Privacy Policy
Last updated September 4, 2026
What we collect, why we collect it, and who else sees it. Written to be read, not to be survived.
1. Who handles your data
BRND Creative Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States, is the controller of the personal data described here. Write to support@brnd.company about anything on this page.
2. What we collect
- Account: your email address, your altr.bio address, and your sign-in method.
- Source material: the public posts, captions, and comments from the accounts you connect, so your ALTR can learn your voice. We fetch these through Apify from the platform you named.
- Conversations: the messages fans send to an ALTR and the replies it writes. Creators see aggregate counts by default; reading an identified fan’s history is a separate, paid action.
- Money: gift and message records, your balance, and the last four digits and brand of a card. Stripe holds the full card number — we never receive it.
- Payout details: the bank account you give us for payouts, stored encrypted. Identity and tax documents go to Stripe, not to us.
- Technical: a hashed version of your IP address, a coarse country derived from it, browser and device type, and pages viewed.
- Support: what you write to us when you ask for help or file a report.
3. Why we use it
We do not sell your personal data, and we do not use your conversations to train our own models.
- To run the service you asked for — building your ALTR, letting fans talk to it, showing your page.
- To take payments and pay you out.
- To keep the place safe: filtering messages, checking age and identity signals, acting on reports, catching fraud.
- To fix what breaks and to understand which parts of the product people use.
- To meet legal obligations, including tax reporting and answering lawful requests.
4. Who else sees it
We use these providers to run the service. Each one only gets what its job needs, and each is bound by contract to use it for nothing else.
- Amazon Web Services — hosting, storage, and the Bedrock model service (United States and Asia Pacific).
- Anthropic, OpenAI, and Google — language and image models that generate ALTR replies and media. Prompts and the conversation context are sent to them to produce a reply.
- Stripe — payments, payouts, identity and tax collection.
- Apify — fetching the public posts from the social accounts you connect.
- Sentry — error reports, so we can fix crashes.
- Mixpanel — product analytics on how the service is used.
5. What happens when an ALTR answers
When a fan sends a message, we send that message, recent conversation context, and the material that defines the persona to one of the model providers above. The provider returns a reply, which we filter and then show.
The reply is generated. It is not written by the creator, and we do not check it for truth.
6. How long we keep it
- Account and persona data: while your account is open, then deleted within 30 days of closure.
- Conversations: while the ALTR is live, then deleted within 30 days of its deletion.
- Payment and payout records: seven years, because tax and accounting law requires it.
- Technical logs: 90 days.
- Backups age out on their own schedule, within 35 days of deletion.
7. Your rights
You can ask us for a copy of your data, ask us to correct it, ask us to delete it, or ask us to stop a particular use. Write to support@brnd.company and we will answer within 30 days.
Depending on where you live you may also have the right to complain to a data protection authority, and to object to processing or ask us to restrict it. Residents of California may ask what we disclosed and to whom; we do not sell or share personal information as those words are defined there.
Deleting your account deletes your ALTR and your conversations. It does not delete the payment records we must keep.
8. Children
The service is for adults. We do not knowingly collect data from anyone under 18. If you believe a minor is using altr.bio, write to support@brnd.company and we will act.
9. Where your data goes
We process data in the United States and in the Asia Pacific region. If you are in the European Economic Area, the United Kingdom, or Korea, your data is transferred to those places under the standard contractual clauses or an equivalent lawful mechanism.
10. How we protect it
Traffic is encrypted in transit. Payout bank details are encrypted at rest with a key held outside the database. IP addresses are hashed before they are stored. Access to production data is limited to the people who need it and is logged.
No system is perfect. If a breach affects you, we will tell you and the relevant authority as the law requires.
12. Changes
When this policy changes we update the date at the top, and we tell you on the site before a material change takes effect.
13. Contact
BRND Creative Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States.
Privacy questions and reports both reach one inbox: support@brnd.company