How Estudatta handles your data
This page explains, in plain language, what data the service collects, what it is used for, who it is shared with and how you export or delete everything. It describes what the service does — it is not a certificate of compliance.
Last updated: September 21, 2026
01Who the controller is and what this policy applies to
Estudatta is operated by [legal name to be defined by the controller], CNPJ (Brazilian tax ID) [to be defined by the controller], with address at [to be defined by the controller] (“we”). This policy applies to the website estudatta.com.br, to the web application it hosts and to the API that serves it.
The service is a study and practice planner: you set a goal, a time target and the days of the week; the service organizes the plan, logs the sessions and turns what was missed into time to make up. We process personal data to provide exactly that, in accordance with Brazil’s General Data Protection Law (LGPD, Law No. 13,709/2018).
02What data we collect
Account data
- Email (required; used as the login identifier and for the emails described in section 3).
- Name (optional) and time zone (default America/Sao_Paulo), used to build the plan in your local time. Interface language (default pt-BR).
- Password, stored only as a cryptographic hash. We never store the password in plain text.
- If you sign in with Google (when that login is enabled): your Google account identifier, the email and the name provided by Google. We do not receive your Google password.
- Dates of account creation, email confirmation and last access.
Data you create while using the service
- Goals (title, description, category, desired outcome, dates, exam deadline, available days and times), goal rules and planned breaks (with the reason, if you write one).
- Subjects, topics, tasks and materials: titles, descriptions, links, page ranges, reading position and the PDF files you upload.
- Study sessions: start, end, duration, topic, pages, free-text notes, pomodoro settings, time zone and the identifier of the device they were logged on.
- Preferences: theme, message tone (warm, direct or firm), first day of the week, default session length, reduced motion, and your answer about consent to usage metrics (yes, no or no answer).
- Reminder preferences: channels (app, push, email), times, days, quiet hours, daily limit and whether the goal name appears in the notification (by default it does not).
Technical and security data
- For each login session: IP address, browser identification (up to 300 characters), a device type label (“iPhone/iPad”, “Android”, “Windows”, “Mac”, “Linux” or “Browser”), creation, expiration and last-use dates.
- A random device identifier, generated by the browser itself and sent with every request, used to sync logs made offline and avoid duplicates.
- Audit records of sensitive actions (account creation, sign-in, password change, account deletion, material upload and deletion, imports, push subscription, billing actions and administrative actions), with date, IP and request identifier.
- Notification queue and delivery results. In push delivery records we keep only a cryptographic digest of the subscription address, not the address itself.
Contact and updates
If you use the contact page form, we keep name (optional), email, subject and message. If you leave your email to receive updates, we keep the email and where you signed up.
Payment (when billing is enabled)
We keep the plan subscribed, the subscription and payer identifiers assigned by the payment processor, the status, the current period, the amount and currency, plus the events the processor sends us about the subscription. We never receive or store card numbers, security codes, tax IDs or billing addresses: payment is completed in the processor’s environment (section 5).
What we do not collect
We do not collect location, contacts, camera or microphone. In the app, we use no usage-metrics service, tracking pixel or third-party cookie; on the website, Google Analytics runs only with your consent (section 4).
03What we use the data for
- Providing the service: calculating today’s goal, the balance, owed time and suggested catch-up; keeping the plan in sync across your devices; working offline and syncing later. Legal basis: performance of the contract.
- Transactional emails: there are only three — email confirmation (link valid for 24 hours), password reset (link valid for 1 hour) and the weekly summary, which is only sent if you enable the email channel and the weekly summary in preferences (both off by default). We do not send marketing email.
- Reminders: in-app notifications and, if you allow it in the browser, push notifications (section 5). The service limits the daily amount, respects quiet hours and cancels reminders that no longer make sense (for example, when the session has already been logged). Legal basis: consent, revocable in preferences.
- Security: limiting sign-in and password recovery attempts, detecting misuse, keeping audit records and letting you see and end sessions on other devices. Legal basis: legitimate interest and compliance with legal obligations.
- Billing (when enabled): starting, tracking and cancelling the subscription and applying plan limits. Legal basis: performance of the contract.
- Support: replying to messages sent through the contact form, at the email you provide.
- AI features, only when enabled and only when you ask (section 6). Legal basis: consent, given with each action.
We do not sell personal data and we do not use your data for advertising.
05Who the data is shared with
We share data only with processors needed for the service to work, each limited to the minimum. All of the following are optional and depend on the environment configuration:
- Asaas (payment processing, when billing is enabled): receives from Estudatta the plan description, the amount, the billing period and a random reference with no personal data. Name, tax ID, email and card details you enter directly on Asaas’s payment page; Estudatta neither receives nor stores that data. The payment itself happens on Asaas’s website, under its privacy policy.
- AI provider (when AI features are enabled): receives only the excerpt needed for the action you requested, as described in section 6. Provider in production: [to be defined by the controller].
- Browser push notification services (operated by the browser or operating system vendor, such as Google, Mozilla and Apple): receive the notification content, encrypted for your subscription. This only happens if you allow notifications.
- Google (only if you choose to sign in with Google): identity exchange under the OpenID Connect protocol, with the email and profile scopes.
- Email server (SMTP) configured by the controller, for the three transactional emails. Sender: no-reply@estudatta.com.br.
- File storage for uploaded PDFs: own disk or an S3-compatible service, in a private area. Provider in production: [to be defined by the controller].
Beyond that, data is only shared under legal obligation or an order from a competent authority.
06AI features (optional)
- AI features come off by default. When off, the app tells you so and you organize everything manually.
- When enabled, they are only triggered by your explicit action, in three situations: suggesting the subject and topic structure from a text or an import; suggesting a plan distribution; writing the weekly summary. Nothing runs in the background.
- What is sent: only the necessary excerpt — the text you pasted or extracted (limited to 60,000 characters, with a warning when truncated), or the goal title and the period’s numbers (minutes, days, owed time), or the topic titles and the days’ availability. We do not send your email, name or account identifiers. The text is sent as data to be analyzed, with instructions not to interpret it as commands.
- What we keep: our usage records hold only counters — action, model, number of characters and tokens, response time and error code. We do not record the content sent or the response.
- Every answer is a preview: nothing in your plan changes until you review and confirm. The answer is validated and the weekly summary goes through a filter that blocks promises and guilt.
- There are daily limits per plan and a global limit; when exhausted, the app tells you and nothing is sent.
07Uploaded materials and import
- We accept only PDF files, verified by content (not just extension), of up to 25 MB and 800 pages. You can also add links (https only) and physical books without uploading a file.
- Files are kept in a private area, tied to your account. To open or download, the app generates a signed link that expires in 10 minutes.
- When importing a syllabus (pasted text, CSV or PDF), we extract only the PDF’s text layer and keep that text together with the proposed subjects and topics, for you to review. We do not do OCR: PDFs scanned as images are rejected with a warning. Nothing is created without your confirmation.
- Deleting a material removes the file from storage. Deleting the account removes all your files.
- You are responsible for having the right to use the files you upload; we do not analyze them or share them with third parties beyond what is described in section 5.
08How long we keep it
- Account data and study content: for as long as the account exists. When you delete the account, they are deleted immediately (section 9).
- Expired login sessions and single-use tokens: deleted automatically 7 days after expiring.
- Notification queue and delivery records: deleted automatically after 90 days.
- Operational records — action audit, events received from the payment processor, AI usage counters, contact messages, updates sign-up and sync queue —: kept for [period to be defined by the controller], anonymized after the account is deleted.
- Tax and billing data required by law: for the applicable legal period.
09Your rights: export, correct and delete
You exercise most of your rights directly in the app, without asking anyone:
- Access and portability: in Preferences, export everything as JSON (account, goals, subjects, topics, materials, tasks, sessions) or the session history as CSV. Uploaded PDFs can be downloaded one by one from the materials screen. Export does not depend on a subscription.
- Correction: edit name, time zone, language, preferences and all study content at any time.
- Deletion: in Preferences, confirm account deletion by typing the requested word and, if there is a password, the password. Deletion is immediate and irreversible: it deletes the account, goals, sessions, materials (including files), notifications, push subscriptions, preferences and imports. Only audit records, AI usage counters and billing events remain, with no link to your identity. Export first if you want to keep a copy.
- Withdraw consent: turn off push, email and the weekly summary in reminder preferences; don’t use the AI features; end sessions on other devices from the sessions screen.
- Cancel the subscription (when there is one): on the plans screen, with no hurdles. Cancelling deletes nothing.
For requests the app doesn’t cover (for example, information about specific sharing or objection to a processing activity), write to contato@estudatta.com.br. You can also file a complaint with Brazil’s National Data Protection Authority (ANPD).
10Security
- Passwords stored with a purpose-built hash; minimum of 8 characters.
- Random, single-use confirmation and password reset tokens, stored only as hashes; resetting the password ends all open sessions.
- HttpOnly session cookie, origin checks and a CSRF token on every change; attempt limits per address and per account.
- Browser protection headers on every response and no caching of API responses.
- A restricted admin area, with every action audited. There is no — and will be no — “sign in as user”: administration sees only aggregate totals, never your study content, notes or files.
No system is infallible. If we identify an incident affecting your data, we will notify you and the authorities as the law requires. This section describes measures taken; it does not claim certification or external audit.
11Changes to this policy
The current version is the one published on this page, with the date shown at the top. If a change expands the use of your data or enables a new processor (for example, usage metrics or an AI provider), we will notify you inside the app before it takes effect.
12Contact and data protection officer
Questions, requests and complaints about personal data: contato@estudatta.com.br or the contact form.
Data protection officer (DPO): [name and email to be defined by the controller].