Skip to content

NEW: Brunos AI Agent is here

Privacy Policy

How Brunos handles personal data, who else processes it, and what you can ask us to do with it.

Effective 2026-08-01 · CMH Media Agency

Who we are

Brunos is operated by CMH Media Agency. This policy covers the Brunos application and the marketing site. It does not cover the advertising platforms you connect — those remain governed by your own agreements with them.

Written notices and requests reach us at privacy@cmhmediaagency.com, which is monitored and is the fastest route to a person.

What we hold

Enumerated rather than summarised, so you can check it against what the product actually asks you for.

NamePurposeWhat it covers
Account identitySo you can sign in and your colleagues can see who you areEmail address, name, profile picture, preferred language and timezone, whether the terms were accepted and when, and whether marketing email was opted into.
WorkspacesSo the product knows which organisation it is showingWorkspace name, URL slug, logo, website and default language. Nothing about a person.
MembershipSo the right people reach the right workspace, and no one else doesWhich workspaces an account belongs to, its role in each, and when it joined.
InvitationsSo a colleague can be added, and the invitation cannot be reusedThe invited email address, the role offered, who sent it, and whether it was redeemed. Codes expire after 14 days.

What we hold from a connected platform

Connecting a platform lets Brunos read part of it. Some of that is copied into our database so it can be shown and compared over time; the rest is read when you ask and kept nowhere.

NamePurposeWhat it covers
Advertising authorisationsSo a connected account can be read without asking you to sign in againFor Meta, the credential is held by our broker and never stored by Brunos; it passes through Brunos's server only while you connect or reconnect. For Google Ads, Google Drive, TikTok and Shopify, Brunos holds it encrypted in an isolated vault, sealed per workspace, and destroys it when the connection is removed or the app is uninstalled. For Google Ads and Google Drive, Brunos also keeps the email address of the Google account that authorised the connection, to show which account is connected.
Shopify orders and productsSo advertising spend can be measured against what actually soldOrder totals, currency, status and timestamps, and product titles and identifiers, for the store you connected. Brunos does not copy customer names, addresses or payment details.
TikTok campaigns and daily metricsSo campaign performance can be shown and compared over timeCampaign names and status, and daily spend, impressions, clicks, conversions and derived rates, for the advertiser accounts you connected.
Google Ads accounts, campaigns and daily metricsSo campaign performance can be shown and compared over timeThe name, currency and time zone of each advertising account your authorisation reaches; campaign names, status, type, dates and budgets; and daily spend, impressions, clicks and conversion totals per campaign. No audience data, no search terms, no keywords and no personal information of any kind.

Meta performance figures are read from the platform at the moment you ask and are not copied. Shopify and TikTok data is synchronised on a schedule and stored, which is what makes historical comparison possible. Removing the connection deletes it.

What we deliberately do not hold

This is load-bearing rather than reassuring: it is what makes the retention and deletion sections below true.

  • Payment card details. Brunos does not process payments directly.
  • The contents of a customer's Shopify order beyond the totals and status listed above — no names, addresses, emails or payment details.
  • Your Meta advertising credentials. When you connect or reconnect Meta, Meta returns a credential to Brunos's server, which exchanges it with Meta for a longer-lived one and hands that straight to our broker, which seals it. Brunos never stores either.
  • The Facebook Pages a connected Meta account manages. Each time the Bulk page is opened, each Page's identifier, name, and whether you can run ads as it are read through our broker to offer you the Page your ads run as; Brunos never stores that list. Only the identifier of the Page you choose is sent, with the batch, to our broker and to Meta, which keep it as part of the batch and the ads it creates.
  • The image and video files you stage for an ad, whether chosen in Google Drive or uploaded from your computer. Brunos streams each one to our broker for upload to Meta and keeps no copy.
  • Google account data beyond what is listed above. Brunos reads the Google Ads data listed above; if you connect Google Drive, it can open only the individual files you choose in Google's file picker; and, if you sign in with Google, it receives your name, email address and profile picture. Nothing else is requested.

Google user data

Brunos requests the adwords scope so it can read the Google Ads accounts you choose to connect. You authorise it with your own Google account, through Brunos’s own Google OAuth client, and you can withdraw that authorisation at any time from the Google Ads page inside Brunos— which revokes it at Google and destroys the tokens Brunosstored. The scope is used to see which Google Ads accounts your authorisation reaches, and to read their campaign names, status, type, dates and budgets together with daily performance per campaign — spend, impressions, clicks and conversions. Search terms, keywords and audience data are not requested and are not read. If you sign in with Google, we additionally receive your name, email address and profile picture.

Brunos’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely: data received from Google APIs is used only to provide and improve the features you connected the account for. It is never sold, never used for advertising, and never used to train generalised artificial-intelligence models. Humans do not read it, except with your explicit permission, to resolve a support issue you raised, or where the law requires it.

Why we hold it

  • To provide the service — your identity and workspace membership are what let you sign in and see the right data. Without them there is no product.
  • To keep it secure — sign-in records and audit information let us detect unauthorised access to a workspace.
  • To contact you about the service — outages, security notices and changes to these terms. This is not marketing and cannot be opted out of while you hold an account.
  • Marketing, only if you opt in — recorded explicitly, and withdrawable at any time without affecting anything above.

The legal basis for each purpose

  • Performance of a contract — account identity, workspaces and membership. Without them there is no service to provide.
  • Legitimate interests — security records and the approval ledger. Our interest is running the service safely and being able to say who authorised a change to an advertising account; we have weighed that against your interest in not being over-recorded, which is why the ledger holds the decision and not the conversation around it.
  • Consent — marketing email, and only that. Withdrawable at any time with no effect on anything above.
  • Legal obligation — records we are required to retain, kept separately from your profile.

Cookies

Brunos sets the cookies it needs to keep you signed in and to protect the sign-in form. They are strictly necessary: without them the application cannot tell one request from another, so there is nothing to consent to and nothing to switch off short of not using the product.

We do not set advertising or cross-site tracking cookies, and we do not embed third-party trackers in the application.

Children

Brunos is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children; if you believe we have, tell us and we will delete it.

Who else processes it

These parties process data on our behalf and under contract. The second is the one most likely to be missing from a policy like this, and it matters most: Argus is not a hosting vendor. It holds the sealed Meta credential and performs the Meta calls made on your workspace’s behalf. The other platforms are called by Brunos directly, under an authorisation Brunos holds itself.

NamePurposeWhat it covers
HostingerServer hostingThe server Brunos runs on. Everything the application processes passes through it in memory, including data read from a connected platform while a request is served. Nothing is stored there permanently — the database is Supabase and the credentials are in its vault.
SupabaseAuthentication and database hostingAccount identity, workspace membership and invitations. All application data at rest.
Argus (CMH Media Agency)Advertising analytics brokerThe sealed Meta credential, the questions asked of it, and the image and video files a workspace stages for its Meta ads — uploaded from a computer or chosen from Google Drive — with each file's name, type and size. When a workspace connects or reconnects Meta, Meta returns a credential to Brunos's server, which exchanges it with Meta for a longer-lived one and hands that to Argus within the same request, storing neither. Argus seals it, performs the Meta calls made on the workspace's behalf — including listing the Facebook Pages the connected Meta account manages and whether ads can run as each — and returns the results. Google Ads, Google Drive, TikTok and Shopify are called by Brunos directly and none of their credentials reaches Argus; the only Google Drive data Argus receives is a file you chose to use in a Meta ad.
Meta Platforms, Inc.Advertising platformRequests to read and modify the advertising accounts a workspace has explicitly connected, made under the authorisation that workspace granted.
Google LLCSign-in provider and advertising platformTwo separate things. As a sign-in provider: the sign-in exchange, only if a user chooses Google rather than an email and password, returning name, email address and profile picture. As an advertising platform: requests to read the Google Ads accounts a workspace has explicitly connected, made under the authorisation that workspace granted.
TikTok Technology LimitedAdvertising platformRequests to read the advertiser accounts a workspace has explicitly connected, made under the authorisation that workspace granted.
Shopify Inc.Commerce platformRequests to read the store a workspace has installed Brunos on, made under the authorisation granted at installation.
Slack TechnologiesOptional alerting channelMessages a workspace has configured Brunos to send, and the channel they are sent to. Only if the Slack integration is connected.

We do not sell personal data, and we do not share it with advertisers or data brokers.

Advertising accounts you connect

Connecting an advertising account authorises Brunos to read it. Brunos makes changes only to a connected Meta advertising account, and only the ones you submit or approve, under the ads_management permission Meta asks you to grant when you connect; Google Ads, TikTok and Shopify are only ever read, even where the authorisation you granted would allow more. The authorisation is always issued by the platform. Where it is held differs by platform: a Meta authorisation passes through Brunos’s server only while you connect or reconnect — Brunos exchanges it with Meta for a longer-lived one and hands that straight to our broker, which seals it, and never stores either. Google Ads, TikTok and Shopify authorisations are held by Brunos encrypted in an isolated vault, sealed per workspace and destroyed when the connection ends.

You can withdraw an authorisation at any time from the platform itself — in your Google account’s third-party access settings, in TikTok Ads Manager, or by uninstalling Brunos from your Shopify admin. Withdrawal takes effect immediately and our stored copy of the authorisation is destroyed with it, along with the platform data synchronised under it. Withdrawing does not require deleting your Brunos account.

Where Brunos proposes a change to an advertising account, that change is applied only after an explicit human approval, and we record who approved it.

How long we keep it

  • Account and workspace data: for as long as the account exists, and up to 30 days after deletion while it clears backups.
  • Invitations: 14 days, after which the code expires and is no longer redeemable.
  • Security and audit records: retained where we are legally required to, separated from your profile.

Your rights

You can ask us to show you what we hold, correct it, delete it, or export it. You can object to processing and withdraw consent. We will not charge you for this and we will not make you explain why.

Deletion has its own page with the exact process: app.brunos.ai/data-deletion.

For anything else, email privacy@cmhmediaagency.com. We acknowledge within 2 business days and respond within 30 days.

Whether we are a controller or a processor

Both, for different data, and the distinction decides which of us answers a request about it.

  • For your account and workspace, we are the controller. We decide what identity data Brunos needs to sign you in, show colleagues who you are and bill your organisation. Requests about that data come to us.
  • For the advertising and commerce data we read on your behalf, we are a processor. You decide which accounts to connect and what we may read from them; we act on those instructions. The platform that holds the data — and your own organisation, as its controller — decide its purposes, not us.

One consequence is worth stating plainly: where we act as processor, a person whose data sits inside a connected advertising account should raise a request with the organisation that runs that account. If it reaches us instead, we will pass it on and tell you we did rather than answer for a controller we are not.

If your organisation needs a Data Processing Agreement to cover the processor role, ask at privacy@cmhmediaagency.com and we will put one in place.

Automated decisions

Brunos produces recommendations automatically — which campaigns to change, what budget to move, which creative is performing. Those recommendations are generated by a model, and the analysis behind them is automated end to end.

No automated decision is applied to your advertising without a person approving it. Brunos never changes a connected account on its own initiative. Someone in your workspace approves each change, and we record who and when. That is a product guarantee, not only a policy statement — the approval step is what the software requires before it will act.

Because a person decides, this is not the kind of solely automated decision-making that data protection law gives you a right to object to. You keep that right anyway: if you believe an automated output has been applied to you without meaningful human involvement, write to privacy@cmhmediaagency.com and we will explain what happened, who approved it, and reverse it where we can.

If you are in the United States

Several US states give residents rights over their personal information — to know what is held, to have it deleted, to correct it, and to opt out of its sale or of targeted advertising based on it.

Brunos does not sell personal information and does not share it for cross-context behavioural advertising. There is no opt-out to offer because there is nothing to opt out of. We do not receive payment for personal data, and we do not pass it to advertising networks for their own targeting.

The rights to know, delete and correct are the same ones set out under Your rights above, and the same route serves them: privacy@cmhmediaagency.com. We do not charge for a request and we do not treat you differently for making one.

Security

Data is encrypted in transit and at rest. Access between workspaces is separated at the database level rather than in application code, so a bug in our software cannot show one customer another’s data. Where Brunos holds an advertising authorisation itself, it is sealed in an isolated vault, encrypted per workspace, and readable only by the service that makes the call — never by the application that serves your session. Where our broker holds it instead, it never reaches Brunos at all. Which applies to which platform is set out under Advertising accounts you connect.

International transfers

Our processors operate infrastructure outside your country, so your data may be transferred and processed elsewhere.

Where a transfer leaves a country whose law restricts it, we rely on the safeguards that law provides — an adequacy decision where one covers the destination, and the European Commission’s Standard Contractual Clauses, or the equivalent instrument for your jurisdiction, where one does not. Each processor named above is engaged under a written agreement carrying those terms.

You can ask us which countries your workspace’s data is processed in at privacy@cmhmediaagency.com. We answer with the current regions rather than a list that goes stale in this document.

Changes

We will tell you before a material change takes effect, by email to the address on your account. Continuing to use Brunos after that date means the updated policy applies.

Contact

Privacy questions and requests: privacy@cmhmediaagency.com.

If you believe we have handled your data wrongly, tell us first — we would rather fix it than be told about it by a regulator. You keep the right to complain to the data protection authority of the country where you live or work, and doing so does not require our agreement or affect anything else you have asked us for.