Privacy Policy
Last updated: 9 July 2026This policy explains what personal data Brohns processes, why, and the choices you have. We aim to be a trustworthy custodian of both your data and the data of the people your agents reach out to.
1. Who we are
Brohns (“we”, “us”) is operated by the Brohns team, based in the Netherlands. For questions about this policy or your data, contact us at privacy@brohns.com. We are the data controller for your account data; see section 6 for the contacts you upload.
2. What we collect
Account & profile: name, email, password hash (via our auth provider), and what you set in your profile.
What you build: the ecosystems, agents, goals, drafts, content and settings you create in the app.
Contacts & leads: business details the agents find or you add (company name, website, public email/phone) and the messages exchanged.
Connected keys: the third-party API keys you add to the Credential Vault. These are stored encrypted and are only decrypted server-side, just in time, to run a tool you approved — never shown back to the browser.
Bookings & operational data: appointments, invoices and datasets you import so agents can work on them (e.g. payment reminders, analysis) — processed only for the features you use them in.
Demo-page visits: when a prospect opens a demo page an agent built (a public link you sent), we log the visit (timestamp and referring page) so you can see the interest. No cookies are set on visitors and no visitor profiles are built.
Media prompts: when you (or an agent) generate an image or video, the prompt and the resulting media URL are stored with the draft.
Usage & technical: log and diagnostic data (IP, timestamps, errors) needed to run, secure and rate-limit the service.
3. Why we use it & legal bases (GDPR/AVG)
To provide the service and the features you ask for (performance of a contract); to keep it secure, prevent abuse and improve it (legitimate interests); and where required, with your consent (which you can withdraw). We do not sell your data.
4. Processors & sub-processors
We share data only with vendors that process it on our behalf to run the service, under contract: hosting & database (Supabase) and AI (Anthropic / Claude — for drafting and reasoning). On top of that sit the providers you choose to connect in the Vault — each receives only what its tool needs, only when a task runs: e.g. Resend or Google/Gmail (sending your email), Google (maps/places), Hunter (email lookup), Higgsfield (image/video generation — it receives your prompts), GitHub (the code workspace — repo contents you connect), a cloud-browser provider (the browser agent), Twilio (SMS), Slack/Discord/ Telegram (notifications), Stripe read-only (invoice import) and your inbound-email provider. Disconnect a key and that flow stops. Some vendors operate outside the EU; such transfers rely on appropriate safeguards (e.g. EU Standard Contractual Clauses).
5. AI processing
To draft messages, content and ecosystem plans, we send the relevant context (your goal, the target business, a conversation) to our AI provider; media generation sends your prompt to the creative provider you connected. Per those providers’ API terms, API content is not used to train their models. Drafts are proposals; nothing is sent or published until you approve it — except where you explicitly granted a capped, revocable autonomy for a specific action type, which you can withdraw at any time in Approvals.
6. The contacts you add (your responsibility)
For the leads and recipients you upload or have the agents find, you are the data controller and we are your processor. You are responsible for having a lawful basis to contact them, honouring opt-outs, and complying with marketing/e-privacy law. We provide a one-click unsubscribe in outreach and a do-not-contact flag to help. On request we’ll put a data-processing agreement (DPA) in place.
7. Retention
We keep your data while your account is active and as needed to provide the service or meet legal obligations. Delete content in-app at any time; delete your account to remove your personal data (subject to limited legal retention).
8. Your rights
Under the GDPR you can access, correct, delete, export, restrict or object to the processing of your personal data, and withdraw consent. Email privacy@brohns.com to exercise these. You may also complain to your supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens.
9. Security
Data is isolated per user with database row-level security; connected keys are encrypted at rest and revealed only server-side, just in time, with every access logged. No method is perfectly secure, but we take reasonable technical and organisational measures.
10. Cookies
We use only the strictly necessary storage to keep you signed in and remember basic preferences. We don’t use advertising cookies. If you add analytics later, update this section and add a consent banner.
11. Changes & contact
We may update this policy; material changes will be notified in-app or by email. Questions? privacy@brohns.com.