Privacy Policy
Transparency and security are our pillars. Understand how we protect your data while you focus on your app.
This page is a translation provided for convenience. In case of any divergence, the Portuguese version prevails.
Welcome to ecoa. We value your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and protect the information you provide to us when using our feedback exchange platform for indie developers.
By accessing or using ecoa, you agree to the practices described in this policy. If you do not agree with any term, please stop using the service immediately.
What information do we collect?
Information you voluntarily provide to us:
- Names and nicknames
- Email addresses
- Usernames and social profiles
- App URLs and technical details of your projects
This information is collected when you create an account, submit an app for testing, or interact with other developers on the platform.
Information collected automatically:
Whenever you interact with ecoa, we collect usage data such as IP address, browser type, operating system, and browsing patterns. Part of this data is collected through cookies and similar technologies — for details on categories, purposes, retention periods, sharing with third parties, and how to manage your preferences, see Section 6 — Cookies and Tracking Technologies. This data helps us improve platform performance and prevent abuse.
How do we process your information?
Account Management
Enable account creation, secure login, and maintenance of your developer profile.
Credit Exchange
Ensure the 'Feedback for Feedback' system works fairly and traceably.
Support and Contact
Answer your questions and send critical updates about the service.
Active Security
Monitor suspicious activity to keep the community free of spam and fraud.
3. Legal Bases for Processing
Under the LGPD (Brazil's General Data Protection Law), we process your data only on valid grounds:
- 01Consent: When you explicitly accept our terms upon signing up.
- 02Performance of a Contract: To deliver the promised testing and credit features.
- 03Legitimate Interest: To improve our services and protect the network.
4. Processing Agents (Art. 5º, VI and VII; Art. 9º, VI)
In compliance with the LGPD, we transparently identify the roles involved in the processing of your personal data:
ecoa
ecoa is the Controller of your personal data, i.e., the entity in charge of the decisions regarding the processing. As Controller, we are responsible for:
- Defining the purposes and means of processing your data (e.g., enabling feedback exchange, managing credits, moderating content).
- Ensuring the appropriate legal bases for each processing activity (Section 3).
- Handling your requests as a data subject (Section 11) and complying with determinations from the ANPD.
- Adopting technical and organizational measures to protect your data (Section 9).
- Notifying the ANPD and affected data subjects of security incidents, where applicable (Art. 48).
Partners listed in Section 5
The partners and service providers listed in Section 5 act as Processors, processing personal data on behalf of ecoa, strictly in accordance with our instructions and documented purposes. Each Processor is contractually required to:
- Process the data only for the purposes authorized by ecoa, with no secondary use.
- Adopt technical and administrative security measures appropriate to the nature of the data (Art. 46).
- Not subcontract other processors without prior authorization.
- Assist ecoa in fulfilling data subjects' rights and complying with legal obligations.
- Return or delete the data at the end of the contract, as applicable.
Note on social logins: Google and GitHub, when used for authentication (OAuth), act as independent Controllers of their own account data — ecoa receives only the information you authorize to be shared.
The role of the Data Protection Officer (DPO) is described in Section 12. For questions about any party's role in the processing of your data, contact us by email at [email protected].
8. Data Retention
We keep your information for as long as your account is active. If you decide to delete your account, your personal data will be removed or anonymized within 30 days, except for data we are legally required to keep.
9. Security First
We use end-to-end encryption in transit (SSL/TLS) and follow database security best practices to ensure your developer secrets are protected.
10. Children and Adolescents (Art. 14)
ecoa is intended for developers over the age of 18 and is not directed at children or adolescents. We do not knowingly collect data from minors. If we identify that a minor's data was provided without the specific, prominent consent of a parent or legal guardian, we will remove that information as quickly as possible.
11. Your Rights (Art. 18 of the LGPD)
As a data subject, the LGPD (Art. 18) grants you the following rights, which can be exercised free of charge at any time:
How to exercise them: send your request to [email protected]. We will respond as quickly as possible, as required by the LGPD. You can also delete your account and data directly in your profile settings.
If you believe your rights have not been honored, you may file a complaint with the Brazilian National Data Protection Authority (ANPD).
12. Data Protection Officer (DPO — Art. 41)
In compliance with Art. 41 of the LGPD, ecoa provides a channel to the Data Protection Officer (DPO), who is responsible for receiving communications from data subjects and the ANPD:
Data Protection Officer
Email: [email protected]
13. Contact Us
If you have questions about how we handle your data, don't hesitate to contact us:
Contact Email
7. Social Logins
We use Supabase Auth to manage authentication. When you log in via Google or GitHub, we receive only the basic data you authorize (name, email, and profile picture). We do not have access to your passwords for third-party services.