Cocoa Dev Privacy Policy
Last updated: June 21, 2025
Welcome to Cocoa Dev! At Cocoa Dev, we value your privacy and are committed to protecting your personal data. This Privacy Policy describes how we collect, use, store, share, and protect your information when you use our mobile applications and related services (hereinafter, "Services").
By using our Services, you agree to the practices described in this Privacy Policy. We recommend that you read it carefully.
1. Scope and Legal Compliance
This Privacy Policy applies to all applications and services offered by Cocoa Dev. Our goal is to comply with applicable data protection laws in the jurisdictions where we operate, including, but not limited to:
- Brazil: General Data Protection Law (LGPD - Law No. 13,709/2018).
- European Union: General Data Protection Regulation (GDPR - Regulation (EU) 2016/679).
- United States: State privacy laws, such as the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), among others.
In case of conflict between the laws of different jurisdictions, we will seek to apply the highest standard of data protection, whenever possible and reasonable.
2. Definitions
For the purposes of this Policy, the terms below shall have the following meanings:
- Personal Data: Any information relating to an identified or identifiable natural person.
- Data Subject: The natural person to whom the Personal Data that is the subject of processing refers.
- Processing: Any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- Controller: The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
- Processor: A natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.
3. Personal Data Collected
We collect different types of Personal Data, depending on the application and how you interact with our Services:
3.1. Data You Provide
- Registration Data: Full name, email address, phone number, date of birth, CPF (for transactions in Brazil), postal address, profile information (photo, username).
- Payment Data: Credit/debit card information, bank account details (collected and processed by third-party payment providers, such as RevenueCat for subscriptions, and not directly stored by us).
- Communication Data: Content of messages, emails, or other communications you send us, including customer support.
- Content Data: Information you create, upload, or publish in our applications (e.g., photos, videos, text, comments), if the application allows.
3.2. Automatically Collected Data
- Device and Connection Data: IP address, device type, operating system (iOS/Android), unique device identifiers (UDID, IDFA, GAID), mobile network information, mobile network data (Wi-Fi, 3G/4G/5G), device settings.
- Usage and Interaction Data: How you use our Services, including features accessed, time spent, functionalities used, clicks, screen views, in-app events. We use tools like Mixpanel for user behavior and event analysis.
- Location Data: If you grant us permission, we may collect precise or approximate location data from your device (GPS, Wi-Fi, cell tower data).
- Transaction Data: Purchase history, subscriptions, acquired items, values (managed by platforms like RevenueCat for subscriptions and in-app purchases).
- Backend and Authentication Data: Information related to your account and authentication, managed by services like Firebase (Google) and Supabase (PostgreSQL, authentication, real-time data storage).
- Error and Performance Data: Crash reports, application performance data, information about bugs and errors.
4. How We Collect Your Data
We collect your Personal Data in the following ways:
- Directly from You: When you register, fill out forms, make purchases, interact with support, or use features that require your data input.
- Automatically: Through the use of technologies such as SDKs (Software Development Kits) and APIs (Application Programming Interfaces) integrated into our applications (e.g., Expo, Firebase, Supabase, Mixpanel, RevenueCat SDKs), which collect usage, device, and interaction data.
- From Third Parties: We may receive information about you from business partners, service providers, or other public sources, always in compliance with applicable laws.
5. Purpose of Personal Data Processing
We use your Personal Data for the following purposes:
- Provide and Manage Services: Operate, maintain, improve, and personalize our applications and services, including creating and managing accounts, processing transactions, and providing requested functionalities.
- Improve User Experience: Understand how you use our Services to develop new features, optimize performance, and personalize content and offers.
- Communication: Send important notifications about your account, Service updates, security information, and respond to your support requests.
- Marketing and Advertising: With your consent (when required by law), send marketing communications about our products and services, offers, and promotions. You can opt out of receiving these communications at any time.
- Analysis and Research: Conduct data analysis, research, and statistics to understand usage trends, measure campaign effectiveness, and improve our products and business strategies. This is done with the help of tools like Mixpanel.
- Security and Fraud Prevention: Protect our Services and users against fraudulent activities, unauthorized access, and other security threats.
- Legal and Regulatory Compliance: Comply with legal, regulatory, and judicial obligations, including responding to requests from competent authorities.
6. Legal Basis for Data Processing
We process your Personal Data based on the following legal justifications, in accordance with LGPD, GDPR, and other applicable laws:
- Consent: When you give us explicit permission to process your Personal Data for a specific purpose (e.g., marketing, precise location collection).
- Contract Performance: When processing is necessary to fulfill a contract with you or to take pre-contractual steps at your request (e.g., providing the service you requested).
- Legal or Regulatory Obligation: When we are legally required to process your Personal Data (e.g., data retention for tax purposes).
- Legitimate Interest: When processing is necessary for our legitimate interests or those of third parties, provided that your fundamental rights and freedoms are not overridden (e.g., product improvement, security, fraud prevention, data analysis for service optimization).
- Regular Exercise of Rights: For the regular exercise of rights in judicial, administrative, or arbitration proceedings.
7. Sharing Personal Data
We may share your Personal Data with third parties in the following situations:
- Service Providers: We share data with companies that assist us in operating our Services, such as:
- Firebase (Google): For authentication, real-time database, file storage, cloud functions, and usage analytics.
- Supabase: For database (PostgreSQL), authentication, and APIs.
- Mixpanel: For user behavior and in-app event analysis.
- RevenueCat: For subscription and in-app purchase management, payment processing.
- Other providers for hosting, payment processing, customer support, marketing, data analytics, and security.
- Business Partners: With your consent, we may share data with partners to offer joint products or services.
- Legal Authorities: When required by law, court order, or request from governmental authorities, we may disclose your data.
- Corporate Transactions: In the event of a merger, acquisition, asset sale, or reorganization, your data may be transferred as part of the company's assets.
- With Your Consent: We may share your data with third parties for any other purpose with your explicit consent.
8. International Data Transfers
As we use global service providers (such as Google Firebase, Mixpanel, RevenueCat, Supabase), your Personal Data may be transferred to and stored on servers located outside your country of residence, including the United States and other jurisdictions that may not offer the same level of data protection as your country.
In such cases, Cocoa Dev implements appropriate safeguards to ensure your data remains protected, such as:
- Standard Contractual Clauses (SCCs): As approved by the European Commission.
- Approved Transfer Mechanisms: Such as the Data Privacy Framework (for transfers to the US, where applicable).
- Explicit Consent: When applicable and required by law.
9. Data Storage and Security
Your Personal Data is stored for as long as necessary to fulfill the purposes for which it was collected, to comply with legal or regulatory obligations, or for the regular exercise of rights. After this period, the data is deleted or anonymized.
We implement robust technical and organizational security measures to protect your Personal Data against unauthorized access, alteration, disclosure, or destruction. This includes encryption, firewalls, access controls, employee training, and regular audits. However, no data transmission over the internet or storage system is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
10. Your Rights as a Data Subject
You have the following rights regarding your Personal Data, according to applicable data protection laws:
- Right of Access: Obtain confirmation as to whether or not Personal Data concerning you are being processed, and, where that is the case, access to the Personal Data.
- Right to Rectification/Correction: Request the correction of incomplete, inaccurate, or outdated data.
- Right to Erasure/Anonymization/Blocking: Request the anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data.
- Right to Data Portability: Receive your Personal Data in a structured, commonly used, and machine-readable format, and transmit it to another controller.
- Right to Object: Object to the processing of your Personal Data when there is no legal basis for it or when the processing is for direct marketing purposes.
- Right to Withdraw Consent: Withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
- Right to Information: Obtain information about the public and private entities with which Cocoa Dev has shared your data.
- Right to Lodge a Complaint: Lodge a complaint with the competent data protection authority (e.g., ANPD in Brazil, DPA in the EU, or state attorney general in the US).
To exercise any of these rights, please contact us through the channels indicated in Section 12 of this Policy.
11. Cookies and Similar Technologies
Our applications and websites may use cookies and other tracking technologies to collect information about your browsing and interaction with our Services. This helps us personalize your experience, analyze trends, administer the website/application, track users' movements, and gather demographic information about our user base as a whole.
You can manage your cookie preferences through your browser or device settings. Disabling certain cookies may affect the functionality of our Services.
12. Changes to This Privacy Policy
Cocoa Dev may update this Privacy Policy periodically to reflect changes in our data practices or legal requirements. When we make significant changes, we will notify you through a notification in our applications, by email, or by publishing the updated policy on our website. We recommend that you review this Privacy Policy regularly.
13. Contact
If you have any questions about this Privacy Policy, the processing of your Personal Data, or wish to exercise your rights, please contact us:
Cocoa Dev
Email: privacy@cocoad.dev (example)
Address: [Your Physical Address, if applicable]