The Brand Voice Generator (“the tool”) is operated by The Lost Agency BV (“The Lost Agency”, “we”, “us”), a company incorporated in the Netherlands. The Lost Agency BV — not any individual — is the data controller responsible for the personal data described in this policy. You can reach us about privacy at [email protected].
| Data | Purpose | Legal basis |
|---|---|---|
| Analytics (page views, feature usage) via Google Analytics 4 and a first-party server beacon | Understand how the tool is used so we can improve it | Consent |
| Security log: IP address, rate-limit counters, and security events (e.g. repeated failed logins) | Protect the service against abuse, fraud and brute-force attacks | Legitimate interest |
| Account data: email address, hashed password, credit balance | Provide your account and the credits you purchase | Performance of a contract |
| Purchase records: email, amount, VAT details, Stripe identifiers | Process payments and issue tax invoices | Contract / legal obligation |
| Content you submit (a website URL, pasted text or an uploaded document) | Generate the brand voice guide or evaluation you requested | Performance of a contract |
Where we can, we minimise what is stored — for example IP addresses used for usage logging are hashed, and analytics is configured with IP anonymisation.
Analytics is loaded in a denied state by default (Google Consent Mode v2), so no analytics cookies are set and no usage data is sent until you click Accept on our consent banner. If you click Reject, or simply ignore the banner, no analytics is recorded. You can change your mind at any time using the cookie/consent option, or by clearing this site’s data in your browser.
Strictly necessary cookies (for example, your login session) are always required for the tool to work and are not used for tracking.
Payments are processed by Stripe, acting as an independent processor. Your card details are entered directly with Stripe and are never seen or stored by us. We retain only the purchase record needed for your credits and tax invoices.
We do not sell your personal data or use it for cross-site advertising.
Who can see your content. Your saved content — brand voice guides, content library documents and approved-claims entries — is scoped to your account and is not visible to other customers. Our administration tools do not display it: they show account, billing, usage and security information only. As the operator of the service we retain technical access to the database and to backups, which we use only where it is necessary to run, support or secure the service — for example to investigate a fault you report to us, or to restore data after an incident. We do not read your content for any other purpose, and it is never used to train AI models, sold, or shared for advertising.
We are established in the Netherlands, but the servers that run the tool are located in Australia (our hosting provider’s Sydney facility). Encrypted off-site backups are held with Google Cloud Storage, and content you submit for analysis is processed by Anthropic, which may process it outside the European Economic Area. These are transfers of personal data to countries outside the EEA.
Where a transfer is outside the EEA and not covered by an adequacy decision, it is made under the European Commission’s Standard Contractual Clauses as incorporated in our providers’ data-processing terms. Backups are encrypted before they leave our server with a key whose private half is held offline, so the storage provider cannot read them.
Account and purchase records are kept while your account is active and for as long as we are legally required to keep invoices. Security logs are kept for a short period needed to detect and prevent abuse. Analytics data is retained according to our Google Analytics settings. You can ask us to delete your account data at any time.
Text you submit for an evaluation or compliance check is processed and returned to you — we do not keep a copy. We retain only a usage record of the request itself (which check ran, the model used, token counts and credits charged). Content you deliberately save is the exception: brand voice guides, documents added to your content library and phrases added to your approved-claims register are stored under your account until you delete, archive or revoke them. Saved reports work the same way: a report is stored only if you press “Save & share” on it, which creates a link anyone holding it can open — so share it only with people who should see the content it contains. Saved reports are deleted automatically 30 days after saving, and you can delete one sooner at any time. Checks run from our Slack app, browser extension and Google Docs add-on are never saved this way — saving is a deliberate action on the web report only.
If you are in the EU/EEA or UK you have the right to access, correct, delete or export your data, to object to or restrict certain processing, and to withdraw consent at any time. To exercise any of these, email [email protected]. You also have the right to lodge a complaint with your local data protection authority.
Our Chrome extension is a companion to the tool. It is covered by this same policy; this section describes what is specific to it.
When it reads page content. The extension reads text only when you explicitly ask it to — when you select text and choose a check from the right-click menu, or choose “Check whole page”. It does not read, monitor or transmit pages in the background, and it does nothing at all on pages where you have not run a check.
What is sent to us. The text you asked to check (or the readable text of the page, for a whole-page scan, trimmed to 8,000 characters), together with your connection credential and the check settings you chose (target markets, audience, language, and the brand profile domain). It is sent to our API at davidiwanow.com over HTTPS for the sole purpose of producing the analysis you requested.
What is stored on your device. Your connection credential and your settings, held in Chrome’s extension storage. If you have Chrome sync enabled, Chrome may sync these across your own signed-in browsers. Uninstalling the extension removes them.
What we retain. The text you check is processed and returned to you; we do not store it. We keep only a usage record of the request — which check ran, the model used, token counts, credits charged and the time — plus the security and rate-limiting records described in section 2. The exception is content you deliberately save: documents you add to your content library and phrases you add to your approved-claims register are stored under your account until you archive or revoke them.
No tracking. The extension contains no analytics, no advertising and no third-party trackers, and it does not read your browsing history, cookies or form data.
Permissions. It requests access to the active tab and scripting (to read your selection and show the results panel), context menus (the right-click entries), storage (your connection and settings), and network access to davidiwanow.com only.
Revoking access. You can disconnect the extension from your account at any time from the “Connect extension” page in your account, which revokes that connection immediately. Uninstalling the extension removes its local data.
We do not sell data collected by the extension, and we do not use it for anything other than providing the analysis you requested.
Our Slack app is a companion to the tool. It is covered by this same policy; this section describes what is specific to it.
When it reads message content. Only when you explicitly ask it to —
the copy you type after a /compliance or /brandvoice command, or the
single message you point the “Check compliance” shortcut at. The app subscribes to
no message or conversation events, cannot browse or search your channels, and reads nothing in
the background. Content is submitted by your deliberate action, one check at a time.
What is sent to us. The copy you submitted (trimmed to 8,000 characters), your Slack workspace and user identifiers, and the check settings. It is sent to our API at davidiwanow.com over HTTPS for the sole purpose of producing the analysis you requested.
What we store. Your Slack workspace ID and user ID, linked to the Brand Voice Generator account you connected, plus a per-person access credential which is encrypted at rest. We do not store a Slack bot token: replies are returned through the temporary response URL Slack includes with each request, so we hold no standing credential for your workspace.
What we retain of your copy. The text you check is processed and returned to you; we do not store it. We keep only the usage record described in section 2 — which check ran, the model used, token counts, credits charged and the time.
Who sees the results. Replies are ephemeral and visible only to the person who ran the check. We do not post to your channels.
Request verification. Every request is verified against Slack’s request signature; unsigned, altered or stale requests are refused.
Revoking access. Remove an individual link, or disconnect an entire Slack workspace, at any time from the “Connect Slack” page in your account — access stops immediately and the underlying credential is revoked. Uninstalling the app from your Slack workspace does the same automatically for everyone in that workspace: we act on Slack’s uninstall notification by revoking the workspace connection and every linked credential in it.
We do not sell data collected by the Slack app, and we do not use it for anything other than providing the analysis you requested.
Our Google Docs add-on is a companion to the tool. It is covered by this same policy; this section describes what is specific to it, and states our obligations under Google’s API Services User Data Policy.
When it reads your document. Only when you press a button in the sidebar — “Check selection” or “Check whole document”. The add-on installs no triggers, does not watch you type, and does nothing at all in a document where you have not run a check. It never edits your document: suggested rewrites are shown in the sidebar for you to apply or ignore.
What it can reach. Three narrow permissions: the current document only (never your Drive, and never another file — the add-on cannot list, open or search anything else you own), the ability to show its own sidebar, and network access restricted to davidiwanow.com. Installing from the Google Workspace Marketplace also grants basic account identity — your email address and basic profile — which Google includes by default for every listed add-on. We do not use it, store it, or link it to your Brand Voice Generator account: the add-on is connected by a key you paste, not by your Google identity. The add-on has no access to your Drive, contacts, calendar or mail.
What is sent to us. The text you asked to check (your selection, or the document body, trimmed to 8,000 characters), your connection credential, and the check settings — target markets, audience, and the brand profile domain for a brand voice check. It is sent to our API at davidiwanow.com over HTTPS for the sole purpose of producing the analysis you requested. Document titles, comments, suggestions, revision history, images and the identities of your collaborators are not read and not sent.
Where the connection is stored. Your connection credential is held in the add-on’s per-user storage in Google’s infrastructure — against your Google account, not the document. Sharing a document therefore never shares your credential or your credits: each collaborator connects their own account.
What we retain. The text you check is processed and returned to you; we do not store it. We keep only the usage record described in section 2 — which check ran, the model used, token counts, credits charged and the time. Checks run from the add-on are never saved as shareable reports.
AI processing. The text you submit is processed by Anthropic’s AI model to produce your result, as described in sections 5 and 5a. It is not used to develop, improve or train any generalised AI or machine-learning model — not ours, and not Anthropic’s.
Human access. No person reads your document content as part of normal operation. As the operator we retain technical access to our systems, which we use only where it is necessary to investigate a fault you report, to protect the security of the service, or to comply with a legal obligation. We do not read it for any other purpose, and we do not transfer it to anyone beyond the providers listed in section 5.
Revoking access. Disconnect the add-on from the sidebar, or revoke its connection key at any time from the “Connect Google Docs” page in your account — access stops immediately. You can separately remove the add-on’s permission to your Google account at myaccount.google.com/permissions, and uninstalling the add-on removes its stored connection.
Limited Use. Brand Voice Generator’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell data obtained through the add-on, do not use it for advertising, and do not use it for anything other than providing the analysis you requested.
Our WordPress plugin is a companion to the tool, installed on a website you control. It is covered by this same policy; this section describes what is specific to it.
When it reads your content. Only when someone editing a post presses “Check compliance” or “Check brand voice” in the editor. The plugin checks nothing on a schedule, nothing in the background, and nothing at the moment you publish — the publish gate reads the result of a check you already ran, so publishing never sends us anything.
What is sent to us. The post content in the editor at that moment, including unsaved changes and trimmed to 8,000 characters, together with the site’s connection credential and the check settings. Shortcodes are stripped rather than rendered before the content is sent. It goes to our API at davidiwanow.com over HTTPS for the sole purpose of producing the analysis requested.
Whose request it is. WordPress calls us from your server, not from the editor’s browser, so the connection credential is never exposed to anyone editing the site. We receive the request from your website; we do not receive the identity of the WordPress user who pressed the button, their WordPress account, or their IP address.
What is stored on your site. The connection credential, the plugin settings, and — against each post — the result of its last check plus a fingerprint of the text that was checked, which is what lets the gate notice that a post changed afterwards. These live in your own WordPress database, under your control, and are removed with the plugin.
What we retain. The content checked is processed and returned; we do not store it. We keep only the usage record described in section 2 — which check ran, the model used, token counts, credits charged and the time. Checks run from the plugin are never saved as shareable reports.
Shared credits. The connection is site-wide by design: everyone who edits that site spends the credits of the account that connected it. Connect only a site you control, and revoke the connection if the site changes hands.
Revoking access. Revoke the site’s connection at any time from the “Connect WordPress” page in your account — access stops immediately. Deactivating or deleting the plugin stops it sending anything further.
We do not sell data collected by the plugin, and we do not use it for anything other than providing the analysis requested.
We may update this policy from time to time. The “last updated” date above will always reflect the current version.
← Back to the tool