Privacy Policy

Last updated: 2026-06-22

This English text is a courtesy translation. The legally binding version is the Portuguese one. Read the binding version.

Jurisdiction: Brazil. Primary legal basis: Law 13.709/2018 (LGPD). This document describes, in plain language, how Patensify collects, uses, stores and deletes data.

1. Who we are

Patensify is a service operated by F.A. RAMOS DESENVOLVIMENTO DE SOFTWARE LTDA, CNPJ 62.243.574/0001-48, with registered office at Rua Professor Walter Carretero, 436 — Sorocaba/SP, CEP 18053-120. For the purposes of this policy, “we”, “our” and “Patensify” refer to the same entity.

Data Protection Officer (DPO): Fabio Alves Ramos, contact dpo@patensify.com.

2. What Patensify does with your data

Patensify analyzes the public behavior of your Instagram audience to generate private insights about who pays attention to you and why. For that we need two categories of data:

  1. Your account data — email, name, and the connection to your Instagram account.
  2. Public behavioral data — likes, comments, mentions, saves and views that happened publicly on your profile. This data already exists on Instagram; Patensify organizes and interprets it.

3. Data we collect

3.1 Data you provide

  • Registration: name, email, password (stored hashed), and the Instagram profile data you connect.
  • Payment: processed by a payment partner. Patensify never stores card numbers — only the transaction identifier.
  • Preferences and onboarding answers: stated goals, notification settings.

3.2 Data collected automatically

  • Public behavioral events captured from Instagram: your followers’ interactions with your public content (likes, comments, mentions, saves, views when available).
  • Patensify app usage metadata: screens visited, insights opened, share cards generated, time between actions — used to improve the product.
  • Technical data: IP, device type, app version, error logs.

3.3 Third-party data (your followers and commenters)

Patensify processes the public username of people who interact with your profile. This data is public on Instagram and is processed under legitimate interest (LGPD Art. 10, II) with the following protections:

  • A third party’s username is never exposed outside your own app — it does not appear in ads, shared reports or exports to external networks.
  • Any third party may request pseudonymization of their username in our database via privacy@patensify.com. We respond within 15 business days.
  • We never collect private content (direct messages, content from private accounts that do not follow you).

4. Why we use your data

PurposeLegal basis
Provide the contracted service (generate insights, send alerts)Contract performance
Transactional communication (billing, security notices)Contract performance
Improve the product and train ML modelsLegitimate interest, with anonymization
Marketing communicationConsent — opt-in
Comply with a legal obligation or respond to authoritiesLegal obligation
Process public third-party data to generate insightLegitimate interest

5. Who has access

  • You: full access to everything that generated your insights, via the app.
  • Patensify: technical team with the minimum necessary access, under internal NDA. Access to production data is logged.
  • Processors (LGPD Art. 5, VII): Supabase (database and authentication), payment provider, PostHog (anonymized telemetry). Each operates under a processing agreement with a protection clause.
  • Authorities: only upon a court order or an explicit legal obligation.

Patensify does not sell personal data. Patensify does not share identifiable data with advertisers, other brands or aggregators.

6. How long we keep it

  • Account data: while your account is active, and up to 12 months after cancellation — then deleted.
  • Behavioral events: kept indefinitely in pseudonymized form (with no link to your email or name) to improve the product.
  • Insights and snapshots: 24 months after the account is disconnected.
  • Backups: 30-day cycle, encrypted.

7. Your rights (LGPD Art. 18)

You have the right to:

  1. Confirm that we process your data.
  2. Access the data we hold about you.
  3. Correct incomplete, inaccurate or outdated data.
  4. Anonymize, block or delete unnecessary data or data processed unlawfully.
  5. Port your data to another provider (structured format).
  6. Delete data processed on the basis of consent.
  7. Withdraw consent at any time.
  8. Object to processing carried out under legitimate interest.
  9. Request review of decisions made solely on the basis of automated processing that affect your interests (Art. 20).

Patensify uses automated processing (algorithms and models) to organize public data and generate insights and priorities about your audience. These outputs are decision support, not decisions that produce legal effects on third parties — and you may request a review of them through the channel below.

To exercise your rights, use the “Delete my account” action inside the app or write to privacy@patensify.com. We respond within 15 business days.

When you request deletion, we remove account data and dissociate your behavioral events — they remain in our database with no link that allows identifying you, as permitted by Art. 12 of the LGPD (anonymization as a functional equivalent of deletion).

8. Security

  • All traffic is encrypted in transit (TLS 1.2+).
  • Personal data at rest is encrypted by the database provider.
  • Passwords stored as a salted hash.
  • Administrative access requires 2FA.
  • Incident response plan per the ANPD — notification within a reasonable period if there is a risk to rights.

9. Cookies and similar technologies

The Patensify website uses only essential and functional cookies — for example, to remember your language and locale preference. We do not use advertising cookies or client-side third-party tracking.

Product telemetry (PostHog) is collected server-side, anonymized. You can block or delete cookies in your browser settings; without essential cookies, parts of the site may not work correctly.

10. Children and adolescents

Patensify is not intended for anyone under 18. If we identify an account created by a minor without their guardian’s authorization, we remove the account and the associated data.

11. International transfers

Processors (Supabase, payment provider, PostHog) may process data on servers outside Brazil. When that happens, we require contractual clauses providing protection equivalent to the LGPD (Art. 33).

12. Changes to this policy

Material changes are notified by email and in the app at least 15 days in advance. The version in force is always the pt-BR one published at /pt/privacidade on the official site. The change history is at the end of this document.

13. Contact

Questions, requests and complaints: privacy@patensify.com.

Authority: Brazil’s National Data Protection Authority (ANPD) — www.gov.br/anpd.

History

  • 2026-06-22 — first publication.