Version:
0.1-draft· Effective date: [FILL IN once out of draft] Final URL: https://www.stopaposta.com.br/privacy (domain not live yet — seereview-notes.md)
Privacy Policy — StopAposta
1. Who the controller is
The controller of your personal data, under LGPD art. 5, VI, is G DA SILVA C ROCHA DESENVOLVIMENTO DE SOFTWARE & TECNOLOGIA (trade name GROCHA Tech), Brazilian company ID (CNPJ) 38.323.551/0001-69, contact contato@grochatech.com.br.
Our data protection officer (DPO), under LGPD art. 41, can be reached at the same email, contato@grochatech.com.br, and phone/WhatsApp +55 (19) 98847-2424 — the official channel for data-subject requests.
This Policy covers www.stopaposta.com.br and the StopAposta apps for Android and iOS. A betting-blocking app inherently touches some sensitive health data (LGPD art. 11) — this Policy is more detailed than average because of that.
2. What data we collect and why
| Data | Purpose | Legal basis (LGPD) |
|---|---|---|
| Account (name, email or phone) | Create and secure your account | Contract performance (art. 7, V) |
| Device (platform, protection level, integrity status, last heartbeat) | Keep protection running, detect tampering | Contract performance |
| Attempts to reach a betting site/app (domain or app, date, time, channel) | Show your history and, if authorized, your guardian | Specific consent (guardian sharing) |
| Hostname of an unknown domain (never full URL/content) | Sentinela real-time classification | Specific consent, explained at onboarding |
| Guardian (name, contact, relationship) | Link who holds your protection's key | Consent |
| PGSI screening (9 gambling-habit questions) | Personalize your experience — sensitive health data | Specific, highlighted consent (art. 11) |
| Banking-app notifications matching known betting payees (Android, optional) | Alert you and, if authorized, your guardian of a betting payment | Specific, highlighted, revocable consent (art. 11) |
| Conversations with StopAposta AI | Respond to you at the moment of urge | Consent; 30-day default retention, opt-out available |
| Community messages | Moderation and abuse prevention | Consent; contract performance (moderation) |
| App usage and crashes | Keep the app working (Firebase Analytics/Crashlytics) | Consent (telemetry opt-in) |
| Subscription data (store receipt, status) | Bill and unlock paid features | Contract performance |
| Advertising (non-subscribers) | Show ads (Google AdMob) | Consent (§7) |
We do not collect: national ID/CPF (not required to create an account), bank balance or statements, page content beyond what's needed to classify an unknown domain, content of notifications that don't match the betting-payee pattern.
3. How each protection mechanism works, and what it sees
- Local DNS filter (on-device VPN, Android
VpnServiceand iOSNEPacketTunnelProvider): runs entirely on your device. It decides to block or allow a domain lookup by comparing it to a signed list; it doesn't inspect your traffic content and doesn't send your browsing to us — only the hostname of an unknown domain goes to Sentinela. - Sentinela: when you reach a domain that's neither on the local list nor among the on-device popular domains, we send only the hostname to our backend, which classifies it and returns a verdict within seconds, with a global cache — whoever reaches a new domain first protects everyone else, without resending.
- Accessibility service (Android): reads the foreground app name, the address in supported browsers, and system Settings screen titles, only to detect and close betting apps/sites and to protect protection from being turned off. It does not read page content or anything typed outside the address bar.
- Device Admin / Device Owner (Android, Guardian Lock and Fortress): adds a step (Device Admin) or makes protection part of device management (Device Owner, Fortress — only after a guided factory reset with your explicit full-screen consent) to make uninstalling harder without going through the guardian.
- NotificationListenerService (Android, optional, Pix/payment detection): reads only banking notifications matching known betting-site payee names. You turn this on yourself, with highlighted consent as sensitive data, and can turn it off anytime.
- Family Controls / Screen Time (iOS): uses Apple's
.individualauthorization to apply the shield to betting apps/domains and to let the guardian set the Screen Time passcode. We don't access your device usage content beyond what the shield needs.
4. Guardian and alerts
If you have a linked guardian, they receive integrity alerts (protection off, device compromised, tampering attempt), unlock requests, and whatever summary you authorize. You choose how much detail of your attempt history the guardian sees.
5. StopAposta AI and Community
Your messages to StopAposta AI go through GROCHA Tech's AI gateway, which injects account context (days without betting, recent attempts, whether you have a guardian) to respond better. The conversation is not confidential clinical care; on signs of risk, we immediately show CVV (188) and other support contacts. Default 30-day retention, with an opt-out. Community messages are anonymous to other participants (no real name, no image), moderated by AI and humans before and after posting, with internal logging for safety and legal compliance.
6. Who we share data with
We share the minimum necessary, only with processors acting on our instructions, under contract and confidentiality:
- Firebase (Google): authentication, push (FCM), usage/crash metrics (Analytics/Crashlytics), only with your telemetry consent.
- Google AdMob: ad delivery for non-subscribers, with consent (§7).
- App Store and Google Play: subscription payment processing; the store returns only purchase confirmation and identification — we never see your card.
- Guardian: as in §4, within what you authorized. Beyond that, we share only under court order or a competent authority's request, to the exact extent required. We do not sell personal data and do not share health or gambling data with advertisers.
7. Advertising
If you don't subscribe, the app shows ads (Google AdMob). Outside the EEA/UK — which includes Brazil — we ask for your specific consent to personalized ads within our own LGPD consent system; in the EEA/UK, Google's consent form (UMP) also appears. If declined or undecided, we show non-personalized ads. We never send health, gambling, or betting data to the ad SDK. On iOS, we also request the system's tracking permission (ATT) before any ad. Gambling, casino, and get-rich-quick categories are blocked in the ad panel. Subscribers never see ads.
8. Retention and deletion
You can export all your data anytime from the app. You can delete your account anytime; deletion enters a 7-day grace period (cancellable within it) and then permanently erases the account and linked data. Deletion is never blocked by an active lock — a linked guardian is notified of the request but cannot block it. AI conversations: 30 days by default. Usage/telemetry data: per Firebase's standard retention, under your consent. Consent-acceptance records and billing data follow the applicable tax/accounting retention period (5 years, Brazilian Tax Code arts. 173 and 174), no longer identifying you after account deletion.
9. Your rights (LGPD art. 18)
Confirmation of processing, access, correction, anonymization/blocking/deletion, portability, deletion of data processed under consent, information about sharing, information about the right to refuse consent, and consent withdrawal. You exercise deletion yourself in the app (§8); other requests go through §1's channel, answered within 15 days (art. 19, II). You may also file a complaint with Brazil's data protection authority (ANPD).
10. Security
Communication between your device and our servers is encrypted in transit (HTTPS/TLS). No measure eliminates risk entirely; if a security incident may cause you relevant risk, we will notify you and the ANPD, describing what happened and the measures taken, per LGPD art. 48.
11. Minors
StopAposta is intended for adults 18 and over and is not directed at children or teenagers. We do not knowingly collect data from minors under 18. Age is self-declared at sign-up; an identified underage account is terminated and its data erased, except what the law requires us to keep.
12. International data transfer
Some of our processors — Firebase/Google and our cloud infrastructure provider — are based outside Brazil. Transfer occurs under LGPD arts. 33–36, supported by those providers' data protection contractual clauses, limited to what's necessary to perform your contract.
13. Users outside Brazil
We operate from Brazil under the LGPD. If you're in another country, we handle your data to the same standard described here and honor rights under your local law where applicable, through the same channels listed here.
14. Changes to this Policy
We may update this Policy. The current version is always published on this page, with a version identifier and effective date. A material change — new controller, new purpose, new data type — is announced in the service and requires new acceptance on your next access.
15. Contact
G DA SILVA C ROCHA DESENVOLVIMENTO DE SOFTWARE & TECNOLOGIA — CNPJ 38.323.551/0001-69. Data Protection Officer and data-subject channel: contato@grochatech.com.br — phone/WhatsApp +55 (19) 98847-2424. Address: [FILL IN].