Brand Passport

Privacy in the private beta.

Updated 9 September 2026. This notice describes the current private preview, not a publicly launched commercial service.

What the app stores

Your sign-in identifier, brand names, domains, account ownership details, email-address records, checklist progress, templates and an activity record of changes are saved to your workspace. The application does not request or intentionally store account passwords, TOTP secrets, or backup codes. Do not paste secrets into notes.

Access and infrastructure

Sign-in is provided through ChatGPT and this preview is hosted through OpenAI Sites on Cloudflare infrastructure. Data access is scoped to the signed-in user. Service operators may have technical access needed to operate the preview. No third-party marketing analytics are configured.

Email and retention

When managed email is connected, Resend receives email for your managed addresses. Brand Passport stores sender, recipient, subject, message content and attachment names, and forwards message content to the verified inbox you select. Attachments remain with Resend. Message content becomes inaccessible after 30 days and is cleared on subsequent mail processing or inbox access. Other brand records remain until you delete the brand. Minimal message-ID records remain to prevent deleted mail from reappearing after webhook retries. Deleting a brand removes its Passport and application activity records; copies may remain in infrastructure backups according to the hosting provider’s retention practices.

Your controls

Export a Passport from its header, edit records in the app, or delete a brand in Brand settings. Templates can be deleted independently. For help, contact the person who provided access to this private preview.

Before public launch

The operator’s legal identity and contact details, applicable data-processing terms and retention procedures must be finalised before opening this service to public customers.

← Back to home