Bruno← Back to Bruno
The details behind your launch

Privacy Policy.

How Bruno handles information when you build, redesign, publish, upload, pay, or connect business services.

Effective and last updated: September 17, 2026 · Version 1.0

1. Who is responsible and what this covers

VEO Shop LLC, a Wyoming limited liability company, operates Bruno and is responsible for personal information it processes for its own platform purposes. This Policy covers iambruno.com, app.iambruno.com, the public builder, account and checkout flows, customer intake links, dashboards, hosted services, and related features. Contact us at help@iambruno.com.

When a business uses Bruno to process information about its own customers, applicants, employees, or website visitors, that business may be the controller or responsible organization and Bruno may act as its processor or service provider for those activities. The business’s privacy notice and any applicable data-processing agreement also apply. This Policy does not replace the customer’s own privacy obligations. Third-party websites, payment pages, linked accounts, and providers may have their own policies.

2. Information we collect

  • Account and lead information: email, username derived from email where applicable, name when supplied, business name, plan selection, onboarding steps, intake responses, and account or service status. Providing email during onboarding may create a lead or account before any purchase.
  • Billing and setup: name, address, country, phone, optional company name, domain choice, ownership/configuration details, and payment identifiers. We receive payment status, amount, currency, and accounting details, including processor fees and net amounts. Payment processors handle payment credentials under their own policies; avoid submitting card details directly in Bruno messages.
  • Content and creative inputs: logos, images, depicted people, website URLs and retrieved content, documents, presentations, prompts, messages, instructions, generated outputs, and editing history. Documents can contain personal information about you or others.
  • Intake and form data: token-link metadata, expiry and submission state, uploaded files, upload-progress metadata, instructions, contact requests, applications, and CV attachments where the feature permits them.
  • Hosted and connected services: domain and mailbox configuration, service credentials or authorization tokens necessary for provisioning/integrations, authorized social or business account details, and communications or call/voicemail data where the selected feature processes them.
  • Technical and usage information: IP address, browser/device details, session and browser identifiers, access timestamps, request/error logs, service events, referrers, campaign parameters, and activity needed to secure, troubleshoot, or attribute use.

We receive information from you, your authorized users, connected providers, payment processors, and the websites you ask us to inspect. Public availability is not permission for every possible reuse. You should only submit information you have authority to share. Do not upload unnecessary sensitive information, identity documents, financial records, private credentials, or information about children.

3. Why we use information and legal bases

We use relevant information to create accounts and leads; save onboarding work; research and generate requested designs; edit and publish websites; operate hosting, domains, mailboxes, and business tools; process and verify purchases; deliver links and service notices; provide support; manage authorized integrations; prevent abuse; investigate failures; maintain accounting records; and comply with legal duties.

Where laws require a legal basis, we rely, as applicable, on performance of a contract or requested pre-contract steps; legitimate interests in secure, reliable operation, proportionate support, fraud prevention, and non-intrusive improvement, balanced against your rights; legal obligations; and consent for activities that require it, such as certain cookies, optional marketing, or specific training uses. Where consent is required, we will obtain it in the appropriate manner rather than treating all processing as automatically consented to.

We may use information to assess payment confirmation, provision eligibility, suspicious activity, and account access. Contact us if an automated action adversely affects you and you wish to request review. We do not describe ordinary design generation as a guaranteed human-reviewed decision process.

4. AI providers and API processing

Current public builder: GPT and GPT Image 2 from OpenAI. Bruno currently uses US-based model providers and does not use Chinese AI models. Other or legacy services may use additional providers, including Google Gemini.

Relevant prompts, instructions, selected documents or extracted text, images, website content, business details, and other inputs may be sent to AI providers to perform the selected feature. Outputs return to Bruno for display, editing, storage, or publication. Not every item in your account is necessarily included in every request.

Requests may pass through authorized APIs, gateways, distributors, provider accounts, credentials, and service intermediaries. Those parties may process request content and operational metadata according to the applicable service arrangement. We cannot promise zero retention, a particular geographic location, or a uniform no-training rule across all external services unless expressly agreed for your arrangement. Provider training practices are distinct from Bruno’s own training activities.

Our provider selection may change, including the introduction of other models, Anthropic/Claude, or providers based in other countries. Current statements do not guarantee future supplier nationality or that all processing occurs in the United States. We will communicate material processing changes and obtain additional consent when law requires it. See, as applicable, OpenAI’s privacy information, Google’s Privacy Policy, and Anthropic’s privacy information; mention of a provider is not a statement that it currently receives your data.

5. Improvement and our own software training

We reserve the right, subject to applicable law, your permissions, and prior commitments, to use lawfully licensed content, generated outputs, feedback, usage data, and genuinely anonymized information to evaluate, improve, develop, and train our own software and systems. The content license in the Terms does not override personal-data protections.

We do not authorize general training on sensitive data, private intake documents, CVs, private mailbox/message contents, confidential records, or identifiable likenesses merely through these pages. Where an identifiable-data training purpose requires express consent or another lawful basis, we will establish it before that use. Optional consent may be declined or withdrawn as provided by law. We will not apply new incompatible training uses retroactively just by changing this Policy.

Contact us to object, request information, or withdraw an applicable permission. We will consider relevant statutory rights and explain what can be stopped or deleted, including the treatment of existing datasets or trained systems. Withdrawal does not make lawful prior processing unlawful. We will not attempt to reidentify genuinely anonymized information.

6. Recipients, disclosure, and international processing

We disclose relevant information to providers and authorized personnel as necessary for the selected services, including:

  • AI model providers and authorized API/intermediary services.
  • Hosting, storage, CDN, infrastructure, DNS, domain registrars, and security providers.
  • Payment providers such as PayPal, and accounting or professional advisers.
  • Email delivery providers such as SendGrid, mailbox infrastructure, and communications providers such as Twilio where used.
  • Integration providers, linked platforms, and contractors or Concierge personnel working on your requested service.
  • The recipients you select, such as the business owner receiving a website form submission or CV, and the public when you publish a site.

We may disclose information in a genuine merger, acquisition, financing, or asset transfer, subject to appropriate safeguards and applicable notice requirements. We may preserve and disclose relevant information for valid legal process, applicable reporting obligations, lawfully permitted investigations, fraud prevention, protection of rights, or serious safety concerns. We disclose only as legally permitted and appropriate, not under an unlimited law-enforcement exception.

Processing may occur in the United States and other countries where providers or authorized personnel operate. Local laws may differ. Where a restricted international transfer requires safeguards, we will use an applicable lawful mechanism, such as appropriate contractual safeguards or another valid transfer basis. We do not claim certification under a transfer framework merely by publishing this Policy. Contact us for information about safeguards relevant to your service.

A public site, business contact address, domain registration, shared link, or published image can be viewed, copied, indexed, or cached by others. A long token is an access credential, not a guarantee that information is private after the link is shared. Keep intake links and account credentials secure. We do not grant a general right to sell personal information through this Policy; any activity legally classified as sale or sharing remains subject to applicable disclosures and opt-out requirements.

7. Cookies, tracking, and communications

Bruno uses session/authentication cookies and persistent browser identifiers to maintain onboarding and preview state, recognize a browser, and support security and account flows. Some integrations or customer websites may use additional storage, campaign attribution, or tracking mechanisms. Browser controls can remove or block cookies, but may disrupt saved progress, sign-in, or related features.

Non-essential cookies or tracking that legally require consent must not be activated solely on the basis of this Policy. A customer’s hosted website may have its own cookie choices and tracking setup. Those choices and the customer’s notice govern its independent tracking activities.

We send requested demo/live links, intake messages, payment and provisioning notices, security communications, and support replies. Such service communications are separate from promotional marketing. We will obtain marketing consent where required, and you may opt out of promotional email by the provided mechanism or by contacting us. Opting out does not prevent necessary transactional or security messages.

8. Retention, access, and security

We retain information for as long as reasonably needed for the service, your account, support, legitimate security purposes, disputes, legally required records, and authorized development purposes. Relevant factors include the service period, whether you request deletion, legal obligations, outstanding disputes, and backup cycles. Link expiry does not itself mean that previously submitted files have been deleted. We do not promise a retention period or automatic deletion mechanism that is not actually implemented.

On closure or expiry, some content may remain temporarily in backups or provider systems, or longer in records retained for a documented lawful reason. We will assess deletion requests and communicate applicable exceptions. Anonymous aggregate information and lawfully developed improvements may be retained where no personal information remains.

We use protective measures appropriate to the nature of the processing, but no internet service is completely secure. Authorized staff, contractors, and providers may access information when needed for their role. Our service is not end-to-end encrypted against all providers or administrators. Customer permissions, compromised devices, shared links, and insecure passwords can expose information. Notify us promptly of suspected unauthorized access. We will address reportable incidents and required notifications under applicable law.

9. Your rights and practical choices

Depending on your location and applicable law, you may request access, correction, deletion, restriction, portability, information about recipients, an objection to certain uses, withdrawal of consent, or an opt-out of legally defined sale/sharing or targeted advertising. You may also have rights concerning consequential automated decisions. These rights have legal limits and exceptions; we will not impose a blanket waiver through our Terms.

Email help@iambruno.com with your request and relevant account/domain. We may take proportionate steps to verify identity or the authority of an agent. Do not send unnecessary identity documents. We will respond within the applicable statutory period, explain any lawful limitation, and provide an appeal or review route where required. We will not unlawfully discriminate against you for exercising rights.

For information submitted to a business using Bruno, you may need to contact that business; where we act on its behalf, we will assist according to our role and legal duties. You may complain to the data-protection authority or regulator with jurisdiction, including authorities in your country of residence where applicable. A request to Bruno does not prevent such a complaint.

Bruno is a business-oriented service for adults and is not directed to children under 18. If you believe a child’s information was provided without appropriate authorization, contact us. We will review and take legally appropriate action.

10. Policy changes and contact

We may update this Policy as services, providers, processing, or legal requirements change. We will revise the date and provide reasonable notice of material changes when required or appropriate, including through the service or your account email. Additional consent will be sought where legally necessary. An update does not retroactively authorize processing that conflicts with prior commitments or required consent.

Contact VEO Shop LLC, Wyoming, United States at help@iambruno.com for privacy, data-use, deletion, security, or provider questions.