Privacy policy
Last updated 17 September 2026
Who we are
Brava (“we”, “us”) helps businesses manage the advertising they already run on Google Ads and Meta. This policy covers the service at nexus.beansmile.ai, and every piece of data we handle on your behalf when you connect an advertising account to it.
Brava is operated by the team that runs nexus.beansmile.ai, who are the data controller for the personal data described in this policy. Every request under this policy — a copy of your data, a correction, a deletion, or a question about any of it — is read at nexusainb@gmail.com and answered within 30 days.
The short version
We take advertising data, not your customers’ data
Campaign structure and daily performance figures from the ad accounts you pick. We do not collect your customers’ personal data, your audience or remarketing lists, or the creative assets inside your ads.
We change nothing you have not approved
Every change to your advertising is proposed to you first and applied only after you approve that specific change. This is enforced in the software, not merely promised.
We do not sell it, advertise with it, or train models on it
Data from your Google and Meta accounts is used to run the features you connected the account for, and for nothing else.
You can get it out, or have it deleted
Ask us and we will send you a copy or delete it, within 30 days. You can withdraw our access from Google’s or Meta’s own settings at any moment without asking us first.
What we collect
Your account
The email address and name you sign up with, and a hash of your password if you set one. If you sign in with Google, we receive your Google account’s stable identifier, email address and name, and store those. We never receive or store your Google password.
Your advertising data
From the ad accounts you choose to manage: campaign, ad set and ad structure and settings; daily performance figures (spend, impressions, clicks, conversions and their value); and the platform’s own identifiers for those objects. We also keep the platform’s raw response alongside what we parsed out of it, so that a figure we showed you can always be traced back to what the platform actually said.
The identity that authorised the connection
The email address of the Google or Meta account used to grant access. This is needed because the platforms decide what may be changed by looking that person up on each account, and we check that before offering you a change we could not apply.
Your access credentials for the platforms
The access and refresh tokens Google and Meta issue when you authorise a connection. These are encrypted before they are stored — see “How it is protected” below.
Changes we make
A permanent record of every change applied to your advertising: what changed, from what value to what value, who approved it, and when.
Your settings
The limits you set — spend ceilings, how far a budget or target may move at once, the hours you advertise in, campaigns marked as not to be touched — and who on your team may approve a change.
Technical and log data
Ordinary web server request logs, which include the IP address a request came from, the page or endpoint requested, and the time. We use them to keep the service running and to investigate abuse. We do not use them to build a profile of you and we do not combine them with your advertising data.
Google user data: what we ask for, and what we do with it
We request two separate Google permissions, at two separate moments, and neither happens without you passing through Google’s own consent screen. This section sets out each one: what it returns, why we need it, how we store it, who it reaches, and when it goes.
Signing in with Google — openid, email, profile
We ask only for your name, email address and Google account identifier, so we know who you are and can keep you signed in. Signing in touches no advertising data, and you can use the product without it. We access your Google account’s stable identifier, email address and display name. We store all three against your Brava account, so the next sign-in recognises you as the same person. We share none of it with anyone. We delete it when your Brava account is deleted.
Connecting a Google Ads account — https://www.googleapis.com/auth/adwords
Separately, and only when you choose to connect an account, we ask for Google Ads access (“manage your AdWords campaigns”). We use it to read your campaign structure and daily performance figures, and to apply the changes you approve. Google publishes no read-only version of this scope, so the same permission covers both; what keeps it narrow is the product, not the permission.
What that scope lets us read
The structure and settings of the campaigns, ad groups and ads in the accounts you selected, and their daily performance figures — spend, impressions, clicks, conversions and conversion value. We read the last 90 days when you connect, and then re-check on the interval you choose (four hours by default). We do not read anything from Google Ads accounts you did not select.
What that scope lets us change, and only after you approve
Three things on Google Ads: pause or resume, daily budget, and target cost per acquisition — each only after you have approved that specific change. (A fourth, the delivery schedule, applies to Meta only.) We never delete a campaign, ad group or ad. The most severe action the software can take is pausing something.
Why a narrower scope will not do
Google publishes no read-only version of the Google Ads scope. The same permission covers reading your figures and applying a change, so requesting less would mean not being able to read your campaigns at all. What keeps our use of it narrow is the product — a change reaches Google only after you have approved that exact change — rather than the permission.
How Google user data is stored
In our own PostgreSQL database, on our own server. Each business’s rows are isolated at the database level rather than by application code. The Google tokens that reach your ad account are encrypted before they are written, under a key held in the server environment and never in the database.
Who Google user data is shared with
Nobody, other than the infrastructure providers listed under “Who else sees it” below, who process it on our instruction and for no purpose of their own. Your Google Ads performance tables are never sent to our language model provider. We do not sell it, we do not transfer it to data brokers, and we do not use it for advertising or to train machine-learning models.
How to take it away
Disconnect the account in Brava, or revoke our access directly from your Google account permissions — either stops all further reading and every possibility of a change. To have the data we already hold erased as well, see “How to have your data deleted” below.
Brava’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically: data obtained through Google APIs is used only to provide and improve the features you connected the account for; it is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition; it is not used for advertising; and no human reads it except with your explicit permission, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised.
Meta data: what we ask for, and what we do with it
Connecting a Meta advertising account requests three permissions: ads_read to read your campaigns and their results, ads_management to apply a change you have approved, and business_management to see which ad accounts the login you used is actually permitted to act on — so that we can tell you up front if it cannot, rather than failing at the moment you approve something.
Everything said above about storage, sharing, approval and deletion of Google data applies identically to Meta data. We read the campaigns and results of the accounts you selected, and change nothing you have not approved.
What we use it for
Only to run the service: to produce optimisation suggestions, to apply the ones you approve, to show you what happened afterwards, and to answer your questions about it. Suggestions are produced by a deterministic rule engine from your own figures. A language model is used to rewrite the resulting explanation into plain language, and is given only the small set of facts already inside that suggestion — an entity name and the few numbers the rule already produced. Your performance tables are never sent to it, and its rewrite is checked back against the underlying figures: if a number appears that the rule engine did not produce, the rewrite is discarded and a fixed template is used instead.
We also use your email address to send you service messages — a password reset, a notification you asked for, or a material change to this policy.
We do not sell your data, use it for advertising, or use it to train machine-learning models.
Cookies and similar technology
We set two cookies, both strictly necessary to sign you in, and no others. We run no analytics package, no advertising or tracking pixels, and no third-party scripts that could set a cookie of their own — so there is no consent banner on this site because there is nothing to consent to.
nexus_session
Set when you sign in, and it is what keeps you signed in. It holds a signed token, not your details. It is HttpOnly and Secure, so page scripts cannot read it and it is never sent over an unencrypted connection. It lasts 30 days, and signing out deletes it.
nexus_signin_state
Set for the few seconds a “Continue with Google” round trip is in flight, and deleted at the end of it. It exists so that we can tell that the browser coming back from Google is the same one that left — without it, somebody could sign you into an account that is not yours.
Your light or dark theme preference is kept in your own browser’s local storage. It never reaches our servers.
Who else sees it
Google and Meta
Because that is where your advertising is. We read from and write to them on your instruction, under the permissions you granted.
Anthropic (language model)
A small set of structured facts from a single suggestion — the entity’s name and the few figures already in that suggestion — is sent to be rewritten into readable prose. Your performance tables are never sent. This can be switched off for a deployment, in which case the wording comes from fixed templates instead.
Contabo GmbH (hosting)
Munich, Germany. Our server and database run on infrastructure they provide. They have no access to your data for any purpose of their own.
Resend (email delivery)
Where email delivery is configured, transactional email — password resets and the notifications you asked for — is sent through them. They receive your email address and the contents of that message.
Each of these is a processor acting on our instruction, under contract, and none of them may use your data for their own purposes. We do not share your data with anybody else, and we do not sell it. If we are ever compelled to disclose data by a valid legal order, we will tell you unless we are prohibited from doing so.
Where it is processed
Your data is stored on our server, hosted with Contabo GmbH, a German provider. The processors listed above operate internationally, so some processing — model rewriting and email delivery in particular — may take place outside your own country, including in the United States. Where personal data leaves the UK or the European Economic Area, the transfer is made under the safeguards those providers offer for it, ordinarily the European Commission’s Standard Contractual Clauses.
How long it is kept
We would rather describe the schedule that is actually running than the one we intend, so this section describes the former.
The record of changes we made — kept indefinitely
It is the audit trail of actions taken on your advertising account, and the one record that answers “who changed this, and when”. Deleting it would remove your own evidence as much as ours.
Raw platform responses — two years after an object was last seen
That clock restarts every time we sync, so the raw data behind a campaign that is still live is in practice kept for as long as it stays live.
Daily performance figures — a deletion schedule runs for some platforms and not yet for others
Where no schedule runs, the figures are kept until you ask us to erase them or delete your account. Closing that gap is work in progress.
Access credentials — deleted the moment you disconnect
Disconnecting a platform deletes the stored token immediately, and with it every ability to read or change anything on that account.
Your account — deleted when you ask
Your email address, name and Google identifier are held while your account exists, and removed when it is deleted.
Disconnecting a platform is not deletion. It deletes the stored credential and stops all checking and any further changes. It does not erase the advertising data already collected, and it does not remove the email address of the account that authorised the connection. To have those erased, ask us — see directly below. We are working to make disconnection erase them automatically; until it does, this paragraph describes what actually happens rather than what we intend.
How to have your data deleted
Write to nexusainb@gmail.com from the email address on the account, saying whether you want a single connected ad account’s data erased or the whole account removed. We do not ask you to justify the request. We complete it and confirm within 30 days, and we tell you what was deleted and what was kept — the audit record of changes we made survives, for the reason given above.
You do not have to wait for us to stop our access. Revoking it in your Google account permissions or in Meta Business Settings takes effect immediately and needs nothing from us.
How it is protected
The credentials that reach your advertising accounts are encrypted before they are stored, under a key held in the server environment and never in the database — so a copy of the database alone does not yield them. Each business’s data is isolated at the database level rather than by application code, and the database connections that serve customer traffic cannot read across businesses. Passwords are stored only as a slow one-way hash. All traffic to the site is encrypted in transit and the site is served over HTTPS only.
No security is absolute. If a breach occurs that is likely to put your rights at risk, we will tell you and the relevant supervisory authority without undue delay and, where the law sets one, within 72 hours.
Your rights, and what we rely on to process your data
You can ask us for a copy of the data we hold about you, ask us to correct it, ask us to delete it, or ask for it in a portable form. Where the UK or EU GDPR or a comparable law applies to you, you also have the right to object to processing, to restrict it, to withdraw consent you have given, and to complain to your local supervisory authority without coming to us first.
To perform our contract with you
Reading your advertising data, producing suggestions, applying the changes you approve, and keeping the record of them. This is the basis for almost everything on this page.
Your consent
Granting each platform connection, which you give on Google’s or Meta’s own consent screen and can withdraw at any time from there.
Our legitimate interests
Keeping the service secure and available, investigating abuse, and the request logs described above — balanced against your interests, which is why those logs are not combined with anything else.
Write to nexusainb@gmail.com to exercise any of these. We respond within 30 days.
Children
Brava is a business tool for people who run advertising accounts. It is not directed at children, we do not knowingly collect personal data from anyone under 18, and there is nothing in the product intended for them. If you believe a child has given us data, write to us and we will delete it.
Changes to this policy
If we change this policy materially we will tell connected customers by email before the change takes effect. The date at the top is always the date of the version you are reading.
How to contact us
Write to nexusainb@gmail.com about anything on this page — a copy of your data, a correction, a deletion, a question about what we hold, or a complaint. Every one of them is read, and answered within 30 days.