Privacy Policy
This policy explains how Brightproof collects, uses, discloses, and protects information when you use the platform, and the choices available to you.
Effective September 14, 2026
1. Introduction
This Privacy Policy explains how whiausbon, LLC dba Brightproof (“Brightproof,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you use the Brightproof platform, including our website, web application, and related services (collectively, the “Service”).
This Policy applies to everyone who uses the Service — team members reviewing and approving creative assets, account administrators, and any other authorized users. By using the Service, you agree to the collection and use of information as described here.
2. Information We Collect
2.1 Information you provide directly
- Account information: name, email address, password (stored in encrypted/hashed form), job title or role, and company/organization name when you register or are invited to an account.
- Content you upload or create: files and assets you upload for review (e.g., documents, presentations, images, video, HTML content), along with comments, annotations, approval decisions, and other feedback you submit within the Service.
- Communications: information you provide when you contact us for support, report a problem, or otherwise correspond with us.
2.2 Information collected automatically
When you use the Service, we and our service providers automatically collect:
- Device and log data: IP address, browser type and version, operating system, device identifiers, referring URLs, and timestamps of activity.
- Usage data: the features and pages you access, actions you take within the Service (e.g., uploading, commenting, approving), session duration, and general navigation patterns. We use this to understand how the product is used and to improve it.
- Interaction and session analytics: to understand usability and identify friction points, certain pages may use technology that records on-page interactions such as clicks, scrolling, and cursor movement, and may generate aggregated heatmaps or session replays. This technology is configured to automatically mask or exclude sensitive input fields (such as passwords) so that typed content in those fields is never captured.
- Diagnostic and error data: when something goes wrong, we automatically collect technical diagnostic information (e.g., error messages, stack traces, the state of the application at the time of the error, browser/device details) so we can identify and fix bugs. This is engineering diagnostic data, not something we use to build a profile of you.
- Cookies and similar technologies: see Section 3 below.
2.3 Information we do not collect through automated security tools
Separately from the analytics described above, we run automated tools against our own codebase and infrastructure — for example, scanning software dependencies for known vulnerabilities and testing our application for security weaknesses. These tools evaluate our code and systems, not the content of your account or your personal data, and are addressed further in Section 7 (Data Security).
3. Cookies and Tracking Technologies
We and our service providers use cookies and similar technologies (such as local storage and pixels) for the following purposes:
| Category | Purpose | Can you control it? |
|---|---|---|
| Essential | Keep you logged in, remember session state, load-balance and secure the Service | No — required for the Service to function |
| Analytics / performance | Understand feature usage and overall performance so we can improve the product | Yes — see below |
| Interaction / session analytics | Understand how users navigate pages (heatmaps, session recordings, click tracking) as described in Section 2.2 | Yes — see below |
You can control non-essential cookies through your browser settings (most browsers let you block or delete cookies) and, where available, through an in-product cookie preference or consent tool. Blocking essential cookies may prevent parts of the Service from working correctly.
4. How We Use Your Information
We use the information described above to:
- Provide, operate, and maintain the Service, including authenticating your account and hosting your uploaded content.
- Enable core functionality such as sharing assets, collecting comments, and tracking approval status.
- Understand how the Service is used, diagnose problems, and improve features and usability.
- Detect, investigate, and fix technical errors and bugs.
- Maintain the security and integrity of the Service, including monitoring for and responding to vulnerabilities.
- Communicate with you about your account, updates, and support requests.
- Comply with legal obligations and enforce our terms.
We do not use your personal information to make automated decisions that produce legal or similarly significant effects on you.
5. How We Share Your Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose information only in the following circumstances:
5.1 Service providers
We use third-party service providers to operate the Service. Each is authorized to use your information only as necessary to provide their service to us, and each is bound by contractual confidentiality and data-protection obligations. These providers fall into the following categories:
| Category | What they do | Data typically involved |
|---|---|---|
| Cloud hosting, database, and authentication infrastructure | Host the application, store account and content data, and manage sign-in | Account data, uploaded content, authentication credentials |
| Product analytics | Measure feature usage and product performance | Usage data, device/log data |
| Interaction/session analytics | Generate heatmaps and session recordings to study usability | Interaction data described in Section 2.2 (sensitive fields masked) |
| Error monitoring and diagnostics | Capture and help us investigate application errors | Diagnostic and error data described in Section 2.2 |
| Email delivery | Send account, notification, and transactional emails on our behalf (e.g., sign-in links, invitations, comment and approval notifications) | Name, email address, and the content of the transactional message |
| File conversion / rendering | Convert certain uploaded file formats (e.g., presentation files) into images or previews so they can be displayed for review | The content of the specific file being converted |
5.2 Legal and safety
We may disclose information if required by law, subpoena, or other legal process, or if we believe in good faith it is necessary to protect the rights, property, or safety of Brightproof, our users, or others.
5.3 Business transfers
If Brightproof is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction, subject to the protections of this Policy.
5.4 With your consent
We may share information for other purposes with your consent.
5.5 Aggregated or de-identified data
We may share information that has been aggregated or de-identified such that it no longer identifies you.
6. Data Retention
We retain personal information for as long as your account is active or as needed to provide the Service. We may retain certain information for longer where required to comply with legal obligations, resolve disputes, enforce agreements, or for legitimate business purposes such as security, fraud prevention, and analytics.
7. Data Security
We maintain administrative, technical, and organizational safeguards designed to protect your information, including:
- Encryption of data in transit and, where applicable, at rest.
- Access controls limiting who within our organization can access personal information, based on role and need.
- Automated vulnerability and dependency scanning of our software components, so known security issues in third-party code are identified and patched promptly.
- Static and dynamic application security testing of our own codebase and running application to identify and remediate security weaknesses before and after release.
- Ongoing monitoring for security events and a process for responding to incidents.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and/or relevant authorities as required by applicable law.
8. Your Privacy Rights and Choices
Depending on where you live, you may have rights under applicable state privacy laws (such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and similar laws in other states), including the right to:
- Know / Access — request confirmation of, and access to, the personal information we hold about you.
- Correct — request correction of inaccurate personal information.
- Delete — request deletion of your personal information, subject to certain exceptions.
- Data portability — request a copy of your personal information in a portable format.
- Opt out of “sale” or “sharing” — we do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of in that respect today; if that ever changes, we will update this Policy and provide an opt-out mechanism.
- Non-discrimination — we will not discriminate against you for exercising your privacy rights.
To exercise any of these rights, contact us at legal@whiausbon.com. We will verify your request and respond within the time required by applicable law (generally within 45 days, extendable once as permitted). You may designate an authorized agent to make a request on your behalf, and you have the right to appeal a denied request by contacting us at the same address.
You can also manage certain cookie- and analytics-based tracking directly through your browser settings or, where available, an in-product cookie preference tool, as described in Section 3.
9. Children's Privacy
The Service is intended for business use by adults and is not directed to children. We do not knowingly collect personal information from anyone under 16 years of age. If you believe a child has provided us with personal information, please contact us so we can delete it.
10. International Users
The Service is hosted and operated in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, which may have different data protection laws than your country of residence.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you (for example, by email or an in-product notice) and update the effective date above. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
12. Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact us at:
whiausbon, LLC dba Brightproof908 Aviator DrFort Worth, Texas 76179legal@whiausbon.comOur Terms of Service incorporate this Policy by reference.