APRUVLY DESENVOLVIMENTO E LICENCIAMENTO DE PROGRAMAS DE COMPUTADOR NAO CUSTOMIZAVEIS LTDA
CNPJ: 66.299.145/0001-43
Contato jurídico: [email protected]
Última atualização: July 10, 2026
This Privacy Policy describes how APRUVLY DESENVOLVIMENTO E LICENCIAMENTO DE PROGRAMAS DE COMPUTADOR NAO CUSTOMIZAVEIS LTDA ("Apruvly", "we" or "Platform") collects, uses, stores, shares and protects the personal information of users ("User", "you"), regardless of their geographic location, who access or use our services available at apruvly.io or through Apruvly's official mobile applications for iOS and Android ("mobile app" or "application"). By creating an Account or using the Platform, you agree to the terms of this policy.
This policy has been prepared in compliance with the General Data Protection Law (LGPD — Law No. 13,709/2018) and other applicable legislation, including for international users.
This Policy describes two distinct processing scenarios that coexist on the Platform:
Apruvly as Controller — regarding the data of the registered User (Platform customer): registration, billing, access logs, support and communications about the service. Processing decisions regarding such data are made by Apruvly, based on the legal grounds described in Section 3.
Apruvly as Processor (Art. 5, VII of the LGPD) — regarding the data of recipients and approvers (third parties who receive workflow notifications triggered by the User). In this scenario, the User is the Controller of such third parties' data and Apruvly acts as Processor, processing email addresses, telephone numbers, channel identifiers (Slack, Microsoft Teams, Telegram, Discord, DingTalk, WhatsApp), message content and delivery metadata exclusively upon instruction and on behalf of the User, within the contractual limits established in the Terms of Service. Decisions on who is notified, which data are included in each notification and for how long such workflows persist rest with the User-Controller, to the extent of the contracted plan.
Requests from approver data subjects (right of access, rectification, deletion, etc.) may be addressed to the User (controller) or directly to Apruvly via the Privacy channel described in Sections 10 and 13. When received by Apruvly, they are handled in accordance with Art. 39 of the LGPD: Apruvly fulfills the request within the limits of its role as Processor and, when necessary, forwards the request to the User-Controller for decision on any additional actions.
_gcl_au, _ga and _gid) are activated for conversion measurement and remarketing (Ads) and for aggregate audience and site usage analysis (Analytics). This processing does not occur in authenticated use of the Platform. Details in Section 9.When the User chooses to authenticate via an external provider (Google, Microsoft, GitHub or Apple), we receive the email address authorized by the User and the account identifier with that provider. We do not receive or store the external provider's password, nor do we collect name or profile photo through SSO. In the case of Apple, the User may choose to hide the real email using Apple's private relay service; in that case we receive only the forwarding address provided by Apple.
To suggest recipients while the User types, the mobile application may read, upon express authorization granted in the operating system (iOS or Android), the names and email addresses from the device's contact list. This processing occurs exclusively on the device itself: the contact list is never sent, copied or stored on Apruvly's servers, and no contact data is transmitted over the network. Only the email addresses that the User actually adds as recipients of a workflow are transmitted and processed, as described in Section 2.2 (workflow message delivery data). Authorization may be revoked at any time in the operating system settings; in that case the application simply ceases to display suggestions, without prejudice to other functions.
The application accesses the camera and photo gallery only upon authorization granted by the User in the operating system (iOS or Android) and only at the moment the User decides to attach an image to an approval request. Files received by sharing from other applications are processed only when the User attaches them to a request. In all cases, the attached file follows the attachment regime described in Section 2.2; there is no access to the camera, gallery or device files in the background. Authorizations may be revoked at any time in the operating system settings.
To record approval decisions (and, optionally, to unlock the application), the application requires biometric or screen credential verification performed by the operating system itself, on the device (Face ID or Touch ID on iOS; biometrics or screen lock on Android). Apruvly does not collect, receive or store biometric data under any circumstances: the operating system informs the application only of the verification result (success or failure), used to allow or disallow the action. Biometric enrollment and deletion are managed exclusively by the User in the device's own settings.
The processing of personal data is carried out on the following legal bases provided in the LGPD:
| Purpose | Legal basis (Art. 7 LGPD) |
|---|---|
| Provision of contracted service | Contract performance (V) |
| Payment processing | Contract performance (V) |
| Sending workflow notifications | Contract performance (V) |
| Sending SMS notifications via Twilio and receiving responses | Contract performance (V) |
| Mobile app device registration and push notification delivery | Contract performance (V) |
| Processing and reconciliation of in-app store purchases | Contract performance (V) |
| Evidence trail of approval decisions (date/time, channel, IP, approximate location) | Contract performance (V) + legitimate interest (IX) |
| Account security and fraud prevention | Legitimate interest (IX) |
| Automated security verification of attachments (antivirus/hash) | Legitimate interest (IX) + contract performance (V) |
| Attachment download trail and evidence retention post-deletion | Legitimate interest (IX) — fraud/abuse prevention and regular exercise of rights |
| Retention of application service logs | Legal obligation compliance (II) — Brazilian Internet Civil Rights Framework, art. 15 |
| Preservation and reporting of child sexual abuse material | Legal obligation compliance (II) — 18 U.S.C. §2258A and ECA |
| Access and diagnostic logs | Legal obligation compliance (II) — Brazilian Internet Civil Rights Framework |
| Service communications | Legitimate interest (IX) |
| Platform improvement | Legitimate interest (IX) |
| Aggregated visit analytics (public pages) | Legitimate interest (IX) |
| Mobile app usage metrics (outside EEA/United Kingdom) | Legitimate interest (IX), with opt-out at any time |
| Mobile app usage metrics (EEA/United Kingdom) | Consent (I), via opt-in |
| Mobile app failure reports (Crashlytics) | Legitimate interest (IX), with opt-out at any time |
| Advertising, remarketing and conversion measurement (Google Ads) and audience analysis (Google Analytics), on public pages | Consent (I) |
| Processing of support tickets by AI (only with opt-in) | Consent (I) |
| Sending newsletters by email | Express consent (I) - Only with explicit opt-in from the User. We do not send spam. |
We use your personal data to:
We do not create behavioral profiles from your Account data nor target advertising based on your authenticated use of the Platform. Visit statistics collected on the server are always aggregated and anonymized. On public pages, conversion measurement and remarketing via Google Ads occur only upon your consent (Section 9) and may be declined at any time, without prejudice to use of the Platform.
We do not sell, rent or commercialize your personal data. We may share it only with:
All third parties that access personal data on our behalf are contractually obligated to treat it with confidentiality and in accordance with this policy.
The current list of processors and sub-processors involved in processing is publicly available at apruvly.io/sub-processors; the [email protected] channel remains available for further clarification. If Apruvly engages new processors that process personal data in a materially different manner from that described above, this Privacy Policy will be updated in accordance with §12.
Public verification page (shared by you). Upon completing a request, the User may generate a proof link ("approval certificate") that opens a public, read-only page with the request result, its title and description, timestamps and the list of approver decisions. To protect approvers, email addresses appear masked on this page (only the initial and domain, e.g. j****@empresa.com), never the full address. The link is the sole access credential: anyone possessing it can view the page, and it is solely the User's decision whether and with whom to share it. The page is not indexed by search engines. As approver data are third-party data processed under the User's responsibility (Section 1.2), the decision to generate and distribute the certificate rests with the User, in the capacity of Controller of such data.
6.1. Apruvly's servers and those of its infrastructure providers may be located outside Brazil. In particular, AWS and Cloudflare operate globally distributed infrastructure that may process data in regions outside Brazilian territory. When enabled by consent, Google (Google Ads) also processes data in the United States and other regions. Mobile app service providers (Google Firebase, Apple) and app stores (Apple App Store, Google Play) also process data in the United States and other regions.
6.2. By using the Platform, the User acknowledges that their data may be processed in the countries where we operate. Apruvly adopts appropriate technical and contractual safeguards — including standard data protection clauses — to ensure a level of protection equivalent to that required by the LGPD, regardless of processing location.
6.3. Apruvly carries out international transfers only when necessary for service provision and in compliance with Art. 33 of the LGPD, primarily based on items I (specific contractual clauses with the processor) and V (performance of contract with the data subject). For processors located in jurisdictions without an adequacy decision from ANPD, Apruvly uses Standard Contractual Clauses (SCC) or specific contractual clauses with equivalent safeguards, aligned with the model approved by ANPD in CD/ANPD Resolution No. 19/2024. A copy of the applicable clauses may be requested via [email protected].
6.4. When the User configures integrations with external providers (notification, messaging, SMS, transactional email, AI, etc.), any international transfers arising from such integrations occur under the User's own account and contractual relationship with the respective provider, governed by the terms the User has agreed with that third party. Apruvly merely executes, as technical intermediary, the calls authorized by the credential provided by the User.
| Data type | Retention period |
|---|---|
| Account data (profile, email) | While the account is active; permanently deleted within 6 months after closure (see 7.1) |
| Workflow data | According to the contracted plan (7 to 90 days, see Pricing page) |
| Corporate push messages (title, body, recipients) | 30 days after message completion (done/canceled). Sender mute preferences and usage cycle counters remain while the Account is active; reports follow administrative message retention |
| SMS delivery data via Twilio (telephone, status, cost) | Same period as workflow data: 7 to 90 days according to the contracted plan |
| Bytes of files attached to approvals | TTL of the contracted plan or early deletion by the User |
| Metadata, SHA-256 hash and download trail of attachments | 24 months after byte deletion (legitimate interest — fraud/abuse prevention and regular exercise of rights; covers the 6-month floor of the Brazilian Internet Civil Rights Framework, art. 15) |
| Application service access logs | ≥ 6 months (Art. 15, Brazilian Internet Civil Rights Framework) |
| Reported material (CSAM) | 1 year preserved (18 U.S.C. §2258A) |
| Files under legal hold | Until release of the hold |
| Opt-out records (STOP) via SMS | Retained indefinitely while the User's Account is active, in compliance with TCPA (USA) and other anti-spam regulations. Data subjects may request removal via [email protected] — removal will be communicated to the Account holder User, as it affects future messages to that number |
| Access logs | 6 months (Art. 15, Brazilian Internet Civil Rights Framework) |
| Billing data and transaction records (Stripe and app stores) | 5 years (tax and fiscal legislation; defense in possible disputes) |
| Support data | 2 years after ticket closure; maximum 6 months after Account closure (see 7.1) |
| Aggregated visit analytics | 90 days in daily detail; indefinitely in monthly aggregation (anonymized data) |
| Visit deduplication hashes | 48 hours (ephemeral data, no identification possible) |
| Device contacts (mobile app) | Not collected or retained: read and processed exclusively on the User's device, never transmitted to Apruvly's servers (see 2.4) |
| Mobile app devices (model, push token, IPs, session) | While the device remains linked to the Account; the session and push token are revoked immediately when the User disconnects the device, and all records are deleted upon Account closure |
| Mobile app purchase intent tokens (correlation token with the store) | 7 days (automatic expiration) |
| Failure diagnostics and mobile app usage metrics (Firebase) | According to Google's retention policies; collection may be disabled at any time in the application settings |
| Google advertising/measurement cookies (upon consent) | According to Google's policies; consent may be revoked at any time by clearing browser cookies |
| Acquisition source (UTM at registration) | While the account is active |
| Forensic request capture (request audit) | 30 days from the request timestamp (automatic daily purge); documented legal/incident holds may extend retention beyond this standard period. Transport queues: up to 24 h (DLQ 72 h) |
| Visit classifier calibration aggregate counters | 90 days (only daily decision/anchor totals, without IP, session, path or identifiers) |
| Newsletter preferences (opt-in) | While the account is active or until consent revocation |
| Personal data export files (LGPD Art. 18) | Generated file available for download for 7 days, then discarded from storage. The request record (status, date and time) is maintained in the Account history for 6 months after expiration, for User visibility and compliance with the limit of one export every 30 days |
7.1. After Account closure, Apruvly retains for 6 months the application access records required by Art. 15 of the Brazilian Internet Civil Rights Framework (Law No. 12,965/2014) and, to the extent strictly necessary to link such records to the data subject's identity, the corresponding registration data (minimum retention for possible response to competent authorities). Support tickets associated with the Account follow the same maximum 6-month period after closure, regardless of the general 2-year period applicable to active accounts. Upon Account closure, the bytes of attached files are deleted immediately; metadata, hash and download trail of attachments follow the specific periods indicated in the table above (evidence for 24 months after byte deletion, or until release of any legal hold). At the end of this period, all remaining personal data are permanently deleted.
7.2. Anonymized data (that do not allow User identification) may be retained indefinitely for statistical purposes.
We adopt technical and organizational measures to protect your data, including:
X-Twilio-Signature in HMAC-SHA1) is performed in constant time before any payload processing, preventing timing comparison attacks;No system is 100% secure. In the event of a security incident that may entail relevant risk or harm to data subjects, Apruvly will notify the ANPD and affected data subjects within 3 (three) business days from knowledge of the incident, in accordance with Art. 48 of the LGPD and CD/ANPD Resolution No. 15/2024, including a description of the incident, the data affected and the measures adopted.
9.1. We use strictly necessary cookies to:
The theme preference (light/dark) is stored in browser local storage (not in a cookie). Campaign parameters (UTM) are temporarily propagated in the server session during navigation until eventual registration, for origin attribution purposes — automatically removed after registration or upon natural session expiration, and not used for cross-visit tracking.
The mobile app does not use cookies. Session credentials and local preferences (theme, language, diagnostic and usage data consents) are stored on the device itself, in the operating system's secure storage (Keychain on iOS, Keystore on Android).
9.2. Marketing and analytics cookies (optional). On public pages and only after your consent in the cookie banner, we use Google Ads and Google Analytics (GA4) (gtag.js), which write third-party cookies (such as _gcl_au, _ga and _gid) and correlated identifiers for conversion measurement and remarketing and for aggregate audience and site usage analysis. The tag operates in Consent Mode (Consent Mode v2): before your acceptance no third-party cookies are written — Google receives only cookie-less and identifier-less signals (aggregate measurement); advertising cookies are activated only after acceptance. These cookies are not used in authenticated areas of the Platform and may be declined — or revoked later via the "Manage cookies" link — without any prejudice to use of the service. The aggregated analytics collection described in Section 2.2 remains entirely on the server, without cookies and without JavaScript tracking code. We do not use browser fingerprinting.
9.3. The strictly necessary cookies listed in 9.1 do not require prior consent (Art. 5(3) of Directive 2002/58/EC — ePrivacy — and necessity principle of the LGPD, Art. 6, III). The marketing cookies described in 9.2 are optional and are activated only after your explicit consent; you may grant or refuse them in the cookie banner and revoke them at any time via the "Privacy preferences" link in the site footer (or by clearing browser cookies), without prejudice to access to the services.
9.4. Privacy preferences. In the footer, the Privacy preferences link opens a dialog with (when applicable) controls for Google marketing cookies and server-side aggregated analytics preference. Refusing server-side analytics writes only the first-party cookie tracking_opt_out=1 (without identifier value), clears UTM keys from the session and prevents pageviews, deduplication hashes and classifier state. Browser signals Global Privacy Control (Sec-GPC) and Do Not Track (DNT) also disable server-side analytics while present — in which case the dialog explains the block and does not offer "reactivate" via cookie. Does not affect registration, login or Platform use; authorized forensic request capture remains independent.
In accordance with the LGPD (Art. 18), the User has the right to:
How to exercise your rights:
Identity verification. To preserve the privacy and security of the data subject, Apruvly may adopt reasonable identity verification measures before fulfilling access, correction, deletion or portability requests — including, when necessary, confirmation via the registered email, multi-factor authentication or documentary proof. Requests where it is not possible to verify the requester's identity may be refused, with justification sent to the address of origin.
Authorized representative. The data subject may exercise their rights through a duly constituted legal representative (specific power of attorney, legal guardian, estate administrator). Apruvly may request proof of the relationship before processing the request.
Non-discrimination. Exercise of any right provided in this section is free of charge and does not entail any prejudice, functional restriction or differentiation in access to contracted services, except in situations where deletion or blocking of data renders continuation of the service technically unfeasible (such as, for example, deletion of the Account).
Complaint to ANPD. If the data subject considers that their rights have not been adequately addressed, they may file a complaint with the National Data Protection Authority (ANPD) through official channels available at www.gov.br/anpd or directly via email [email protected].
Data subjects in the European Economic Area and United Kingdom. For data subjects located in the EEA or the United Kingdom, equivalent rights under the GDPR/UK GDPR (Arts. 15 to 21 — access, rectification, erasure, restriction, portability and objection) may be exercised through the same channels described in this section, including the right to lodge a complaint with the competent supervisory authority of their country.
The Platform is intended for persons over 18 years of age. We do not intentionally collect personal data from minors. If we become aware that data of a minor have been collected, we will proceed with immediate deletion.
12.1. Apruvly may update this Privacy Policy periodically to reflect changes in processing practices, the service or applicable legislation.
12.2. Material changes — considered those that expand processing purposes, include new data categories or new operators with significant impact, or reduce data subject rights — will be communicated to the User by email or notice on the Platform at least 15 days in advance, offering the User the opportunity to review the new version before it takes effect.
12.3. Continued use of the Platform after the changes take effect implies acceptance of the updated policy. If the User disagrees, they may close their Account before the changes take effect.
12.4. Previous versions of this Privacy Policy are preserved internally and may be requested at any time via [email protected].
For questions, requests or complaints related to this policy or the processing of your personal data: