← Back to homeBeta

VERSÃO privacidade-2026-10-02.beta.9

CognoSaga Privacy Notice

The original document is in Portuguese. Translations refer to the same version.

Updated on 02/10/2026

1. Controller and your rights

CognoSaga is operated by GUILHERME GONCALVES DESENVOLVIMENTO DE SOFTWARE LTDA, Brazilian company registration (CNPJ) 64.165.783/0001-46, at Rua Lactâncio, 25, Lote 25 Quad, Vila Nova Curuçá, São Paulo/SP, postal code 08031-310, Brazil. Support, privacy and review requests: [email protected].

The company identified above is the controller of personal data processed by CognoSaga. You may request confirmation of processing, access, correction, information about sharing, deletion or objection where applicable, and withdrawal of consent, in addition to the controls available in your profile. We will verify your identity proportionately before fulfilling requests. You may also contact Brazil’s National Data Protection Authority (ANPD) and other competent authorities.

We process account and learning data to provide the service you request; security and abuse-prevention data to protect the service and its users, assessing necessity and impact; and legally required records to comply with obligations or exercise rights. Optional analytics require consent and remain disabled at launch. We do not sell your personal data or use behavioural advertising.

2. Data used

We store your name, email, hashed password, preferences, sessions, terms acceptance, answers, question exposures, evidence, results, revisions, goals, plans, activities, achievements and submitted reports.

This data supports authentication, progress retention, assessment explanations, study planning, content corrections and export or deletion requests. Sessions may record an IP address and browser identifier.

3. Abuse protection

ALTCHA protection is hosted by CognoSaga: your device solves a computational challenge and the API validates it. We do not use an external CAPTCHA service or behavioural tracking for this challenge.

Identifiers derived from IP addresses using a secret key limit attempts for short periods. Nonces prevent challenge reuse. These records expire and are removed by periodic cleanup. Passwords and challenge proofs are not written to logs.

We also limit requests by IP and, after authentication, by account, using identifiers protected with a secret key and temporary counters. These counters do not store request contents, passwords or assessment answers. Rate-limit windows expire automatically, and expired records are removed during periodic cleanup at intervals of up to one hour. These essential security mechanisms are independent of optional browsing analytics.

4. Browser and exported files

On the web, essential cookies maintain sessions and protect changes against forged requests. Knowledge map display preferences may be stored in your browser.

Exporting downloads a JSON file through your browser only when you request it. Once saved on your device, the file is under your control; CognoSaga does not automatically remove these copies.

5. Infrastructure and emails

The CognoSaga API and PostgreSQL database are hosted on a dedicated Amazon Web Services (AWS) instance in Northern Virginia, United States. Cloudflare Pages distributes the website and apps through its global network. Amazon SES in São Paulo sends transactional emails. Amazon S3 in the United States stores encrypted backups. GitHub Actions automates builds and triggers backups; secrets are not included in source code or public images.

We send an email confirmation when you register; access requires that confirmation. Password recovery and account restoration use temporary links. Resetting a password does not remove two-factor authentication when enabled. These emails are necessary to operate your account. Activity notifications remain inside the app and admin.

6. Your controls

In your profile, you can edit preferences, change your password, revoke other sessions, export JSON data and request deletion with password confirmation. These features are available in your browser on desktop and mobile.

Access is revoked when deletion is requested. You have 30 days to restore by email; after that, an hourly task deletes personal data, retaining global content, effectively anonymized records and financial records subject to the specific retention described below. The acceptance record is also deleted.

7. Optional measurement and your choices

Navigation and acquisition measurement is optional and only starts after you accept. Declining does not limit access to CognoSaga. You can review your decision in “Privacy preferences”. Your choice is versioned and valid for 180 days; material changes will require a new choice.

When enabled by the operator and accepted by you, we record fixed page categories, clicks on identified buttons, permitted sources and campaigns, registration form views and confirmed registration and assessment operations. Measurement sessions end after 30 minutes of inactivity. We do not send names, emails, answers, form content, tokens or private identifiers to Google.

Google Analytics only loads after consent and integration validation. Advertising measurement remains disabled. Optional cookies identify the measurement session; the preference may be shared across configured first-party subdomains. Different domains require separate choices.

First-party events remain in PostgreSQL for 90 days by default, configurable from 7 to 365 days. When you decline, we stop new events, discard first-party events associated with the preference and remove measurement cookies accessible to CognoSaga. Events already sent to Google cannot be recalled by the browser; retention settings, providers, any international transfers and support procedures must be reviewed before enabling this integration in production.

Events associated with your account are included in your data export. Account deletion revokes associated measurement and removes your first-party events. Aggregate operational counts, such as accounts created and assessments completed, support product operations and remain separate from visitor attribution. We do not send these counts to Google.

8. Rankings and achievements

Participation in rankings is optional and stays disabled until you choose a nickname and confirm you want to join. Other signed-in learners can see your nickname, crest, position, knowledge title, demonstrated goals and exploration level. Weekly rankings also show XP earned that week. Your account name, email, answers and private identifiers are not displayed.

You can leave rankings anytime from your profile or the rankings page. Leaving removes your identity from the lists without erasing progress. Suspended accounts, accounts pending deletion and staff accounts do not participate. Quests and achievements remain available without public participation.

Your nickname, participation choice and quest rewards are included in your personal data export and removed upon permanent deletion. Activity history and evidence support quests and achievements. Question revisions may change performance achievements and rankings; XP does not prove knowledge mastery.

9. Hosting, authentication and backups

These services may process data in Brazil, the United States and other countries where they operate. Sharing is limited to the purposes described and the providers’ data-protection agreements, with applicable international-transfer mechanisms, including standard contractual clauses where appropriate. Information about providers, transfers and safeguards can be requested through our privacy contact.

The beta accepts only adults aged 18 or over. Two-factor authentication is optional during this phase, including for administrative staff. Anyone who enables it must confirm the second factor when signing in. Authenticator secrets and recovery codes are protected; do not share these codes. Operational logs must not contain passwords, tokens or personal answers.

We run encrypted daily backups retained for seven days. The frequency is an operational target subject to failures and delays; a restore may lose changes made after the last successful backup. We do not offer continuous recovery to any point in time. Restores must respect deletion requests and retention periods; older copies expire through the backup cycle.

The beta may experience interruptions due to technical failures, maintenance or provider limits. Monitoring and recovery procedures reduce the impact without guaranteeing continuous availability. Optional browsing analytics remain disabled at launch.

10. Profiles, conversations and reports

The community is optional and restricted to signed-in users. Your account name, email, assessment answers and detailed study history do not appear on your public profile. The nickname is shared with the ranking. You control profile visibility and, separately, whether to receive messages.

Conversations are accessible only to participants. Content is stored in the service database; there is no end-to-end encryption. Reporting a message allows the administrative team to review that message and the reason provided. The panel does not provide general access to conversations. Blocking prevents visits and new messages in both directions.

Each message is available for up to 90 days. Messages and associated reports are removed by periodic batch cleanup after that period. Your export includes retained conversations, blocks and reports from your account. Requesting deletion makes your profile private and disables messages. Permanent deletion erases your conversations and social records; copies already exported by participants cannot be recalled. Backups follow the retention described in this notice.

11. Profile visual identity

Free accounts choose an avatar and colour; accounts with active Plus benefits can also use a photo and social media links. Images are cropped, resized to 256 by 256 pixels and reprocessed as WebP without the original file’s metadata. Photos and links follow profile visibility and blocking settings. Do not upload other people’s photos or data without permission. When following external links, the destination site’s rules also apply.

The photo remains in the database while saved to your account. You can remove it from your profile; permanent account deletion also erases it. The data export includes the saved image. Backups follow the retention period described in this notice. Choosing an avatar may keep the photo for reuse; use Remove photo to erase it.

You may feature up to three earned badges. Badges and knowledge rank are derived from confirmed activities and results. Ranking positions appear only for those who opted in; positions consider the participants visible to the signed-in visitor.

12. Forum data

When you post in the forum, signed-in users can see the title, text, subject, dates, your nickname and your photo or avatar. Your account name and email are not published. Private profiles, suspended accounts, pending account deletions and blocks restrict contribution visibility. You can still manage your own questions after making your profile private; posting again requires a public profile.

Questions and answers remain until they are removed or their author’s account is permanently deleted. Deleting a question removes its answers and linked reports. Deleting an accepted answer also removes the solved indication. Your export includes only your own contributions and reports. Moderators access reported posts and reasons; reports are not shown to participants. Copies already saved by readers cannot be recalled; backups follow the retention period stated in this notice.

13. Groups, classrooms and notifications

We store groups, invitations, members, activity metadata and individual assessments for synchronisation, permissions and progress. Classroom drawings and chat remain only in API memory, with no meeting archive: closing the room or restarting the server discards this content. Admins see metadata and limits, without administrative access to classroom drawings or conversations. Internal notifications record events relevant to your account. These personal data are included in export and deletion processes.

10. Energy, attempts and financial data

We record daily allowance, energy policy and consumption receipts linked to activities, separately from XP. Practice attempts retain a reference to an immutable exercise version and its completion, allowing resumption without another charge. This learning data is included in exports and deleted with the account.

Stripe and Mercado Pago receive payment details directly in their checkouts. The account email is sent to Mercado Pago to link the requested subscription. CognoSaga does not receive or store full card numbers or CVV. We store financial identifiers, payment option, currency, amounts, exchange rate used, paid periods, confirmations, cancellations, refunds and disputes. We do not store complete financial webhook payloads.

When purchases are enabled, financial records will be separated from learning data. SPEDY will process tax data required to issue documents, based on the information supplied by the buyer. We will disclose specific tax and financial retention periods before purchase and apply them through a versioned policy. New purchases remain unavailable until that policy and tax configuration are complete. Requesting account deletion does not remove records whose retention is required by law or necessary to exercise rights; access to those records is restricted.

Exchange-rate queries use the Central Bank of Brazil without sending students’ personal data. Stripe, Mercado Pago and SPEDY process data necessary for payment, reconciliation and tax-document issuance according to the selected purchase and their own privacy notices. Shared data are limited to what each operation needs.

Forum drafts may remain in the browser session to prevent text loss during failures or navigation. Users can remove them, or clear them by signing out. Do not include sensitive data in posts.

Terms of Use · Privacy Notice · Delete account