Privacy policy
Updated on September 6, 2026
The Portuguese version is the reference text. If the versions diverge or contradict each other, the Portuguese one prevails. If the version you read when you entered into the contract says anything more favorable to you, that is the one that applies to your contract (art. 47 of the CDC, the Brazilian consumer protection code). Read the Portuguese version
This policy explains which personal data oculos.io processes, what for, who it is shared with and how long it is kept.
It is part of the terms of use.
1. Who is responsible for your data
The controller of your personal data is Colabtec Digital LTDA, company number CNPJ 65.787.255/0001-91, Alameda Rio Negro, 503, sala 2020, Alphaville, Barueri, SP, CEP 06454-000, Brazil. It decides what is processed and what for, and it is the company you complain to.
Zhuhai Colabtec Technology Co., Ltd., in Zhuhai, Guangdong, China, is a processor: it handles data on instruction from Colabtec Digital, and only to answer what you asked for. It receives the import requests, the development requests and the device test requests.
The other providers listed in section 4 receive data only to deliver the service they were hired for. Some of them, as section 4 says, also process part of that data on their own account, and for that part they act as controllers, each under its own policy.
Requests about personal data are received and answered directly by Colabtec Digital LTDA through the channel [email protected].
2. What we collect, when and why
We collect as little as the site needs to work. Each line below gives the data, the purpose and the legal basis under the LGPD, the Brazilian general data protection law.
Your name, your email address and your payment details are a condition for the subscription to exist: without them we cannot create the account or charge you. Your rights over that data, and how to exercise them, are in sections 7 and 8.
- Account: name, email address, password kept as a hash or the identifier of your Google or Microsoft account, and the language you chose. Purpose: creating and keeping your account. Legal basis: performance of a contract (art. 7, V).
- Login attempts: the email address entered, the result and a value derived from the IP address. Purpose: blocking repeated brute-force login attempts. Legal basis: legitimate interest in keeping the service running and protected against abuse (art. 7, IX).
- Card payment: the customer and subscription identifiers at Stripe, the amount, the currency, the status and the date. The card number never passes through oculos.io. Purpose: charging for the subscription. Legal basis: performance of a contract.
- Pix payment: the transaction identifier, the amount, the date, and the payer's name and Brazilian tax number, CPF for a person and CNPJ for a company, as reported to us by our Pix provider. Purpose: charging and meeting tax obligations. Legal basis: performance of a contract and compliance with a legal obligation (art. 7, II).
- Requests sent through the forms: name, email address, company, country, phone, WhatsApp, WeChat, website, message, the request fields, the page it came from, and values derived from the IP address and the browser. Purpose: answering your request and preparing a proposal. Legal basis: preliminary steps toward a contract (art. 7, V) and legitimate interest.
- Downloads in the member area: the material downloaded, the date, and values derived from the IP address and the browser. Purpose: protecting the licensed material and looking into account misuse. Legal basis: performance of a contract and legitimate interest.
- Emails sent: recipient, subject, delivery event and the automatic blocking of an address that refuses the message. Purpose: proving that the message went out and stopping messages to a mailbox that does not exist. Legal basis: performance of a contract and legitimate interest.
- Technical error records: message, page path, browser and IP address. Purpose: finding and fixing faults. Legal basis: legitimate interest.
- Administrative audit: which person on the team did what in the admin panel, and when. Purpose: security and traceability. Legal basis: legitimate interest.
- Visit telemetry: described in section 3.
- Captcha: the puzzle on the forms is generated on our own server, with no third-party service, and it keeps no visitor data.
3. How we measure visits without cookies and without IP addresses
To know which pages are read, the site records the page path, the language, the host the click came from, the country reported by Cloudflare, the device class and the campaign parameters in the address.
Alongside it goes a value calculated from your IP address and your browser, mixed with a secret that changes at midnight every day. The IP address is not kept.
That value cannot be reversed, and it does not link today's visit to tomorrow's, because the next day's secret is a different one.
There is no measurement cookie, no persistent identifier, no third-party audience tracker and no social network pixel. Robot visits stay out of the counts.
Legal basis: legitimate interest in measuring our own site (art. 7, IX).
4. Who we share with
We share personal data only with those who need it for the service to work. None of them receives more data than the job requires.
Some of them also process part of that data on their own account: Stripe, to prevent fraud; Cloudflare, to protect the network; and Google and Microsoft, to run the account you use to sign in. For that part, each of them acts as a controller, under its own policy.
- Hetzner Online GmbH, in Germany: hosts the server, the database and the site files.
- Cloudflare, Inc., in the United States and on its global network: DNS, proxy, certificate and abuse protection. It sees the IP address of whoever visits and reports the country.
- Resend, Inc., in the United States: sends the confirmation, receipt and reply emails.
- Stripe, Inc. and Stripe Brasil: card charges, in US dollars and in Brazilian reais.
- Efí S.A.: Pix charges, in Brazil.
- Google LLC and Microsoft: only if you choose to sign in with their account. We receive a name, an email address and an identifier.
- Zhuhai Colabtec Technology Co., Ltd., in China: receives the import requests, the development requests and the device test requests, in order to answer them.
- Cloudflare, Inc., in the United States, on its R2 service: keeps the backup, with the files encrypted before they leave the server.
- Public authorities, when there is a legal order, and only as far as the order goes.
5. What leaves Brazil, and on what basis
Part of the processing happens outside Brazil, and the law requires us to say where (art. 33).
The destinations outside Brazil are: Germany, where the server is; the United States, where the proxy, the email sending, the backup and part of the card charging happen, and where signing in with a Google or Microsoft account happens if you choose that route; Ireland, where Stripe also handles the charging; and China, where the requests answered by the Zhuhai team go.
A Pix payment is processed in Brazil, by Efí. The record of that payment, with the amount, the date, the transaction identifier and the payer's name, sits in our database, hosted in Germany, like the rest of your account.
What leaves Brazil leaves on two different bases, and the first one is the contract. Your account, the charging and the service emails leave because without a server, without a payment method and without email there is no service: this is a transfer needed to perform the contract you make with us (art. 33, IX, read together with art. 7, V).
The second basis is legitimate interest in keeping the site secure and running (art. 7, IX). Technical error records sit on the server in Germany and keep the IP address for up to 7 days; login attempts, download records and the administrative audit sit on that same server. Cloudflare, in the United States, sees the IP address of whoever visits and filters abuse before the request reaches the server, and Resend, in the United States, delivers the emails.
Each of those companies is bound by a data protection agreement signed with Colabtec Digital LTDA, and the transfer happens under art. 33 of the LGPD. The part Cloudflare processes on its own account, to protect the network, is in section 4.
Visit measurement is not on that list. It keeps a value calculated for that day alone, which does not lead back to the IP address and does not identify you, as section 3 explains.
The transfer to China happens when you yourself send a request that only the Zhuhai team can answer, and it goes no further than what is needed to answer the request you made (art. 33, IX, read together with art. 7, V).
Zhuhai Colabtec processes that data only on instruction from Colabtec Digital, and only to answer you.
What crosses the border is the content of the request and the contact details needed to reply. Payment data and passwords do not travel with it.
6. How long we keep each kind of data
Each retention period below is the longest time that kind of data is kept.
- The account and what is in it: for as long as the account exists. You export and delete your account from the account area.
- Pix payment records, with the tax details of the transaction: 5 years, because Brazilian tax law requires it. Deleting your account does not reach these records.
- Card payment records, with the Stripe identifier, the amount, the currency, the status and the date: for as long as the account exists and, after that, a further 5 years, because Brazilian tax law requires it, as with Pix. Deleting your account does not reach these records.
- Requests sent through the forms: up to 24 months after the last contact, or sooner if you ask.
- Download records in the member area: 13 months.
- Visit telemetry: 13 months.
- Emails sent: 12 months.
- Administrative audit: 12 months.
- Technical error records: the IP address is removed in 7 days, and the whole line is deleted in 90 days.
- Login attempts: at most 24 hours. The record lasts 15 minutes, and the automatic cleanup, which runs every hour, deletes whatever has expired.
- Card data: oculos.io never keeps the card number. It stays with Stripe, under Stripe's own policy.
7. What your rights are
The LGPD gives you, over your own data, the rights in art. 18:
- confirmation that we are processing your personal data;
- access to the data;
- correction of data that is incomplete, inaccurate or out of date;
- anonymization, blocking or deletion of data that is unnecessary, excessive or processed outside the law;
- portability to another provider;
- deletion of data processed on the basis of your consent;
- information about who we shared your data with;
- information about the option not to consent, and about what happens if you do not consent;
- withdrawal of consent;
- objection to processing carried out on the basis of legitimate interest.
8. How to exercise your rights
In the account area you export your data as a file and delete your account on your own, without talking to anyone.
For any other request, write to [email protected]. We answer within 15 days (art. 19).
To handle a request, we may need to confirm that you are you. That confirmation goes through the account email address, and it asks for no new documents.
Some data stays after the account is deleted, when the law requires us to keep it. That is the case of the Pix and card payment tax records, in section 6.
You can also complain to the Brazilian data protection authority, the ANPD.
9. How we protect your data
The site answers only over HTTPS, with HSTS. Passwords are kept as hashes, and third-party service keys are stored encrypted in the database.
Administrative access is restricted, and every action the team takes in the admin panel is recorded.
Member area files have no public address. They go out through a signed, individual link, valid for 10 minutes and tied to your session.
Backups are encrypted before they leave the server.
No measure removes risk, and we do not promise a completely secure system.
10. What happens if there is an incident
If a security incident happens that may bring relevant risk or harm to you, we notify the Brazilian data protection authority, the ANPD, and we notify you, within a reasonable time (art. 48).
The notice says which data was affected, what has already been done and what you can do to protect yourself.
11. Minors
oculos.io is meant for people aged 18 or over, and it does not knowingly collect data from children or teenagers.
If we find that an account belongs to a minor, the account is closed and the data is deleted. Whatever was paid on that account is refunded under section 7 of the refund policy. If you are a parent or guardian and believe this happened, write to the channel in section 1.
12. What we do not do with your data
- We do not sell, rent or trade personal data.
- We do not run behavioral advertising and we do not install social network pixels.
- We do not use a third-party audience tracker.
- We do not process sensitive data, as defined in art. 5, II.
- We do not use automated decisions to set a profile, a price or access to the material. Automatic security blocks after repeated attempts do exist, and a person reviews one if you ask through the channel [email protected] (art. 20 of the LGPD).
- We do not buy contact lists from data brokers.
13. Cookies
The site uses cookies to keep you signed in, to protect the login form and to remember the language you chose. Visit measurement is done without cookies, as section 3 says.
That is why the site shows no consent banner. The cookie policy lists each one of them and explains how to block them in your browser.
14. Changes to this policy
A change to what we do with your data is announced by email at least 30 days in advance. If you are a subscriber, it takes effect for you at the same moment the change to the terms of use takes effect, as section 15 of those terms says.
The version and the date sit in the footer of this page, so you can tell which text was online on a given date.
Version 1 of 06/09/2026 (day/month/year)
Colabtec Digital LTDA · CNPJ 65.787.255/0001-91 · Alameda Rio Negro, 503, sala 2020, Alphaville, Barueri, SP, CEP 06454-000, Brazil · [email protected]