This Policy explains what data Minha Capy uses, why, who we share it with and how you stay in control. It follows Brazil’s General Data Protection Law (LGPD, Law No. 13,709/2018) and applies to the Minha Capy app and to this website.
Summary
- You can use Minha Capy without an account. In that case, your data stays only on your phone.
- If you create an account, we keep a copy of your progress so you can sync and restore it.
- Your mood is sensitive data: it only goes to the cloud with your consent. What you write about your day never leaves your phone.
- If you do not subscribe, the app shows non-personalized ads from Google AdMob. They do not use your mood, your notes or your goals.
- We do not sell your data.
- In the app, crash and usage reports are only sent if you turn on the “Help improve the app” option.
- On this website, we only use Google Analytics if you accept analytics cookies.
- You can delete your account and your data at any time, right in the app or on the web.
1. Who takes care of your data
The controller of your personal data, that is, who decides how it is used, is:
- Company
- Sirtori Dev Solutions (61.787.580 Juliano Sirtori), CNPJ 61.787.580/0001-01
- Address
- Maringá, Paraná, Brazil
- Data protection officer
- Juliano Sirtori, contato@julianosirtori.dev
The data protection officer (DPO, called “encarregado” in Brazil) is the person who handles your questions, and those of Brazil’s National Data Protection Authority (ANPD), about your data.
2. What data we use
2.1 If you use Minha Capy without an account
Everything is stored on your phone: your capybara’s name and look, your goals and what you completed, your mood and what you write about your day, your streak, your items and your preferences, such as language and reminder time. This data is not sent to us. The exceptions are your subscription (item 2.4), ads (item 2.8) and, if you turn the option on, crash and usage reports (item 2.7).
2.2 If you create an account
- Sign-in data: your email. If you sign in with Apple or Google, we receive an account identifier and the email those services share. With Apple’s “Hide My Email”, we receive a forwarding address, not your real email. If you sign up with email and password, your password is stored encrypted: we never have access to it in plain text.
- Your progress: a copy of the data in item 2.1, to sync across devices and restore it if you change phones. Your mood is only included with your consent (item 2.3), and what you write about your day stays on your phone.
- Account dates: when it was created and when it was last synced.
2.3 Mood and notes about your day
Your mood and what you write about your day may reveal information about your emotional health. Under the LGPD, this is sensitive personal data (art. 5, II). What you write about your day never leaves your phone. When you have an account, your mood only goes to the cloud with your consent, which the app asks for in a specific and prominent way after your first sync (art. 11, I). You can withdraw this consent at any time, with the “Mood in the cloud” switch in Settings > Account. If you do, your mood stops syncing and is deleted from our servers, but it stays on your phone.
2.4 Subscription (optional)
The subscription is optional and removes the ads. Payment is handled by the App Store or Google Play. To know whether your subscription is active, we receive subscription information from the store through RevenueCat: plan, status, start and renewal dates, country or currency, and a purchase identifier. If you have an account, RevenueCat also receives your Minha Capy account identifier (not your email), so your subscription follows you to another device. We never receive your card details.
2.5 Reminders
Reminders are notifications scheduled on your own phone, at the time you choose. You can turn them off in the app or in your phone’s notification settings.
2.6 Technical data
When the app talks to our servers, for example to sign in or sync, we record basic technical data: IP address, date and time, device model, operating system version and app version. We use this data to keep the service secure, fix bugs and comply with the law.
2.7 Crash and usage reports (optional)
In the app, the “Help improve the app” option, in Settings > About, decides whether the app sends this data to Google’s Firebase:
- Crash reports (Firebase Crashlytics): when the app crashes or hits an error, what happened in the code, the device model, the operating system and app versions, the date and time, and an identifier for the app installation.
- App usage (Google Analytics for Firebase): which screens and features are used, such as completing a goal or starting an adventure, with the language, approximate country, device type and an identifier for the app installation.
This data does not include your mood or what you write about your day. Crashlytics and Google Analytics for Firebase do not use your phone’s advertising identifier and are never used for ads (ads are covered in item 2.8). With the option off, none of this is sent. You can change the option at any time.
2.8 Ads (Google AdMob)
If you do not subscribe, the app shows ads from Google AdMob. They are not personalized: they do not use your history or what you do in other apps and websites to choose what appears. They use the app’s context and your approximate location. The app does not ask for permission to track you. To show and measure ads, limit how often each one appears and prevent fraud and abuse, the Google AdMob SDK collects from your phone:
- Device identifiers: on Android, the advertising ID and the app set ID (an identifier shared by one developer’s apps on the device). On iPhone, Apple’s advertising identifier (IDFA) is not accessed, because the app does not ask for tracking permission.
- IP address and approximate location, inferred from the IP (city or region, never your exact location).
- Device and app data: model, operating system, language and app version.
- App and ad interactions: app launches, which ads were shown and whether you tapped them.
- Diagnostics: crashes and performance of the ads SDK.
Ads never receive your mood, what you write about your day, your goals, your email or your Minha Capy account identifier. Even with non-personalized ads, Google uses identifiers for frequency capping, aggregated reporting and fraud prevention, under the Google Privacy Policy and the page How Google uses information from sites or apps that use its services.
The “Help improve the app” option (item 2.7) does not change the ads. To stop seeing ads, subscribe: for subscribers, the app does not even load AdMob. On Android, you can also delete or reset your advertising ID in your phone’s settings.
3. What we use your data for
Each use has a legal basis under the LGPD:
- Running the app, creating and maintaining your account and syncing your progress: performance of our contract with you (art. 7, V).
- Storing your mood history in your account: your consent (art. 11, I).
- Managing your subscription, if you subscribe: performance of the contract (art. 7, V).
- Showing non-personalized ads, counting how often they appear and preventing fraud, to keep the app free: our legitimate interest (art. 7, IX). If you would rather not see ads, you can subscribe.
- Keeping the service secure, preventing fraud and fixing bugs: our legitimate interest, using only the minimum necessary (art. 7, IX).
- Understanding crashes and how the app is used, to fix bugs and improve the app, if you turn on the “Help improve the app” option: your consent (art. 7, I).
- Understanding how this website is used (Google Analytics), if you accept analytics cookies: your consent (art. 7, I).
- Keeping access logs and complying with legal obligations or court orders: compliance with a legal obligation (art. 7, II), such as Brazil’s Internet Civil Framework (Marco Civil da Internet).
- Answering your messages and requests about your data: performance of the contract and compliance with a legal obligation.
- Letting you know about important changes to these documents or to your account: performance of the contract.
We do not use your data for personalized ads, we do not build marketing profiles and we do not sell your data.
5. Data outside Brazil
Some of our partners store data outside Brazil. The Firebase servers that store your account and progress are in the United States, as are RevenueCat’s. Ad data (Google AdMob) may also be processed in the United States and in other countries where Google has servers. In these cases, we follow art. 33 of the LGPD and use appropriate safeguards, such as the standard contractual clauses approved by the ANPD.
6. How long we keep it
- Account and synced progress: for as long as your account exists. When you delete your account, we erase this data from our systems within 30 days. Backups are overwritten within 90 days.
- Access logs (IP, date and time): 6 months, as required by Brazil’s Internet Civil Framework (Law No. 12,965/2014, art. 15).
- Subscription information: for as long as needed to meet legal, tax and consumer protection obligations.
- App crash reports (Crashlytics): 90 days.
- Ad data (Google AdMob): for Google’s own time frames, explained in How Google retains data.
- App usage data (Google Analytics for Firebase): up to 14 months, the retention period set in Firebase.
- Website usage data (Google Analytics): up to 14 months, the retention period set in Google Analytics. The cookies stay in your browser for up to 2 years, or until you decline or delete them.
- Data on your phone: until you delete the app or its data. If you have an account and sign out, the app deletes the data on your phone after confirming your progress is saved to your account.
7. Your rights
Under the LGPD (art. 18), you can at any time:
- confirm whether we process your data and get a copy of it;
- correct incomplete, inaccurate or outdated data;
- ask for unnecessary or excessive data to be anonymized, blocked or deleted;
- ask to port your data to another service;
- ask for the deletion of data processed with your consent;
- find out who we share your data with;
- be told that you may refuse consent and what happens if you do;
- withdraw your consent;
- object to any use that does not comply with the law.
Minha Capy does not make automated decisions that affect your interests. To exercise your rights, use the options in the app or write to contato@julianosirtori.dev. We reply within 15 days. If you are not satisfied, you can file a complaint with the ANPD at gov.br/anpd.
8. How to delete your data
- Without an account: delete the app, or clear its data in your phone’s settings.
- With an account: in the app, open the Menu, tap Settings and then “Delete account”. This deletes your account and synced progress, within the time frames in section 6.
- Without the app: request deletion on the web, on the Delete account page, or by email at contato@julianosirtori.dev.
- Only your mood: turn off “Mood in the cloud” in Settings > Account (item 2.3). It is deleted from our servers and stays on your phone.
- Subscription: deleting your account does not cancel your subscription. Cancel it in the App Store or Google Play, as explained in the Terms of Use.
- Ads: Minha Capy does not store ad data. On Android, delete or reset your advertising ID in your phone’s settings. To stop seeing ads, subscribe (item 2.8).
9. Security
We use technical and organizational measures to protect your data, such as an encrypted connection between the app and our servers, passwords stored encrypted, and access limited to the people who need it for their work. No system is 100% secure. If an incident could bring you relevant risk or harm, we will notify you and the ANPD (art. 48).
10. Children and teenagers
Minha Capy is for people aged 13 and over. People under 18 should use the app with permission from their parent or legal guardian. We always process teenagers’ data in their best interest (art. 14). If we learn that a child under 13 has created an account, we will delete it. The app’s ads are not personalized and limited to content suitable for teenagers (Google’s T rating), with no sensitive categories such as gambling, alcohol, dating, weight loss or sexual content. Parents and guardians can ask for deletion by writing to contato@julianosirtori.dev.
11. This website
This website, including the home page, the support and account deletion pages, the Terms of Use and this Policy, does not show ads. If you accept in the cookie notice, we use Google Analytics 4, by Google, to understand in aggregate how people use the site: pages visited, clicks on the store badges, language, device and browser type, approximate region and where the visit came from. To do this, Google Analytics stores cookies (such as _ga) in your browser. Google signals and ad personalization are turned off, and this data is not linked to your app account. If you decline, Google Analytics is not even loaded.
The website also stores in your browser (localStorage) your language preference, Portuguese or English, and your choice about analytics cookies. You can change that choice at any time, right below. The service that hosts the website may record technical access data, such as your IP address, to keep the website online and secure.
12. Changes to this Policy
We may update this Policy. When a change is important, we will let you know in the app or by email before it takes effect. If a change requires new consent, we will ask for it again. The date of the last update is always shown at the top of this page.
13. Contact us
- Data protection officer
- Juliano Sirtori
- contato@julianosirtori.dev
- Company
- Sirtori Dev Solutions (61.787.580 Juliano Sirtori), CNPJ 61.787.580/0001-01
- Address
- Maringá, Paraná, Brazil