Brunto
Features Pricing Contact Sign in

Brunto Privacy Policy

Last updated: August 8, 2026

Brunto ("we", "us") provides mobile and web applications that help sales representatives manage leads and follow-up communication. This policy explains what data we collect, why, and how it is handled.

Data we collect

Account data. Your name and email address, from the email and password you register with or from signing in with Apple or Google. We store these to identify your account and display you to your teammates.

Lead data you enter. Names, phone numbers, addresses, email addresses, project codes, and notes about customers you add to the app. This data belongs to you and your team. You are responsible for having a lawful basis to store and contact the people you add.

Follow-up messages. The content and delivery status of messages you schedule and send through the app.

Images and documents you choose to import. When you use Import leads, the screenshots, photos, or PDFs you select are uploaded so their contents can be read and turned into lead records (see "Automated lead extraction" below). We only receive the specific files you pick — we do not browse or scan your photo library or your device.

Location, only when you ask for it. If you tap "Use current location" while adding a lead, the app reads your device location at that moment and converts it into a street address to fill in the address field. We store the resulting address as part of the lead. We do not track your location in the background or build any history of your movements.

Push notification token. A device token used to deliver notifications about sent follow-ups, reminders, and lead transfers.

Subscription data. Your subscription status and renewal date. Payment details are handled by Stripe; we never see your full card number.

Diagnostic data. Basic logs needed to operate the service, such as delivery errors from our SMS provider.

We do not collect your contacts, browsing history, or advertising identifiers, and we do not track you across other apps or websites. We do not sell your data or share it with advertisers.

How data is used

Data is used solely to provide the service: syncing leads across your team, sending the follow-up messages you schedule, extracting leads from files you import, notifying you about activity, and processing your subscription.

Automated lead extraction

The Import leads feature uses an artificial intelligence model provided by Anthropic to read the files you select and identify contact details in them. The files and the details extracted from them are sent to Anthropic solely to perform that extraction and return the result to you. Under our agreement with Anthropic, this content is not used to train their models. Nothing is saved to your pipeline until you review the extracted leads and confirm them.

Automated extraction can make mistakes. Please review what it produces before saving, and do not upload files containing personal information you do not have a lawful basis to process.

Service providers

We use a small number of processors to run the service: Supabase (database, authentication, and hosting), Anthropic (automated lead extraction from files you import), Twilio (SMS delivery), Stripe (payments; we never see your full card number), Expo (push notification delivery), Vercel (website hosting), and Apple or Google (sign-in). Each receives only the data required for its function.

Text messaging

Messages scheduled in Brunto are sent on your behalf and at your direction. You are the sender of record and are responsible for having the recipient's consent to receive texts, and for honoring opt-out requests, in line with applicable law, including the TCPA in the United States.

Where your data is stored

Brunto's database and backups are hosted in the United States (Supabase, AWS us-east-1). Our other processors may handle data in the United States or elsewhere. If you use Brunto from outside the United States, your data is transferred to and stored there. Where the law requires a transfer safeguard — for example the EU Standard Contractual Clauses — we rely on the terms in place with each processor.

Local storage on your device

Brunto does not use advertising or tracking cookies. The web app stores a small amount of data in your browser to keep you signed in and make the app work: your session token, your team identifier, and — if you arrived through a referral link — the referral code until it is used. Clearing your browser storage signs you out and removes these. The mobile app stores the equivalent session data in the iOS Keychain or Android Keystore.

Your rights

Wherever you are, you can ask us to give you a copy of your data, correct it, or delete it. The quickest route for most of this is the app itself: your leads and follow-ups are visible and editable in place, and Delete account removes them.

Depending on where you live you may also have the right to object to or restrict certain processing, to receive your data in a portable format, and to complain to your local data protection authority. If you are in the EU or UK, our legal basis for handling account and lead data is performance of our contract with you; for security and service diagnostics it is our legitimate interest in operating a reliable service. California residents: we do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we will not discriminate against you for exercising your rights.

To make a request, email support@brunto.ai from the address on your account. We respond within 30 days.

If something goes wrong

If a security incident affects your personal data, we will notify affected users and, where required, the relevant regulator, without undue delay.

Data retention and deletion

Your data is retained while your account is active. You can delete your account at any time — Profile → Delete account in the app, or Settings → Delete account on the web — which permanently removes your account, the leads you created, and your follow-up history. You may also request deletion by contacting us. Deleted data can persist in encrypted database backups for up to 30 days before those backups age out.

Files you import are used to extract leads and are not stored by us after the extraction completes. Records we are required to keep for legal or accounting reasons — invoices and payment records, held by Stripe — are retained for as long as the law requires, regardless of account deletion.

Referrals

If you share your referral link and someone signs up through it, we record the connection between your account and theirs so we can credit your free month. Your referrer can see that you joined through their link and whether it earned them a reward; they cannot see your leads, your activity, or anything else in your account.

Team visibility

Leads and follow-ups are shared within your team (organization). Team admins can invite and see members. Data is never visible to other organizations.

Security

Data is encrypted in transit and at rest. Access is enforced with row-level security in the database, so each team can only reach its own records, and administrative credentials are held server-side and never shipped to the app. Session tokens are stored in the iOS Keychain or Android Keystore on mobile, and in your browser's local storage on the web. No system is perfectly secure, but we design for least privilege and keep the number of processors small.

Children

Brunto is a business tool intended for users 18 and older. We do not knowingly collect data from children.

Changes

We will update this page when the policy changes and revise the date above. If a change materially affects how we handle your data, we will tell you in the app or by email before it takes effect.

Contact

Questions or requests: support@brunto.ai

© Brunto Features Pricing Contact Privacy Terms