Privacy Policy
Last updated: January 17, 2026 Version: 1.0
1. Introduction
APUAMA TECNOLOGIA LTDA ("HAID", "we", "us", or "our") operates the HAID mobile application and related services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
Company Information:
- Company: APUAMA TECNOLOGIA LTDA
- CNPJ: 55.038.380/0001-45
- Location: São Paulo, SP - Brasil
- Contact: [email protected]
By using HAID, you agree to the collection and use of information in accordance with this policy.
2. Data We Collect
Account Data
- Name and email address
- Username and profile photo
- Password (stored securely using hashing)
Profile Data
- Age, gender, height, and weight
- Fitness goals and preferences
Activity Data
- Workouts and exercises
- GPS routes and location data
- Duration, distance, pace, and calories
- Photos and notes attached to activities
Health Data
- Heart rate and heart rate variability (HRV)
- Sleep patterns and quality
- Daily steps and movement
- Other metrics from connected wearables
Social Data
- Comments on activities
- Challenge participation
- Followers and following relationships
Device Data
- Device model and operating system
- App version
- IP address
- Device identifiers
Usage Data
- Features used and screens viewed
- Session duration and frequency
- Interaction patterns
Payment Data
- Transaction identifiers
- Subscription status
- We do not store credit card numbers
3. How We Collect Data
You provide directly:
- Registration and account setup
- Profile information
- Manual activity logging
- Comments and social interactions
From wearable integrations:
- Apple HealthKit
- Google Fit / Health Connect
- Garmin Connect
- Fitbit
- Polar
- Amazfit
- Other integrations as added
Each integration requires your explicit authorization. You can connect or disconnect integrations at any time in the app settings.
Automatically collected:
- Device information when you use the app
- Usage analytics and crash reports
- Location data when you record activities (with permission)
4. How We Use Your Data
We use your information to:
- Provide our services: Display your activities, sync health data, enable social features
- Improve HAID: Analyze usage patterns, fix bugs, develop new features
- Personalize your experience: Tailor content and recommendations to your goals
- Enable social features: Challenges, comments, profiles, and sharing
- Future AI features: Provide personalized insights and recommendations (coming soon)
- Display advertisements: Show relevant ads to free tier users through Google AdMob
- Communicate with you: Service updates, security alerts, and support
- Comply with legal obligations: Respond to legal requests and protect our rights
5. Data Sharing
We share your information with:
| Recipient | Purpose | Data Shared |
|---|---|---|
| Google AdMob | Advertising (free tier) | Device identifiers, usage patterns, ad interactions |
| Analytics providers | App improvement | Anonymized usage data |
| Wearable platforms | Two-way sync (your choice) | Activity and health data |
| Cloud infrastructure | Data storage | All data (encrypted) |
| Legal authorities | When required by law | As legally required |
We never sell your personal health data. Advertising partners receive limited device and usage information, not your health metrics.
6. Your Rights
All HAID users have the following rights:
- Access: Download a copy of your data at any time
- Correction: Update inaccurate or incomplete information
- Deletion: Delete your account and associated data
- Export: Receive your data in a portable format (JSON/CSV)
- Opt-out: Disable targeted advertising, disconnect integrations
- Withdraw consent: Revoke permissions at any time
To exercise these rights, contact us at [email protected] or use the in-app settings.
7. Regional Rights
Brazil (LGPD)
If you are in Brazil, you have additional rights under the Lei Geral de Proteção de Dados:
- Confirmation of data processing
- Access to your data
- Correction of incomplete or inaccurate data
- Anonymization, blocking, or deletion of unnecessary data
- Data portability
- Information about sharing with third parties
- Information about the possibility of denying consent
- Revocation of consent
Data Protection Officer: [email protected]
You may file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).
European Union & United Kingdom (GDPR)
If you are in the EU or UK, we process your data under the following legal bases:
- Contract performance: To provide the services you requested
- Consent: For optional features like marketing communications
- Legitimate interests: For analytics, security, and service improvement
You have the right to:
- Access, rectify, and erase your data
- Restrict or object to processing
- Data portability
- Lodge a complaint with your supervisory authority
We will notify you within 72 hours of any data breach that affects your rights.
California (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect and how we use it
- Delete your personal information
- Opt-out of the "sale" or "sharing" of your information
- Non-discrimination for exercising your rights
Under CCPA, sharing data with advertising partners may constitute a "sale." You can opt-out using our "Do Not Sell or Share My Personal Information" option in the app settings.
8. Data Storage & Security
Storage location: Your data is stored on Hetzner servers in Germany (European Union).
International transfers: If you are outside the EU, your data is transferred to Germany under adequate data protection standards. For Brazilian users, Germany provides adequate protection under LGPD provisions.
Security measures:
- Encryption in transit (TLS)
- Encryption at rest (AES-256)
- Role-based access controls
- Regular security audits
Data retention:
- Active accounts: Data is kept while your account exists
- Deleted accounts: Data is removed within 30 days (some technical data may be retained up to 90 days)
- Legal requirements may extend retention periods
- Anonymized analytics data may be kept indefinitely
9. Children's Privacy
HAID is intended for users 13 years of age or older.
- Users aged 13-15 in the European Union require parental consent
- We do not knowingly collect data from children under 13
- If we discover we have collected data from a child under 13, we will delete it promptly
Parents or guardians can contact us at [email protected] to request deletion of a child's data.
10. Cookies & Tracking
Mobile app: We do not use traditional cookies. We use device identifiers for analytics and advertising purposes.
Website: We use:
- Essential cookies for site functionality
- Analytics cookies to understand usage (optional)
- Advertising cookies for relevant ads (optional)
You can manage cookie preferences in your browser settings.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes:
- We will notify you via in-app notification
- We will send an email to registered users
- We will update the "Last updated" date at the top
Your continued use of HAID after changes constitutes acceptance of the updated policy.
Previous versions are available upon request.
12. Contact Us
If you have questions about this Privacy Policy or your data:
APUAMA TECNOLOGIA LTDA
- Email: [email protected]
- Data Protection Officer: [email protected]
- Location: São Paulo, SP - Brasil
We aim to respond to all requests within 30 days.