Privacy Policy
Last updated: September 25, 2026
This policy explains what Broma (“we”) collects when you use bromaapp.com, the Broma desktop app and the Broma cloud services, what we use it for, and the choices you have. It describes what our software actually does today — when that changes, this page changes with it.
Your account
You need an account to use Broma. When you sign up with email, we collect your email address, an optional name and your password, which we store only as a one-way hash. Until you enter the 6-digit code we email you, the signup is held for 10 minutes and then discarded.
If you continue with Google, Google shares your name, email address and Google account ID with us. We don't store your Google profile photo.
We also keep your current plan, its start and end dates, and a history of plan changes.
The desktop app
When you sign in, the app registers your computer with a random device ID it generates itself (never derived from your hardware), together with the computer's name (your hostname by default), operating system and app version, and we record when the device was last active. We also record when you first and last used the desktop app, and in how many distinct hours you have used it.
Your flows, run history, settings and any profile you don't sync stay on your computer.
If you use the AI agent, the app sends your prompts and what the agent works with — screenshots, page text and page structure from the pages it automates — directly to the AI provider you configured with your own API key. That data does not pass through Broma's servers, and the provider's own privacy policy applies. Your API key is stored encrypted on your computer.
Proxies
Proxies you add to your proxy pool — host, port, username and password — are synced to our servers so they are available on every computer you sign in on. This happens for every signed-in account, on every plan including Free. A proxy you enter directly on a profile is also saved to our servers once it passes a proxy check.
Proxy usernames and passwords are stored on our servers as you entered them, without additional encryption. Deleting a proxy removes it from your account, but the record, including its credentials, is currently kept on our servers.
When you check a proxy, the app contacts ipwho.is through that proxy to look up the proxy's exit IP address and location.
Cloud sync and teams
Cloud sync is available on paid plans and is turned on per profile. For each profile you sync, the app uploads an archive of that profile's browser data: cookies, saved logins (the usernames and passwords saved in that profile), autofill data, history, bookmarks, local storage, IndexedDB, extension data and browser preferences, along with the profile's ID, name, operating system and browser version.
Archives are transferred over HTTPS and stored as zip files in Cloudflare R2. The app does not encrypt them before upload, so anyone who gains access to that storage could read them — only sync profiles you are comfortable keeping in the cloud.
On a team, the owner and admins can access every profile synced to the team; members and viewers can access the profiles shared with them. When you invite someone, we store the email address you invited; invitations expire after 14 days.
Payments and referrals
When you buy a plan, we keep the order: plan, period, amount, order code, status and timestamps.
You pay by bank transfer via VietQR. The QR image is generated by VietQR (img.vietqr.io) and loaded by your browser. Casso, a bank reconciliation service, notifies us of transfers arriving in our bank account, and we store the transaction details it sends, which include the sender's name, account number and bank. Casso reports every transfer to that account, so these details are stored even for transfers unrelated to an order. We never receive card details.
If you sign up through a referral link, we record who referred you and the IP address you signed up from, to prevent referral fraud; the code from the link is kept in a cookie for 30 days. If you join the referral program, we store your display name, avatar and the bank details you provide for payouts, along with the version and date of the referral terms you accepted.
If you buy or sell in the in-app store, we keep the purchase records, sellers' payout bank details, and a download log (a hashed IP address, the user agent and the device ID) for 180 days.
Crash reports and diagnostics
The desktop app sends crash reports and diagnostic logs to Sentry and Better Stack so we can find and fix problems. They contain error details, the app version and update channel, your device ID, and your account ID and email address. Diagnostic logs describe what the app was doing — for example the proxy host and port a profile was launched with — and are not designed to contain profile contents, cookies or passwords.
This is on by default and can be turned off in the app's Settings. Crashes that happen while the app is starting or while you are signing in are still reported, because your setting has not loaded yet at that point.
Website cookies and storage
bromaapp.com is served by Cloudflare. On the sign-in and sign-up pages, the “Continue with Google” button loads Google Identity Services from accounts.google.com, which may set Google's own cookies. The website itself uses these cookies and browser storage:
- broma_at — keeps you signed in; expires after 15 minutes.
- broma_rt — renews your session; expires after 30 days.
- broma_ref — the referral code from a referral link; expires after 30 days.
- i18n_redirected — remembers your language; expires after 1 year.
- broma-theme (local storage) — remembers light or dark mode.
- broma_order_key (session storage) — prevents creating the same order twice during checkout; cleared when you close the tab.
- _ga and _ga_XXXXXXXXXX — Google Analytics cookies, described below; expire after 2 years.
Google Analytics
We use Google Analytics 4 on bromaapp.com to understand how the website is used: which pages are visited, how visitors arrived, and interactions such as scrolling, outbound clicks and downloads. Google collects device and browser information and derives an approximate location from your IP address; Google Analytics does not log or store IP addresses.
We send Google the page address without its query string, except for campaign parameters (utm_ tags and ad click IDs), so sign-in codes, order codes and referral codes in our URLs are not sent. Google Analytics runs only on bromaapp.com and www.bromaapp.com.
You can block these cookies in your browser or use Google's opt-out add-on:
Server logs
Every request to our API is logged with your IP address, the requested path (without its query string), the response status and timing. These logs, and the desktop app's diagnostic logs, are stored with Better Stack. We use them to keep the service running and to investigate abuse.
How long we keep data
- Unconfirmed signups: 10 minutes.
- Account, plan and device records: for as long as your account exists. Devices you remove are marked as revoked, not erased.
- Synced profiles: as many versions as your plan allows. When you delete a synced profile, its files are removed from storage within about an hour. If your paid plan ends, we keep the latest version of each synced profile so you can download it again.
- Orders, payments and payouts: kept for accounting; we do not delete them automatically.
- Team invitations: expire after 14 days; the record of the invitation is kept.
- Proxies: kept until you delete them — and, as noted above, deleted proxy records are currently retained.
- In-app store download log: 180 days.
- Logs: kept for a limited time for troubleshooting and security.
- Cookies: as listed under Website cookies and storage.
Your choices and rights
You can turn off cloud sync for any profile, turn off crash reports in the app's Settings, and block or delete cookies in your browser.
You can ask us for a copy of your data, to correct it, or to delete your account and its data. There is no self-service deletion yet, so email privacy@bromaapp.com and we will handle it. You may also withdraw consent or object to processing where the law gives you that right. Some records, such as payment records, may have to be kept to meet legal obligations.
Security
All traffic between the app, the website and our servers uses HTTPS. Access tokens expire after 15 minutes, and the desktop app stores your session and AI API keys encrypted on your computer.
Synced profile archives and proxy credentials are not encrypted by the app before they reach our storage. No system is perfectly secure; if we learn of a breach affecting your data, we will notify you as required by law.
Children
Broma is not intended for children under 16, and we do not knowingly collect their data.
Changes to this policy
When our data practices change, we update this page and the date at the top. For significant changes, we will also let you know on the website or in the app.
Contact
For privacy questions or requests, email us:
