Last updated July 31, 2026
Signals is an internal operations console operated by Brillion Studio for advertising agencies and the businesses they serve ("clients"). This policy explains what data Signals processes, why, and the choices you have. Signals is used by a business to view and manage its own connected accounts; we act as a data processor on that business's behalf.
When a business connects an account to Signals, we access only the data that account authorizes, to render it back to that same business inside the app. Depending on which integrations are connected, this may include:
Signals can connect a Google Account so a business can work its own mail, calendar and files inside the app. Google data is handled separately from everything else on this page, and the commitments in this section are binding.
We request only the scopes the connected features actually use:
gmail.modify — read the connected mailbox and mirror its state. Signals displays your threads and messages, and applies the changes you make in the app (read/unread, archive, move to Trash, labels) back to Gmail. It does not delete mail permanently.gmail.send — send, reply to and forward messages as you, only when you press send.calendar.readonly and calendar.events — show your calendar alongside the pipeline, and create or update the events you book in Signals.drive — the in-app file browser: list and search your Drive, create folders, rename, upload, move files to Trash, and import a file you choose into Signals. This is full Drive access because the browser can navigate any folder you can; Signals touches a file only when you act on it.Google data is used only to provide these features to the person who connected the account. Specifically, Signals does not:
Limited Use. Signals's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and revocation. Gmail messages are cached so the app can render your inbox without re-fetching everything; Calendar and Drive are read live and not warehoused. You can revoke Signals's access at any time from your Google Account permissions, or by disconnecting inside Signals (Integrations → Disconnect), which also revokes the token. On revocation we stop accessing your Google data immediately, and the cached copy is deleted on request to privacy@brillionstudio.com.
Only to provide the Signals service to the business that connected the account: displaying its inbox, reports, pipeline, and related tooling. We do not sell personal data, we do not use it for advertising, and we do not share it with third parties except the infrastructure providers below that operate the service on our behalf.
Data is stored in our database and object storage hosted by Supabase, and served through Vercel. Access is restricted to the connecting business (enforced by per-account access controls) and to Brillion Studio personnel who operate the service. Tokens are encrypted at rest.
We retain connected data for as long as the account remains connected. You can remove it at any time:
Meta data deletion callback: /data-deletion
You control which accounts are connected and can disconnect or request deletion at any time. If you are an end user who messaged a business that uses Signals and want your data removed, contact that business, or email us at privacy@brillionstudio.com and we will act on verified requests.
We may receive requests from public authorities (courts, regulators or law enforcement) for personal data we hold. Brillion Studio applies the following to every such request:
Where we are legally permitted to do so, we will notify the affected business or person before disclosing their data.
We may update this policy; material changes will be reflected by the "last updated" date above.
Brillion Studio · privacy@brillionstudio.com
This policy covers Signals's use of the Meta Platform (Instagram & Messenger APIs), Google APIs, and other connected integrations, consistent with the Meta Platform Terms and Developer Policies and the Google API Services User Data Policy.