Privacy Policy
Last updated: July 28, 2026
This Privacy Policy describes how Cents collects, uses, shares, retains, and protects your personal data, in line with Brazil's General Data Protection Law (LGPD — Law No. 13,709/2018) and general applicable data-protection principles. By creating an account or using the Service, you agree to the data handling described here, together with our Terms of Use.
1. Who We Are and the Scope of this Policy
This Policy applies to all visitors, registered users, and family environments of Cents, available at cents.gbinder.com. For LGPD purposes, the operator of Cents acts as the controller of the personal data processed in the Service.
2. Data We Collect
We collect the data you provide directly and some technical data needed to operate the Service:
- Signup data: name, email, password (stored only as a hash, never in plain text), phone number, country, identification document (e.g., a national ID), and preferred language.
- Financial data you enter: transactions, accounts, cards and statements, goals, budgets, investments, real estate and vehicles, shopping lists, and other information in your environment.
- Technical data: IP address — used transiently at signup to suggest your country and default language and, on each visit, converted locally into an approximate region (country/state/city) for the aggregate usage statistics described above; the IP itself is neither stored nor sent to third parties —, browser language, theme (light/dark), and session information.
- Communication data: support messages, survey responses, and records of notifications sent to you.
- Usage data: we count, per day, how many visits each Cents screen receives and the approximate region they come from (resolved from the IP against a local database, without querying external services) — both counters are aggregates, not linked to your account. We also record, per user, on which days the account was used and the time of its last activity, to measure active accounts — without recording which screens you opened. None of this leaves our servers.
3. Purpose and Legal Basis for Processing
We process your data to: (i) perform the contract for the Service you entered into with us — signup, authentication, recording and calculating your financial data, sending transactional emails; (ii) comply with legal or regulatory obligations, where applicable; (iii) pursue the operator's legitimate interest, for fraud prevention, security, and improving the Service, always proportionally and without harming your rights; and (iv) obtain consent, where required — for example, optional marketing communications, if and when they exist. You may withdraw optional consents at any time without affecting essential use of the Service.
- Improving the Service from your feedback: messages sent through the suggestion and reporting channels and interactions with the artificial intelligence features — including complaints, feature requests, questions, and error reports made in conversations with the AI, which the assistant may automatically log as an internal suggestion, identifying the user who sent them — are reviewed by our team to fix errors, prioritize improvements, and evolve the Service. These records are for internal use, are never sold or used for advertising, and follow the retention and deletion rules of this Policy.
4. We Do Not Sell Your Data
We never sell, rent, or trade your personal or financial data to third parties for marketing or advertising purposes. Your financial data is used exclusively to operate the Service for you.
5. Sharing with Third Parties
We share data only with third parties strictly necessary to operate the Service, under contractual confidentiality and security obligations:
- Asaas (payment institution): receives the data needed to process your subscription billing — name, ID document, email, and billing data. We do not share your personal financial data (transactions, accounts) with Asaas.
- Email and push-notification providers: receive your email or notification address and the content strictly necessary to deliver transactional communications, such as signup confirmation, alerts, and the monthly summary.
- Public authorities, when required by law, court order, or for the regular exercise of rights in administrative or judicial proceedings.
- Google Analytics, ONLY on public marketing pages (such as the visitor homepage): it measures visits and traffic sources via cookies. Inside the app, after login, there is no Google Analytics nor any third-party tracker.
6. Data Retention and Deletion
We keep your data while your account or family environment is active, and for the additional periods below once that relationship ends:
- Closing YOUR individual account: you can close your own access at any time in Profile → Close my account. This deactivates your login immediately, but does NOT delete the environment's data — that follows the rules below, since other people in the same environment may keep using the Service normally.
- Closing the ENVIRONMENT (the whole family's account): an administrator can request the complete closure of the environment in Settings. From the request, there is a 15 (fifteen) day grace period during which everything keeps working normally and the request can be reversed at any time ("Cancel the closure"). Once the grace period ends without reversal, all environment data is permanently deleted and cannot be recovered.
- Inactive free accounts: a Free-plan account with no access at all for 45 (forty-five) days is marked inactive; if it remains without access for another 15 (fifteen) days — 60 (sixty) days total from the last access —, its data is permanently deleted through the same environment-deletion process.
- In both time-based deletion cases (environment closure and free-account inactivity), we notify you by email before the final deletion, so you can react in time — by reactivating the environment or downloading a copy of your data.
- You can download a full copy of your data at any time, including during a grace period, using the "Download my data" button in Profile — you don't need to wait for closure to export.
- Audit and security logs (for example, who changed what) may be kept for an additional period where required by law or for the regular exercise of rights, even after other data has been deleted.
7. Your Rights as a Data Subject
As the subject of your personal data, you have the right to:
- Confirmation that processing exists, and access to your data.
- Correction of incomplete, inaccurate, or outdated data, directly in the Profile/Settings screens or through support.
- Portability: download a structured (CSV) copy of all your data at any time, using the "Download my data" button in Profile.
- Deletion of your data, by closing your account or the environment as described in Section 6.
- Information about who we share your data with (Section 5), and revocation of optional consents.
- Objection to processing based on legitimate interest, where applicable, and review of automated decisions that affect your interests.
8. Information Security
We adopt technical and organizational measures to protect your data:
- Passwords are never stored in plain text: we use Argon2id hashing, one of the most recommended algorithms for this purpose today.
- Sensitive secrets stored in the system, such as integration keys, are protected with authenticated encryption (libsodium).
- All communication between your device and the Service happens over HTTPS (encrypted connection).
- Isolation between environments: data from one family environment is never visible to another, and access within your own environment is controlled by permissions the administrator configures.
- Audit logging of relevant actions taken in the Service, to help detect misuse.
9. Cookies and Sessions
We use only cookies and local storage strictly necessary for the Service to work: keeping your session authenticated, remembering your language and theme (light/dark) preference, and enabling the installable app to work, including offline. We do not use third-party advertising tracking cookies.
10. International Data Transfers
Our servers and databases are hosted in Brazil. Some providers that help operate Cents, such as email providers, may process data on servers outside Brazil; in those cases, we require those providers to offer data-protection safeguards compatible with the LGPD.
11. Use by Minors
Cents is not directed at anyone under 18 and we do not intentionally collect data from children or teenagers outside the context of a family signup carried out by an adult legal guardian. If you are a legal guardian managing a minor's data within your family environment, you are the controller of that data with respect to the minor; we only process what you enter, under the same rules as this Policy.
12. Changes to this Policy
We may update this Policy periodically to reflect changes in the Service, the law, or our data-handling practices. Material changes will be announced by email or a notice within the Service itself, with reasonable advance notice, and the date at the top of this page will always reflect the version in force.
13. Data Protection Contact
For questions, requests related to your personal data, or to exercise your rights as a data subject, reach us through the support channels within Cents itself (Profile → Help/Support). We will do our best to respond within the timeframes required by the LGPD.
Reach us through the support channels within Cents (Profile → Help/Support).