Privacy Policy

Effective since February 1, 2026

1. Introduction

ScannerMindAI ("we", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store and protect your information when you use our platform, in compliance with applicable data protection laws.

2. Data We Collect

We collect the following types of data:

Registration Data

Name, email, password (encrypted). When via OAuth: public profile data (name, photo, email).

Usage Data

Pages visited, features used, configuration preferences (exchange, language, theme).

Payment Data

Processed directly by Stripe. We do not store credit card data on our servers.

Technical Data

IP address, browser type, operating system, screen resolution. Collected automatically to improve the experience.

3. How We Use Your Data

  • Provide and maintain Platform services
  • Personalize your experience (preferences, language, theme)
  • Process payments and manage subscriptions
  • Send notifications about your account and service updates
  • Improve the Platform based on aggregated usage data
  • Prevent fraud and ensure Platform security
  • Comply with legal obligations

4. Legal Basis

The processing of your personal data is carried out based on the following legal grounds: user consent, contract execution, compliance with legal obligations, and legitimate interest of the controller.

5. Data Sharing

We do not sell your personal data. We share data only with:

  • Stripe — payment processing
  • OAuth Providers — authentication (Google, GitHub, Discord)
  • Hosting Services — secure data storage
  • Legal Authorities — when required by law

6. Data Security

We implement technical and organizational measures to protect your data, including: password encryption (bcrypt), HTTPS/TLS communication, JWT tokens with expiration, and restricted data access by the team. No system is 100% secure, but we strive to maintain the highest security standards.

7. Your Rights

Under applicable data protection laws, you have the right to:

  • Confirm the existence of processing of your data
  • Access your personal data
  • Correct incomplete or outdated data
  • Request anonymization or deletion of unnecessary data
  • Request data portability
  • Revoke consent at any time
  • Request deletion of your account and data

8. Cookies

We use essential cookies for Platform operation (authentication, preferences) and analytics cookies to understand how the Platform is used. Tools like Google Analytics may set cookies in your browser to measure audience and events, always in aggregated format. You can configure your browser to refuse cookies, but this may affect Platform functionality.

9. Data Retention

We retain your personal data while your account is active or as necessary to provide services. After account deletion, your data will be removed within 30 days, except when retention is required for compliance with legal obligations.

10. International Transfer

Your data may be processed on servers located outside your country. We ensure that any international data transfer is carried out with adequate levels of protection, as required by applicable data protection laws.

11. GDPR (International Users)

If you are located in the European Union or European Economic Area, the following additional rights apply under the General Data Protection Regulation (GDPR):

  • Right of access and data portability (Art. 15, 20)
  • Right to erasure / right to be forgotten (Art. 17)
  • Right to restriction and objection to processing (Art. 18, 21)
  • Right not to be subject to automated decisions (Art. 22)
  • Right to lodge a complaint with a supervisory authority

12. Export and Delete Your Data

You can exercise your data portability and deletion rights directly through the Platform:

Export Data

Download all your data in JSON format from your Account Settings.

Delete Account

Permanently remove all your data from your Account Settings or contact support.

13. Changes to this Policy

We may update this Policy periodically. Significant changes will be communicated via email or notification on the Platform. We recommend reviewing this page regularly.

14. Data Protection Officer (DPO)

To exercise your rights or clarify questions about the processing of your personal data, contact our Data Protection Officer: privacidade@scannermind.com