Privacy Policy

Last updated: 30 June 2026

Broto ("Broto", "we", "us") operates the website and application at brotoai.com. Broto is a software platform that helps Indian Customs House Agents (CHAs), customs brokers, and importers and exporters automate their day-to-day customs-compliance work — HSN and HS classification, duty and FTA calculation, ICEGATE Bill of Entry and Shipping Bill preparation, document extraction, shipment tracking, and government-portal automation.

This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. It applies to the Broto web application, our backend services, and our companion browser extensions.

Information you provide to us

  • Account and firm details. Your name, work email, and the customs firm you belong to, used to create and secure your account.
  • Customs and shipment data. The operational data you enter or upload to do your work — for example importer and exporter details, invoices, packing lists, Bills of Entry, Shipping Bills, HSN codes, container and IGM numbers, and the PDF documents you upload for extraction.
  • Third-party portal credentials. If you choose to use our portal-automation features, the credentials needed to act on your behalf — for example your ICEGATE portal password and the mailbox that receives your ICEGATE login OTP. These are encrypted at rest (see How we protect your data) and are never displayed back to you or shared.

Google user data (Gmail)

Connecting a Google account is entirely optional and is used for one purpose only: reading the one-time password (OTP) that ICEGATE emails you when you log in, so that Broto can complete the ICEGATE login on your behalf and fetch your Bill of Entry status automatically. Broto does not use Google for signing in to Broto itself.

What we request

  • gmail.readonly — read-only access to your Gmail messages.
  • openid and email — to identify the email address of the mailbox you connect.

How we use Google data

  • When Broto logs in to ICEGATE for you, it searches your Gmail for the most recent message from icegate.gov.in (sent within the last day) and reads it only to extract the numeric OTP.
  • Access is strictly read-only. We never compose, send, modify, label, or delete any email.

What we store

  • Only an encrypted Google OAuth refresh token (so we can read a future OTP without asking you to sign in each time) and the email address of the connected mailbox.
  • We do not store the contents of your emails. The OTP is extracted in memory at login time and used immediately; the message body is never written to our database or logs.

What we never do

  • We never sell, share, or transfer your Gmail data to anyone.
  • We never use your Gmail data for advertising.
  • We never use your Gmail data to train artificial-intelligence or machine-learning models, and we never send it to our AI providers.
  • No human at Broto reads your email, except where you give explicit consent for support or troubleshooting, where required for security or to comply with the law, or where the data has been aggregated and de-identified.
Broto's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking access

  • You can disconnect your Google account at any time from Broto's ICEGATE settings, which deletes the stored refresh token.
  • You can also revoke Broto's access from your Google Account at myaccount.google.com/permissions.

Information we collect automatically

To run and secure the service we keep basic operational records such as timestamps, diagnostic logs, and error logs, and we use a session token to keep you signed in. We do not use third-party advertising networks or cross-site tracking cookies.

How we use your information

  • Provide and operate the features you use — classification, duty and FTA calculation, Bill of Entry and Shipping Bill generation, document extraction, tracking, and portal automation.
  • Authenticate you and secure your account and your firm's data.
  • Process the documents and data you submit to produce drafts, filings, and results.
  • Provide support, fix problems, and improve the reliability of the service.
  • Comply with legal obligations.

How we share information

We do not sell your personal information. We share data only with the infrastructure and service providers that help us run Broto, under their terms and only as needed:

  • Cloud hosting and database — to run the application and store your account and shipment data (for example Railway, Vercel, and Supabase / Postgres).
  • AI providers — to classify goods and extract data from documents we send the relevant product and document text to our AI providers (for example OpenAI and Anthropic). Your Google and Gmail data is never sent to AI providers.
  • Email delivery — to send you notifications and alerts (for example Resend).
  • Government portals you direct us to — when you use portal automation, we transmit the relevant data to the government systems you are filing with (for example ICEGATE, PQMS, DGFT, and GST) to perform the action you requested.

We may also disclose information where required by law, or to protect the rights, safety, and security of Broto, our users, or the public.

How we protect your data

  • Sensitive credentials — your ICEGATE password, OTP-mailbox credentials, and Google refresh token — are encrypted at rest using authenticated AES encryption and are decrypted only in memory at the moment they are needed. They are never returned to the browser or written to logs.
  • Data is transmitted over HTTPS / TLS.
  • Access to production data is restricted to authorized personnel.

No method of storage or transmission is completely secure, but we work to protect your information using industry-standard measures.

Data retention

  • We keep your account and shipment data for as long as your account is active or as needed to provide the service, and as required to comply with legal obligations, resolve disputes, and enforce our agreements.
  • Your Google refresh token is kept until you disconnect Google or delete your account, whichever comes first. Gmail message contents are not retained at all.
  • You can request deletion of your data at any time (see below).

Your rights and choices

  • Access and correct your account and shipment data within the app.
  • Disconnect any connected mailbox (Google, Microsoft 365, or IMAP) at any time in Settings.
  • Request a copy or deletion of your personal data by emailing support@brotoai.com. We will respond consistent with applicable law.

Browser extensions

Our companion Chrome extensions help you fill Indian government forms using data from your own Broto account:

  • On the Broto dashboard, an extension reads your Broto session token from the page so it can fetch your shipment data as you. The token is stored only in your browser's extension storage and sent only to the Broto backend.
  • On government form pages (for example India's PQMS Import Release Order), the extension fills fields with your data. It never clicks Submit — you review every value and submit yourself. It does not read your portal logins or captchas.
  • The extensions use no analytics, advertising, or tracking, and share nothing with third parties. Removing an extension deletes its locally stored data.

Children's privacy

Broto is a business tool that is not directed to children under 18, and we do not knowingly collect personal data from them.

Changes to this policy

We may update this policy from time to time. We will revise the Last updated date above and, for material changes, take reasonable steps to notify you.

Contact us

Questions or requests, including data-deletion requests, can be sent to support@brotoai.com.