Privacy Policy
Last updated: October 6, 2026
BrandStack ("we", "us") is operated by Winter Advisory LLC. This policy explains what BrandStack collects when you use the website at www.brandstack.org or the BrandStack iOS app, how we use it, and the choices you have.
The short version
- BrandStack reads your Gmail to find mail from brands and stores: offers, receipts, order confirmations, subscription notices and similar messages. Unless you switch it off, it also files the brand mail it is confident about into a "BrandStack" label, out of your inbox. It never sends email as you, never permanently deletes anything, and never files personal mail.
- You can connect more than one Gmail inbox to one BrandStack account.
- We keep only mail we classify as commercial. Personal mail is skipped, and for skipped mail we keep only its Gmail message id so we do not fetch it again.
- BrandStack uses one AI model, TypeSafe's Jev, through OpenRouter, and you agree to this when you set up your account. Jev gets the sender, subject and preview text of shopping mail the built-in rules can't place; the brand, subject and preview text of offer emails, with the names of items you saved; the part of a receipt that lists the amounts; and each sender's brand name and domain. It uses these to keep what isn't shopping out of BrandStack, pick order totals, categorize brands and rank the offers that matter. Jev never receives full email bodies.
- We do not sell your data, show ads, or share your Gmail data with anyone except the service providers listed below.
- You can delete your account and all its data from Settings at any time.
What we collect
From your Google account, when you sign in
- Your name, email address and profile picture.
- Permission to read your Gmail and change its labels (the
gmail.modifyscope), for the account you sign in with and any other inbox you add. This scope cannot send mail or permanently delete it. Google gives us an access token and a refresh token for each inbox. We store the refresh tokens on BrandStack's server, encrypted with AES-256-GCM under a key held only in the server's environment, so new mail can be sorted and filed while the app is closed. We revoke an inbox's tokens with Google when you remove that inbox, disconnect Gmail or delete your account.
From your Gmail
For mail we classify as commercial (from brands and stores), we store:
- sender name, address and domain, subject line and Gmail's short snippet;
- what we extract from it: offers, order numbers, order totals, subscription details (price, how often it renews, the next date, the store's manage link), whether it is a receipt, order or promotion, and whether it is unread;
- the Gmail message and thread ids;
- links to the pictures in the email (the brand's logo, product photos and order line-item thumbnails) and where the email linked them. We store the links, not the images. The app loads them through BrandStack's own server, so the brand sees our server's request, not your device or IP address. Brand site icons are loaded the same way, from Google's public icon service by the brand's domain.
We read the rest of the message text only while sorting it and do not store it.
For senders BrandStack doesn't show (banks, software, travel and other non-stores), we keep at most the 20 most recent messages, which is what we need to recognize the sender; older ones are deleted and kept only as skipped ids.
For mail we skip (personal, unreadable or not commercial), we store only the Gmail message id and the reason it was skipped, never its content.
What you create in BrandStack
Lists of saved items, tiers you set for a brand, subscriptions you mark as cancelling or not a subscription, and when you finished setting up.
Operational records
A record of each sync (when it ran, how many messages it looked at, whether it succeeded). Our server logs requests by route and result only; our hosting providers also keep standard request logs, which can include IP address and request time. We do not use analytics, advertising or tracking tools.
Filing brand mail out of your inbox
Inbox filing is on by default. About every 15 minutes, even when the app is closed, BrandStack looks at new mail in each connected inbox. When it is confident a message is from a store you shop with (a brand BrandStack shows, and the message is a campaign or an automated order, shipping or loyalty email), it makes three label changes in Gmail: it marks the message read, removes it from the inbox (archives it), and adds a label called "BrandStack" so you can find it there.
It never files personal email (1:1 or group mail), sign-in or security codes, payment or delivery problems, mail that needs you to act, or anything you starred. It files each message once: if you move a message back to your inbox, BrandStack leaves it alone. It never sends, replies to or forwards mail, and it never moves mail to the trash or permanently deletes it.
To stop or undo it:
- Turn it off: Settings, then "Keep brand email out of my inbox". When you turn it off you can choose to move every message it filed back to your inbox, or leave them in the label.
- Hide a brand: that brand's filed mail moves back to your inbox. The same happens if BrandStack stops showing a sender.
- In Gmail: move any message back to the inbox yourself; BrandStack won't file it again.
Removing an inbox or deleting your account stops filing; messages already filed stay in that inbox's BrandStack label.
How we use it
Only to provide BrandStack's features to you:
- show the brands you hear from, their offers, your purchases, spend and subscriptions;
- show you offers, renewals and changes that matter, and keep everything up to date as new mail arrives;
- file brand mail out of your inbox, as described above, unless you turn it off;
- keep the service secure and working (preventing abuse, fixing errors).
We do not use Gmail data for advertising, we do not sell it, and we do not use it to train generalized AI or machine-learning models.
Google API Services: Limited Use
BrandStack's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular: we use Gmail data only to provide and improve the user-facing features described above; we transfer it only to the service providers below, as needed to provide those features, to comply with law, or as part of a merger or acquisition with notice to you; people at BrandStack do not read your mail unless you ask us to for support, it is needed for security or to comply with law, or the data has been aggregated and anonymized for internal operations.
Who processes your data for us
| Provider | What they do | Data involved |
|---|---|---|
| Sign-in and the Gmail API | Your Google account and mail in each connected inbox | |
| Vercel (USA) | Hosts the website and app pages | Session cookie, request logs |
| Railway (USA) | Hosts our server and database | Everything we store, listed above |
| TypeSafe (USA) | Its Jev model filters shopping mail, picks receipt totals, categorizes brands and ranks offers | Sender, subject and preview text of mail the rules can't place; brand name, subject, preview text and received date of offer emails; the amounts section of receipts (up to 700 characters); each sender's brand name and domain; the names of items you saved |
| OpenRouter (USA) | Routes those requests to TypeSafe | The same data, in transit |
Nothing goes to TypeSafe or OpenRouter until you agree to this during setup. If you agreed to an earlier version of this text, BrandStack asks you to agree again before anything more is sent. TypeSafe processes the data under its data processing terms and does not train its models on it. OpenRouter does not keep prompts or responses unless an account opts in to logging.
How long we keep it
We keep your data while you use BrandStack, and delete your account and all its data automatically:
- if you never finish setting up, BrandStack holds no Gmail connection for you, and you don't come back for 30 days;
- if Google access to your account is revoked and you don't open BrandStack for 30 days;
- if you don't open BrandStack for 12 months.
When you delete your account, we delete your profile, stored mail, brands, purchases, subscriptions, saved lists, sync records and skipped-message ids straight away, and revoke BrandStack's access to your Google accounts. We keep a one-way hash of your Google user id and the deletion time, so a session still open on another device cannot recreate the account. Our database has no scheduled backups; a backup taken before maintenance is deleted within 30 days. Sync records (counts of messages checked and any error) are deleted after 30 days, except the most recent one, which we keep until the account is deleted.
Your choices
- Remove an extra inbox: Settings, then Remove next to the inbox. We revoke access to it and delete the mail we stored from it; brands that came only from that inbox go away.
- Turn off inbox filing: Settings, as described above.
- Delete your account: Settings, then Delete account. This deletes everything listed above.
- Revoke Gmail access: at any time at myaccount.google.com/permissions. BrandStack then stops syncing and asks you to reconnect.
- Access or correct your data: BrandStack shows what we store. For a copy or a question, email andrew@winteradvisory.llc.
If you live in the EEA, the UK or California you have rights to access, correct, delete and port your data and to object to processing. We honor them for everyone. We process your data to provide the service you asked for and to keep it secure. We do not sell or share personal information as those terms are defined under California law.
Security
Data is encrypted in transit (HTTPS to our website and to Google). Calls between our website and our server use short-lived signed tokens, and our server reaches its database over our hosting provider's private network. Google refresh tokens are encrypted at rest.
Children
BrandStack is not for children under 13 (or the minimum age in your country) and we do not knowingly collect their data.
Changes
If we change this policy in a way that matters, we will tell you in the app before the change takes effect.
Contact
Winter Advisory LLC · andrew@winteradvisory.llc