Skip to content

Privacy Policy

Transparency and security are our pillars. Understand how we protect your data while you focus on your app.

Last updated: 9/23/2026

This page is a translation provided for convenience. In case of any divergence, the Portuguese version prevails.

Welcome to ecoa. We value your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and protect the information you provide to us when using our feedback exchange platform for indie developers.

By accessing or using ecoa, you agree to the practices described in this policy. If you do not agree with any term, please stop using the service immediately.

1

What information do we collect?

Information you voluntarily provide to us:

  • Names and nicknames
  • Email addresses
  • Usernames and social profiles
  • App URLs and technical details of your projects

This information is collected when you create an account, submit an app for testing, or interact with other developers on the platform.

Information collected automatically:

Whenever you interact with ecoa, we collect usage data such as IP address, browser type, operating system, and browsing patterns. Part of this data is collected through cookies and similar technologies — for details on categories, purposes, retention periods, sharing with third parties, and how to manage your preferences, see Section 6 — Cookies and Tracking Technologies. This data helps us improve platform performance and prevent abuse.

2

How do we process your information?

Account Management

Enable account creation, secure login, and maintenance of your developer profile.

Credit Exchange

Ensure the 'Feedback for Feedback' system works fairly and traceably.

Support and Contact

Answer your questions and send critical updates about the service.

Active Security

Monitor suspicious activity to keep the community free of spam and fraud.

4. Processing Agents (Art. 5º, VI and VII; Art. 9º, VI)

In compliance with the LGPD, we transparently identify the roles involved in the processing of your personal data:

Controller

ecoa

ecoa is the Controller of your personal data, i.e., the entity in charge of the decisions regarding the processing. As Controller, we are responsible for:

  • Defining the purposes and means of processing your data (e.g., enabling feedback exchange, managing credits, moderating content).
  • Ensuring the appropriate legal bases for each processing activity (Section 3).
  • Handling your requests as a data subject (Section 11) and complying with determinations from the ANPD.
  • Adopting technical and organizational measures to protect your data (Section 9).
  • Notifying the ANPD and affected data subjects of security incidents, where applicable (Art. 48).
Processors

Partners listed in Section 5

The partners and service providers listed in Section 5 act as Processors, processing personal data on behalf of ecoa, strictly in accordance with our instructions and documented purposes. Each Processor is contractually required to:

  • Process the data only for the purposes authorized by ecoa, with no secondary use.
  • Adopt technical and administrative security measures appropriate to the nature of the data (Art. 46).
  • Not subcontract other processors without prior authorization.
  • Assist ecoa in fulfilling data subjects' rights and complying with legal obligations.
  • Return or delete the data at the end of the contract, as applicable.

Note on social logins: Google and GitHub, when used for authentication (OAuth), act as independent Controllers of their own account data — ecoa receives only the information you authorize to be shared.

The role of the Data Protection Officer (DPO) is described in Section 12. For questions about any party's role in the processing of your data, contact us by email at [email protected].

5. Data Sharing (Art. 9º, V)

We never sell your data to third parties. Sharing occurs only with the Processors and partners listed below (as defined in Section 4), strictly to enable the operation of the service, each with its respective purpose:

Partner / ServicePurpose
Google Cloud PlatformHosting of the application and microservices.
Supabase (Auth, Database, and Storage)Authentication; storage of accounts, content, and files.
CloudflareCDN, network security, and performance metrics (static.cloudflareinsights.com).
flagcdn.comDelivery of country flag images in the interface.
StripeSubscription payment processing (we do not store card data).
BrevoSending transactional emails and notifications.
Google (Gemini API)Automated AI content moderation.
PostHogProduct analytics and usage metrics (enabled only upon cookie consent).
Google and GitHubSocial login (OAuth), when you choose to use it.
Appetize.ioIn-browser app emulation, when enabled.

International data transfers (Art. 33)

Some of these partners process data on servers located outside Brazil. In such cases, we ensure the transfer takes place with adequate safeguards, as required by the LGPD.

We may also share data to comply with legal or regulatory obligations, respond to court orders, or protect our rights.

6. Cookies and Tracking Technologies

Cookies are small text files stored on your device when you visit a website. ecoa also uses equivalent technologies — local storage, session storage, and tracking pixels — all covered here under the generic designation "cookies". In compliance with Art. 9º of the LGPD, we transparently describe below the categories used, their specific purposes, retention periods, sharing with third parties, and how you can manage them.

6.1. Categories of cookies we use

CategoryPurposeRetentionConsent
Strictly NecessaryMaintain your login session (Supabase Auth), CSRF protection, load balancing, and bot protection (Cloudflare). Without them, the platform does not work.Session up to 12 monthsNot required (Art. 7º, IX of the LGPD)
Functional / PreferencesRemember your interface choices, such as theme (light/dark), language, sidebar state, and the record of your cookie consent (ecoa_cookie_consent).Up to 12 monthsLegitimate interest
Performance and AnalyticsAggregated usage and performance metrics to improve the product (PostHog for product analytics and Cloudflare Web Analytics for traffic). We do not use this data for advertising profiles.PostHog: up to 12 months · Cloudflare: up to 24 hOpt-in required
Marketing / AdvertisingWe do not use third-party marketing, retargeting, or behavioral advertising cookies.

6.2. Third-party cookies and technologies

Some cookies are set by third-party services we use to operate the platform. These partners act as Processors (Section 4) — or independent Controllers in the case of social logins — and each has its own privacy policy:

  • Supabase Auth: essential authentication and session cookies. Policy: supabase.com/privacy.
  • Cloudflare: security cookies (bot and DDoS protection) and performance metrics. Policy: cloudflare.com/privacypolicy.
  • PostHog: product analytics, enabled only after explicit consent; before that, it runs in "memory" mode without writing cookies. Policy: posthog.com/privacy.
  • Stripe: anti-fraud cookies during subscription checkout. Policy: stripe.com/privacy.
  • Google and GitHub (OAuth): cookies set during social login, under the providers' own policies.

6.3. How to manage your preferences

You can control the use of non-essential cookies at any time, in the following ways:

  • Consent banner: on your first visit, we display a notice allowing you to accept or decline analytics cookies. By default, before you make your choice, we keep analytics in cookieless mode.
  • Withdrawing consent: to change a previous decision, clear the ecoa_cookie_consent record in your browser's local storage, or send a request to [email protected] — the banner will be shown again on your next visit.
  • Browser settings: most browsers let you block, restrict, or delete cookies. Official instructions: Chrome, Firefox, Safari, Edge.

Note: blocking strictly necessary cookies may prevent login and basic platform features from working. Declining analytics cookies does not affect access to the service.

Data collected without cookies: regardless of cookies, we record technical data in server logs, such as IP address, browser type, and request time (Section 1), based on our legitimate interest in maintaining security and preventing abuse. These logs are retained for up to 90 days and are not used to build commercial profiles.

7. Social Logins

We use Supabase Auth to manage authentication. When you log in via Google or GitHub, we receive only the basic data you authorize (name, email, and profile picture). We do not have access to your passwords for third-party services.

8. Data Retention

We keep your information for as long as your account is active. If you decide to delete your account, your personal data will be removed or anonymized within 30 days, except for data we are legally required to keep.

9. Security First

We use end-to-end encryption in transit (SSL/TLS) and follow database security best practices to ensure your developer secrets are protected.

10. Children and Adolescents (Art. 14)

ecoa is intended for developers over the age of 18 and is not directed at children or adolescents. We do not knowingly collect data from minors. If we identify that a minor's data was provided without the specific, prominent consent of a parent or legal guardian, we will remove that information as quickly as possible.

11. Your Rights (Art. 18 of the LGPD)

As a data subject, the LGPD (Art. 18) grants you the following rights, which can be exercised free of charge at any time:

Confirmation and access
Data correction
Anonymization or deletion
Portability
Information about sharing
Withdrawal of consent

How to exercise them: send your request to [email protected]. We will respond as quickly as possible, as required by the LGPD. You can also delete your account and data directly in your profile settings.

If you believe your rights have not been honored, you may file a complaint with the Brazilian National Data Protection Authority (ANPD).

12. Data Protection Officer (DPO — Art. 41)

In compliance with Art. 41 of the LGPD, ecoa provides a channel to the Data Protection Officer (DPO), who is responsible for receiving communications from data subjects and the ANPD:

Data Protection Officer
Email: [email protected]

13. Contact Us

If you have questions about how we handle your data, don't hesitate to contact us: