1Two groups of people, two roles
The platform processes data from two very different groups, and our legal role changes for each one:
- Subscribers (who creates an account and pays for the plan). Here we are controllers: we explain why and how we process this data. This is covered in sections 2 to 9.
- Leads (companies and professionals found on the platform from public sources). Here we are processors: we process it according to the subscriber's instructions, who is the controller of this processing. This is covered in section 10, which also provides the removal channel.
2Data we collect from the subscriber
| What | When | Why |
|---|---|---|
| Name, email, phone | Signup | Create and identify the account, activate it by email, provide support, and send billing and service notifications |
| Password | Signup | Authentication. We only store the hash (scrypt): there is no way for us to read your password |
| IP address (in hashed form), browser identifier, user agent | Sign-up and login | Security and fraud prevention (mass accounts, free trial abuse) |
| Billing data | Plan subscription | Process the payment. The card is entered in Stripe’s environment and never reaches our servers; we only store the customer and subscription ID in Stripe |
| Email credential (app password) | When you connect your email account | Send, on your behalf, the emails you ask to send. Stored encrypted and removable at any time |
| Usage log (searches made, credits spent, account actions, errors) | Platform usage | Provide the service, charge correctly, measure usage, investigate problems, and comply with legal record-retention obligations |
| Date and version of Terms acceptance | Signup | Demonstrate consent, as required by art. 8, §1 of the LGPD |
We don't request or store the subscriber's CPF, CNPJ, identity document, or sensitive data (racial origin, health, biometrics, political opinion, among others).
3Legal bases
- Contract performance (Art. 7, V): registration, authentication, service provision, billing, and support.
- Compliance with a legal obligation (Art. 7, II): storing application access records for 6 months, as required by the Brazilian Internet Civil Framework, and storing tax and financial records.
- Legitimate interest (Art. 7, IX): platform security, fraud and abuse prevention, and product improvement based on usage data.
- Consent (Art. 7, I): marketing communications, when applicable. You can withdraw your consent at any time without affecting the contracted service.
4Cookies
We use only a few, and each has a defined purpose:
- Session cookie: keeps you logged in. It is essential, and without it there is no login.
- Device identifier: helps detect mass account creation during the free trial.
- Language: remembers whether you prefer to view the interface in Portuguese or English.
- Cookie preferences:
vr_consentkeeps your choice for up to 180 days and shares it between the website and app. - Audience measurement: Google Analytics, Meta pixel, and the first-party cookie
vr_origemonly use measurement storage after of your consent. Thevr_origemlasts up to 30 days and stores the public entry page, the referring domain, and campaign identifiers. When you sign up, this data is associated with your account to measure which sources generate usage and payments. We do not store the full URL or other browsing parameters in this cookie.
Session, device, and language cookies are necessary for the service to work and don't require consent (Art. 7, V, of the LGPD: contract performance). Audience measurement depends on your “Accept,” and refusing doesn't remove any functionality. Separately: when you purchase or renew a plan, our server tells Meta that a purchase occurred, using your hashed email — this doesn't use any cookies and is covered by §5, with the exact list of what is sent.
How to change your mind: the "Cookie preferences" link, in the site's footer, reopens the notice at any time — withdrawing consent is as easy as giving it (art. 8, § 5). You can also block cookies in your browser; blocking the session cookie prevents login, because it's what keeps you authenticated.
5Who we share with
We don't sell personal data. We share it only with providers necessary for the service to work, and only the minimum each one needs:
| Provider | Why | What they receive |
|---|---|---|
| Stripe | Payment and subscription | Name, email, and card details entered by you in its environment |
| Hosting provider | Server where the application runs | All data, at rest and in transit, under contract |
| AI providers | Generate copy and analyses when you trigger an AI feature | Only the content of that request (the lead’s public data and what you wrote). We do not send your password or billing information |
| Your email provider | Send your campaigns | The credential you connected and the content of the messages you send |
| Meta (Facebook and Instagram) | Measure which ads bring in subscribers | When payment is confirmed, directly from our server: your scrambled email (SHA-256, which cannot be restored to the original), a scrambled identifier for your account, the purchase amount, and the currency. No name, phone number, address, or any information about your leads is sent. If you have accepted cookie-based measurement, it also receives the visits measured by the pixel |
We may also share data pursuant to a court order or request from a competent authority, to the extent required.
6International transfer
Some providers listed above operate outside Brazil. In these cases, the transfer is based on Article 33 of the LGPD, for the performance of the contract with you, with contractual data protection clauses in place with the provider.
7How long we retain
- Active account: for as long as the relationship lasts.
- After termination: we delete or anonymize the registration data. Only the records the law requires us to keep are retained (tax and financial records, for 5 years; access logs, for 6 months), along with the billing history in anonymized form.
- Email credential: deleted immediately when disconnected or when the account is closed.
- Lead data: see section 10.
8Security
- Encrypted traffic with HTTPS across the entire service.
- Password stored as a hash, never in readable text.
- Subscriber email credential encrypted at rest, with the key stored outside the database.
- Account isolation: each subscriber sees only their own data.
- Daily database backup.
- Restricted and logged administrative access.
No system is immune. If a security incident occurs that poses a significant risk to your data, we will notify you and the ANPD, as required by Article 48 of the LGPD.
9Your rights as a subscriber
The LGPD guarantees you, among other things, the right to:
- confirm whether we process your data and access it;
- correct incomplete, inaccurate, or outdated data;
- request anonymization, blocking, or deletion of unnecessary data or data processed unlawfully;
- request the portability of your data;
- revoke consent;
- know who we share your data with;
- object to processing based on legitimate interest.
You can handle most of this yourself, right away: within the account, you can edit your details, export your searches and funnel as CSV, and close the account through the subscription screen. For the rest, write to [email protected]. We respond within 15 days.
10Company and professional data (leads)
The platform gathers information published openly on the internet by companies and professionals: business name, business address, business phone, published business email, website, public social media profile, reviews, and search engine ranking. We do not access restricted areas, crack passwords, or purchase databases.
When this data identifies a person (a self-employed professional, for example), it is personal data and the LGPD applies. The processing is based on legitimate interest (Art. 7, IX) for commercial contact between businesses (B2B), limited to the professional context in which the information was published.
What the subscriber is required to do
- Every email sent by the platform must include the sender's identification and a unsubscribe link attached by the system, which the subscriber cannot remove.
- Anyone who clicks unsubscribe is added to that sender’s do-not-contact list, and the platform starts rejecting new sends to that address.
Retention period
Profiles collected from public sources are recycled based on their lifespan: anything unused is removed from the database. Contacts the subscriber saved in their funnel remain as long as their account exists and are deleted along with it.
How to leave the list
If you are a professional or responsible for a company and don't want your data on the platform, use the removal channel:
- Write to [email protected].
Requests are handled by our team, after verifying the requester's identity and their relationship to the data provided.
11Minors
The service is not intended for anyone under 18, and we do not knowingly collect data from children or teenagers. If this occurs, the data is deleted as soon as it is identified.
12Changes to this policy
The current version is always the one published on this page, with the date at the top. Significant changes are communicated by email to subscribers at least 15 days in advance.
13Person in charge and contact
To exercise your rights, ask questions about this policy, or contact the data protection officer:
- Email: [email protected]
- Through the platform: Support button Support, within your account.
You can also file a complaint with ANPD, the National Data Protection Authority.
