← Back

Privacy Policy

Last updated: June 8, 2026 · Compliant with the LGPD (Brazilian General Data Protection Law — Law 13.709/18) and the EU GDPR (Regulation (EU) 2016/679)

This is a courtesy translation. In case of any conflict, the Portuguese version prevails.

1. What we collect

Account data (in our central platform database, Postgres):

Agent usage data(in your container’s isolated volume):

Important: agent usage data never enters the central database. It resides exclusively in your container’s Fly volume, encrypted at rest.

2. How we use your data

We do not sell your data. We do not use it to train our own models. We do not share it with partners for marketing purposes.

3. Third parties that process data

4. Your rights (LGPD)

You may, at any time:

5. Users in the European Union (GDPR)

If you are located in the European Economic Area (EEA), the processing of your data is also governed by the General Data Protection Regulation — GDPR (Regulation (EU) 2016/679). In that context we act as the data controller for platform data, and you are entitled to the safeguards below.

5.1. Legal basis for processing (GDPR Art. 6)

5.2. Your rights under the GDPR

You may, at any time, exercise the rights to:

To exercise any of these rights, contact our Data Protection Officer (section 8). We respond within the timeframes set by the GDPR (generally within 30 days).

5.3. International data transfers

Your data may be processed outside the EEA — for example, by infrastructure and service providers such as Vercel, Fly.io, Neon, Clerk, and Stripe, whose servers may be located in the United States or other countries. In such cases, we rely on appropriate safeguards, such as the Standard Contractual Clauses (SCCs) approved by the European Commission, to ensure a level of protection equivalent to that of the EEA.

5.4. Lodging a complaint with a supervisory authority

Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority (Data Protection Authority) in your EEA country if you believe the processing of your data infringes the GDPR.

6. Security

In the event of a security incident involving your data, you will be notified within 72 hours, as required by the LGPD.

7. Retention

We retain personal data only for as long as necessary for the purposes described in this policy or as required by law:

8. Data Protection Officer (DPO)

Our Data Protection Officer (DPO), the point of contact for both the LGPD and the GDPR, is Paulo Augusto Minari — contact@myndo.io

See also Terms of Use.