Esmerum

Privacy Policy

This Policy explains what personal data Esmerum collects, for which purposes, how long it is retained, and how you can exercise your rights. Processing follows the Brazilian General Data Protection Law (LGPD, Law 13.709/2018) and, for users in the European Economic Area, the General Data Protection Regulation (GDPR).

1. Controller and data protection officer

Esmerum acts as the controller of personal data processed on the platform. To exercise your rights, ask questions, or file a privacy complaint, contact our data protection officer (DPO) at privacy@esmerum.com.

2. Data we collect

Account data: name, email, and profile picture, provided by you or received from Google/Microsoft when you choose social login. User content: files, notes, decks, questions, automations, and messages sent to the AI assistant. Usage data: access logs, IP address, device and browser type, pages visited, and review history. Payment data: processed directly by our payment provider — we do not store full card numbers.

4. Artificial intelligence and submitted content

When you use AI features, the text or file you submit is transmitted to language model providers we contract with, solely to generate the requested response. These providers act as processors, are bound by data protection agreements, and may not use your content to train their own models. Avoid submitting unnecessary sensitive data in assistant interactions.

5. Sharing with third parties

We share data only with processors necessary to deliver the service: cloud infrastructure and database hosting, authentication providers (Google, Microsoft), transactional email delivery, payment processing, and AI providers. All act under contractual instruction. We do not sell personal data. Disclosure to authorities occurs only under court order or legal obligation.

6. International transfers

Part of our infrastructure is located outside Brazil and the European Economic Area. Such transfers rely on standard contractual clauses and other safeguards provided under Article 33 of the LGPD and Chapter V of the GDPR, ensuring a level of protection equivalent to that of the originating jurisdiction.

7. Retention and deletion

We retain account data and content for as long as your account remains active. After a deletion request, content is removed from production systems within 30 days and from backups within 90 days. Access logs are retained for six months as required by law. Tax documents are kept for the statutory period of five years.

8. Information security

We apply encryption in transit (TLS) and at rest, sessions authenticated via httpOnly cookies, role-based access control, per-project data isolation through row level security policies, audit logging, and continuous monitoring. No system is entirely immune to incidents; in the event of a breach posing significant risk, we will notify you and the competent supervisory authority within legal deadlines.

9. Your rights

You may at any time request: confirmation that processing exists; access to your data; correction of incomplete or outdated data; anonymization, blocking, or deletion of unnecessary data; portability to another provider; information about data sharing; and withdrawal of consent. Requests should be sent to privacy@esmerum.com and are answered within 15 days. Users in the EEA may also lodge a complaint with their local supervisory authority.

10. Cookies

We use strictly necessary cookies for authentication, session management, and security — these cannot be disabled without breaking the platform. Analytics cookies, where used, depend on your consent and may be declined without affecting access. Preferences such as language and theme are stored locally in your browser.

11. Children and adolescents

The platform is not intended for users under 16 without specific and prominent consent from at least one parent or legal guardian, as required by Article 14 of the LGPD. When we identify an irregular registration, the account is suspended and the data deleted.

12. Changes to this Policy

We may update this Policy to reflect legal or product changes. The date of the latest revision appears at the top of this page, and material changes will be communicated by email or in-platform notice at least 30 days in advance.