Privacy policy
What we collect when you use the service, why we hold it, and the choices you keep over it.
Last updated 29 July 2026
Who we are
This service is operated by Brainer Private Limited, registered in India at Waterwoods, Varthur Main Road, Whitefield, Bengaluru, Karnataka. For anything in this policy, the controller of your personal data is Brainer Private Limited.
Questions about privacy can go to support@brainer.ceo.
Information you give us
We collect what you provide in order to create and run a company workspace:
- Account details: name, email address, and password credentials.
- Billing details, handled by our payment processor — we do not store full card numbers.
- The description of the business you want to build, and everything you write, upload, or approve inside the workspace.
- Messages you send us for support.
Information we collect automatically
When you use the service we record technical and usage data: IP address, device and browser type, pages viewed, actions taken in the product, and timestamps. We use this to keep the service working, to investigate faults and abuse, and to understand which features are used.
Business and customer data you bring
Running a company through the service may involve data about other people — prospects you research, recipients you contact, and customers who buy from you. You remain responsible for having a lawful basis to process that data, and for the accuracy of any contact list you introduce.
For that data we act as a processor on your instructions. We use it to perform the actions you have asked for and do not sell it.
Connected Meta accounts
You can connect your own Meta Business portfolio so the service can run Facebook and Instagram advertising for your company. Connecting is optional and you start it yourself. Inside Meta’s own dialog you choose which business, Facebook Page, and ad account to grant access to, and we hold the access token that grant produces so we can act on that account through Meta’s APIs.
Through that connection we may receive and process:
- Identifiers for the Meta business portfolio you connect.
- The Facebook Pages available to that grant — their names, identifiers, and whether the grant allows us to publish as them.
- Ad account identifiers and metadata: name, currency, time zone, account status, minimum daily budget, and whether a funding source is attached.
- The identifier of the advertising pixel created in your business when you connect.
- The campaigns, ad sets, advertisements, and creatives we create in your ad account, together with their configuration — budget, schedule, and targeting settings such as locations and interests.
- Campaign and advertisement status, including Meta’s review decisions and the reason it gives for refusing an ad.
- Delivery and performance figures for that advertising — spend, impressions, clicks, click-through rate, cost per click, and cost per thousand impressions — by day and per advertisement.
- The access token representing the permissions you granted.
Why we process Meta data
Information reached through Meta’s APIs is used to provide the advertising functionality you asked for, and for nothing else. Specifically, to:
- Let you connect a Meta account and choose which business, Page, and ad account this company advertises from.
- Show you the businesses, Pages, and ad accounts available to that grant, and whether the ad account is in a state that can run advertising.
- Write advertising copy and creatives, and create the campaign, ad set, and advertisements inside your ad account.
- Update budgets, targeting, and configuration, and start or pause delivery, according to the settings and approvals you give.
- Retrieve campaign and advertisement status, including Meta’s review decisions, so you can see and correct what Meta refused.
- Show delivery and performance figures back to you in the product.
- Let the automated parts of the service plan and adjust that advertising within the approval boundaries you set.
- Investigate faults and support requests about the connection.
Acting inside your Meta account
We act in your ad account on your authorisation, and only within it. Which of those actions run on their own and which wait for you is set by you, in the same approval policy that governs every other outward action the service takes.
Anything created in your ad account belongs to you and stays in your account. Meta bills your advertising spend to the payment method on your ad account; it does not pass through us.
Ending a Meta connection
You can end our access at any time, in either direction:
- Disconnect the integration in the product, on the company’s advertising panel. We attempt to pause delivery first, then stop using the connection — after which the service makes no further calls to Meta for that company.
- Remove or deauthorise the app in your Meta Business settings. Meta notifies us through our deauthorize callback, and we mark the connection inactive when that notice arrives.
- Ask us to delete the data, as described on the data deletion page.
What disconnecting does not do
Disconnecting Meta ends our access to that ad account. It does not close your account with us, delete the rest of your workspace, or remove the advertising already created inside your Meta ad account — that remains yours, in your account, for you to keep or delete there.
Deleting the company itself does remove what we hold for it, including the connection record, the access credential, and the advertising data we retrieved.
If you want the data we hold deleted, follow the data deletion instructions at /data-deletion.
How we use information
We use personal data to:
- Provide the service: plan, build, publish, and operate the company workspace you set up.
- Carry out actions you have authorised, and hold back the ones you have not.
- Keep a record of actions taken on your behalf, so they remain reviewable by you.
- Bill you, prevent fraud and abuse, and meet legal obligations.
- Improve the service, and — where required — ask your consent before using your content to train models.
AI processing
The service uses automated systems, including large language models, to produce plans, content, code, and outbound messages. Content you provide may be sent to model providers acting as our sub-processors in order to generate those outputs.
Advertising copy and creatives for a connected account are written from your company’s own product, brand, and site information, which is what is sent to those model providers for that purpose.
Automated output can be wrong. Decisions with legal or financial consequences remain subject to the approval boundaries you configure.
Sharing and processors
We share personal data only with service providers who help us run the service — hosting, model providers, email delivery, payment processing, analytics, and error monitoring — each under contract and only for those purposes.
Where you connect a third-party account such as Meta, we use what that platform makes available to us only to provide the functionality you asked for on that account. We do not sell it, and we do not use it to advertise anything other than the company you connected it to.
We may also disclose data where legally required, to protect our rights or someone's safety, or as part of a merger or acquisition, in which case we will tell you.
Cookies
We use cookies and similar technologies to keep you signed in, remember preferences, and measure usage. You can refuse non-essential cookies without losing access to core functionality; blocking essential cookies will stop the service from working.
Retention
We keep account and workspace data for as long as your account is active, and afterwards only as long as needed for legal, accounting, or dispute-resolution purposes. Action history is retained so it stays auditable. You can ask us to delete your workspace at any time.
For a connected advertising account we keep the connection record, the advertising we created for you, and the delivery figures we retrieved for as long as the integration is connected and the workspace is active. A disconnected connection is kept in an inactive state so the product can show what happened and offer to reconnect.
Deleting a company in the product removes that company and the records attached to it, including any connected advertising account, the stored access credential for it, and the advertising and performance data we held for it. Deleting your account removes your account and every company in it on the same terms.
You can also ask us to delete your data, as described on the data deletion page. We complete deletion requests within 30 days. Two things are not edited in place: operational logs, and encrypted backups, which age out on their own cycle — so a copy may persist in them for a period after the live data is gone.
We may keep information beyond that where we are required or permitted by law to — for example for accounting, fraud prevention, or an unresolved dispute.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, contact support@brainer.ceo.
You also have the right to complain to your local data protection authority.
International transfers
We and our processors handle data in the United States, which may not be the country you are in. Where we transfer personal data out of its country of origin, we rely on an appropriate safeguard such as standard contractual clauses.
Security
We use encryption in transit, access controls, and audit logging to protect data. No service can promise perfect security; if a breach affects your personal data, we will notify you and any regulator as required.
Children
The service is not intended for anyone under 18, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
If we make a material change we will update the date above and, where the change matters to you, tell you directly before it takes effect.