Privacy Policy
Last updated: May 8, 2026
This Privacy Policy describes how Aprendendo a Papar collects, uses, stores, shares and protects your data and your baby's data. By using the app, you agree to the practices described here. We process personal data in accordance with the Brazilian LGPD (Law No. 13.709/2018) and general privacy principles.
1. Who is the controller
Aprendendo a Papar is operated by Filipe Costa (Brazilian CPF available upon request), the data controller responsible for the data collected through the app. For any request about your data, contact us at contato@aprendendoapapar.com.br.
2. Data we collect
We only collect data strictly necessary to operate the app. Specifically:
3. Sensitive data (LGPD art. 11)
IMPORTANT NOTICE.
Health information, allergies and food reactions of the baby are sensitive personal data under the Brazilian LGPD. By using the app you expressly consent to processing of these data by Aprendendo a Papar for the purposes described in this Policy. You may revoke that consent at any time by deleting your account — in that case all sensitive data linked to it is erased (see section 8).
4. How we use your data
Collected data is used exclusively to:
5. Where data is stored
We use Supabase as our database and file storage infrastructure. Data lives on Amazon Web Services (AWS), in the region configured for the project. By default, baby and user data is encrypted in transit and at rest.
We use Vercel to host the app. Operational logs (access, errors) may be stored temporarily on these platforms. We don't share these data with third parties for commercial purposes.
6. Sharing with third parties
We don't sell your data. We share with third parties only:
7. Cookies and similar technologies
We use strictly necessary cookies: authentication, session and preferences (language, theme). We don't use marketing cookies or third-party tracking tools (Facebook Pixel, Google Analytics, etc.) at the moment. If that changes, this Policy will be updated and you will be notified.
8. Your rights (LGPD art. 18)
You may, at any time:
To exercise any of these rights, write to contato@aprendendoapapar.com.br informing the registered email. We respond within 15 calendar days.
9. Data retention
We keep your data while your account is active. When you delete the account, all personal and sensitive data (yours and the baby's) is removed within 30 days. Technical logs (access, errors) are retained for up to 6 months for security and audit purposes, as required by law.
10. Security
We use reasonable measures to protect your data: encryption in transit (HTTPS/TLS) and at rest, permission-based access control (Row-Level Security on Supabase), passwords stored hashed. Even so, no system is 100% secure — in case of an incident that affects your data, we'll notify you and the ANPD within the timeframes required by the LGPD.
11. Children and adolescents
The app is intended for parents, guardians and adult caregivers — it isn't used directly by children. Baby data entered into the app is provided by legal guardians, who confirm they have the authority and legal capacity to do so. We treat children's data with the additional care required by the LGPD (art. 14): only what's necessary, based on the child's best interest and with the guardian's consent.
12. International transfers
Infrastructure providers (Supabase, Vercel, Google) may store or process data on servers outside Brazil. This is done in accordance with the LGPD (art. 33), in countries with adequate levels of protection or under contractual clauses ensuring the same level of protection required here.
13. Changes to this Policy
We may update this Policy periodically. Significant changes are communicated by email and/or inside the app. The date of the last update appears at the top of this page. Continued use of the app after the update means acceptance of the revised version.
14. Contact
Questions, requests or complaints about privacy: