Data transparency

Privacy Policy

This Policy explains what data Palang handles, why, for how long, and how you can exercise your rights.

Version 1.0 · Effective and updated September 22, 2026

1. Controller and contact

The data controller is Hostit Desenvolvimento de Programas LTDA, CNPJ 68.949.396/0001-51. Contact hostit.application@gmail.com for privacy questions or requests.

2. Data we process

Account and identity

Learning profile

Activity and progress

Local data

Your device stores the authentication session, a UID-scoped profile cache, and the theme preference to preserve sign-in and a consistent experience.

Technical data

Google, Firebase, and Google Cloud may process IP addresses, user agents, browser/device information, request, failure, and security logs to authenticate, deliver this website and content, run Functions, prevent abuse, and diagnose issues.

3. Data we do not currently collect

Palang does not record, store, or transmit your voice. You speak along with audio without capture by the app. We also do not collect precise location, contacts, personal files, payment data, advertising identifiers, or notification tokens. We do not use Google Analytics, Crashlytics, advertising, advertising cookies, or commercial profiling.

4. Purposes and legal bases

5. Children and teenagers

Palang does not ask for age, and its educational content may be used by different age groups. Processing minors’ data must serve their best interests. Parents or guardians should understand and monitor use, authorize processing where required, and may request access, correction, or deletion.

6. Sharing and processors

We do not sell personal data. We may share the minimum required by law, security needs, or a protected corporate reorganization.

7. International transfers

Google/Firebase and their processors may handle data outside Brazil, including the United States, under their infrastructure, terms, and applicable safeguards. Firebase Authentication operates in US infrastructure; other services may use global infrastructure.

8. Retention

Profiles and history remain while the account is active or needed to provide the service. Account deletion removes the user document, sessions, and active identity. Providers may retain residual backups for technical cycles — Firebase states up to 180 days for deleted authentication data — and authentication IP logs for a few weeks. Operational logs remain for configured security or legal periods.

9. Security

We use authentication, UID-scoped private rules, encrypted connections, separation of public and personal data, and an authenticated deletion Function. No system is infallible; we will take legally required steps following a relevant incident.

10. Your rights

Under Brazil’s LGPD, you may request confirmation and access, correction, sharing information, applicable portability, anonymization, blocking or deletion of unnecessary data, review of automated decisions, objection, and consent withdrawal. We may verify identity to protect the account.

11. Deletion

In the app, open Profile → Legal and privacy → Delete my account. Without the app, see Account deletion or email hostit.application@gmail.com.

12. Changes

Material updates will be published with a new date and appropriate notice. The current version remains at this address.