Who we are
Brunos is operated by Brunos AI LLC. This policy covers the Brunos application and the marketing site. It does not cover the advertising platforms you connect — those remain governed by your own agreements with them.
Written notices and requests reach us at support@brunos.ai, which is monitored and is the fastest route to a person.
What we hold
Enumerated rather than summarised, so you can check it against what the product actually asks you for.
| Name | Purpose | What it covers |
|---|---|---|
| Account identity | So you can sign in and your colleagues can see who you are | Email address, name, profile picture, preferred language and timezone, whether the terms were accepted and when, and whether marketing email was opted into. |
| Workspaces | So the product knows which organisation it is showing | Workspace name, URL slug, logo, website and default language. Nothing about a person. |
| Membership | So the right people reach the right workspace, and no one else does | Which workspaces an account belongs to, its role in each, and when it joined. |
| Invitations | So a colleague can be added, and the invitation cannot be reused | The invited email address, the role offered, who sent it, and whether it was redeemed. Codes expire after 14 days. |
What we hold from a connected platform
Connecting a platform lets Brunos read part of it. Some of that is copied into our database so it can be shown and compared over time; the rest is read when you ask and not kept in our database.
| Name | Purpose | What it covers |
|---|---|---|
| Platform authorisations | So a connected account can be read without asking you to sign in again | For Meta, the credential is held by our broker and never by Brunos. For Google Ads, Google Drive, TikTok, Shopify and Slack, Brunos holds it encrypted in an isolated vault, sealed per workspace, and destroys it when the connection is disconnected, revoked or uninstalled. |
| Shopify orders and products | So advertising spend can be measured against what actually sold | Order totals, currency, status and timestamps, and product titles and identifiers, for the store you connected. Brunos does not copy customer names, addresses or payment details. |
| TikTok campaigns and daily metrics | So campaign performance can be shown and compared over time | Campaign names and status, and daily spend, impressions, clicks, conversions and derived rates, for the advertiser accounts you connected. |
| Google Ads accounts, campaigns and daily metrics | So campaign performance can be shown and compared over time | The name, currency and time zone of each advertising account your authorisation reaches; campaign names, status, type, dates and budgets; and daily spend, impressions, clicks and conversion totals per campaign. No audience data, no search terms, no keywords and no personal information of any kind. |
| Google Drive files you pick | So an ad can be built from a file you already keep in Drive | Only the individual files you select in Google's own file picker: their name, type and size, and their contents — Brunos reads the bytes and passes them to the service that creates the ads. Brunos cannot list, search or open anything else in your Drive. |
Meta performance figures are read from the platform at the moment you ask and are not copied. Shopify, TikTok and Google Ads data is synchronised on a schedule and stored, which is what makes historical comparison possible. Disconnecting does not erase any of it. Synchronised data belongs to the workspace rather than to the connection, so Shopify's orders and products and TikTok's and Google Ads' campaigns and daily metrics all stay after a disconnect, which is what keeps your reporting history intact. Deleting the workspace removes them. Uninstalling Brunos from your Shopify admin is the one case that also erases: Shopify sends us an erasure request and the synchronised shop data is purged.
What we deliberately do not hold
This is load-bearing rather than reassuring: it is what makes the retention and deletion sections below true.
- Payment card details. Brunos does not process payments directly.
- The contents of a customer's Shopify order beyond the totals and status listed above — no names, addresses, emails or payment details.
- Meta advertising credentials. Those are sealed by our broker and never reach Brunos.
- Google account data beyond the three things Brunos asks Google for, listed in full in the next section: the Google Ads accounts your authorisation reaches, the individual Drive files you pick yourself, and — if you sign in with Google — your name, email address and profile picture. Brunos does not request a scope that would let it browse, search or read the rest of your Drive, and it reaches no other Google service.
Google user data
Brunos asks Google for three things, and these are all three.
The `adwords` scope, so it can read the Google Ads accounts you choose to connect. It is used to see which accounts your authorisation reaches, and to read their campaign names, status, type, dates and budgets together with daily performance per campaign — spend, impressions, clicks and conversions. Search terms, keywords and audience data are not requested and are not read.
The `drive.file` scope, if you connect Google Drive. It grants access to the individual files you pick in Google's own file picker and to nothing else — no folder listing, no search, no other file in your Drive. Brunos reads the contents of the files you picked, because those contents are the images and videos the ads are built from, and passes them to the service that creates the ads.
Your basic Google profile, if you sign in with Google rather than with an email address and a password: your name, email address and profile picture.
You authorise each of these with your own Google account, through Brunos's own Google OAuth client, and each is sealed to the one workspace you connected it in. You can withdraw either connection at any time from its page inside Brunos — Disconnect revokes the authorisation at Google and destroys the tokens Brunos stored.
Brunos's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely: data received from Google APIs is used only to provide and improve the features you connected the account for. It is never sold, never used for advertising, and never used to train generalised artificial-intelligence models. Humans do not read it, except with your explicit permission, to resolve a support issue you raised, or where the law requires it.
Why we hold it
- To provide the service — your identity and workspace membership are what let you sign in and see the right data. Without them there is no product.
- To keep it secure — sign-in records and audit information let us detect unauthorised access to a workspace.
- To contact you about the service — outages, security notices and changes to these terms. This is not marketing and cannot be opted out of while you hold an account.
- Marketing, only if you opt in — recorded explicitly, and withdrawable at any time without affecting anything above.
The legal basis for each purpose
- Performance of a contract — account identity, workspaces and membership. Without them there is no service to provide.
- Legitimate interests — security records and the approval ledger. Our interest is running the service safely and being able to say who submitted or approved a change to an advertising account; we have weighed that against your interest in not being over-recorded, which is why the ledger holds the decision and not the conversation around it.
- Consent — marketing email, and only that. Withdrawable at any time with no effect on anything above.
- Legal obligation — records we are required to retain, kept separately from your profile.
Cookies
Brunos sets the cookies it needs to keep you signed in and to protect the sign-in form. They are strictly necessary: without them the application cannot tell one request from another, so there is nothing to consent to and nothing to switch off short of not using the product.
We do not set advertising or cross-site tracking cookies, and we do not embed third-party trackers in the application.
Children
Brunos is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children; if you believe we have, tell us and we will delete it.
Who else processes it
These parties process data on our behalf and under contract. The second is the one most likely to be missing from a policy like this, and it matters most: Argus is not a hosting vendor. It holds the sealed Meta credential and performs the Meta calls made on your workspace's behalf. The other platforms are called by Brunos directly, under an authorisation Brunos holds itself.
| Name | Purpose | What it covers |
|---|---|---|
| Hostinger | Server hosting | The server Brunos runs on. Everything the application processes passes through it in memory, including data read from a connected platform while a request is served. Nothing is stored there permanently — the database is Supabase and the credentials are in its vault. |
| Supabase | Authentication and database hosting | Account identity, workspace membership and invitations. All application data at rest. |
| Argus (CMH Media Agency) | Advertising analytics broker and ad builder | The sealed Meta credential, and the questions asked of it. Argus performs the Meta calls made on the workspace's behalf and returns the results; the Meta credential never reaches Brunos. Argus is also what creates ads in bulk, so the images and videos a person selects for a batch — including files picked from Google Drive — are uploaded to it. Google Ads, Google Drive, TikTok, Shopify and Slack are otherwise called by Brunos directly and do not pass through Argus. |
| Meta Platforms, Inc. | Advertising platform | Requests to read and modify the advertising accounts a workspace has explicitly connected, made under the authorisation that workspace granted. |
| Google LLC | Sign-in provider, advertising platform and file storage | Three separate things. As a sign-in provider: the sign-in exchange, only if a user chooses Google rather than an email and password, returning name, email address and profile picture. As an advertising platform: requests to read the Google Ads accounts a workspace has explicitly connected. As file storage: requests to read the individual Drive files a person picked in Google's own file picker. Each made under the authorisation that workspace granted. |
| TikTok Technology Limited | Advertising platform | Requests to read the advertiser accounts a workspace has explicitly connected, made under the authorisation that workspace granted. |
| Shopify Inc. | Commerce platform | Requests to read the store a workspace has installed Brunos on, made under the authorisation granted at installation. |
| Slack Technologies | Optional alerting channel | Messages a workspace has configured Brunos to send, and the channel they are sent to. Only if the Slack integration is connected. |
We do not sell personal data, and we do not share it with advertisers or data brokers.
Advertising accounts you connect
Connecting an advertising account authorises Brunos to read it, and — where you grant that permission separately — to make changes to it. The authorisation is always issued by the platform. Where it is held differs by platform: a Meta authorisation is sealed by our broker and never reaches Brunos, while Google Ads, Google Drive, TikTok, Shopify and Slack authorisations are held by Brunos encrypted in an isolated vault, sealed per workspace and destroyed when the connection ends.
Disconnect inside Brunos is the control to use, and it exists for all six connections — Meta, Google Ads, Google Drive, TikTok, Shopify and Slack. It takes effect at once: the stored authorisation is destroyed, and for five of the six the withdrawal is also sent to the platform, so the access stops being listed there. Meta is the exception, and only because Brunos never holds that credential — our broker's copy is destroyed, but removing Brunos from your Business Integrations is something only you can do from your Facebook account.
You can also withdraw at the platform instead — in your Google account's third-party access settings, in TikTok Ads Manager, by uninstalling Brunos from your Shopify admin, or by removing the app in Slack. Access stops working straight away, but Brunos is not always told, and the difference matters: Shopify and Slack notify us and the stored authorisation is destroyed on receipt, whereas Google and TikTok send no signal at all. In those two cases Brunos goes on holding a sealed credential it can no longer use until a sync fails or someone presses Disconnect. If you want our copy gone immediately, use Disconnect inside Brunos.
Disconnecting withdraws access; it does not erase reporting history. Shopify's synced orders and products, and TikTok's and Google Ads' synced campaigns and daily metrics, stay in your workspace and are removed when the workspace itself is deleted — see brunos.ai/data-deletion. Withdrawing an authorisation does not require deleting your Brunos account.
Every change Brunos makes to an advertising account originates in something a person in your workspace did; Brunos does not act on its own initiative or on a schedule. Where Brunos proposes a change, approving it is a separate act and is recorded against the person who approved it. Where a person creates ads in bulk, the submission is itself the checkpoint — there is no second approval step, which is why only a workspace administrator may submit: a submission spends real money.
How long we keep it
- Account and workspace data: for as long as the account exists, and up to 30 days after deletion while it clears backups.
- Invitations: 14 days, after which the code expires and is no longer redeemable.
- Security and audit records: retained where we are legally required to, separated from your profile.
Your rights
You can ask us to show you what we hold, correct it, delete it, or export it. You can object to processing and withdraw consent. We will not charge you for this and we will not make you explain why.
Deletion has its own page with the exact process: brunos.ai/data-deletion.
For anything else, email support@brunos.ai. We acknowledge within 2 business days and respond within 30 days.
Whether we are a controller or a processor
Both, for different data, and the distinction decides which of us answers a request about it.
- For your account and workspace, we are the controller. We decide what identity data Brunos needs to sign you in, show colleagues who you are and bill your organisation. Requests about that data come to us.
- For the advertising and commerce data we read on your behalf, we are a processor. You decide which accounts to connect and what we may read from them; we act on those instructions. The platform that holds the data — and your own organisation, as its controller — decide its purposes, not us.
One consequence is worth stating plainly: where we act as processor, a person whose data sits inside a connected advertising account should raise a request with the organisation that runs that account. If it reaches us instead, we will pass it on and tell you we did rather than answer for a controller we are not.
If your organisation needs a Data Processing Agreement to cover the processor role, ask at support@brunos.ai and we will put one in place.
Automated decisions
Brunos produces recommendations automatically — which campaigns to change, what budget to move, which creative is performing. Those recommendations are generated by a model, and the analysis behind them is automated end to end.
Brunos does not change a connected advertising account on its own initiative or on a schedule. Every change originates in an action a person in your workspace took. How that person signals it depends on the lane, and the two are not the same:
- Recommendations. Approving one is a distinct act. Brunos will not apply a recommendation without it, and the approval is recorded against the person who gave it. There is no screen in the product that shows you that record — ask us and we will give it to you.
- Bulk ad creation. There is no second approval step: the submission is the checkpoint. A person assembles the batch and submits it, and that submit is what creates the ads. Because a submission spends real money, only a workspace administrator can make one.
Because a person acts in both lanes, this is not the kind of solely automated decision-making that data protection law gives you a right to object to. You keep that right anyway: if you believe an automated output has been applied to you without meaningful human involvement, write to support@brunos.ai and we will explain what happened, who acted and when, and reverse it where we can.
If you are in the United States
Several US states give residents rights over their personal information — to know what is held, to have it deleted, to correct it, and to opt out of its sale or of targeted advertising based on it.
Brunos does not sell personal information and does not share it for cross-context behavioural advertising. There is no opt-out to offer because there is nothing to opt out of. We do not receive payment for personal data, and we do not pass it to advertising networks for their own targeting.
The rights to know, delete and correct are the same ones set out under Your rights above, and the same route serves them: support@brunos.ai. We do not charge for a request and we do not treat you differently for making one.
Security
Data is encrypted in transit and at rest. Separation between workspaces is enforced in two places, and both are worth naming rather than claiming the stronger one alone: everything you read in the product goes through row-level security in the database, which decides what your session may see; the integration paths that talk to Meta, Google, TikTok, Shopify and Slack run with elevated database privileges and scope every query to one workspace in application code. Where our broker holds an advertising authorisation — Meta's — it never reaches Brunos at all. Where Brunos holds one itself, it is sealed in an isolated vault, encrypted per workspace, decrypted only at the moment a call is made, never sent to your browser and never readable across workspaces. Which applies to which platform is set out under Advertising accounts you connect.
International transfers
Our processors operate infrastructure outside your country, so your data may be transferred and processed elsewhere.
Where a transfer leaves a country whose law restricts it, we rely on the safeguards that law provides — an adequacy decision where one covers the destination, and the European Commission's Standard Contractual Clauses, or the equivalent instrument for your jurisdiction, where one does not. Each processor named above is engaged under a written agreement carrying those terms.
You can ask us which countries your workspace's data is processed in at support@brunos.ai. We answer with the current regions rather than a list that goes stale in this document.
Changes
We will tell you before a material change takes effect, by email to the address on your account. Continuing to use Brunos after that date means the updated policy applies.
Contact
Privacy questions and requests: support@brunos.ai.
If you believe we have handled your data wrongly, tell us first — we would rather fix it than be told about it by a regulator. You keep the right to complain to the data protection authority of the country where you live or work, and doing so does not require our agreement or affect anything else you have asked us for.