Privacy policy
Effective 11 September 2026 · botmust.com
This policy explains what [your registered company name] collects when you use Botmust, why, who else sees it, and how to get it back or get rid of it. It covers both your own account and the advertising data Botmust reads on your behalf.
1. Who is responsible
[your registered company name] operates this installation of Botmust and is the data controller for your account information.
For the advertising and lead data Botmust reads from your ad accounts, you are the controller and [your registered company name] is a processor — it is your data, held on your instruction, and it is deleted when you say so.
2. What is collected
When you create an account
- Your name, email address and (optionally) company name.
- A one-way hash of your password. The password itself is never stored and cannot be recovered.
- If you sign in with Google or Facebook: the account ID that provider gives us, your email, your display name and your profile picture URL. The access token from that sign-in is used once to identify you and then discarded — it is not stored.
- Your currency, time zone and display preferences.
When you use the product
- The targets and business details you enter, so campaigns can be judged against them.
- A record of every change made to a connected ad account: what changed, the old value, the new value, the reason you gave, when, and whether the platform accepted it.
- Standard web server logs, which include IP addresses, kept by the hosting provider.
Botmust does not use advertising cookies, does not run third-party analytics or trackers, and does not sell or rent anything it holds.
3. Data from Facebook and Google
When you connect an ad account, the platform gives Botmust an access token. That token is encrypted with AES-256 before it is written to the database, using a key generated for this installation, and it is never shown again after connection.
With it, the following is read on a schedule you control:
- Ad accounts, campaigns, ad sets and ads — names, status, budgets, objectives, dates.
- Ad creative — headlines, body copy, calls to action, image and video URLs.
- Daily performance — spend, impressions, reach, clicks, conversions, conversion value.
- Lead form submissions, where you use lead ads.
- Click-to-WhatsApp metrics — conversations started and message counts. The content of WhatsApp messages is never read or stored.
Disconnecting deletes Botmust’s copy and changes nothing at the platform. Campaigns, ad sets, ads, metrics, leads and conversations are erased from this database. At Meta and Google nothing moves: campaigns keep running, budgets stay as they are, live ads stay live, paused ads stay paused, and lead forms keep collecting. Botmust simply stops reading.
Permission to change your ad accounts is asked for separately and is off by default. Nothing is written to a live account without you approving that specific change on a review screen first. Even with the permission granted, the only fields Botmust can change are a daily budget, a status and a bid cap — one object at a time. It has no ability to create, delete or archive anything, or to alter targeting, audiences, creative or copy.
Data received through the Meta and Google APIs is used only to provide the reporting and optimisation features described here. It is not used to build advertising profiles, is not combined with data from other sources for that purpose, and is not passed to any data broker.
4. Your customers’ data
If you run lead ads, Botmust stores the leads those ads produce so it can show you which campaign, ad set and creative each one came from. That typically includes a person’s name, email address, phone number and city, plus the status you give them and any value you record.
These are people who filled in your form, not users of Botmust. You remain responsible for having a lawful basis to collect and hold them, for your own privacy notice at the point of collection, and for answering their requests. [your registered company name] processes them only to display them to you, and acts on your deletion instructions.
Lead records can be deleted individually from the Leads screen, or all at once from Settings → Data.
5. Why it is used
| Purpose | Basis |
|---|---|
| Running your account and signing you in | Performing our contract with you |
| Showing your advertising performance | Performing our contract with you |
| Producing recommendations and applying approved changes | Performing our contract with you |
| Keeping a log of changes made to your ad accounts | Legitimate interest — you need to see what was done and be able to undo it |
| Keeping the service secure and diagnosing faults | Legitimate interest |
| Billing, where a paid plan is in use | Performing our contract, and legal obligation for records |
6. What is sent to BMX engine providers
The built-in advisor runs entirely on this server and sends nothing anywhere. It is the default.
If you switch the advisor to a BMX engine in Settings → Advisor — Anthropic’s Claude, or any OpenAI-compatible endpoint you nominate — then for each campaign or ad you view, the following is sent to the provider you chose:
- Aggregate figures: spend, impressions, clicks, conversions, cost per result, rates.
- Your ad copy: headlines, body text, calls to action.
- Lead counts by stage — how many are new, contacted, qualified, converted, lost.
- The business profile you typed in Settings.
Never sent: any lead’s name, email address, phone number or city; any WhatsApp message content; your access tokens; or your password.
You supply your own API key, so your relationship for that processing is directly with that provider under their terms. Answers are cached against your figures to limit how often requests are made. Turning the advisor back to the built-in rules stops all of it immediately.
8. How long it is kept
| What | Kept for |
|---|---|
| Your account | Until you delete it |
| Campaign and performance data | Until you disconnect and clear it, or delete the account |
| Leads | Until you delete them, individually or in bulk |
| Access tokens | Erased the moment you disconnect a platform |
| Change log | Retained while the account exists, so past changes stay auditable |
| Billing records | As long as tax law requires |
Deleting your account removes your data from the live database within 30 days, backups included.
9. How it is protected
- Passwords are hashed; nobody can read them, including us.
- Platform access tokens are encrypted at rest with a per-installation key.
- All database access uses prepared statements.
- Every form carries a CSRF token, and change proposals are signed so they cannot be altered in the browser.
- Application code, the configuration file and the database file are blocked from direct web access.
- Write access to your ad accounts is opt-in, per-change approved, logged, and reversible.
No system is perfectly secure. If a breach affects you, you will be told without undue delay.
10. Your rights
Depending on where you live, you can ask to:
- see what is held about you, and get a copy in a portable format;
- correct anything wrong — most of it you can edit yourself in Settings;
- delete your account and everything in it;
- object to or restrict a particular use;
- withdraw consent where consent was the basis, without affecting what came before;
- complain to your data protection authority.
Much of this is self-service: Settings → Data exports and clears, and every screen has an export. For anything else, write to [your contact email] and expect a reply within 30 days.
If you are a lead rather than a customer — your details reached Botmust because you filled in an advertiser’s form. Contact that advertiser; they control the record. Forward a request to [your contact email] and it will be passed to them.
12. Children
Botmust is a tool for businesses and is not directed at anyone under 16. If a child’s data has reached it, write to [your contact email] and it will be removed.
13. Changes
When this policy changes, the date at the top changes with it. Anything that materially affects how your data is handled will be told to you by email before it takes effect.
14. Contact
See also the terms of service.