Legal

Privacy Policy

Last updated: September 16, 2026

Firmo90 takes your privacy seriously. This policy describes how we collect, use, and protect your personal information when you use our application and services.

Data Collection

We collect only the information necessary to provide our services. This includes: email address for account creation, display name (can be a nickname), daily progress data (check-ins, streak), and app preferences.

We do not collect real-time location, contact lists or your browsing history. The exception is the content blocker, which is optional and switched on by you: while it is active, the app records the access attempts the block list reaches, and the address involved is stored encrypted. Beyond that we collect no data that is not directly related to how the app works.

Optional data such as community posts and emotional check-ins are collected only when you voluntarily choose to share them.

Data Usage

Your data is used exclusively to: provide and improve Firmo90 services, personalize your experience in the app, send relevant notifications (which you can disable), and generate anonymous aggregated statistics to improve the app.

We never sell or rent your personal information. The app shows ads to keep the free plan running, and that involves sharing device data with the ad network — what exactly, and what never leaves here, is set out in the Advertising section.

Anonymized and aggregated data may be used for research and service improvement, but never in a way that allows identifying individual users.

Data Protection

All communications between the application and our servers are protected by TLS (Transport Layer Security) encryption. Sensitive data such as personally identifiable information receives an additional layer of encryption in the database.

We use industry-standard security best practices, including secure password hashing with bcrypt, short-lived JWT tokens, and regular security audits.

Our servers are hosted on cloud providers with internationally recognized security certifications.

Your Rights

You have the right to: access all data we have about you, request correction of incorrect data, request complete deletion of your account and data, export your data in a readable format, and revoke consent for data processing at any time.

To download a copy of your data, go to firmo90.com/en/my-data: enter the account email and a single-use link arrives there. To delete your account, use the app settings. For anything else, write to support@firmo90.com.

We will respond to all privacy-related rights requests within 30 business days.

GDPR Compliance (European Union Users)

For users residing in the European Union or the European Economic Area, Firmo90 processes your data based on explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR) for the processing of sensitive health data.

You have the following data subject rights: right of access to your personal data, right to rectification of incorrect data, right to erasure (right to be forgotten), right to data portability, right to restriction of processing, and right to object to processing.

You have the right to lodge a complaint with the data protection supervisory authority in your country of residence.

Data Protection contact: support@firmo90.com

Data Retention Periods

Account data (email, nickname): for as long as the account exists. The moment the deletion request is accepted, the email and the nickname are replaced by meaningless values; the account row, already stripped of them, is erased about 90 days later.

Emotional check-ins: 2 years from the date of the entry.

Journal: no automatic clock. Entries stay for as long as the account exists and are erased when you delete the account.

Posts and comments: removed from the service and their content is erased immediately when the account is deleted; residual backup copies follow the backup retention below.

Payment records: 5 years (Brazilian fiscal obligation / Stripe requirement).

Checkouts that never completed: the whole row is deleted 90 days after the checkout expires. When a checkout does become an account, the personal data on that row is erased in the same transaction that creates the account.

Waitlist: 365 days for someone who never created an account, 90 days after the account is created. If you ask to leave the list, the contact details on that entry are erased right away and only the count remains.

Server logs: the server writes one compressed file per day, and rotation keeps at most 90 days of application files and 365 days of the audit file. Those files live inside the application container, which has no dedicated volume for them: a new deploy recreates the container and takes what was there with it. These periods are a ceiling, not a promise that the record will still be there at the end of them.

Backup data: the database has continuous automated backup with 35-day retention, replicated to another AWS region for the same period. There is also a manual snapshot of the server disk, taken on 2026-09-14, which does not expire on its own.

Sensitive Data Processing

The sensitive fields of your profile (name, bio, gender, orientation, ethnicity and region) and the content you write (diary, direct messages, community messages, partner conversation and support chat) are encrypted at rest with AES-256-GCM. Your email stays readable in the database: it is the key for signing in, for the unsubscribe link and for reconciling payments. What protects the email is access control and deletion on a clock.

Emotional and addiction-related data is not sold, rented or sent to ad networks or data brokers. It leaves our environment on three fronts, all described in this policy: the AI features, which run through Groq in the United States; automated content moderation; and the operational alert of the crisis protocol. Having the AI read your diary and your conversations depends on you switching personalisation on in settings, and it can be switched off whenever you want.

Automated content moderation depends on external AI providers. The text to be analysed is sent to Groq, in the United States, and images go to Amazon Rekognition. The request carries only the text or the image under analysis: your email and your account identifier do not travel with it, and the provider returns only a verdict. When what is being analysed is the nickname you chose or your bio, they are the text being sent, because that is exactly what has to be read.

For aggregate analytics we use counts, without the fields that identify a person.

Crisis Protocol

When what you write in the AI support chat, in support messages or in the accountability partner follow-up carries signs of risk to your life or of serious self-harm, the system records a case and shows it in the team's authenticated panel. The immediate alert to whoever is on call always goes out for support messages and for the partner follow-up; in the AI chat, only when the detection rates the case as critical.

What the case keeps depends on where you wrote it. In support messages and in the partner follow-up, the case keeps the listed word that triggered the protocol and an excerpt of what you wrote, cut at 120 characters and with emails, phone numbers and links replaced by a marker; that excerpt sits readable in the database, without the extra layer of encryption that protects the original message inside the chat. In the AI chat, the case keeps your whole message, encrypted at rest, in two records — the crisis log and the safety incident — and the words that triggered the detection sit readable beside it, as detection metadata.

These records have no clock of their own: they exist for as long as your account exists. When the anonymised account is finally erased, about 90 days after the deletion request, the support-message case and the AI chat crisis log go with it, cascaded from the account row. The safety incident record is the exception we are not hiding from you: at that moment it loses the link to the account, and the encrypted text stays.

The on-call alert travels through a messaging app the team uses (Telegram, United States). We have no data processing agreement with that service, and the message stays in the chat history of everyone in the channel. That is why the alert never carries the sentence you wrote.

In the AI chat, the alert only says that a critical case exists and links to the panel. In support messages and in the partner follow-up, the alert still carries the internal account identifier and the word that triggered the protocol, taken from a list the team maintains, without your name, your nickname or your email.

Apart from automated moderation, described further down, this is the only situation in which someone on the team is alerted on the spot because of something you wrote. The assistant's safety filter also keeps a record the team reads in the panel, with no immediate alert: that happens when a message tries to jailbreak the assistant, carries explicit sexual content or involves minors.

Cookie Policy

On the website we use essential cookies only: Cloudflare security cookies and session management. No advertising cookies are used on the site.

The mobile application does not use cookies. Authentication is handled via JWT tokens stored securely on the device.

The Android app uses the device advertising identifier to serve and measure ads. You can reset it or turn off personalisation at any time in Android Settings → Privacy → Ads.

You can configure your browser to reject cookies, although this may affect some site features.

Advertising

The free plan is paid for by ads, served through Google AdMob and on Android only. Premium subscribers see no ads at all: for a subscriber the advertising component is never even started, so nothing is requested and nothing is measured.

To serve and measure ads, Google receives the device advertising identifier, the IP address, and technical data about the device and the app. We do not send the ad network your email, your name, your journal entries, your messages, your emotional check-ins, or any data about your recovery.

If you are in the European Economic Area, the United Kingdom or Switzerland, a Google-certified consent form appears before the first ad, and your answer decides whether ads are personalised. You can review that choice at any time in Settings, under Privacy and personalisation.

In any country, you can reset the advertising identifier or turn off personalisation in your own Android settings, and the app respects that choice.

We never show ads in the crisis flow or on the immediate-help button. This is not a setting anyone can change: those moments do not exist in the set of screens that can carry an ad.

In the ad network dashboard we block ad categories that are incompatible with what this app is for.

App Usage Measurement

The Android app uses Firebase Analytics, from Google, to measure usage. In the version currently published on the store, that service receives app usage events (open, sign-in, sign-up and the name of the feature used, such as logging a relapse, writing in the diary, an emotional check-in or a community post), together with the installation identifier, the IP address, technical device data and your internal account identifier.

The text of your diary, your messages, your posts and your check-ins is never sent to that service.

The next version of the app cuts that stream. The account identifier stops leaving and gives way to a code drawn at random on the device itself, which is not derived from your account and is discarded when you sign out or withdraw consent. The feature name stops leaving too. What remains are the lifecycle events (open, sign-in, sign-up, sign-out, failure and which entry door was tapped on the login screen) and two facts about the session: whether the account is free or Premium, and how many days old it is. Even that is collected only if a consent of yours is on record; while there is none, the app sends nothing to that service.

That change applies from then on. What earlier versions already sent stays with Google, under its own service retention, and we cannot erase it there item by item. You can reset the device advertising identifier and ask Google directly to delete your data.

The feature usage counts we rely on to follow the product stay on our own server, alongside the rest of your account, and are deleted with it.

Third-Party Data Processing

Stripe (USA, PCI-DSS Level 1): Payment processing and subscription management.

Amazon Web Services — AWS (Brazil sa-east-1 and USA, SOC 2 / ISO 27001): Hosting, backups and image analysis (Rekognition).

Firebase / Google Cloud (USA): Push notification delivery (FCM) and app usage measurement (Firebase Analytics). What goes out for measurement is described in the App Usage Measurement section.

Sentry (USA): Error monitoring. Before sending we remove credentials, tokens and identity fields. In request bodies only fields from a short list travel (identifiers, pagination and status codes); everything else, including any text you wrote, is replaced by a marker.

Groq (USA): AI Coach inference, nickname and bio screening, and text analysis for automated moderation. In the support chat, messages are sent without a real name or personal identifiers, only a nickname. In moderation what travels is the text under analysis, without your email and without your account identifier; when what is under analysis is the nickname or the bio, they are that text. Our account is on Groq’s free plan and we have no signed data processing agreement with that provider: what applies today are its public terms of service. That is why the request is held to the minimum the analysis needs.

Cloudflare (Global): CDN, WAF and Turnstile (anti-bot CAPTCHA) — processes IP address and browser fingerprint for security only.

Telegram (USA): Messaging channel the team uses to receive operational alerts, and not a processor under contract with us. Today, besides the crisis protocol alert, this channel receives the new sign-up notice (declared gender, country, sign-in method, platform and the day’s counts, with no name, email or account identifier), the automatic block of an IP address including the IP itself, the record of emergency access to conversations with the email of whoever accessed it, the internal identifier of the account involved and the justification, and infrastructure notices such as a failed backup, the AI API limit and the daily numbers summary. None of those notices carries what you wrote: the closest thing to it is the crisis list word that triggered the protocol, never the sentence around it. The sign-up notice is edited and deleted from the channel when the account is deleted.

Google Analytics 4 (USA, optional): Aggregate site usage analytics, only loaded after explicit consent on the cookie banner.

Gmail SMTP (Google, USA): Transactional email delivery (sign-up confirmation, password reset).

International transfers: rely on LGPD Art. 33 II (contractual clauses offered by the providers) and Art. 33 IX (necessary for contract execution). As of this date we hold no signed Data Processing Agreement (DPA) we could show for any provider on this list, and no statement on this page rests on one. Clauses equivalent to the EU SCCs are still being formalized; once they exist they will be made available on request at support@firmo90.com.

Google AdMob (USA): Serving and measuring ads in the Android app, for free-plan accounts only. Receives the advertising identifier, IP address and technical device and app data.

Each provider is there for one concrete function, and we send it the minimum that function needs; this list describes, provider by provider, what leaves here. We do not sell personal data or hand it to data brokers. Sharing with the ad network is limited to what the Advertising section describes.

Automated Content Moderation

To ensure community safety, we use automated content moderation systems, including: keyword filtering, AI-powered content analysis (Groq, gpt-oss models), and AI-powered image analysis (Amazon Rekognition).

Keyword filtering runs on our servers. The other two stages do not: the text to be analysed is sent to Groq, in the United States, and the image to Amazon Rekognition. The request carries only the text or the image under analysis: your email and your account identifier do not travel with it, and the provider returns only a verdict. This applies to community posts, comments, group messages, direct messages, partner messages and audio transcripts.

At sign-up and when you edit your profile, the same check runs over the nickname and the bio. In those two cases the nickname and the bio are the content sent to Groq, because that is exactly what has to be analysed. Your legal name does not enter this stage: it is checked only against lists and rules that run on our own servers.

These systems automatically check posts, comments, and images uploaded by users to detect content that violates our guidelines: explicit content, hate speech, harassment, spam, and self-harm incitement.

Violations may result in warnings, content censorship, temporary suspension, or permanent ban, depending on severity and recurrence.

Processors involved in this check: Groq (text analysis, United States) and Amazon Rekognition, from Amazon Web Services (image analysis).

Protection of Minors

Firmo90 is intended exclusively for users aged 18 and over. We do not knowingly collect, process, or store personal data of minors under 18.

At sign-up, we require a declared date of birth. Any user under 18 is automatically blocked by the system and cannot complete registration.

If we discover that a minor has registered (for example, using a falsified date of birth), the account is blocked immediately and all associated personal data is purged within 30 days, in compliance with applicable child protection legislation (LGPD Art. 14, COPPA, GDPR-K). Parents or legal guardians may request immediate deletion at support@firmo90.com.

Contact

If you have questions, concerns, or requests related to this privacy policy, please contact us:

General email: support@firmo90.com

Data Protection Officer (DPO), as required by LGPD Art. 41: Charles Machado — support@firmo90.com

We will respond within 48 hours on business days. For formal data subject requests (LGPD Art. 18 / GDPR rights), the deadline is up to 30 days in accordance with applicable legislation.