Privacy Policy
In force since 30 July 2026 · version 1.1, of 2 September 2026
This policy explains, without hedging, what happens to the data of people who use ShvIA — the site shvia.org, the web app at ai.shvia.org, and the iPhone, Android and desktop applications.
Translation notice. This is a translation provided for convenience. The controller is a Brazilian company and the governing law is Brazil's LGPD, so the Portuguese version prevails in the event of any divergence: Política de Privacidade.
The part that matters most: ShvIA is an AI gateway. Some models run on our own infrastructure and the text never leaves it; others are third-party models, and there the content of your message is sent to the provider you chose, including outside Brazil. You decide which model to use, conversation by conversation. Section 5 sets out what leaves, what never leaves, and the barriers that sit along the way.
- 1. Who processes your data
- 2. What data we process
- 3. What we use it for
- 4. On what legal basis
- 5. The AI providers and where your text goes
- 6. International transfer
- 7. How long we keep it
- 8. Your rights
- 9. Cookies
- 10. The mobile applications
- 11. Security
- 12. Minors
- 13. Changes to this policy
1. Who processes your data
The controller of the personal data processed in ShvIA, under Brazilian Law 13.709/2018 (LGPD), is BLUE3 TECNOLOGIA LTDA, registered under CNPJ no. 19.648.136/0001-30.
For any privacy matter — a question, or a request for access, correction or deletion — write to privacidade@shvia.org. For problems using the product, the channel is the support page.
2. What data we process
Data you provide when you sign up
- First and last name, e-mail address and date of birth.
- Phone number (country code, area code and number).
- Optionally, and only if you fill them in: job title, department, company, city, state, country and a free-text description of yourself.
- Your password, stored only as a hash — we have no way to read it.
Content you create using the product
- The messages in your conversations and the models' answers.
- Files you attach and the text extracted from them.
- Projects and folders, with the instructions and sources you attach to them.
- Your personal instructions (the “persona” that steers the answers).
- Long-term memories, when you use the memory feature — they exist so the assistant can recall context across conversations.
Data generated by use
- One record per inference call: the model and provider used, token counts, cost, latency and where the data was at that moment (our own infrastructure or the cloud). This is what backs the usage panel and the limits on your account.
- Activity and error logs, for audit and diagnosis.
- The date of your last access.
- Your IP address on authentication attempts — used to contain brute-force attacks.
Settings and third-party credentials
- Your preferences: theme, favourite models, usage limits.
- The API keys you register in order to use your own account at AI providers. They are per user: a call to a cloud provider uses the key of whoever is signed in, and a model only appears in the picker for someone who holds a key for it.
- If you enable notifications in the mobile app, the device identifier supplied by Apple or Google to deliver those notifications.
3. What we use it for
- Running the service: authenticating you, storing your conversations and answering.
- Measuring and limiting usage — the product shows the token and cost account, and applies the limits configured for your account.
- Security, audit and incident investigation.
- Support, when you come to us.
- Service announcements. E-mail or SMS messages that are not operational depend on your consent, which you may withdraw.
What we do not do: we do not sell personal data, we do not use your content for advertising, and we do not track you across third-party sites or applications.
4. On what legal basis
- Performance of a contract (LGPD art. 7, V) — registration, conversation content and usage records: without them there is no product.
- Legitimate interest (art. 7, IX) — security, audit and diagnostic records.
- Consent (art. 7, I) — non-operational communications by e-mail or SMS, and sending content to cloud providers when you choose one of those models.
- Compliance with a legal obligation (art. 7, II), where applicable.
5. The AI providers and where your text goes
This is the most important section in the document, because it is the one with concrete consequences for your day-to-day work.
ShvIA routes each message to the model you chose. There are two situations, and the product shows which one applies on every call:
- A model on our own infrastructure. The text is processed on servers under our control and is not sent to third parties.
- A model from a cloud provider. The conversation content — your message, the history that gives it context, and the files you attached to that conversation — is sent to the provider so that it can generate the answer. Available providers include Anthropic, OpenAI, Google, xAI, Mistral, Groq, DeepSeek, Perplexity, Z.ai and others, and that list may change over time. What each of them does with the data is governed by its own privacy policy.
The barriers along the way
When a call leaves for the cloud, the gateway applies protections before sending:
- Corporate knowledge never leaves. Context coming from the internal knowledge base is zeroed out on any call that is not on our own infrastructure. This is neither optional nor configurable.
- Masking of personal data on the way out. The text passes through a masker before going to a cloud provider. It is an automatic barrier, not an absolute guarantee: a personal detail written in a form the masker does not recognise can get through.
- LGPD protection, in your profile. With that option on, your project context and your personal instructions also stop accompanying calls to the cloud.
Rule of thumb: if a piece of data must not leave the country or your organisation, use a model on your own infrastructure. No amount of masking substitutes for that choice, and the choice is always yours.
Other third parties
Besides the AI providers, we use hosting and e-mail delivery services necessary for the product to work, and Apple and Google to deliver notifications to the mobile applications. All of them process data under our instruction and only for those purposes.
6. International transfer
By choosing a cloud model, you determine that the content of that conversation be processed where the provider operates — typically the United States and, for some providers, China. On every call the product records whether it ran on our own infrastructure, in a US cloud or in a Chinese cloud, so that this information remains auditable.
If you do not want international transfer, use the models on our own infrastructure.
7. How long we keep it
- Registration and content (conversations, files, projects, memories): as long as your account exists. You can delete conversations and files at any time from within the product.
- Inference, activity and error records: the configured retention policy is 180 days, with automatic daily purging.
- Once the account is closed, the data is deleted, except for whatever we need to retain to comply with a legal obligation or to exercise a right in legal proceedings.
8. Your rights
Article 18 of the LGPD guarantees you: confirmation that we process your data, access to it, correction of anything incomplete or out of date, anonymisation or deletion of unnecessary data, portability, information about whom we share it with, and withdrawal of consent.
To exercise any of them, write to privacidade@shvia.org. We will ask you to confirm your identity — so as not to hand your data to somebody else — and answer within 15 days.
9. Cookies
ShvIA uses only cookies necessary for it to work:
- Session and CSRF protection: they keep you authenticated and protect the forms.
- Theme: stores the visual preset you chose, so that it carries from the site into the application.
- Language: stores the language you chose, for the same reason — so the choice survives the sign-in instead of being made twice.
There is no advertising cookie and no third-party analytics cookie on this site.
10. The mobile applications
The iPhone and Android applications show the same product you use in the browser, authenticated by the same session. What is specific to them:
- Face ID, Touch ID or Android biometrics can be enabled to unlock the app. That verification happens on your device, by the operating system: no biometric data is sent to us or leaves the device.
- Camera and microphone are accessed only when you use voice dictation or attach a photo, and always after you have granted permission in the system.
- Notifications are only sent if you allow them. For that we store the device identifier supplied by Apple or Google.
- The application does not track you across other applications or sites, and integrates no advertising network.
11. Security
All traffic travels encrypted over HTTPS. Passwords are stored only as a hash. Administrative access is restricted by role and relevant actions are written to an audit log. Repeated login attempts are rate-limited by IP address.
No system is immune. Should a security incident occur with relevant risk to you, we will notify you and Brazil's National Data Protection Authority, as article 48 of the LGPD requires.
12. Minors
ShvIA is a professional tool and is not intended for people under 18. We do not intentionally collect data from children or adolescents. If we identify an account in that situation, it will be removed.
13. Changes to this policy
When this policy changes, the date at the top of the page changes with it. Material changes — especially any that widen the use of your data — are announced by e-mail before they take effect.