Privacy and Security

Privacy Policy

Last updated: October 7, 2026 • In accordance with Brazil’s LGPD (Law No. 13.709/2018)

Technify Tecnologia LTDA

CNPJ: 35.478.295/0001-90

Curitiba/PR - Brazil • Miami/FL - USA

math@technify.cloud

01. Who we are and what this policy covers

Technify Tecnologia LTDA (CNPJ 35.478.295/0001-90), based in Curitiba/PR, Brazil, develops Cérebro and is the controller of the personal data processed to provide the service. When a company creates a workspace and invites people, it decides what is recorded there, and we process that content to provide the service it signed up for.

This policy applies to the useocerebro.com website, the app.useocerebro.com app, Bob’s WhatsApp and Telegram channels, and the integrations with AI assistants, such as ChatGPT and Claude, through Cérebro’s MCP server. It follows Brazil’s General Data Protection Law (LGPD, Law No. 13.709/2018) and the Brazilian Internet Bill of Rights (Marco Civil da Internet, Law No. 12.965/2014).

02. Data we collect

We collect only what Cérebro needs to work:

Account data

Name, e-mail, phone (when provided), company or organization name and profile photo.

Login and authentication

If you sign in with Google or Meta (Facebook), we receive the account identifier, name and e-mail you authorized. If you use e-mail and password, the password is stored by the authentication service only as a hash.

Workspace content

Projects, briefs, phases, tasks, comments, documents, goals, contracts, focus sessions, time logs, uploaded files (such as images and meeting audio) and your conversations and commands with Bob and the agents.

Messaging channels

If you link WhatsApp or Telegram, we process the account number or identifier and the messages exchanged with Bob, including voice messages, which may be transcribed into text.

Integrations you turn on

Google Calendar and Google Meet (events and, when you authorize it, meeting data used to create minutes), Apple iCloud Calendar (the Apple ID and app-specific password you provide), Linear (issues) and the access tokens for these connections.

Connected AI assistants (MCP)

What ChatGPT, Claude or another MCP client sends or requests through the Cérebro connector, and the access tokens for that connection. Details are in the section on AI assistant integrations.

Payments

Plan, subscription status, amounts, billing history and Stripe customer identifiers. Card data is handled by Stripe; Cérebro does not store the full card number.

Your own AI key

On plans where you use your own OpenRouter or OpenAI key, we store the key encrypted. Once saved, the app only shows its last 4 characters.

Technical and browsing data

IP address, browser, operating system, access records, action audit logs and cookies. On the useocerebro.com website we use Google Tag Manager, Google Analytics and Meta Pixel (see the section on cookies).

03. Why we use data and on what legal basis

We process personal data only for the purposes below, each with a legal basis under Article 7 of the LGPD:

  • Create and maintain your account, the workspace and the integrations you turn on: performance of a contract (Art. 7, V).
  • Answer requests made to Bob, the agents and the assistants connected through MCP: performance of a contract (Art. 7, V).
  • Send notes, reminders and operational notices through the app, e-mail, WhatsApp or Telegram: performance of a contract (Art. 7, V).
  • Authenticate access, protect the account, prevent fraud and keep audit logs: legitimate interest (Art. 7, IX) and compliance with a legal obligation (Art. 7, II), such as keeping the access records required by the Marco Civil da Internet.
  • Bill subscriptions and issue invoices: performance of a contract (Art. 7, V) and compliance with a legal obligation (Art. 7, II).
  • Measure website visits and campaign results (Google Tag Manager, Google Analytics, Meta Pixel and Conversions API): legitimate interest (Art. 7, IX). You can object at any time, as explained in the section on cookies.
  • Defend rights in judicial, administrative or arbitration proceedings: regular exercise of rights (Art. 7, VI).

If a new feature depends on your consent, we will ask first, and you can withdraw it whenever you want.

04. Artificial intelligence

Bob, the agents, audio transcription and meaning-based search use third-party AI models accessed through APIs: OpenAI and, through OpenRouter, models from other providers such as Anthropic and Google, depending on the model used. For each request, we send the provider the context needed to generate the answer.

Technify does not use your data to train its own models and does not provide your data to train third-party models. AI providers are accessed through APIs, under terms that, by default, do not use data sent through the API to train models.

If you use your own OpenRouter or OpenAI key, requests are sent with that key and also follow the terms of your account with those providers.

AI suggestions (priorities, due dates, estimates, assignees) are proposals: you review and decide. Cérebro does not make decisions with legal effects on you based solely on automated processing. Even so, you can ask for a review of any automated decision (Art. 20 of the LGPD).

On the Free plan, Cérebro’s own AI features (Bob and the agents) are turned off.

05. AI assistant integrations (ChatGPT, Claude and MCP)

Cérebro has an MCP (Model Context Protocol) server at https://app.useocerebro.com/mcp. With it, you connect ChatGPT, Claude or another MCP client, such as Cursor, Claude Code, Codex and Antigravity, so your assistant can look up and organize your work in Cérebro. The integration is available on every plan, including Free.

In ChatGPT and Claude, the connection uses OAuth 2.1 with PKCE: you sign in to your Cérebro account, choose the workspace and click Allow. In desktop clients, you generate a key under Profile → Integrations and paste it into the client.

  • What the assistant can read: the list of projects; a project’s brief and phases; the list and content of documents; open tasks, task search by title and a task’s details with its most recent comments.
  • What the assistant can write: create tasks and phases, save documents (including the content of a conversation or summary you ask it to keep) and change a task’s status, with an optional comment.
  • Scope: only the workspace chosen during authorization, with your account’s permissions in that workspace. The assistant acts on your behalf: what it creates is recorded as yours.
  • Tokens and keys: we store only the hash of the tokens, never the token itself. Access lasts 1 hour and is renewed automatically for up to 60 days while the connector is on. The desktop key lasts 90 days, is shown only once, and generating a new one cancels the previous one.
  • Records: we do not keep a separate history of calls beyond the infrastructure’s technical logs. What the assistant creates shows up in the workspace like any other content.

What you type in ChatGPT, Claude or another assistant is processed by OpenAI, Anthropic or that assistant’s provider, under their own privacy policies. Cérebro only receives what the assistant sends through the connector’s tools (for example, a task title or a document’s text) and only returns the data it asks for, within the authorized workspace.

To revoke access: turn off or remove the connector in ChatGPT or Claude settings (the assistant stops using and renewing access, and the last token expires within 1 hour); in desktop clients, generate a new key, and the previous one stops working; or delete your account, which erases all tokens and keys. You can also ask us by e-mail (math@technify.cloud) to end all connections.

06. Sharing and processors

Technify does not sell or rent personal data. We share data only when needed, with:

  • The people in your workspace, according to the permissions set by whoever manages it;
  • Public authorities, when there is a legal obligation or a court order;
  • The processors below, which handle data on our behalf and only for the purposes described.
  • Supabase (USA): database, authentication, file storage and the app’s server functions.
  • Hostinger: hosting for the website and the web app.
  • OpenAI: AI models, real-time voice, audio transcription and meaning-based search (embeddings).
  • OpenRouter: access to AI models from other providers, such as Anthropic and Google, depending on the model used.
  • Meta: Facebook login, WhatsApp Cloud API (Bob’s channel), Meta Pixel on the website and Conversions API. When you buy a paid plan, the Conversions API receives the hashed e-mail, IP address, browser (user agent) and the fbp and fbc cookie identifiers, to measure campaigns.
  • Google: Google login, Google Calendar and Google Meet (when you connect them), Google Tag Manager and Google Analytics on the website.
  • Apple: iCloud Calendar sync (CalDAV), when you connect it.
  • Telegram: Bob’s channel, when you link it.
  • Stripe: payments, subscriptions and billing portal.
  • Resend: sending app e-mails, such as invitations and notices.
  • Linear: issue sync, when you connect it.
  • Manus: task execution by agents, when the feature is used.
  • v0 (Vercel): interface prototype generation, when the feature is used.

The assistants you connect through MCP (ChatGPT, Claude and others) are not Technify’s processors: you choose to connect them, and they follow their own providers’ policies.

07. International data transfers

Cérebro’s database is in the United States (Supabase, us-west-2 region), and several of the processors listed above handle data outside Brazil. As a result, your personal data is transferred to other countries.

These transfers follow Article 33 of the LGPD: they are necessary to perform the contract with you (Art. 33, IX) and rely on the contractual data protection commitments made by the providers (Art. 33, II). We choose providers that offer protection compatible with the LGPD.

08. How long we keep data

  • Account and workspace content: for as long as the account is active.
  • After the account is deleted: we remove the data from active systems. Copies in security backups expire within 30 days.
  • Assistant tokens and keys (MCP): expire on their own (access in 1 hour, renewal in 60 days, desktop key in 90 days) and are erased together with the account or the workspace. Authorization codes last 10 minutes.
  • Tax and payment records: for the period required by tax and accounting law (Art. 16 of the LGPD).
  • Technical and access logs: for as long as needed for security and troubleshooting; application access records, for the period required by the Marco Civil da Internet (Art. 15).
  • Website measurement data: according to the retention settings of Google Analytics and Meta.
  • Requests sent to AI providers: processed to generate the answer; providers may keep them for a limited period, under their own API terms.

09. Cookies and similar technologies

We use cookies and the browser’s local storage in three categories:

  • Essential: keep your session in the app and remember the chosen language. Without them, login does not work.
  • Analytics: Google Tag Manager and Google Analytics, on the useocerebro.com website, to measure visits and page usage.
  • Marketing: Meta Pixel, on the website, to measure campaigns. The fbp and fbc identifiers may also be sent through the Conversions API when you subscribe to a plan.

You can block or delete analytics and marketing cookies in your browser settings, use the Google Analytics opt-out add-on and adjust your ad preferences at Meta and Google. Blocking essential cookies prevents login to the app.

10. Your rights as a data subject

Under the LGPD (Art. 18), you can request at any time:

  • Confirmation that we process your data;
  • Access to your data;
  • Correction of incomplete, inaccurate or outdated data;
  • Anonymization, blocking or deletion of data that is unnecessary, excessive or processed in breach of the LGPD;
  • Portability of your data to another provider, upon express request;
  • Deletion of data processed based on your consent;
  • Information about the public and private entities we share your data with;
  • Information about the possibility of not giving consent and the consequences of refusing;
  • Withdrawal of consent;
  • Objection to processing based on legitimate interest;
  • Review of decisions made solely on the basis of automated processing (Art. 20).

You can download a copy of your projects and tasks yourself under Profile → Data, in CSV or JSON.

To exercise any right, write to math@technify.cloud from your account e-mail. We may ask you to confirm your identity. We reply within 15 days.

You can also file a complaint with Brazil’s National Data Protection Authority (ANPD), at gov.br/anpd.

To delete your account and your data, see the Data Deletion Instructions.

11. Information security

We use encryption in transit (TLS/HTTPS) and at rest, per-workspace access control in the database, access-privilege control, integration tokens stored only as hashes and customer AI keys stored encrypted.

No system is immune to failure. If a security incident may cause relevant risk or harm, we will notify the ANPD and the affected people, as required by Art. 48 of the LGPD.

12. Children and teenagers

Cérebro is a service for professional use and is not intended for people under 18. If we learn that we collected data from a child or teenager without the authorization required by law, we will delete it.

13. Changes to this policy

We may update this policy. The date at the top changes with each version and, when the change is material, we notify you in the app or by e-mail. The current version is always at useocerebro.com/privacidade.

14. Contact and data protection officer

For questions, requests or to exercise your rights over your personal data, contact the data protection officer:

Technify Tecnologia LTDA - Data Protection Officer

E-mail: math@technify.cloud

Address: Francisco Rocha, 62 - sala 05, Curitiba - PR, Brazil

Back to the home page

© 2026 Cérebro • Technify Tecnologia LTDA