🔐 Data Protection

Privacy Policy

Last updated: June 1, 2026

1. Introduction

Spy Nation operates the competitive intelligence platform available at spynation.com.br and app.spynation.com.br. This Privacy Policy describes how we collect, use, store, and protect your personal data.

Our practices comply with applicable data protection laws (e.g., GDPR/CCPA) and other relevant regulations. By using our services, you agree to the practices described here.

2. Data we collect

Data you provide

Full name and email address
Profile photo and display name (optional)
Payment processed by a partner; never stored by us.
Account preferences and personalized settings

Data collected automatically

IP address and approximate geographic location
Device type, browser, and operating system
Pages visited and time spent browsing
Session and preference cookies (see Section 7)

Google data (when you use "Sign in with Google")

Email address of your Google account
Public name and profile photo
Authentication token — we do not store your Google password

We use only the minimum scopes required: email and profile.

3. How we use your data

Authentication: verify your identity and grant access to the platform
Service delivery: provide all the features you've subscribed to
Communication: send essential transactional emails (confirmation, password recovery)
Billing: process payments and manage your subscription
Personalization: tailor your experience based on your preferences
Security: detect fraud and protect the integrity of the platform
Improvements: analyze aggregated and anonymized data to enhance the service
Legal obligations: comply with applicable tax and regulatory requirements

We never sell your personal data to third parties, under any circumstances.

4. Sharing with third parties

We share data only when necessary to operate the service, with partners that maintain equivalent data protection standards:

Payment processor: managing billing and subscriptions
Authentication provider: secure login and session management
Transactional email provider: sending confirmation and notification emails
Google (OAuth): authentication via your Google account, at your choice
Network infrastructure: content protection and delivery

All partners are contractually required to use your data solely for the agreed purpose. In the event of a legal requirement or court order, we may be obligated to share information with the competent authorities.

5. Data retention

Account data: for the duration of the subscription + 12 months after cancellation
Financial data: as required by applicable tax law (5 years)
Access logs: 6 months (as required by applicable law)
Communication history: 24 months
Cookies: according to the lifespan of each category

After the periods above, data is anonymized or securely and irreversibly deleted.

6. Data security

We adopt rigorous technical and organizational measures to protect your data:

Encryption for all data transmissions
Encrypted storage with per-user access controls
Secure authentication with short-lived access tokens
Passwords stored using a secure hashing algorithm — never in readable text
Continuous monitoring of access and suspicious activity
Two-factor authentication available and encouraged

In the event of a security incident, we will notify affected users and the relevant authorities as required by applicable law, within a maximum of 72 hours after becoming aware of the incident.

7. Cookies and similar technologies

Essential cookies (always active)

Session token — keeps you signed in while you use the platform
Interface preferences — theme and visual settings

Analytics cookies (with your consent)

Aggregated and anonymized browsing data to improve the platform

You can manage or delete cookies in your browser settings. Removing essential cookies may disrupt the operation of the service.

8. Your rights

As the data subject, the law guarantees you the following rights:

Access: confirm and obtain a copy of the data we hold about you
Correction: update inaccurate or outdated data
Deletion: request the removal of unnecessary or improperly processed data
Portability: receive your data in a structured, machine-readable format
Objection: contest the processing in certain circumstances
Withdrawal: revoke consents previously granted

To exercise any right, email privacidade@spynation.com.br with the subject line "Data Rights — [your request]". We respond within 15 business days. Account deletion can be requested at any time through the same channel.

9. Google authentication

When you choose "Sign in with Google," we strictly follow the platform's policies:

We request only the minimum scopes required: openid, email, and profile
We do not access Google Drive, Gmail, Calendar, or any other Google service
We never store your Google password under any circumstances
Data obtained via Google is used exclusively for authentication and identification
We do not transfer Google data to advertisers or third parties unrelated to the operation of the service

You can revoke our access at any time at: myaccount.google.com/permissions

10. Minors

Spy Nation is intended exclusively for users aged 18 and over. We do not knowingly collect data from minors. If we identify such a situation, the data will be deleted immediately. Please contact us if you notice any irregularity in this regard.

11. International transfer

Some of our operational partners maintain servers outside your country. When this happens, we ensure that recipients adopt equivalent protection measures through contractual clauses and internationally recognized certifications, in accordance with applicable data protection laws.

12. Changes to this policy

We may update this Policy from time to time. In the event of significant changes, we will notify you by email and/or a notice on the platform at least 15 days in advance. The most recent version will always be available at spynation.com.br/privacy.

13. Contact

For questions, requests, or complaints related to your privacy:

Email: privacidade@spynation.com.br
Suggested subject: "Privacy — [your request]"
Response time: up to 15 business days

Questions about privacy? Get in touch.

✉️ privacidade@spynation.com.br