Findy stores the documents of your life — so privacy isn't a footer section, it's part of the product. This policy explains, in plain language, what data we collect, what we use it for, who we share it with, and how you exercise your rights under Brazil's General Data Protection Law (Law No. 13,709/2018 — LGPD).
1.Who we are (controller)
Findy is a product operated by Guilherme Niclewicz, available at askfindy.com. For LGPD purposes, we are the controller of the personal data processed in the service. For any privacy matter, contact the data protection officer listed in section 12.
2.Data we collect
- Account data — name, email and login credentials, provided by you at sign-up.
- Documents you upload — the files you upload can contain personal data of any kind, including sensitive data (medical results, for example). You decide what goes in; we protect all of it to the same standard.
- Data derived from your documents — extracted text (including OCR), automatically generated title, summary, dates, category and issuer, search representations (embeddings) and preview thumbnails.
- Usage data — technical data such as IP address, device information and access logs. On this website (not in the app), navigation events are also collected via PostHog's cookieless analytics (see section 9).
3.What we use your data for
- Running the service — storing, organizing, searching and answering questions about your documents. Legal basis: performance of a contract (art. 7, V, LGPD).
- Improving the product — measuring usage and understanding how Findy is used, via analytics. Legal basis: legitimate interest (art. 7, IX), with the right to object (see section 9).
- Security and fraud prevention — protecting accounts, detecting abuse and meeting legal obligations. Legal basis: legitimate interest and compliance with legal obligations.
We don't sell your data. And Findy does not use your documents to train AI models. Processing by the providers we rely on is governed by each provider's own terms (see section 4).
4.Who we share it with (processors)
To work, Findy relies on three providers. They act as processors and handle data only under our instructions:
- Amazon Web Services (AWS) — hosting and storage. Your files live in a private, encrypted bucket (at rest and in transit), isolated per account. Nothing is public.
- Google (Gemini API) — document content is sent to Google's API strictly for reading it (including OCR), extracting the title, summary, dates, category and issuer, and generating the search indexes and answers. Findy does not use your documents to train AI models; processing by Google Gemini is governed by Google's API terms.
- PostHog — analytics on this website only, not in the app. It receives navigation events and metadata — never the content of your documents.
There is no other sharing, unless we are required to by law or by order of a competent authority.
5.International transfers
AWS, Google and PostHog may process data outside Brazil (in the United States, for example). These transfers rely on the contractual safeguards those providers offer — such as standard contractual clauses and data protection certifications — under art. 33 of the LGPD, and happen only for the purposes described in this policy.
6.Retention and deletion
- Documents and derived data are stored for as long as your account exists.
- Deleting a document removes the file and everything extracted from it: text, summary, dates, search indexes and thumbnails.
- Deleting your account is self-service, right in the app: Account → Delete account, with a double confirmation. Deletion is permanent and wipes everything — your original files, everything extracted from them (text, summaries, dates, search indexes and thumbnails), your search history and the account itself. Residual copies in backups expire within 30 days. You can also request account deletion at any time from the data protection officer listed in section 12.
- Technical logs (access and operation records) are kept for up to 6 months, for security and diagnostics.
7.Your rights
Under art. 18 of the LGPD, you may at any time request:
- confirmation that we process your data, and access to it;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of unnecessary or excessive data;
- portability of your data to another provider;
- information about who we share your data with;
- withdrawal of consent, where processing is based on it, and objection to processing based on legitimate interest.
Access and portability are yours right in the app: your original documents are always available to download. Deletion is self-service too — delete any document at any time, or the whole account under Account → Delete account (see section 6). For everything else, contact the data protection officer listed in section 12; we respond within a reasonable time, using 15 days as a reference.
8.Security
- Encryption in transit (TLS) and at rest.
- Per-owner isolation enforced inside search itself: the system cannot return another account's document.
- Sanitized error messages — they never expose the content of your documents, not even in internal logs.
- Least-privilege internal access — operating the service does not include browsing your files.
9.Cookies and analytics
The app uses only essential local storage: keeping you signed in and remembering preferences (theme, language, view mode). None of it is used for tracking. On this website, we use PostHog for cookieless analytics: events are kept in memory only for the duration of your visit and create no persistent identifiers in your browser.
If you want to opt out of analytics, just use a content blocker — the site keeps working normally. Since the analytics uses no cookies and creates no persistent identifiers, nothing lingers in your browser after the visit.
10.Children and teenagers
Findy is intended for people aged 18 and over. We do not knowingly create accounts for, or process data of, children or teenagers.
11.Changes to this policy
We may update this policy to reflect changes in the product or in the law. We will announce meaningful changes by email or inside the product, with the effective date shown at the top of this page.
12.Data protection officer and contact
The data protection officer (DPO) is Guilherme Niclewicz — guilherme.saddock@gmail.com. If you believe your rights have not been honored, you may also petition Brazil's National Data Protection Authority (ANPD).
See also the Terms of Use.