Legal
Privacy Policy
Last updated: September 4, 2026
How SinalFlag handles the data you share with us, in plain language, with no hidden fine print.
This page describes how SinalFlag (the app and the site sinalflag.com) handles personal data. The product helps you look at the health of a relationship through a private snapshot. It is not therapy, a clinical diagnosis, or an emergency service.
URL for this policy (use in the App Store and Play Store listings): https://www.sinalflag.com/privacidade
1. Who is responsible
Processing is carried out by the operator of SinalFlag, at sinalflag.com. Questions: privacidade@sinalflag.com. If that inbox is not yet active, use the support email listed on the store listing or visit the support page.
2. What data the app collects
- Account: display name, email, how you signed in (email and password, Google, or Apple) and, if you choose, gender and year of birth (optional; you may prefer not to say).
- Relationship profile: intake answers (situation, stage, focus, etc.).
- Assessment: questionnaire answers, health score (calculated on the server, deterministically), dimensions, safety flags, and snapshot history.
- Content you write: journal, conversations with the specialist, situation analysis, and clarity summary.
- Subscription: plan (none, monthly, or yearly) and store billing events when purchases are active.
- Technical: session tokens (JWT) on the device and server; password reset code when you request one.
- Website quiz: if you take the snapshot at sinalflag.com/quiz, we store the email, answers, and result band to send the snapshot and at most two follow-up emails. You can leave the list via the link in each message.
We do not require the other person’s name as mandatory registration data. We do not collect clinical health data, continuous location, or address-book contacts.
3. Why we collect and how we use data
- create and authenticate the account;
- show the snapshot, trend, and flags based on what you shared;
- generate specialist replies (and situation and clarity flows) using only the context needed. The specialist does not calculate the health score;
- send a welcome email, password-reset code, or the quiz snapshot if you requested it;
- operate the subscription when the store is charging;
- remind you on the device to update the snapshot (14 and 21 days), if you allow notifications.
We do not sell your texts. We do not use journal, chat, or assessment content for targeted advertising.
4. Who we share with
We share only what is needed for the app to work, with contracted providers:
- Hosting and database: API server and Postgres (today, a cloud provider in Brazil) to store the account and content.
- Social authentication: Google or Apple if you sign in with them (they see the login; we receive the token and the email/name the provider sends).
- Email: sending provider (today Resend) for codes and account notices.
- Specialist chat: the chat provider (today Anthropic) receives the snapshot needed for the reply: messages from the specialist conversation and the situation description (and, in some flows, journal titles). The body of the journal (what happened / how you felt) is not sent to that provider. The specialist does not set the score.
- Store / billing: Apple, Google, and, when enabled, RevenueCat, to validate the subscription. We do not send journal text to those services.
Public authorities only if the law requires it. We do not sell email lists or relationship content.
5. How to request deletion (LGPD)
In the app, under More, you can delete the account. That removes assessment, journal, conversations, and data linked to that account on the server.
We may keep anonymous exit feedback (reason for leaving), without email and without the text of the records.
You can also request deletion by emailing privacidade@sinalflag.com or via the support page. Access, correction, or deletion responses follow Brazil’s LGPD.
6. Cookies and analytics
App: we do not use advertising cookies. Snapshot reminders are local on the device. We do not yet send push tokens to Apple or Google. Score, flags, and journal text do not appear on the lock screen.
Website: if you accept the statistics notice, we use Google Analytics 4 to count visits, pages viewed, country, device type, and traffic source (for example, search or social). That creates _ga and _ga_* cookies. Google processes this data in the United States. We do not send journal, chat, or assessment text. If you refuse, the script does not load. We also use Google Search Console (no cookie on your device) to see clicks from Google Search. Technical cookies from the hosting provider may exist so the site can load.
7. Where data is stored and for how long
The staging/production API and database run on infrastructure we operate (server and Postgres). Specialist chat and email providers may process the snapshot outside Brazil. We keep data while the account exists. After deletion, account content is erased, except what the law requires us to keep for a short period (for example, a deletion record).
8. Security and access
Your content (journal, chat, situation) stays private in your account: tied to you as the data subject and used so the app can work (sync, score, and specialist conversation in the contracted flows). This is not end-to-end encryption (E2EE): the server needs to read the text to provide the service.
- In transit: communication between the app and the API uses HTTPS (TLS).
- At rest: the database volume is encrypted at the provider (when infrastructure matches the internal checklist) and intimate texts (journal, chat, situation) use field-level encryption on the server. This is not end-to-end: the company holds the key to provide the service and meet legal obligations.
- Team: we do not read journal, chat, or situation content in day-to-day support.
- Legal obligation: if a valid court order or legal duty requires it, we may access and deliver what is necessary (exceptional access, with internal logging), then restore usual controls.
The health score is calculated on the server deterministically. The specialist does not score.
9. Minors
SinalFlag is built for adults. It is not directed at anyone under 18. If we learn of a minor’s account, we will delete it.
10. Changes
If this policy changes in a material way, we update the date at the top of this page. The current version is always the one published at sinalflag.com/privacidade.
This text describes the product as it works today. It does not replace legal advice. When the store, billing, or app analytics change, this page should be updated.