1. Data Controller
The Data Controller responsible for your personal data is:
- Legal entity: 66.709.390 BRUNO OSORIO GONCALVES (Brazilian individual entrepreneur)
- CNPJ (Brazilian taxpayer ID): 66.709.390/0001-81
- Privacy contact: privacy@meuthor.com.br
- General contact: suporte@meuthor.com.br
The Data Protection Officer (DPO) — also serving as our point of contact under GDPR (Art. 37) and LGPD (Art. 41) — is Bruno Osorio Gonçalves, reachable at the privacy email above.
2. Personal Data We Collect
2.1. Registration data (provided by you)
- Name (optional);
- Email address (authentication and service communications);
- Preferences (language, currency, region).
2.2. Content you submit
- Audio recordings for expense logging;
- Images (receipt photos, invoice screenshots, chat screenshots);
- PDF and CSV documents you choose: the original file remains on your device and only sanitized derived text is transmitted for financial extraction;
- Free-text input describing your transactions;
- Personal financial data extracted from the above: amounts, dates, categories, descriptions, counterparties (e.g., "Uber Eats", "Whole Foods").
2.3. Payment data (Premium subscribers only)
- App Store or Google Play subscriptions: billing is handled by Apple or Google. We never see or store your card number, CVV, or bank credentials — we receive only your subscription status (active/expired) via RevenueCat, our subscription manager.
- One-time access via Pix (Brazil): processed by Hubla outside the app stores. We receive only the purchase email and a redemption code, never your Pix key, bank account, or card. This is distinct from the referral program (Section 2.6), where you optionally provide your Pix key so we can pay you a reward.
2.4. Automatically generated data
- Technical logs (date/time of access, device type, app version, OS);
- Device identifiers and push token (for analytics and, only after your consent, notifications);
- Internal account identifier (UUID);
- App interaction events and selected properties, including limited financial amounts required to measure feature reliability;
2.5. Data we do NOT collect
- Bank account numbers, credit card numbers, or financial institution passwords;
- Open Banking / Open Finance connections to your bank;
- Biometric data;
- Precise GPS location;
- Contacts, calendar, photos library, or device files (beyond what you explicitly send).
2.6. Referral program data ("Earn with Thor")
If you choose to join the referral program, we collect:
- Your Pix key (of type CPF, phone, email, or random), entered by you on the program screen in your profile. We collect this key only if and when you register it, for the sole purpose of paying program rewards.
- Referral records: your referral code, the status of each referral (joined, subscribed, paid), and the reward amount.
The Pix key is payment data. It is stored on a restricted basis, accessible only to our backend under a service credential (service-role) to generate the payout list, is never exposed to other users or to parts of the app running on your device, and is not shared with third parties beyond the financial institution needed to execute the Pix payment. You may change or remove your key at any time on the program screen, or request deletion at privacy@meuthor.com.br.
3. Purposes of Processing
We process your personal data to:
- Enable account creation, authentication, and access to the Service;
- Process inputs (audio, images, text, and sanitized text derived from PDF/CSV) via AI to generate extraction suggestions;
- Store your financial records so you can view and consult them;
- Generate dashboards, insights, and goal tracking;
- Operate the chat assistant feature;
- Process subscription payments (Premium tier);
- Operate the referral program, attribute referrals, and pay rewards due;
- Send essential service notifications (and optional ones with your consent);
- Detect, prevent, and investigate fraud, abuse, and security incidents;
- Comply with applicable legal and regulatory obligations;
- Improve the Service through aggregated, anonymized analytics (when applicable).
4. Legal Basis for Processing
Under the EU/UK General Data Protection Regulation (GDPR Article 6) and the Brazilian General Data Protection Law (LGPD Article 7), we rely on the following legal bases:
- Contract performance (GDPR 6(1)(b) / LGPD 7(V)): for everything necessary to deliver the Service you signed up for, and to pay any referral reward you become entitled to.
- Consent (GDPR 6(1)(a) / LGPD 7(I)): for optional push notifications, processing the content you voluntarily submit, and joining the referral program (including the Pix key you optionally register).
- Legitimate interest (GDPR 6(1)(f) / LGPD 7(IX)): for product improvement, security, fraud prevention, and technical diagnostics. You can object at any time — see Section 8.
- Legal obligation (GDPR 6(1)(c) / LGPD 7(II)): to comply with court orders, tax law, and other legal duties.
We do not rely on legitimate interest where it is overridden by your fundamental rights.
5. Recipients (Sub-Processors)
We never sell your data. We share with the following sub-processors strictly to operate the Service:
5.1. OpenAI, L.L.C.
Provides the AI models for audio transcription, image vision, and structured extraction from free text. Submitted content is transmitted to OpenAI exclusively for real-time processing.
- Privacy policy: openai.com/policies/privacy-policy
- Country: United States
- Data training: Per OpenAI's API terms, your data is not used to train their models.
5.2. Supabase Inc.
Provides database, file storage, and authentication infrastructure.
- Privacy policy: supabase.com/privacy
- Country: United States.
5.3. Apple Inc.
App Store distribution, iOS subscription billing, push notifications via APNs, and optional Sign in with Apple.
- Privacy policy: apple.com/legal/privacy
5.4. Google LLC
Android distribution and subscription billing through Google Play, Google authentication, and Android notifications through Firebase Cloud Messaging (FCM), only after push consent.
- Privacy policy: policies.google.com/privacy
- Country: United States.
5.5. RevenueCat, Inc.
Manages your subscriptions and Premium access status (entitlements) across devices. Receives your internal account identifier and purchase history to validate and sync your subscription.
- Privacy policy: revenuecat.com/privacy
- Country: United States.
5.6. Hubla Tecnologia Ltda.
Processes one-time access purchases made via Pix (outside the app stores; Brazilian entity, CNPJ 36.062.381/0001-80). When you buy access via Pix, Hubla processes the payment and sends us a redemption code tied to the purchase email, used solely to unlock your Premium access. We do not receive your Pix key, bank account, or card details.
- Privacy policy: app.hub.la/privacy_policy
- Country: Brazil.
5.7. PostHog, Inc.
Product analytics and experimentation platform: in the apps, receives an internal account ID, an SDK-generated identifier, app interaction events, and selected event properties, including limited financial amounts. On the public landing pages, it receives anonymous pageview and interaction metrics in a cookieless mode without persistent browser storage. Email, name, and free-form chat text are not sent to PostHog.
- Privacy policy: posthog.com/privacy
- Country: United States.
5.8. Sentry
Error monitoring and crash reporting: receives technical failure reports (stack traces and sanitized context) for diagnostics and fixes. The app does not send raw error messages or default PII to Sentry.
- Privacy policy: sentry.io/privacy
- Country: United States.
5.9. Resend
Transactional email provider: receives your email address and the content required to send the message.
- Privacy policy: resend.com/legal/privacy-policy
- Country: United States.
5.10. Public authorities
We may disclose data in response to a valid court order, subpoena, or other legal request from a competent authority, after assessing the legitimacy of the request.
5.11. Payment financial institution
To pay referral program rewards, we transmit your Pix key and the amount to the financial institution or payment arrangement through which the Pix is sent, strictly to execute the payment.
6. International Data Transfers
As noted above, sub-processors are primarily located in the United States. Cross-border transfers are made under the following safeguards:
- For EU/UK users: Standard Contractual Clauses (SCC) approved by the European Commission, supplemented where needed by additional technical measures (encryption, pseudonymization).
- For US transfers specifically: Reliance on the EU-US Data Privacy Framework (DPF) when applicable, plus SCC as backup.
- For Brazilian users (LGPD Art. 33): Transfer based on contract performance (33-II) and adoption of contractual safeguards with operators.
- Encryption in transit and at rest applies to all transferred data.
7. Data Retention
- Account data and financial records: retained while your account is active.
- Original audio and images: retained while needed to provide the Service and support re-audit; removed when the account is deleted or upon an applicable request, subject to legal obligations.
- Technical logs and analytics events: retained for the period configured with the relevant processors and needed for security, diagnostics, and Service improvement, subject to applicable rights and legal obligations.
- Payment records: retained as required by tax law (typically 5-7 years).
- Referral program data (Pix key and records): retained while you take part in the program and for the period needed to meet legal and tax obligations related to payments; the Pix key is removed when you delete it, when you close your account, or on request, subject to the minimum retention required by law.
- After account deletion: personal data is erased within 30 days, except where retention is required by law or for the establishment, exercise, or defense of legal claims (GDPR Art. 17(3) / LGPD Art. 16).
8. Your Rights Under GDPR (EU/UK)
If you are in the European Union, European Economic Area, United Kingdom, or Switzerland, you have the following rights:
- Right of access (Art. 15): obtain a copy of your data.
- Right to rectification (Art. 16): correct inaccurate data.
- Right to erasure / "right to be forgotten" (Art. 17): delete your data.
- Right to restriction (Art. 18): limit how we process your data.
- Right to data portability (Art. 20): receive your data in structured, machine-readable format (CSV/JSON).
- Right to object (Art. 21): especially to processing based on legitimate interest.
- Right to withdraw consent (Art. 7(3)): at any time, without affecting prior processing.
- Right not to be subject to automated decision-making (Art. 22): including profiling that produces legal effects (we don't do this — AI suggestions always require your manual confirmation).
- Right to lodge a complaint with your local data protection authority — list at edpb.europa.eu/members.
To exercise any of these rights, email privacy@meuthor.com.br with subject "GDPR Request — [your request]". To delete your account, use Settings → Delete account in the app or visit meuthor.com.br/deletar-conta. We respond within 30 days (extendable by 60 days for complex requests per Art. 12(3)).
9. Your Rights Under CCPA/CPRA (California)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to know: what personal information we collect, use, disclose, and sell.
- Right to delete: request deletion of personal information.
- Right to correct: request correction of inaccurate personal information.
- Right to opt out of sale: not applicable — we do not sell personal information as defined by the CCPA.
- Right to opt out of sharing for cross-context behavioral advertising: not applicable — we do not engage in such sharing.
- Right to limit use of sensitive personal information: we don't process sensitive info beyond what's necessary for the Service.
- Right to non-discrimination: we won't deny service, charge different prices, or provide a different quality of service for exercising your rights.
To exercise CCPA rights, email privacy@meuthor.com.br with subject "CCPA Request — [your request]". We verify your identity before fulfilling requests. Response within 45 days (extendable by 45 days). You may also file a complaint with the California Privacy Protection Agency at cppa.ca.gov.
"Do Not Sell My Personal Information": Since we don't sell, no opt-out mechanism is needed, but you can confirm this status by writing to the email above.
10. Your Rights Under LGPD (Brazil)
If you are in Brazil, you have all rights set out in LGPD Article 18:
- Confirmation of processing existence;
- Access to data;
- Correction of incomplete, inaccurate, or outdated data;
- Anonymization, blocking, or deletion of unnecessary or non-compliant data;
- Portability to another service provider;
- Deletion of data processed with consent;
- Information about data sharing with public/private entities;
- Information about the possibility of refusing consent and its consequences;
- Revocation of consent at any time.
Email privacy@meuthor.com.br with subject "LGPD Request — [your request]". Response within 15 days per LGPD. Complaints to the Brazilian National Data Protection Authority (ANPD): gov.br/anpd.
11. Information Security
We implement technical and administrative measures appropriate to the risk:
- Encryption in transit: TLS 1.2+ on all client-server communication.
- Encryption at rest: AES-256 for stored data.
- Row-Level Security (RLS) in the database for strict account isolation.
- Least-privilege access control for internal team.
- Multi-factor authentication required for all administrative access.
- Audit logging of administrative actions and security events.
- Periodic backups with limited retention.
- Vendor security review for all sub-processors.
In the event of a personal data breach involving risk to data subjects, we notify the competent supervisory authority within 72 hours (GDPR Art. 33 / LGPD Art. 48 / state breach notification laws) and affected users without undue delay.
12. Cookies and Local Storage
This website (meuthor.com.br) uses PostHog for anonymous pageview and interaction metrics. The integration honors Do Not Track, disables session replay, and uses in-memory persistence without PostHog cookies or persistent browser storage. We do not use:
- Advertising or marketing cookies;
- Cross-site tracking;
- Third-party analytics that profile individual users.
The iOS and Android apps do not use browser cookies but may use platform-protected and local storage for session data and preferences.
13. Children
Thor is not directed to children under 18. We do not knowingly collect data from minors:
- Under 13 (US — COPPA);
- Under 16 (EU — GDPR Art. 8, varying by Member State);
- Under 18 (Brazil — LGPD Art. 14 plus our internal policy).
If we learn we have collected data from a minor without verified parental consent, we will delete it promptly. Parents or guardians who believe their child has provided personal data may contact privacy@meuthor.com.br.
14. Changes to this Policy
We may update this Policy from time to time. The current version is always available at meuthor.com.br/privacy with the date of last update at the top.
For material changes, we notify users at least 30 days in advance via in-app notice and email. Continued use after the effective date constitutes acceptance.
15. Contact
Privacy questions, requests, or complaints:
- Data Protection Officer (DPO): Bruno Osorio Gonçalves
- Privacy: privacy@meuthor.com.br
- General support: suporte@meuthor.com.br
Supervisory authorities:
- 🇪🇺 EU: your local DPA via EDPB
- 🇬🇧 UK: Information Commissioner's Office (ICO)
- 🇺🇸 California: California Privacy Protection Agency
- 🇧🇷 Brazil: ANPD