Data Deletion

You can ask Brunos to delete your data at any time, and we will do it. This page explains what we hold, how to make the request, and what happens next.

Disconnecting a platform

If you only want to stop Brunos reading a connected account, you do not need to delete anything. Open Integrations in Brunos, choose the platform, and use Disconnect. All six platforms have that control — Meta, Google Ads, Google Drive, Shopify, Slack and TikTok. The authorisation we hold is destroyed at that moment rather than left to expire, and for five of them — Google Ads, Google Drive, Shopify, Slack and TikTok — the withdrawal is sent to the platform as well, so the access stops being listed there too.

TikTok is worth one extra line, because its access does not lapse on its own: the token it issues has no expiry date, so an authorisation left alone stays valid indefinitely. Disconnecting is what ends it — Brunos asks TikTok to revoke the token and destroys its own copy in the same step.

Meta is the exception to that second half: the credential is held by our broker and never by Brunos, so we can destroy it but cannot remove the grant from your Facebook account. Disconnect here, then remove Brunos under Settings → Business Integrations on Facebook.

Withdrawing at the platform instead is not the same act, and it matters which platform. Shopify and Slack tell us: uninstalling Brunos there delivers a notification to us, and the authorisation we hold is destroyed without you asking. Google and TikTok send us nothing — Brunos reads its own records, never theirs — so a withdrawal made only in your Google account's third-party access settings or in TikTok Ads Manager stops the access working, but the sealed credential stays with us until a synchronisation next fails against it. If you want it gone at once, use Disconnect inside Brunos.

Google Ads was once the exception here, with no control of its own and an earlier version of this page asking you to email us instead. It no longer is. You grant it on Google's own consent screen with your own Google account, the authorisation is sealed for that one workspace, and Disconnect revokes it at Google before destroying our copy. If Google does not confirm the revocation, Brunos tells you so rather than claiming a revocation that did not happen, and you can clear the entry yourself from your Google account.

Disconnecting withdraws access; it does not erase what was already synchronised. Your Shopify orders and products, your TikTok and Google Ads campaigns and daily metrics, and anything else read before you disconnected, stay in your workspace so your reporting history survives — that holds for every platform, including the five whose disconnect reaches the platform. Uninstalling Brunos from your Shopify admin is the one case that also erases: Shopify sends us an erasure request 48 hours later, and the synchronised orders and products are purged. Otherwise, ask us at the address below if you want the synchronised data deleted, or ask us to delete the whole workspace, which takes it with it.

What Brunos holds about you

  • Account identity — The email address and display name from your sign-in, held so a Space can show who its members are.
  • Space membership — Which workspaces you belong to, your role in each, and any invitations you sent or redeemed.
  • Product preferences — Your preferred language, your preferred timezone, whether you opted in to marketing email, and which workspace you last had open — settings, not advertising data.

What Brunos holds from a platform you connected

Stated separately because it is held per workspace rather than per person, and removing the connection is what reaches it:

  • Platform authorisations — For Meta, the credential is held by our broker and never by Brunos. For Google Ads, TikTok, Shopify, Google Drive and Slack, Brunos holds it encrypted in an isolated vault, sealed per workspace, and destroys it when the connection is removed or the app is uninstalled.
  • Shopify orders and products — Order totals, currency, status and timestamps, and product titles and identifiers, for the store you connected. Brunos does not copy customer names, addresses or payment details.
  • TikTok campaigns and daily metrics — Campaign names and status, and daily spend, impressions, clicks, conversions and derived rates, for the advertiser accounts you connected.
  • Google Ads accounts, campaigns and daily metrics — The name, currency and time zone of each advertising account your authorisation reaches; campaign names, status, type, dates and budgets; and daily spend, impressions, clicks and conversion totals per campaign. No audience data, no search terms, no keywords and no personal information of any kind.
  • Google Drive files you pick — Only the individual files you select in Google's own picker. Brunos reads their contents in order to build ads from them and passes them to the ads service; it does not keep the files or their names, and it cannot list, browse or reach anything else in your Drive.

What Brunos does not hold

Worth stating, because it changes what deletion can and cannot reach:

  • Payment card details. Brunos does not process payments directly.
  • The contents of a customer's Shopify order beyond the totals and status listed above — no names, addresses, emails or payment details.
  • Meta advertising credentials. Those are sealed by our broker and never reach Brunos.
  • Google account data beyond the three things Brunos asks Google for, which are all of them: the adwords scope, to read the Google Ads accounts you connect; your name, email address and profile picture, if you sign in with Google; and the drive.file scope, which reaches only the individual files you pick in Google's own picker and whose contents Brunos reads in order to build ads from them. Nothing beyond those three, and no file in your Drive that you did not pick.

Requesting deletion

Email support@brunos.ai from the address you sign in with, with the subject Data deletion request. Sending from the account's own address is how we confirm the request is yours; if you no longer control it, say so and we will verify another way rather than refuse.

Email is the route because there is no delete button in the product to press: deletion is something you ask us to do, and we do it. The same is true of a copy of your data — there is no export feature, so if you want one, ask in the same message and we will send it to you.

We acknowledge within 2 business days and complete deletion within 30 days, including from backups on their normal rotation.

What deletion affects

Deleting your account removes your identity, your memberships and your preferences. Platform authorisations and synchronised platform data belong to the workspace rather than to you, so deleting a person does not reach them: they end when the connection is disconnected, and the synchronised data goes when the workspace itself is deleted.

A workspace with other members is not deleted with you — it belongs to the organisation rather than to any one person, and removing it would delete your colleagues' access alongside your own. If you are the last member, the workspace goes with you, and its connections and everything synchronised into it go with the workspace. To delete a workspace that still has members, say so in the request and we will confirm with its owner first.

Records we are required to keep — such as an audit trail of changes made to an advertising account — are retained where the law obliges it, and separated from your profile.