional improvement programme would be off by default, clearly disclosed, and require explicit opt-in or an enterprise contract term.
Provider behaviour is governed by their terms, the commercial API product we use, and our configuration. The table below summarises the production paths Brownbox operates as of this Policy's last update.
| Provider | Service (typical) | Training on API inputs | Retention / monitoring (typical) |
|---|---|---|---|
| Google (Gemini API) | Default image generation; brand-scrape and prompt-enhance LLM | Under Google's paid Gemini API / Generative Language API terms for applicable commercial services, prompts and responses are not used to improve Google products | Google may retain certain API logs for abuse monitoring (Google documents periods on the order of weeks for relevant Gemini API logging). Brownbox does not control Google's internal monitoring systems. |
| OpenAI | Optional image generation and scrape/enhance fallback | Under OpenAI's API data-usage policies, API inputs are not used to train OpenAI models by default | OpenAI may retain certain API content for a limited period (commonly up to about 30 days) for abuse monitoring under its standard API terms. Brownbox does not currently enable a separate zero-data-retention arrangement for self-serve traffic. |
| Fal.ai | Optional / failover image profiles (e.g. FLUX) | Governed by Fal's terms and DPA for client personal data | Brownbox configures Fal so request inputs and outputs are not persisted beyond inference. Brownbox stores its own copy in private EU storage. Temporary delivery URLs may exist briefly while Brownbox downloads the result. |
Human review: Support or trust-and-safety staff may access content on a need-to-know basis to handle abuse reports, legal requests, or tickets you open.
Review outputs before commercial use. If you need specific zero-retention or no-training contractual commitments from providers, contact us about enterprise arrangements — public self-serve use follows the provider configurations described above.
Storage, recipients and international transfers#
- Primary database and file storage: Supabase, region eu-central-1 (Frankfurt, Germany).
- Application hosting: Vercel (global edge/CDN).
- AI, payments, email, monitoring, scrape helpers, and integrations: may process in the EEA, UK, US, or other countries.
We do not promise EU-only residency for all processing.
Where personal data is transferred outside the EEA or UK to a country without an adequacy decision, we rely on appropriate safeguards, which may include:
| Recipient (summary) | Typical locations | Transfer mechanism |
|---|---|---|
| Supabase | EU primary (eu-central-1); global support possible | EEA processing for primary storage; EU Standard Contractual Clauses in the vendor DPA where transfers occur |
| Vercel | Global edge | EU Standard Contractual Clauses; vendor DPA |
| Google (Gemini / OAuth) | US / global | EU Standard Contractual Clauses; EU–US Data Privacy Framework for certified Google entities where applicable |
| OpenAI | US / global | EU Standard Contractual Clauses; vendor DPA |
| Fal.ai | US / global | EU Standard Contractual Clauses; Fal DPA for client personal data |
| Stripe | US / EU entities | EU Standard Contractual Clauses; Stripe DPA; adequacy or EU–US Data Privacy Framework where applicable to the receiving entity |
| Firecrawl, Resend, Sentry, Shopify, screenshot helpers | Vendor-dependent | EU Standard Contractual Clauses and/or vendor DPA where required; see Subprocessors |
Brownbox maintains internal transfer assessments for material US vendors. You may request a summary of applicable safeguards by contacting privacy@usebrownbox.com.
Retention#
Retention periods below are policy targets aligned with our systems and Dutch legal obligations. Backup cycles and provider-side retention may extend availability briefly after deletion triggers.
| Data category | Retention |
|---|---|
| Account / profile | Life of Account; after deletion request, 30-day grace period, then hard delete or anonymisation |
| Prompts, shoots, turns, jobs | Until you delete the content or complete account deletion |
| Reference uploads and generated images (Brownbox copy) | Until you delete the asset, Workspace purge, or account deletion |
| Brand kit, products, models, presets | Until deleted by you or account purge |
| Credit ledger | Life of Account plus 7 years after final transaction for Dutch tax and accounting compliance (amounts may be anonymised where feasible after account closure) |
| Stripe billing records | Per Stripe retention plus 7 years for Dutch bookkeeping (certain records may require 10 years — we retain per applicable tax law) |
| Support / privacy correspondence | 3 years after case closure unless a legal hold or longer statutory period applies |
| Security and infrastructure logs | 90 days operational retention unless an incident investigation requires longer |
| In-memory IP rate-limit data | Minutes (sliding window) |
| AI provider copies | Per provider retention (see §7.2); may outlive Brownbox copies under the provider's standard abuse-monitoring terms |
| Infrastructure backups | Rolling backup cycles; deleted data may persist until backup expiry (typically up to 30 days on primary infrastructure) |
Legal holds: We may pause deletion to preserve evidence for disputes, abuse investigations, or legal obligation. Holds are limited in scope and duration.
Account deletion does not automatically erase Stripe records we must keep for tax and finance, nor does it create a commercial refund — see Refund Policy.
Children and minors#
You must be 18+ (or the age of digital consent in your country, if higher) to create a Brownbox Account. We do not knowingly collect personal data from children for Account registration. Contact privacy@usebrownbox.com if you believe a minor created an Account.
Customers must not upload, generate, or use imagery of minors in violation of our Acceptable Use Policy and Likeness & Model Policy. If we become aware of prohibited child imagery, we will act under those policies and applicable law, which may include removal, account action, and reporting to authorities where required.
If you believe a minor's personal data was processed through Brownbox without authorisation, contact privacy@usebrownbox.com or abuse@usebrownbox.com.
Your rights#
Subject to legal limits, you may exercise the following rights under GDPR and similar laws:
| Right | How to exercise |
|---|---|
| Access / copy | In-app data export (Settings) or email privacy@usebrownbox.com |
| Rectification | Account Settings or email |
| Erasure | Settings → Account deletion, or email — see §13 |
| Restriction | Email privacy@usebrownbox.com |
| Portability | In-app export (JSON or ZIP archive) |
| Object (Art. 21) | Email — especially for legitimate-interest processing |
| Withdraw consent | Where processing is consent-based (e.g. future marketing) |
| Complaint | AP or your local supervisory authority |
Response time: We aim to respond within one month (extendable by up to two further months for complex requests, as permitted by Article 12 GDPR).
Identifiable persons who are not Account holders: If your data was uploaded by a customer, we may need to verify your identity and coordinate with the customer where they are the controller. We will still assist within our role and legal obligations.
Data export
Signed-in Account holders can export their data from Settings → Privacy & data (JSON or ZIP). Download links for bundled assets expire after approximately one hour.
Account deletion
- Self-serve Account deletion (product path): Settings → Account → Delete account (requires confirmation). This starts a 30-day recovery/grace period during which login is disabled and you may contact support to cancel the deletion if the product still supports recovery. After the grace period, we permanently purge Account data as described below.
- By email: privacy@usebrownbox.com from your Account email with subject "Account deletion request".
GDPR erasure (Article 17)
An Article 17 erasure request is legally distinct from voluntary Account deletion. Email privacy@usebrownbox.com with subject **GDPR ERASURE — Article 17. We handle valid erasure requests without undue delay (and within one month under Article 12, extendable as permitted), subject to legal exceptions (for example tax retention, legal claims, and freedom of expression limits). We will not** force a valid Article 17 request through a 30-day recovery delay where that would unlawfully postpone erasure of data that must be erased. Where a recoverable Account-deletion path is used instead, we will explain the difference and offer the irreversible erasure path when requested.
After confirmed erasure or completed Account purge: auth, profile, Workspace content, and storage assets under our control are deleted or anonymised; ledger rows may be anonymised where retention law requires; provider residual copies may remain briefly under their terms. We confirm by email when complete, subject to legal holds.
Automated decision-making (Article 22)#
We use automated systems that can affect your access to the Service, including:
- signup and generation rate limits;
- prompt blocklists and provider safety filters;
- abuse-state flags that may suspend generation or access;
- billing entitlement checks that may block purchases or generation when payment fails; and
- automated content-policy blocks from AI providers.
These are generally security, fraud-prevention, and contract-performance controls, not marketing profiling. They are not intended to produce legal or similarly significant effects solely by automated means without human involvement.
Significant enforcement (such as account suspension) may be reviewed by staff on request via support@usebrownbox.com or privacy@usebrownbox.com. If Article 22 applies to a specific decision, we will provide the additional information and rights required by law.
Security and personal-data breaches#
We implement technical and organisational measures including TLS encryption in transit, private storage with access controls, workspace isolation, authenticated server-side functions, password requirements, signup abuse prevention, and log scrubbing.
No method is perfectly secure. Report suspected vulnerabilities to security@usebrownbox.com.
Breach notification:
- When Brownbox is controller, we assess personal-data breaches and notify the AP within 72 hours where required, and affected individuals when the breach is likely to result in a high risk to their rights and freedoms.
- When Brownbox is processor, we notify the relevant customer controller without undue delay after becoming aware of a personal-data breach affecting Customer Content, and assist with regulatory and individual notifications as required by our DPA and Article 28 GDPR.
Changes to this Policy#
We update this Policy when processing changes materially. The version and "Last updated" fields will change. For material adverse changes affecting existing users, we provide prominent in-app or email notice where appropriate. Terms re-acceptance is separate from Privacy Policy updates.
Separation from Terms#
- Terms = contract (acceptable use, IP, liability, billing).
- Privacy = personal-data transparency and rights.
- Cookies = storage inventory and consent posture.
- Refunds and pricing are not governed by this Privacy Policy.
Business customers and DPA#
Business customers processing personal data through Brownbox must ensure a valid Article 28 DPA is in place for Customer Content. Our Data Processing Agreement is incorporated into the Terms by reference for all Customers and governs Brownbox's processor role for Customer Content. All Customers under that DPA receive prior notice and objection rights for new Subprocessors (DPA §8). Signed enterprise copies with custom schedules: privacy@usebrownbox.com.
Brownbox remains an independent controller for account, billing, and platform security data even when it processes Customer Content as processor.
Contact#
| Privacy / data-subject requests | privacy@usebrownbox.com |
| Security incidents / vulnerabilities | security@usebrownbox.com |
| Abuse / unauthorised content | abuse@usebrownbox.com |
| General support | support@usebrownbox.com |
| Registered office | Makreelstraat 24, 3192 AM Hoogvliet Rotterdam, the Netherlands |
| Supervisory authority | Autoriteit Persoonsgegevens — autoriteitpersoonsgegevens.nl |