Privacy policy
In effect since
miolo is a time-tracking app developed by Fuzalabs LTDA (“Fuzalabs”, “we”). This policy explains which personal data we process when you use miolo, why we process it, who we share it with and what your rights are, under Brazil’s General Data Protection Law (Law No. 13,709/2018, “LGPD”).
1. Who is responsible for your data
Controller: Fuzalabs LTDA, Brazilian company registration (CNPJ) 50.833.910/0001-23, with its registered office at Rua Manoel Severo Simões, 31, apto. 504, Centro, Guarapari, ES, 29200-265, Brazil.
Fuzalabs is a micro-enterprise and, under Resolution CD/ANPD No. 2/2022, is not required to appoint a data protection officer. The channel for anything about this policy, your personal data and your rights is privacidade@fuzalabs.com.br.
2. What this policy covers
This policy applies to the miolo app, available for iPhone and Android, to the cloud services behind it, and to the miolo.day website.
The website uses no cookies and requires no sign-up. The only measurement it makes is a cookieless visitor count provided by Cloudflare, which does not identify you or follow your browsing on other sites.
This policy does not cover the Apple and Google services the app uses to sign you in. They have policies of their own.
3. What data we process
3.1 Your account
miolo can be used in three ways, and each involves different data.
- Without an account. You can use miolo without signing up. In that case we create only a technical identifier, generated automatically, that ties your records to this installation of the app. We collect no name, email or anything else that identifies you.
- Google account. When you sign in with Google, we receive your name, your email address and your Google account identifier.
- Apple account. When you sign in with Apple, we receive your Apple account identifier, your email (which may be a relay address if you choose “Hide My Email”) and, only on your first sign-in and only if you allow it, your name.
When you turn an account-less installation into a Google or Apple account, your existing records are kept and become part of the new account.
3.2 What you record in the app
Everything you create in miolo is stored in your account:
- categories and subcategories, with the names you choose;
- activities, with an optional title, a category, a day, and start and end times;
- goals, with the category, measure, amount and recurrence you set;
- time totals per period, computed from your activities.
This data is yours. We do not read it, analyze it individually or use it for any purpose other than showing the app to you.
3.3 Preferences
We store in your account your timezone, the language you chose, the date the account was created and the date of your last sign-in. The appearance (light, dark or automatic) and the reminders switch stay on the device only and are never sent to our servers.
3.4 Reminders
If you turn reminders on, miolo schedules two notifications a day on the device itself, at 12:00 and 20:00, inviting you to record. They are created and delivered by the device without passing through our servers: no notification token is sent to us, and nothing about your records goes into them. Reminders start off, and the app asks the system for permission to notify only when you turn them on. In usage analytics we record only whether reminders are on, that you flipped the switch, and that you tapped a reminder.
3.5 Technical and usage data
To keep miolo running and understand how it is used, we collect automatically:
- Usage events (Firebase Analytics): actions you take in the app, such as recording an activity or creating a category, always without the content itself. We send, for example, that a category was created, never its name. Alongside go the device model, the operating system, the app version, the language, the approximate country, the sign-in type (no account, Google or Apple) and installation and device identifiers, including, on Android, the advertising identifier, which we use only to measure usage and never for ads.
- Crash reports (Firebase Crashlytics): when the app hits an error, we receive the technical details of the failure, the device model, the operating system, the app version and an installation identifier.
- Integrity attestation (Firebase App Check): before accepting a request, we verify that it comes from a genuine copy of miolo, through Apple’s App Attest and DeviceCheck or Google’s Play Integrity. This produces technical tokens that do not identify you.
3.6 What we do not collect
miolo does not collect precise location, contacts, photos, files, payment data or sensitive personal data. We show no ads, send no marketing messages and do not track you across other apps or websites.
4. Why we use the data, and on what legal basis
- Creating and maintaining your account, syncing and displaying your records. Data involved: account data, records and preferences. Legal basis: performance of a contract (LGPD, art. 7, V).
- Protecting the service against abuse and fraud. Data involved: integrity attestation and technical identifiers. Legal basis: legitimate interest (art. 7, IX).
- Fixing failures and improving the app. Data involved: usage events and crash reports. Legal basis: legitimate interest (art. 7, IX).
- Answering your requests and meeting legal obligations. Data involved: account data and the emails you send us. Legal basis: performance of a contract and legal obligation (art. 7, II and V).
Where we rely on legitimate interest, we do so to the minimum extent necessary, without collecting personal content, and you may object as described in section 8.
5. Who we share it with
We do not sell personal data and do not hand it over for advertising. We share data only with:
- Google LLC, which runs the app’s infrastructure through Firebase (authentication, database, cloud functions, usage analytics, crash reports and integrity attestation) and provides Sign in with Google;
- Apple Inc., for Sign in with Apple and for integrity attestation on iPhone;
- Cloudflare, Inc., which hosts the miolo.day website and provides its cookieless visitor count;
- public authorities, when required by law, court order or a request from a competent authority.
These providers act as processors, handle the data under our instructions and are bound by contractual data protection obligations.
6. International transfers
The servers that store the app’s data are in the United States, on Google infrastructure. The website is served by Cloudflare’s global network. These transfers rest on standard contractual clauses and on the data protection commitments made by those providers, under article 33 of the LGPD.
7. How long we keep it
- Google or Apple account: for as long as the account exists. When you request deletion, it takes effect 30 days after the request, during which signing in again is enough to cancel it. After the 30 days, the account, your records and everything we know about you are erased within a day, permanently.
- Use without an account: when you tap “Sign out”, the account and its records are erased within a day. If you uninstall the app without signing out, or simply stop opening it, the account and its records are erased automatically once six months pass without use.
- Usage events: retained by Firebase Analytics for up to 14 months at the individual level; aggregated totals may be kept longer.
- Crash reports: retained for 90 days.
- Emails you send us: kept for as long as needed to handle the request and to show that it was made, and for any period the law requires.
8. Your rights
The LGPD gives you the right to obtain, at any time:
- confirmation that we process your data, and access to it;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of data that is unnecessary or processed unlawfully;
- portability of your data;
- information about who we share your data with;
- withdrawal of consent, where processing rests on it;
- objection to processing based on legitimate interest.
Much of this you can do directly in the app: edit and delete categories, activities and goals, change the language and delete the account. For the rest, write to privacidade@fuzalabs.com.br. We reply within 15 days. You may also file a complaint with Brazil’s National Data Protection Authority (ANPD).
9. How to delete your account
From the app. Open miolo, tap the settings icon, then Delete account and Continue, and sign in again with Google or Apple to confirm. Deletion happens 30 days after confirmation, and you are signed out on every device. Signing in again within that period keeps the account. If you signed in with Apple, confirming also removes miolo from the list of apps in your Apple Account.
Without the app. Write to privacidade@fuzalabs.com.br from the email address you sign in to miolo with, asking for deletion. We can only act on requests sent from the account’s own address, because that is what lets us confirm the request is yours. A request sent from another address is not acted on, and nothing from the message is stored in your account. We reply with the date your account will be deleted. If you signed in with Apple and hid your email, include in the message the relay address Apple created for miolo; the account deletion page explains how to find it. Through this path miolo is not removed from the list of apps in your Apple Account, and the same page explains how to do that.
Without an account. If you use miolo without an account, tapping Sign out in settings erases everything.
10. Security
All data travels encrypted between the app and our servers. The database access rules ensure each person can reach only their own data. Every request is verified as coming from a genuine copy of the app before it is accepted. Administrative access to our systems is restricted to the Fuzalabs team and logged.
No system is fully secure. If we identify an incident that may pose a relevant risk to you, we will notify you and the ANPD as the law requires.
11. Children and teenagers
miolo is not directed at children, and we do not knowingly collect data from anyone under 12. If you are responsible for a child and believe they have given us data, write to privacidade@fuzalabs.com.br and we will erase it.
12. Changes to this policy
We may update this policy to reflect changes in the app or in the law. The date at the top of this page identifies the version in force, and what changed from one version to the next is described there. When a change is significant, we will let you know inside the app before it takes effect.
13. Contact
Fuzalabs LTDA
CNPJ 50.833.910/0001-23
Rua Manoel Severo Simões, 31, apto. 504, Centro, Guarapari, ES, 29200-265, Brazil
privacidade@fuzalabs.com.br