Privacy Policy
Last updated Sep 13, 2026. Version 1.0.0.
This policy explains how Testimoniacs collects, uses, stores and shares personal data when you use the platform or interact with a public collection page.
1. Controller identification
[NOME DO CONTROLADOR], registered under [CNPJ/CPF], with address at [ENDEREÇO] and contact at [E-MAIL], is the controller for the processing described here. Please complete these fields before launch.
2. Data Protection Officer
The data protection officer is [NOME DO DPO] and can be contacted at [E-MAIL DO DPO]. Even when a microenterprise may be formally exempt under ANPD Resolution CD/ANPD No. 2/2022, the controller should designate a contact for data subject requests.
3. Data we collect
Account data: name, email, password credentials handled by Supabase Auth, avatar, language, account status and identifiers.
Testimonials and case studies: author name, email, avatar, title, company, website, social links, written content, ratings, custom fields, answers, images, video and audio.
NPS: name, email, score, reason/comment and timestamps.
Billing: Stripe customer, subscription and invoice identifiers, plan, price, billing period and payment status. We do not store full card numbers.
Technical data: hashed IP used for rate limiting, session and device data, browser data, local language preference and technical request logs. Free-form fields may incidentally contain sensitive data; do not submit health, biometric, political, religious or other sensitive information.
4. Why we process data
We process data to create and secure accounts, authenticate users, recover passwords, operate spaces and collection pages, receive and publish testimonials when authorized, collect and analyze NPS responses, host media, provide billing, send transactional notifications, provide support, prevent abuse, maintain audit records, comply with legal duties and process account deletion requests.
5. Legal bases
Depending on the purpose, processing is based on: performance of a contract (Article 7, V, LGPD); compliance with a legal or regulatory obligation (Article 7, II); exercise of rights in judicial, administrative or arbitral proceedings (Article 7, VI); consent (Article 7, I), especially for public promotional publication of a testimonial, image, video or audio; and legitimate interests (Article 7, IX), such as security, abuse prevention and service improvement, always respecting the rights and reasonable expectations of data subjects. The controller must validate this mapping for each business relationship.
6. Sharing with service providers
Supabase receives account, authentication, database and Storage data. Mux receives uploaded video, audio and technical media metadata. Stripe receives billing identifiers, email and subscription/payment information. Resend receives email addresses and the content of transactional messages. Tawk.to may receive authenticated user identity, email, account status, plan, role and workspace names for support. Google may receive data involved in OAuth, fonts and favicon requests. Vercel runs scheduled account-purge jobs. We do not currently use dedicated analytics or advertising pixels. Providers act under their own terms and privacy notices and only for the services enabled by the app.
7. International transfers
Some providers may process data outside Brazil, including Supabase, Mux, Stripe, Resend, Tawk.to and Google. The exact region depends on each account and provider configuration and must be confirmed by the controller. Where applicable, transfers must use a valid LGPD safeguard under Article 33, such as an adequacy decision, standard contractual clauses, specific contractual guarantees or another legally recognized mechanism.
8. Retention and deletion
Specific retention periods are PENDING — the controller must define them by category before launch. As a rule, data is kept only as long as necessary for the stated purpose, legal obligations, fraud prevention or exercise of rights. Account deletion currently schedules a purge that attempts to remove Mux assets, Storage files, Stripe customer data and the Supabase Auth user; some application records depend on database cascades, while audit and purge records may be retained. Signed avatar URLs expire after seven days, but that expiration does not delete the underlying file.
9. Your rights
You may request: confirmation that your data is processed; access to your data; correction of incomplete, inaccurate or outdated data; anonymization, blocking or deletion of unnecessary or excessive data; portability where applicable; deletion of data processed on consent; information about public and private entities with which data is shared; information about the possibility and consequences of refusing consent; revocation of consent; and review of decisions made solely by automated processing that affect your interests, under Article 20. Rights may have legal limits, including retention required for compliance or defense.
10. How to exercise your rights
Send a request to [E-MAIL] or [E-MAIL DO DPO], identifying the account and describing the request. We will respond within up to 15 days, subject to identity verification and any lawful exception. The controller should replace these placeholders with a dedicated channel before launch.
11. Security measures
The platform uses authentication controls, password handling by Supabase Auth, row-level database policies, signed file URLs, server-side separation of privileged keys, webhook signature validation, rate limiting, access checks, audit records and account-purge routines. No service is risk-free; users must protect credentials and report suspected incidents through the official contact channel.
12. Cookies and similar technologies
Necessary technologies support authentication, security, language preference and interface state, including the Supabase session, the testimoniacs.locale local-storage preference and a sidebar-state cookie. The app currently has no dedicated analytics or marketing pixel identified in the audit. If non-essential analytics or marketing technologies are enabled, they must be disclosed separately and activated only after the required consent. You can delete cookies and local storage through browser settings, but doing so may affect functionality.
13. Children and teenagers
The public collection forms do not currently verify age. The service is not intentionally designed to collect data from children. Do not submit a child's data without the legally required parental or legal representative involvement. For children under 12, consent from a parent or legal representative and the child's best interest must be observed; for teenagers under 18, enhanced protection applies under Article 14. Contact us if a minor's data was submitted improperly.
14. Security incidents
We investigate suspected incidents, contain their effects and document corrective actions. When an incident may cause relevant harm or risk, the controller will notify the ANPD and affected data subjects within the applicable legal timeframe, using a reasonable period and the ANPD guidance, including the commonly recommended 72-hour target when appropriate.
15. Complaints to the ANPD
You may contact the Brazilian data protection authority (ANPD) through its official channel: https://www.gov.br/anpd/pt-br.
16. Effective date and changes
Effective date: [PREENCHER DATA DE VIGÊNCIA]. This policy will be updated when processing practices or legal requirements change. Material changes will be communicated through the platform or another suitable channel, and the version in force will be identified here.
17. Applicable law and forum
This policy is governed by Brazilian law, including the LGPD, the Brazilian Internet Civil Framework and the Consumer Protection Code. Disputes will be handled by the consumer's legally competent forum where applicable. This document is informational and should be reviewed by a qualified Brazilian privacy lawyer before public launch.