Apruvly Apruvly
  • Home
  • Product

    From access requests to deploys, see how teams put Apruvly to work.

    Access Approval Grant access to systems and data with a traceable approval. Deploy Pipelines A human approval gate before shipping to production. Process Management Standardize any process that needs a sign-off to move forward. Finance & Procurement Purchases, expenses and contracts approved within the right limits. HR & Onboarding Time off, reimbursements and hires approved by the right people. AI Agent Guardrails Put a human in the loop before an AI agent takes sensitive action. Compliance & Audit Formal approvals with a complete trail for audits. Operations & Exceptions Discounts, refunds and operational exceptions without spreadsheets.
    View all applications

    Multi-level chains, escalation, notifications and a full audit trail — without writing approval logic yourself.

    Multi-level approvals Approval chains with as many steps and people as you need. Automatic escalation No response? The request moves up to the next person on its own. Notifications where your team already is Email, Slack, Teams, WhatsApp, Telegram, Discord, SMS and more. One-click approval Approvers decide right in the notification — no account needed. Complete audit trail Who, when and why recorded for every decision. People & areas directory Register who approves what and reuse it across every flow. API & MCP integration Connect your systems and AI agents with a single call. Enterprise-grade security Encryption, scoped API keys and abuse protection.
    View all features
  • Documentation
    • Documentation
    • Integrations
  • Pricing
  • Articles
  • About
  • Contact Us
Login Register

Privacy Policy

APRUVLY DESENVOLVIMENTO E LICENCIAMENTO DE PROGRAMAS DE COMPUTADOR NAO CUSTOMIZAVEIS LTDA
CNPJ: 66.299.145/0001-43
Contato jurídico: [email protected]
Última atualização: July 10, 2026


This Privacy Policy describes how APRUVLY DESENVOLVIMENTO E LICENCIAMENTO DE PROGRAMAS DE COMPUTADOR NAO CUSTOMIZAVEIS LTDA ("Apruvly", "we" or "Platform") collects, uses, stores, shares and protects the personal information of users ("User", "you"), regardless of their geographic location, who access or use our services available at apruvly.io or through Apruvly's official mobile applications for iOS and Android ("mobile app" or "application"). By creating an Account or using the Platform, you agree to the terms of this policy.

This policy has been prepared in compliance with the General Data Protection Law (LGPD — Law No. 13,709/2018) and other applicable legislation, including for international users.

1. Definitions and Roles

1.1. Definitions

  • Personal Data: any information relating to an identified or identifiable natural person.
  • Processing: any operation performed on personal data (collection, storage, use, sharing, deletion, etc.).
  • Controller: APRUVLY DESENVOLVIMENTO E LICENCIAMENTO DE PROGRAMAS DE COMPUTADOR NAO CUSTOMIZAVEIS LTDA (CNPJ 66.299.145/0001-43), responsible for decisions regarding the processing of personal data.
  • Processor: third party that processes personal data on behalf of the Controller.
  • Privacy Channel: Apruvly qualifies as a small-scale processing agent, pursuant to CD/ANPD Resolution No. 2/2022, and is exempt from appointing a Data Protection Officer (DPO). In compliance with Art. 11, sole paragraph, of the same Resolution, we provide the channel [email protected] for communication with data subjects and with the National Data Protection Authority (ANPD).

1.2. Apruvly as Controller and as Processor

This Policy describes two distinct processing scenarios that coexist on the Platform:

  1. Apruvly as Controller — regarding the data of the registered User (Platform customer): registration, billing, access logs, support and communications about the service. Processing decisions regarding such data are made by Apruvly, based on the legal grounds described in Section 3.

  2. Apruvly as Processor (Art. 5, VII of the LGPD) — regarding the data of recipients and approvers (third parties who receive workflow notifications triggered by the User). In this scenario, the User is the Controller of such third parties' data and Apruvly acts as Processor, processing email addresses, telephone numbers, channel identifiers (Slack, Microsoft Teams, Telegram, Discord, DingTalk, WhatsApp), message content and delivery metadata exclusively upon instruction and on behalf of the User, within the contractual limits established in the Terms of Service. Decisions on who is notified, which data are included in each notification and for how long such workflows persist rest with the User-Controller, to the extent of the contracted plan.

Requests from approver data subjects (right of access, rectification, deletion, etc.) may be addressed to the User (controller) or directly to Apruvly via the Privacy channel described in Sections 10 and 13. When received by Apruvly, they are handled in accordance with Art. 39 of the LGPD: Apruvly fulfills the request within the limits of its role as Processor and, when necessary, forwards the request to the User-Controller for decision on any additional actions.

2. Information We Collect

2.1. Data Provided by the User

  • Registration data: name, email address and password (stored exclusively in irreversible cryptographic hash format).
  • Profile data: additional information the User chooses to provide (e.g., display name, preferred language).
  • Billing data: subscription information and transaction history. Credit card data are processed directly by Stripe and never stored on Apruvly's servers. In-app purchases made within the mobile app are processed by the app store (Apple App Store or Google Play): Apruvly receives from the store only transaction and subscription identifiers, the product purchased, purchase status (acquisition, renewal, cancellation, refund) and the store country, and never has access to the payment data used in the store.
  • Communications and support: messages, problem descriptions and files sent by the User via the support ticket system, contact form or other support channels. When the User expressly opts for AI-assisted support when opening a ticket, the content of such messages is forwarded to a third-party artificial intelligence service to generate automated responses. These responses are identified as AI-generated, may contain inaccuracies and the User may request human review at any time; low-confidence cases are escalated to human support.
  • External provider integration credentials: when the User configures providers that require credentials — such as Twilio (SMS and WhatsApp via Twilio), WhatsApp Business API direct (Meta), Slack, Microsoft Teams, Telegram, Discord or DingTalk — the tokens provided (Account SID, Auth Token, API Keys, Messaging Service SID, Bot Tokens, OAuth Tokens, Webhook URLs, etc.) are stored encrypted with AES-256-GCM. These credentials are never displayed in plain text in the dashboard after registration nor included in data exports. They do not in themselves constitute the User's personal data, but may identify the account contracted by the User with the third party.

2.2. Data Collected Automatically

  • Technical data: IP address, browser type and version, operating system, screen resolution and device identifiers. The IP address of authenticated sessions is stored in access logs for 6 months, in compliance with Art. 15 of the Brazilian Internet Civil Rights Framework (see §7).
  • Access data: authentication logs, access times and pages visited, for security and diagnostic purposes.
  • Mobile app device and session data: upon authenticating in the application, we record per installation: device model, operating system and application version, an installation identifier generated by the application itself, the device identifier provided by the system (IDFV on iOS, Android ID on Android; never the advertising identifier), the store of origin and the store country, the push notification token (only after notification permission is granted) and the status of such permission, the IP address and the approximate country and city derived from the IP, as well as registration and last access dates. These data support the application session (revocable tokens), push notification delivery and Account security auditing; the User may view and disconnect devices in the application settings.
  • Usage data: workflows created, provider configurations, generated API keys, approval history and actions performed on the Platform.
  • Decision records (evidence trail): when recording an approver's decision (approval or rejection, in any channel, including the mobile app), we record date and time, decision channel, approver's comment (when provided), IP address and approximate location derived from the IP (country and city). These records form part of the workflow audit trail, support the certificate described in Section 5 and follow the retention cycle of the contracted plan.
  • Workflow message delivery data: when the User sends notifications by SMS (via Twilio) or email via transactional providers, we record the recipient's telephone number or email address, delivery status, any error codes returned by the provider and correlation data necessary to reconcile received responses. These records belong to the corresponding workflow and follow the same retention cycle as the contracted plan. Part of these data relates to approver recipients who may not be the registered User.
  • Files attached to approvals: when the User attaches files to an approval request created by the application, we process the file bytes, their metadata (name, size and type), the cryptographic hash (SHA-256) and a download event trail (recipient's email address, IP address, device data and date/time of each download issuance). The bytes and metadata are content inserted by the User; the download trail records the activity of recipients indicated by the User. In this activity, Apruvly acts as Processor of the content on behalf of the User-Controller, mirroring the roles described in §1.2, and as controller of the audit trail, based on legitimate interest (§3).
  • Aggregated analytics data: on public (unauthenticated) pages of the site, we collect visit statistics in anonymized and aggregated form to understand visitor origins and improve the service. This collection is distinct from the recording of authenticated sessions described above and is performed entirely on the server (no JavaScript tracking, no tracking cookies and no third-party services). We collect: page accessed, country of origin (derived from IP), browser family and operating system (without version), referring domain and campaign parameters (UTM). No data allowing individual identification of the visitor is stored: the IP address is processed exclusively in memory to derive the country and generate a temporary deduplication hash, without being persisted — the hash is automatically discarded within 48 hours. The automated classification of visits (strong evidence of human interaction vs. unverified browser vs. declared bot/scan) serves only acquisition aggregate metrics: it does not block access, alter pricing, support, advertising or fraud treatment.
  • Forensic request capture (request audit): in authorized investigation windows (per user or global), internal operators may record rich HTTP request metadata (IP, User-Agent, path, redacted query, allowed headers and redacted bodies) for security and incident support. Capture does not occur with all windows closed; exploration access and window opening are separated by permission; global opening and purge are restricted to root operators. This trail is absolutely separate from visit analytics: there is no joining, cross-export or automatic reuse for marketing. Standard retention: 30 days (longer retentions require documented hold). Transport transient queues retain messages for a maximum of 24 h (DLQ 72 h).
  • Advertising and measurement data (Google Ads and Google Analytics): on public pages (and on the purchase confirmation page) we load the Google tag (gtag.js) from Google Ads and Google Analytics (GA4) in Consent Mode (Consent Mode v2). Before your consent, the tag operates with consent denied: no third-party cookies are written and Google receives only cookie-less and identifier-less signals (including the request IP address) for aggregate measurement and modeling. After your consent (cookie banner), third-party cookies (such as _gcl_au, _ga and _gid) are activated for conversion measurement and remarketing (Ads) and for aggregate audience and site usage analysis (Analytics). This processing does not occur in authenticated use of the Platform. Details in Section 9.
  • Mobile app usage data: when collection is active ("Share usage data" control in application settings), we collect via Google Analytics for Firebase interaction events without personal content: screens visited (by screen name), login by SSO provider, decision recorded (approved/rejected, without identifying the workflow), notification openings and in-app purchase events (product, period, value and currency), accompanied by technical device attributes (model, operating system, app version). We do not collect advertising identifiers (Advertising ID/IDFA), email, tokens or the content of approvals; purchase events may be used, in aggregate form, to measure conversion of our Google Ads campaigns. The initial collection state depends on the device's store region: disabled by default for stores in the European Economic Area and United Kingdom (opt-in) and enabled by default in other regions (opt-out). In any region, collection may be turned on or off at any time in the application settings, and the User's choice always prevails over the regional default.

2.3. SSO Authentication Data

When the User chooses to authenticate via an external provider (Google, Microsoft, GitHub or Apple), we receive the email address authorized by the User and the account identifier with that provider. We do not receive or store the external provider's password, nor do we collect name or profile photo through SSO. In the case of Apple, the User may choose to hide the real email using Apple's private relay service; in that case we receive only the forwarding address provided by Apple.

2.4. Device Contacts (mobile app)

To suggest recipients while the User types, the mobile application may read, upon express authorization granted in the operating system (iOS or Android), the names and email addresses from the device's contact list. This processing occurs exclusively on the device itself: the contact list is never sent, copied or stored on Apruvly's servers, and no contact data is transmitted over the network. Only the email addresses that the User actually adds as recipients of a workflow are transmitted and processed, as described in Section 2.2 (workflow message delivery data). Authorization may be revoked at any time in the operating system settings; in that case the application simply ceases to display suggestions, without prejudice to other functions.

2.5. Camera, Gallery and Shared Files (mobile app)

The application accesses the camera and photo gallery only upon authorization granted by the User in the operating system (iOS or Android) and only at the moment the User decides to attach an image to an approval request. Files received by sharing from other applications are processed only when the User attaches them to a request. In all cases, the attached file follows the attachment regime described in Section 2.2; there is no access to the camera, gallery or device files in the background. Authorizations may be revoked at any time in the operating system settings.

2.6. Local Biometric Confirmation (mobile app)

To record approval decisions (and, optionally, to unlock the application), the application requires biometric or screen credential verification performed by the operating system itself, on the device (Face ID or Touch ID on iOS; biometrics or screen lock on Android). Apruvly does not collect, receive or store biometric data under any circumstances: the operating system informs the application only of the verification result (success or failure), used to allow or disallow the action. Biometric enrollment and deletion are managed exclusively by the User in the device's own settings.

3. Legal Bases for Processing

The processing of personal data is carried out on the following legal bases provided in the LGPD:

Purpose Legal basis (Art. 7 LGPD)
Provision of contracted service Contract performance (V)
Payment processing Contract performance (V)
Sending workflow notifications Contract performance (V)
Sending SMS notifications via Twilio and receiving responses Contract performance (V)
Mobile app device registration and push notification delivery Contract performance (V)
Processing and reconciliation of in-app store purchases Contract performance (V)
Evidence trail of approval decisions (date/time, channel, IP, approximate location) Contract performance (V) + legitimate interest (IX)
Account security and fraud prevention Legitimate interest (IX)
Automated security verification of attachments (antivirus/hash) Legitimate interest (IX) + contract performance (V)
Attachment download trail and evidence retention post-deletion Legitimate interest (IX) — fraud/abuse prevention and regular exercise of rights
Retention of application service logs Legal obligation compliance (II) — Brazilian Internet Civil Rights Framework, art. 15
Preservation and reporting of child sexual abuse material Legal obligation compliance (II) — 18 U.S.C. §2258A and ECA
Access and diagnostic logs Legal obligation compliance (II) — Brazilian Internet Civil Rights Framework
Service communications Legitimate interest (IX)
Platform improvement Legitimate interest (IX)
Aggregated visit analytics (public pages) Legitimate interest (IX)
Mobile app usage metrics (outside EEA/United Kingdom) Legitimate interest (IX), with opt-out at any time
Mobile app usage metrics (EEA/United Kingdom) Consent (I), via opt-in
Mobile app failure reports (Crashlytics) Legitimate interest (IX), with opt-out at any time
Advertising, remarketing and conversion measurement (Google Ads) and audience analysis (Google Analytics), on public pages Consent (I)
Processing of support tickets by AI (only with opt-in) Consent (I)
Sending newsletters by email Express consent (I) - Only with explicit opt-in from the User. We do not send spam.

4. How We Use the Information

We use your personal data to:

  • Provide, operate and improve the Platform's services;
  • Authenticate your access and ensure Account security;
  • Process payments and manage subscriptions and credits;
  • Send workflow-related notifications (email, Slack, Microsoft Teams, WhatsApp) as configured by you;
  • Send SMS notifications via Twilio when the User configures this channel, and process responses (approval, rejection, opt-out) received through the same channel;
  • Deliver mobile app push notifications and maintain session security on mobile devices (device registration, rotation and token revocation);
  • Process and reconcile purchases made in app stores (correlation of the transaction with the Account, granting of acquired credits and benefits and handling of renewals, cancellations and refunds notified by the store);
  • Monitor usage for credit-based billing (workflow units);
  • Respond to support and contact requests;
  • When the User provides consent, forward the ticket content to a third-party AI service to generate AI-identified automated support responses subject to possible inaccuracies; the User may request human review at any time;
  • Detect, prevent and investigate fraudulent activities or violations of the Terms of Service;
  • Generate aggregated and anonymized statistics on traffic on the site's public pages, to understand the effectiveness of acquisition channels and improve the service experience;
  • When you consent to marketing cookies, measure the conversion of our campaigns and display remarketing ads through Google Ads, exclusively on public pages;
  • Send newsletters by email only to Users who have provided explicit opt-in, with an explicit statement that we do not send spam;
  • Comply with legal and regulatory obligations.

We do not create behavioral profiles from your Account data nor target advertising based on your authenticated use of the Platform. Visit statistics collected on the server are always aggregated and anonymized. On public pages, conversion measurement and remarketing via Google Ads occur only upon your consent (Section 9) and may be declined at any time, without prejudice to use of the Platform.

5. Sharing of Information

We do not sell, rent or commercialize your personal data. We may share it only with:

  • Stripe (payment processing): receives billing data under contractual confidentiality obligations and in compliance with PCI DSS.
  • Amazon Web Services (AWS) — cloud infrastructure provider responsible for hosting the application, database and object storage (including data export files). Acts as processor under contract with standard data protection clauses.
  • Cloudflare — edge provider (CDN, DNS, DDoS mitigation and WAF) that processes request metadata (IP, headers, route) in transit as processor under contract with standard data protection clauses. When the Cloudflare Turnstile anti-bot challenge is enabled, Cloudflare also processes interaction signals (including IP and device/browser attributes) to distinguish humans from bots on public forms and administrative login; processing of such data by Cloudflare is governed by the Turnstile Privacy Addendum.
  • Cloudflare (R2 and Queues) — storage of files attached to approvals and event queue for security verification. Upload and download of files occur directly between the User's device and Cloudflare, via temporary short-lived access addresses; security verification of files runs on Apruvly's own infrastructure, which reads the bytes for antivirus examination and hash calculation. Acts as processor under contract with standard data protection clauses.
  • SendGrid (Twilio, Inc.) — transactional email provider used for delivery of Platform operational messages (notifications, support and service communications), acting as processor under contract with standard data protection clauses.
  • Mailgun (Sinch Email) — alternative transactional email provider and inbound response receipt (reply-by-email) for the Platform, acting as processor under contract with standard data protection clauses.
  • Integrations configured by the User (notification providers such as Slack, Microsoft Teams, WhatsApp Business API — directly with Meta Platforms, Inc. — or via Twilio, Discord, Telegram, DingTalk, and SMS providers via Twilio, Inc., transactional email or similar): sharing of data with these third parties occurs only if and to the extent the User configures the integration. If no integration is configured, no data is shared with third parties in this category. When configured, calls to the provider are made under the User's own account and credential — Apruvly acts as technical intermediary authorized by the credential provided; the contractual relationship with the external provider is the User's, and processing of data by the provider is governed by the terms between the User and that third party.
  • xAI (artificial intelligence provider): used only in the Platform's optional AI features — knowledge base and AI-assisted support. Activation depends on explicit use of the feature by the User (in the case of support, express opt-in per ticket). Content forwarded is limited to what is strictly necessary for response generation and is subject to contractual confidentiality obligations and prohibition of use for model training or any purpose other than the strictly contracted one.
  • Google (Google Ads / Google Analytics): on public pages, in Consent Mode. Before your consent, receives only cookie-less and identifier-less signals (aggregate measurement, including request IP); with your consent, begins receiving third-party cookies and navigation data for conversion measurement and remarketing (Google Ads) and site audience and usage analysis (Google Analytics). Acts as processor under contract with Standard Contractual Clauses; processing of data by Google is governed by Google's Privacy Policy.
  • Mobile approval app (when the User uses the application): to deliver push notifications we use Google Firebase Cloud Messaging (FCM) and, on iOS, Apple Push Notification service (APNs) underneath FCM — both receive only the device token and a minimal routing payload, never the content of the approval. For application stability diagnostics we use Firebase Crashlytics (device model, operating system, app version and stack traces, without personal data), active by default and disableable at any time in the "Share crash reports" control in application settings. When usage data collection is active (Section 2.2; initial default varies by store region and the "Share usage data" control is in application settings), we use Google Analytics for Firebase for app usage metrics — screens visited and interaction and purchase events, without advertising identifiers (Advertising ID/IDFA), without email and never the content of approvals. Application authentication may also use Apple as an SSO provider. All act as processors under Standard Contractual Clauses.
  • Apple (App Store) and Google (Google Play) — in-app purchases: subscriptions and credit packs purchased within the mobile app are sold and processed by the store itself, which acts as merchant of record and independent controller of payment data, under the privacy policies of Apple and Google. Apruvly receives from the store only transaction notifications (purchase and subscription identifiers, product, status and store country), never the payment data.
  • Legal authorities: when required by law, court order, administrative proceeding or to protect our legal rights in judicial proceedings. This includes retention of records required by art. 15 of the Brazilian Internet Civil Rights Framework and, in the case of child sexual abuse material (CSAM) of which we become aware, mandatory reporting to the CyberTipline (NCMEC) and to the competent Brazilian authorities (ECA; SaferNet).

All third parties that access personal data on our behalf are contractually obligated to treat it with confidentiality and in accordance with this policy.

The current list of processors and sub-processors involved in processing is publicly available at apruvly.io/sub-processors; the [email protected] channel remains available for further clarification. If Apruvly engages new processors that process personal data in a materially different manner from that described above, this Privacy Policy will be updated in accordance with §12.

Public verification page (shared by you). Upon completing a request, the User may generate a proof link ("approval certificate") that opens a public, read-only page with the request result, its title and description, timestamps and the list of approver decisions. To protect approvers, email addresses appear masked on this page (only the initial and domain, e.g. j****@empresa.com), never the full address. The link is the sole access credential: anyone possessing it can view the page, and it is solely the User's decision whether and with whom to share it. The page is not indexed by search engines. As approver data are third-party data processed under the User's responsibility (Section 1.2), the decision to generate and distribute the certificate rests with the User, in the capacity of Controller of such data.

6. International Data Transfers

6.1. Apruvly's servers and those of its infrastructure providers may be located outside Brazil. In particular, AWS and Cloudflare operate globally distributed infrastructure that may process data in regions outside Brazilian territory. When enabled by consent, Google (Google Ads) also processes data in the United States and other regions. Mobile app service providers (Google Firebase, Apple) and app stores (Apple App Store, Google Play) also process data in the United States and other regions.

6.2. By using the Platform, the User acknowledges that their data may be processed in the countries where we operate. Apruvly adopts appropriate technical and contractual safeguards — including standard data protection clauses — to ensure a level of protection equivalent to that required by the LGPD, regardless of processing location.

6.3. Apruvly carries out international transfers only when necessary for service provision and in compliance with Art. 33 of the LGPD, primarily based on items I (specific contractual clauses with the processor) and V (performance of contract with the data subject). For processors located in jurisdictions without an adequacy decision from ANPD, Apruvly uses Standard Contractual Clauses (SCC) or specific contractual clauses with equivalent safeguards, aligned with the model approved by ANPD in CD/ANPD Resolution No. 19/2024. A copy of the applicable clauses may be requested via [email protected].

6.4. When the User configures integrations with external providers (notification, messaging, SMS, transactional email, AI, etc.), any international transfers arising from such integrations occur under the User's own account and contractual relationship with the respective provider, governed by the terms the User has agreed with that third party. Apruvly merely executes, as technical intermediary, the calls authorized by the credential provided by the User.

7. Data Retention

Data type Retention period
Account data (profile, email) While the account is active; permanently deleted within 6 months after closure (see 7.1)
Workflow data According to the contracted plan (7 to 90 days, see Pricing page)
Corporate push messages (title, body, recipients) 30 days after message completion (done/canceled). Sender mute preferences and usage cycle counters remain while the Account is active; reports follow administrative message retention
SMS delivery data via Twilio (telephone, status, cost) Same period as workflow data: 7 to 90 days according to the contracted plan
Bytes of files attached to approvals TTL of the contracted plan or early deletion by the User
Metadata, SHA-256 hash and download trail of attachments 24 months after byte deletion (legitimate interest — fraud/abuse prevention and regular exercise of rights; covers the 6-month floor of the Brazilian Internet Civil Rights Framework, art. 15)
Application service access logs ≥ 6 months (Art. 15, Brazilian Internet Civil Rights Framework)
Reported material (CSAM) 1 year preserved (18 U.S.C. §2258A)
Files under legal hold Until release of the hold
Opt-out records (STOP) via SMS Retained indefinitely while the User's Account is active, in compliance with TCPA (USA) and other anti-spam regulations. Data subjects may request removal via [email protected] — removal will be communicated to the Account holder User, as it affects future messages to that number
Access logs 6 months (Art. 15, Brazilian Internet Civil Rights Framework)
Billing data and transaction records (Stripe and app stores) 5 years (tax and fiscal legislation; defense in possible disputes)
Support data 2 years after ticket closure; maximum 6 months after Account closure (see 7.1)
Aggregated visit analytics 90 days in daily detail; indefinitely in monthly aggregation (anonymized data)
Visit deduplication hashes 48 hours (ephemeral data, no identification possible)
Device contacts (mobile app) Not collected or retained: read and processed exclusively on the User's device, never transmitted to Apruvly's servers (see 2.4)
Mobile app devices (model, push token, IPs, session) While the device remains linked to the Account; the session and push token are revoked immediately when the User disconnects the device, and all records are deleted upon Account closure
Mobile app purchase intent tokens (correlation token with the store) 7 days (automatic expiration)
Failure diagnostics and mobile app usage metrics (Firebase) According to Google's retention policies; collection may be disabled at any time in the application settings
Google advertising/measurement cookies (upon consent) According to Google's policies; consent may be revoked at any time by clearing browser cookies
Acquisition source (UTM at registration) While the account is active
Forensic request capture (request audit) 30 days from the request timestamp (automatic daily purge); documented legal/incident holds may extend retention beyond this standard period. Transport queues: up to 24 h (DLQ 72 h)
Visit classifier calibration aggregate counters 90 days (only daily decision/anchor totals, without IP, session, path or identifiers)
Newsletter preferences (opt-in) While the account is active or until consent revocation
Personal data export files (LGPD Art. 18) Generated file available for download for 7 days, then discarded from storage. The request record (status, date and time) is maintained in the Account history for 6 months after expiration, for User visibility and compliance with the limit of one export every 30 days

7.1. After Account closure, Apruvly retains for 6 months the application access records required by Art. 15 of the Brazilian Internet Civil Rights Framework (Law No. 12,965/2014) and, to the extent strictly necessary to link such records to the data subject's identity, the corresponding registration data (minimum retention for possible response to competent authorities). Support tickets associated with the Account follow the same maximum 6-month period after closure, regardless of the general 2-year period applicable to active accounts. Upon Account closure, the bytes of attached files are deleted immediately; metadata, hash and download trail of attachments follow the specific periods indicated in the table above (evidence for 24 months after byte deletion, or until release of any legal hold). At the end of this period, all remaining personal data are permanently deleted.

7.2. Anonymized data (that do not allow User identification) may be retained indefinitely for statistical purposes.

8. Security

We adopt technical and organizational measures to protect your data, including:

  • Encryption in transit: all communications use TLS 1.2 or higher;
  • Passwords: stored exclusively in irreversible cryptographic hash format (bcrypt);
  • Sessions: authentication with automatic expiration and CSRF protection;
  • Mobile app sessions: opaque rotating session tokens, stored in the database only as hash, with reuse detection (indication of token theft) and per-device revocation; on the device, credentials reside in the operating system's secure storage (Keychain on iOS, Keystore on Android);
  • Local biometric confirmation: decisions recorded by the mobile app require biometric or screen credential verification performed by the operating system on the device, without transmission of biometric data to Apruvly (see 2.6);
  • API keys: stored securely with partial hash for identification;
  • Integration credentials (Twilio and other external providers): encrypted at rest with AES-256-GCM and decrypted in memory only during execution of authenticated calls to the external provider;
  • Webhook signatures: validation of authenticity of received webhooks (e.g., X-Twilio-Signature in HMAC-SHA1) is performed in constant time before any payload processing, preventing timing comparison attacks;
  • Access control: access to production data restricted to the minimum necessary;
  • Attachment verification: files attached to approvals undergo automated antivirus verification before any distribution; access to bytes is restricted to temporary short-lived access addresses, in a fail-closed model — unverified files are not distributed;
  • Monitoring: audit logs for detection of anomalous access.

No system is 100% secure. In the event of a security incident that may entail relevant risk or harm to data subjects, Apruvly will notify the ANPD and affected data subjects within 3 (three) business days from knowledge of the incident, in accordance with Art. 48 of the LGPD and CD/ANPD Resolution No. 15/2024, including a description of the incident, the data affected and the measures adopted.

9. Cookies and Local Storage

9.1. We use strictly necessary cookies to:

  • Maintain the User's authenticated session;
  • Protect against CSRF attacks;
  • Store language preference;
  • Remember trusted devices after two-factor verification (multi-factor authentication).

The theme preference (light/dark) is stored in browser local storage (not in a cookie). Campaign parameters (UTM) are temporarily propagated in the server session during navigation until eventual registration, for origin attribution purposes — automatically removed after registration or upon natural session expiration, and not used for cross-visit tracking.

The mobile app does not use cookies. Session credentials and local preferences (theme, language, diagnostic and usage data consents) are stored on the device itself, in the operating system's secure storage (Keychain on iOS, Keystore on Android).

9.2. Marketing and analytics cookies (optional). On public pages and only after your consent in the cookie banner, we use Google Ads and Google Analytics (GA4) (gtag.js), which write third-party cookies (such as _gcl_au, _ga and _gid) and correlated identifiers for conversion measurement and remarketing and for aggregate audience and site usage analysis. The tag operates in Consent Mode (Consent Mode v2): before your acceptance no third-party cookies are written — Google receives only cookie-less and identifier-less signals (aggregate measurement); advertising cookies are activated only after acceptance. These cookies are not used in authenticated areas of the Platform and may be declined — or revoked later via the "Manage cookies" link — without any prejudice to use of the service. The aggregated analytics collection described in Section 2.2 remains entirely on the server, without cookies and without JavaScript tracking code. We do not use browser fingerprinting.

9.3. The strictly necessary cookies listed in 9.1 do not require prior consent (Art. 5(3) of Directive 2002/58/EC — ePrivacy — and necessity principle of the LGPD, Art. 6, III). The marketing cookies described in 9.2 are optional and are activated only after your explicit consent; you may grant or refuse them in the cookie banner and revoke them at any time via the "Privacy preferences" link in the site footer (or by clearing browser cookies), without prejudice to access to the services.

9.4. Privacy preferences. In the footer, the Privacy preferences link opens a dialog with (when applicable) controls for Google marketing cookies and server-side aggregated analytics preference. Refusing server-side analytics writes only the first-party cookie tracking_opt_out=1 (without identifier value), clears UTM keys from the session and prevents pageviews, deduplication hashes and classifier state. Browser signals Global Privacy Control (Sec-GPC) and Do Not Track (DNT) also disable server-side analytics while present — in which case the dialog explains the block and does not offer "reactivate" via cookie. Does not affect registration, login or Platform use; authorized forensic request capture remains independent.

10. Data Subject Rights

In accordance with the LGPD (Art. 18), the User has the right to:

  • Confirmation and access: know whether we process your data and obtain a copy;
  • Correction: request updating of incomplete, inaccurate or outdated data;
  • Anonymization, blocking or deletion: of unnecessary, excessive or non-compliant data;
  • Portability: receive your data in structured and interoperable format;
  • Deletion: request deletion of data processed based on consent;
  • Information: know with which entities your data have been shared;
  • Consent withdrawal: withdraw consent at any time, without prejudice to processing previously carried out;
  • Objection: object to processing when carried out on the basis of legitimate interest.

How to exercise your rights:

  • Data access and portability: available directly at Settings → Export Data. Apruvly provides a structured file containing personal and usage data linked to the Account. The User may request a new export every 30 days; the file is accessible via private link for up to 7 days after generation;
  • Account and data deletion: available directly at Settings → Close Account, with email confirmation before any irreversible action;
  • Other requests (correction, objection, consent withdrawal, anonymization, information about sharing): send email to [email protected] with subject "LGPD Rights". We will respond within 15 (fifteen) days, counted from the date of the request (Art. 19, §2 of the LGPD).

Identity verification. To preserve the privacy and security of the data subject, Apruvly may adopt reasonable identity verification measures before fulfilling access, correction, deletion or portability requests — including, when necessary, confirmation via the registered email, multi-factor authentication or documentary proof. Requests where it is not possible to verify the requester's identity may be refused, with justification sent to the address of origin.

Authorized representative. The data subject may exercise their rights through a duly constituted legal representative (specific power of attorney, legal guardian, estate administrator). Apruvly may request proof of the relationship before processing the request.

Non-discrimination. Exercise of any right provided in this section is free of charge and does not entail any prejudice, functional restriction or differentiation in access to contracted services, except in situations where deletion or blocking of data renders continuation of the service technically unfeasible (such as, for example, deletion of the Account).

Complaint to ANPD. If the data subject considers that their rights have not been adequately addressed, they may file a complaint with the National Data Protection Authority (ANPD) through official channels available at www.gov.br/anpd or directly via email [email protected].

Data subjects in the European Economic Area and United Kingdom. For data subjects located in the EEA or the United Kingdom, equivalent rights under the GDPR/UK GDPR (Arts. 15 to 21 — access, rectification, erasure, restriction, portability and objection) may be exercised through the same channels described in this section, including the right to lodge a complaint with the competent supervisory authority of their country.

11. Data of Minors

The Platform is intended for persons over 18 years of age. We do not intentionally collect personal data from minors. If we become aware that data of a minor have been collected, we will proceed with immediate deletion.

12. Changes to This Policy

12.1. Apruvly may update this Privacy Policy periodically to reflect changes in processing practices, the service or applicable legislation.

12.2. Material changes — considered those that expand processing purposes, include new data categories or new operators with significant impact, or reduce data subject rights — will be communicated to the User by email or notice on the Platform at least 15 days in advance, offering the User the opportunity to review the new version before it takes effect.

12.3. Continued use of the Platform after the changes take effect implies acceptance of the updated policy. If the User disagrees, they may close their Account before the changes take effect.

12.4. Previous versions of this Privacy Policy are preserved internally and may be requested at any time via [email protected].

13. Contact

For questions, requests or complaints related to this policy or the processing of your personal data:

  • Email: [email protected]
  • Form: apruvly.io/contact
Apruvly Apruvly

Approvals that actually happen — on any channel, with a full audit trail.

Product

  • Pricing
  • Features
  • Integrations
  • Documentation
  • Articles
  • Enterprise

Company

  • About
  • Press
  • Contact Us
  • Status

Legal

  • Privacy Policy
  • Terms of Service
  • Sub-processors
  • Privacy preferences

© 2026 Apruvly. All rights reserved.

We use essential cookies required for the platform to function and, with your consent, Google measurement and advertising cookies on public pages. Learn more

Privacy preferences

Loading