Draft — legal review requiredLast updated 10 August 2026

Privacy Policy

What LazyOne collects, why it is collected, who processes it, how long it is kept, and how to get it deleted.

This document has not been legally reviewed

It is a working draft written to describe how the platform actually behaves. It has not been reviewed against the operating entity, jurisdiction, tax and consumer requirements, subscription terms, intellectual-property terms or grievance-contact obligations that apply. Do not rely on it as a binding agreement. Questions: brandbucksconsulting@gmail.com.

1. Scope

This policy covers the LazyOne website and workspace. It describes the platform as it is actually built. Where a protection is not yet implemented, this document says so rather than implying otherwise.

2. What we collect

Account information

Email address, display name and account role. Authentication is handled by our authentication provider; we do not store your password.

Content you create

Brand profiles, discovery briefs, product records, campaign briefs, generated outputs, your edits, approvals, and files you upload such as logos, product images and video clips.

Operational records

Generation job status, attempt counts, safe error codes, request identifiers, timestamps and audit events for security-relevant actions such as role changes and administrative edits.

Technical data

Standard request metadata needed to serve pages and apply rate limits. Where we use a network address for abuse prevention it is hashed on receipt, so the raw address is not retained.

What we do not collect

We do not ask for payment card details, because there is no billing in this version. We do not use advertising trackers or third-party analytics profiling on the public site. We do not want passwords, API keys or client confidential documents sent through the contact form.

3. Why we process it

  • To create and secure your account.
  • To store your brand profile and produce the output you request.
  • To keep generation history so you can see what was generated, edited and approved.
  • To provide support, and to investigate faults using request identifiers and safe error codes.
  • To protect the platform — rate limiting, abuse prevention and audit trails.
  • To meet legal obligations that apply to us.

4. AI processing — read this section

When you request generation, the relevant parts of your brief and brand profile are sent to our AI text-generation provider so it can produce the requested output. That means your brief content leaves our infrastructure and is processed by that provider under their terms.

We cannot promise on that provider’s behalf that your content is never retained or never used for their own purposes. If your brief contains information you cannot share with a third-party processor, do not submit it for generation.

Retrieved website content and uploaded documents are treated as untrusted data rather than instructions, and we do not store more of a fetched page than the generation requires.

5. Processors we rely on

  • Hosting and content delivery — serves the application.
  • Database, authentication and file storage — stores your account, content and uploads.
  • AI text generation — processes briefs to produce generated output.
  • External workflow automation — optional. When enabled, it processes notification payloads such as a job identifier and a notification email address.

The named provider list, their locations and their data-processing terms must be published here before this policy is final. That is part of the outstanding legal review.

6. Cross-border processing

Our providers may process data outside your country. The specific regions depend on the deployment configuration, and we will not assert a particular storage location until the implemented configuration has been verified.

7. Retention

  • Account records — kept while your account exists.
  • Brand profiles, projects and outputs — kept until you delete them.
  • Uploaded assets — kept until you delete them or delete the brand they belong to.
  • Operational logs and failed generation payloads — kept for a limited period for debugging and abuse investigation, then removed.
  • Audit events — retained longer than ordinary content, because their purpose is to record who changed what.

Exact retention periods per category will be published here once they are set. Content you delete is soft-deleted first where recovery matters, then permanently removed.

8. Security

What is implemented:

  • Server-side authentication and authorisation for every protected action.
  • Database row-level security, so a query cannot return another user’s rows.
  • Secrets restricted to server environments and kept out of browser bundles.
  • Input validation at every trust boundary, and validation of AI output before it is stored.
  • Rate limits on authentication, generation, search, contact and uploads.
  • Restrictions on URL retrieval that block private and local network addresses.
  • Upload checks on type, extension, file signature and size.
  • Sanitisation of rich content before it is rendered.
  • Audit events for administrative and security-relevant actions.

We will not claim a specific encryption standard, certification or data-residency guarantee until the deployed configuration verifies it. No platform can promise absolute security.

9. Your rights

You can access the content in your workspace at any time, correct it directly, export generated output, and delete brands, assets and your account. To ask about data we hold, or to request deletion you cannot complete in the product, write to brandbucksconsulting@gmail.com.

Depending on where you live, you may have additional statutory rights including objection, restriction, portability and complaint to a supervisory authority. The applicable framework and the response timelines we commit to will be stated here after legal review.

10. Deleting your account

Deleting your account removes your brand profiles, projects, generated outputs and uploaded assets. Audit records of security-relevant actions and limited operational logs are retained for their documented period. Deleted content is not recoverable once permanent removal has run, so export anything you want to keep first.

11. Children

LazyOne is a business tool and is not directed at children. We do not knowingly create accounts for people below the age at which they can consent in their jurisdiction.

12. Changes

When this policy changes materially we will update the date above and, for account holders, notify you through the product or by email.

13. Contact

Privacy questions and requests: brandbucksconsulting@gmail.com. The grievance-officer details required in our operating jurisdiction will be added here before this policy is treated as final.