01
1. Data we collect
We collect data provided directly by you, such as name, email, password, language preference, requested plan, and intended use in chat, workspace, API, integrations, or business solutions. We may also process usage data, technical logs, IP address, minimal product events, and the content of documents uploaded for processing.
02
2. Purpose of processing
Your data is used to: (a) create and operate your account; (b) evaluate guided access for businesses, API, and integrations; (c) provide and maintain chat, library, workspace, and contracted solutions; (d) authenticate your identity; (e) process payments when applicable; (f) send operational communications; (g) measure usage through optional analytics and minimal metadata; (h) comply with legal obligations.
03
3. Legal basis (LGPD Art. 7 / GDPR Art. 6)
We process your data based on: consent (for non-essential cookies and marketing communications), contract execution (to provide the service), legitimate interest (for security and product improvement), and legal obligation compliance.
04
4. Data sharing
We may share data with providers necessary to operate the service, such as infrastructure and hosting, payments, transactional email, consented analytics, and AI providers used to generate answers. These providers must process data according to contract, purpose, and applicable security measures.
05
5. Documents, private bases, and answers
Uploaded documents may be extracted, chunked, vectorized, queried, and sent as context to AI models as needed to answer questions and maintain the private library. Answers are informational and should be reviewed alongside sources, documents, and conclusions.
06
6. Security and isolation
We apply encryption in transit (TLS/HTTPS), authentication, file validation, logical account separation, and access controls. No measure eliminates all risk, but the platform is operated to reduce improper data exposure.
07
7. Data retention
We keep data while the account, contract, or guided access request is active and for the time needed to meet operational, legal, and security purposes. Documents may be deleted by the user when the feature is available; removal requests can also be made through the privacy contact.
08
8. Cookies and tracking technologies
We use essential cookies for platform functionality, authentication, security, and language preferences. Analytics is only loaded after consent. We currently do not load marketing pixels; if that changes, non-essential tags will be conditioned on consent.
09
9. International transfer
Data may be processed outside Brazil by infrastructure, payment, email, analytics, or AI providers. We seek to use providers and contractual mechanisms suitable for LGPD requirements and, where applicable, GDPR.
10
10. Children's data
Apeirum is not intended for individuals under 18 years of age. We do not intentionally collect data from minors. If you become aware that a minor has provided personal data, please contact us to request deletion.