Back

Privacy policy

Effective Date: January 1, 2026 | Last Updated: August 24, 2026

At Brand Peel (operated by MerginIT e.U.), we believe your intellectual property, brand assets, and product vision belong to you. We design our software with a local-first architecture, meaning your files and projects remain stored on your machine.

1. Data controller information

The data controller responsible for the processing of personal data in connection with this website and the Brand Peel desktop application pursuant to Article 4(7) of the General Data Protection Regulation (GDPR) is:

MerginIT e.U.
Owner: Jonas Fröller
Nußböckstraße 92
4060 Leonding
Austria (European Union)
Telephone: +43 6643279885
Email: support@brandpeel.app / jonas@merginit.com
Commercial Register: Landesgericht Linz (FN 654298 d)

2. Local-first desktop architecture & data storage

The Brand Peel desktop application stores your project databases, brand strategy documents, conversation histories, design token configurations, Sandbox sessions, and exported assets locally on your hard drive.

  • No Cloud Sync Required: We do not mirror your local brand files, typography rules, or exported code to central servers.
  • Data Ownership: You retain 100% ownership and copyright of all generated copy, brand books, design tokens, and exported artifacts.

3. AI processing & zero model training policy

When you explicitly trigger AI-assisted features (such as discovery chat, logo concept generation, or Sandbox prototyping):

  • Ephemeral Transmission: Only the specific prompt, attached references, and relevant project context are transmitted to our secure backend proxy via TLS-encrypted connections (HTTPS).
  • No AI Model Training: Brand Peel does NOT use your prompts, uploaded attachments, or brand documents to train, fine-tune, or improve artificial intelligence foundation models.
  • Retention: Inputs and outputs are processed ephemerally in memory to fulfill your request. Operational metadata (e.g., timestamp, token counts, and credit allowance usage) is logged to manage billing quotas.

4. Website visiting data & server logs

When you access https://brandpeel.app, our hosting infrastructure automatically processes technical connection data necessary to deliver the web pages securely:

  • IP address (anonymized/truncated where feasible)
  • Date, time, and timezone of access
  • Requested URI path and HTTP status code
  • User-Agent header and browser identification
  • Referrer URL (if supplied by your client)

The legal basis for this processing is our legitimate interest pursuant to Art. 6(1)(f) GDPR in ensuring website availability, network security, and defense against malicious attacks or scraping abuse.

5. Cookie-free marketing & privacy-preserving analytics

The marketing website https://brandpeel.app does not use third-party tracking cookies or advertising pixels. We do not sell, rent, or monetize your personal information under any circumstances.

6. User accounts & payment processing

If you purchase a paid subscription (such as Brand Peel Pro), checkout and recurring billing are processed securely by our authorized merchant of record, Polar (Polar Software Inc.). Payment card information is handled directly by PCI-DSS certified processors. MerginIT e.U. does not receive or store your credit card numbers.

7. Your rights under the GDPR

As an individual in the European Union or European Economic Area, you hold extensive rights under Chapter III of the GDPR:

  • Right of Access (Art. 15 GDPR): You have the right to obtain confirmation as to whether personal data concerning you is being processed and to receive a copy of that data.
  • Right to Rectification (Art. 16 GDPR): You have the right to request the correction of inaccurate or incomplete personal data.
  • Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): You have the right to request the deletion of your personal data when it is no longer necessary.
  • Right to Restriction of Processing (Art. 18 GDPR): You have the right to request the restriction of processing under certain legal conditions.
  • Right to Data Portability (Art. 20 GDPR): You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to Object (Art. 21 GDPR): You have the right to object to processing based on legitimate interests at any time.

To exercise any of these rights, contact us at support@brandpeel.app. We will respond within the statutory one-month period.

8. Supervisory authority

If you believe that the processing of your personal data violates data protection regulations, you have the right to lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR. The competent supervisory authority in Austria is:

Österreichische Datenschutzbehörde (DSB)
Barichgasse 40–42
1030 Vienna
Austria
Website: https://www.dsb.gv.at

9. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our desktop application features, public API endpoints, or legal requirements. Updates will be posted on this page with an updated revision date.