Who to contact
BrandMyDoom operates brandmydoom.bid. For privacy questions, access, correction or deletion requests, email support@brandmydoom.bid. Include your public brand URL, if relevant. Never send your private edit link or full payment-card details.
Information you provide
Brand names, website addresses, descriptions, logos, artwork, videos, interaction messages and demo contributions are used to build your previews. Local demo history stays in your browser until you explicitly publish it. Uploaded files are stored privately during review; approved files can be accessed through their media URLs. Do not upload confidential material.
Publishing makes your selected brand profile, demo contribution history and artwork available through a public page and wall-preview links. Search engines and other people can access or copy public material. Support emails contain the information you choose to send.
A public demo boost records its amount, selected brand and wall, date and an optional display name. You can leave the name blank to appear as Anonymous. Display names are self-reported, not verified identities, and are screened before publication. Boost badges identify the supported brand and the individual demo amount; no email is required or collected for this flow. We retain a salted IP hash to limit abuse and keep a pending request ID in browser session storage to avoid duplicate submissions. Contact support with the boost ID for a privacy request.
Cookies, storage and activity counts
Local storage keeps your demo ledger and preferences on your device. A private edit link signs you into a seven-day management session using an HttpOnly, same-site cookie. The server stores hashes of edit keys and session tokens. We use browser session storage for a random visit identifier and temporary publishing state.
For shared wall previews, we count sustained visible-wall views, interactions and website-link clicks. Counts are deduplicated by preview, activity type and visit per day. They are demo activity counts, not verified people or guaranteed advertising impressions. We do not use third-party advertising pixels or sell personal data.
To limit abuse, the server uses salted hashes derived from IP addresses for upload, free-board, publishing and event limits. Cloudflare also processes IP addresses and request information when delivering and protecting the service. Hashing an identifier does not make it anonymous in every circumstance.
Service providers and purposes
Cloudflare hosts the site, database and uploaded media and helps protect the service. Data may be processed outside your country. We use information to deliver the requested features, secure the service, respond to requests and meet applicable obligations. Where a legal basis is required, these purposes rely on providing the requested service, legitimate operational and security interests, consent where required, or legal obligations.
Cloudflare Workers AI processes submitted images and text for content safety checks. We send destination hostnames to Cloudflare's filtered DNS service. We store review decisions, content references and manual-review notes to prevent unapproved publication and handle appeals. Authorized operators may inspect quarantined files for this purpose. Automated screening can make mistakes; contact support to request human review.
Real-money checkout is disabled. Optional sandbox checkout is hosted by Dodo Payments, which asks for contact and billing details under its own privacy terms. Use fictional test details and test cards. BrandMyDoom stores order and provider reference IDs, selected brand and wall, test amount, status, review references and an optional supporter name. We do not store full card details or copy checkout email and billing addresses into our order records. Confirmed test contributions and badges are public; the private order-status link does not grant brand editing access. Browser session storage keeps its access key for returning from checkout. We remove provider return parameters from the displayed URL and suppress the referrer on order pages.
Retention and control
Public profiles and media remain while needed to provide the published preview, unless removed. Per-visit activity records are scheduled for deletion after seven days; aggregate counts remain. Expired management sessions and short-lived quota records are removed by a daily cleanup. Browser history remains until you clear it or remove the site data.
You may edit your public profile using your private link, or ask us to correct, unpublish or delete information by email. We may need to verify your authority before acting. We retain information only where needed for a continuing service, security, disputes or legal obligations. Removing a page does not erase copies already held by other people, search engines or provider backups.
Depending on where you live, you may have rights to access, correct, erase, obtain a copy of or object to certain processing of your data, withdraw consent, or complain to a relevant privacy authority. Contact us to exercise a right. We do not knowingly collect information from children under 13; contact us if you believe a child has submitted personal information.