
Is my brand kit secure?
Brand kits are proprietary assets. ReBrandIt Studio treats palettes and tokens as confidential by design.
Brand kit JSON lives in Cloud SQL on Google Cloud with encryption at rest and encrypted API connections. Workspaces are isolated so kits cannot be listed across organizations.
You authenticate with a magic link and HttpOnly session cookie. Logout clears the API cookie and the mirrored product-origin cookie used for premium exports, and bumps a server-side token version.
Share links use unguessable tokens—treat them like passwords. From Settings you can export all kits or delete your account to erase kits, share links, and branding while we retain contact and billing for legal obligations.
Daily automated backups support recovery.
When you use optional features, content may briefly leave GCP. This post is our published subprocessor list:
- Google Cloud Platform — https://cloud.google.com/
- Stripe — https://stripe.com/
- Brevo — https://www.brevo.com/
- Mailgun — https://www.mailgun.com/
- pdf.co — https://pdf.co/
- Google Gemini — https://ai.google.dev/
- Perplexity — https://www.perplexity.ai/
- ElevenLabs — https://elevenlabs.io/
- Brand kits encrypted at rest and org-scoped
- HttpOnly sessions with logout revocation
- Share links are capability URLs—handle carefully
- Download or erase business data in Settings