What we collect, who else touches it, and how to make us delete it. Specific enough to check.
V3Ads LLC is the controller of the personal data described here. This policy covers brdgy.com and the Brdgy application. It is written to be verified rather than trusted: where we say we do not do something, it is because the system does not do it.
This is the complete list. Brdgy has no forms, integrations or scripts that gather anything beyond it.
| What | Why it exists |
|---|---|
| Email address | It is your account. It is also where sign-in codes and service notices go. |
| IP address, at sign-in only | Recorded against each sign-in code request so that codes can be rate-limited per address and per network. It is not attached to your account, not used to build a profile, and not logged as you use the product. |
| What you type in — workspace and offer names, descriptions, features, benefits, and any document you upload to a workspace | It is the input the product works from. Usually business information rather than personal data, but whatever you put there, we hold. |
| What Brdgy generates — audiences, messaging angles, campaigns, assets, audit scores | So it is there when you come back, and so a later run can avoid repeating an audience you already have. |
| Usage records — which engine ran, when, which model answered, token counts and what the call cost us | Metering your plan, and letting us price honestly from real costs rather than guesses. |
| Billing records — plan, status, billing period, and your Stripe customer and subscription identifiers | Knowing what you are entitled to without calling Stripe on every request. |
| Stripe event records — the payment events Stripe sends us | So a duplicate is not processed twice, and so there is evidence if a payment is disputed. |
| Support access records — when a member of our staff opened your account, who, and why | See section 7. This log exists to hold us accountable, not you. |
| Server logs — kept briefly by our hosting provider, and containing IP address and request path | Diagnosing errors and identifying abuse. |
For customers in the UK and EEA, our lawful bases under the UK GDPR and GDPR are:
We do not rely on consent for anything, because we do not do anything that needs it.
These are our sub-processors. Each one is here because the product cannot work without it, and each receives only what its job requires.
| Provider | Does what | Receives | Where |
|---|---|---|---|
| Supabase | Database and authentication | Everything in section 2 except card data | AWS, us-east-1 (USA) |
| Vercel | Hosting and delivery | Requests in transit; short-lived server logs | USA |
| Stripe | Payments and subscriptions | Email, card data (directly from you), billing history | USA and Ireland |
| Brevo | Sending sign-in codes and service email | Email address and the message | EU |
| OpenRouter | Routes model calls to the providers below | The prompt: your offer content and our knowledge base | USA |
| Anthropic, OpenAI, Google | Generate the output | The same prompt, and their response | USA |
We will update this table before adding a provider, not afterwards. We do not sell personal information, and we do not share it for cross-context behavioural advertising — under the CCPA/CPRA definitions, we have never done either.
Running a discovery sends the model your offer description, any workspace documents relevant to it, and our knowledge base. That is the point of the product — but it means your positioning, pricing and unlaunched plans leave our systems, so it is worth being precise about what happens next.
Every model call we make carries an instruction not to route to any provider that retains prompts for training. It is set in our code on each request rather than in an account setting, so it cannot be switched off by accident.
OpenRouter does not store prompts or responses unless prompt logging is switched on for the account. Ours is off. It does keep request metadata such as token counts and latency.
Providers may hold a request briefly for abuse monitoring under their own policies. We do not control those policies and cannot promise on their behalf beyond the instruction above.
We do not train models on your content, and we do not use one customer’s material to generate for another. If we ever want to use aggregate patterns to improve the product, it will be from data with no customer identifiers in it, and this policy will say so before we start.
If you supply your own model API key, calls run on your key and your provider agreement governs them.
Most SaaS privacy policies leave this out. Ours says it plainly: an administrator at V3Ads LLC can open your account and see it as you see it, in order to investigate a fault you have reported.
Brdgy sets one kind of cookie: the Supabase authentication session that keeps you signed in and is refreshed as you browse. It is strictly necessary — without it you would be signed out on every page — so no consent banner is required, and there is nothing to opt out of short of not signing in.
There are no analytics cookies, no advertising cookies and no third-party cookies.
| What | Kept for |
|---|---|
| Account, workspaces, offers, documents and generated output | Until you delete them, or 30 days after you close your account |
| Sign-in codes, and the IP address recorded beside them | A code expires in 10 minutes. The row and its IP are deleted the following day by a job that runs every hour |
| Support-access tokens | Expire after 2 hours, deleted the following day by the same hourly job |
| Usage and metering records | For as long as your account is open; deleted with it |
| Support-access records — who opened your account, and why | For as long as your account is open; deleted with it |
| Billing and payment records | 7 years, because tax law requires it — this survives account deletion |
| Server logs | As kept by our hosting provider, typically under 30 days |
Wherever you are, you can ask us to show you what we hold, correct it, delete it, or send you a copy in a portable format. Email support@brdgy.com from your account address and we will respond within 30 days.
If we cannot act on a request we will tell you why. The usual reason is section 9: invoices have to survive an account deletion because tax law says so.
Deletion on request is done by hand at our current size, rather than by a button. It is a small company doing it, not an automated pipeline — which is why the commitment above is 30 days rather than instant, and why we would rather promise something we can keep.
You additionally have the right to object to processing based on legitimate interests, to ask us to restrict processing while a dispute is resolved, and to complain to your supervisory authority — in the UK, the Information Commissioner’s Office. We would rather you came to us first, but that right does not depend on it. There is no automated decision-making with legal or similarly significant effects.
Under the CCPA/CPRA you have the rights to know, delete, correct and opt out of sale or sharing, and not to be discriminated against for exercising them. We do not sell or share personal information, so there is nothing to opt out of — no “Do Not Sell” link appears because there is no such link to give you. The categories we collect, and why, are section 2; the parties we disclose to for business purposes are section 5.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant regulator as the law requires — within 72 hours of becoming aware, where the UK GDPR or GDPR applies.
If you have found a vulnerability, please tell us at support@brdgy.com before disclosing it publicly. We will not pursue anyone who reports one in good faith and does not access other customers’ data.
We are based in the United States and most of our providers are too, so data about you is processed there. Where we transfer personal data out of the UK or EEA we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, which our providers enter into as part of their data-processing terms.
Brdgy is a business tool and is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has created an account, tell us and we will delete it.
If we change what we collect, add a sub-processor, or change how your content is handled, we will email account holders before the change takes effect and update the version and date at the top of this page. Adding a provider to section 5 after the fact would defeat the point of publishing the table.
V3Ads LLC, Delaware, United States — support@brdgy.com
For anything about how we handle data — a request, a correction, or a complaint — write to that address. See also the Terms of Service.