Privacy Policy

Health data is sensitive personal data under Brazil's LGPD (art. 5, II). This page explains, plainly, what we do with yours.

Last updated on September 10, 2026.

Who is responsible for your data

The data controller is Hatching Code LTDA, registered in Brazil under CNPJ 54.934.111/0001-02. For any privacy matter, including requests for access, correction or deletion, write to privacidade@acalento.ai. We reply within 15 days.

What data we collect

We only collect what you type or upload. We do not buy databases, we do not import your history from anywhere and we do not track you outside the app.

  • Account data: name, email and a password, which we store only as a hash (we cannot read your password)
  • Health data you record: tests, vaccines, appointments, medications, symptoms and measurements, with dates, values and notes
  • Documents you upload: photos and PDFs of tests, reports and vaccination cards
  • Record profile: date of birth and biological sex, used to compute preventive reminders
  • Dependents' records you create, with the same types of data as above
  • Technical logs: date and time of access, IP address and the audit trail of who accessed whose data

Why we process this data

The legal basis is your consent, given explicitly at sign-up and recorded with date and version (LGPD, art. 7, I and art. 11, I). You can withdraw it at any time by deleting your account.

  • Organize your health history in one place and show how your test results evolve
  • Read the documents you upload and propose structured records from them
  • Show preventive reminders applicable to your age and sex, based on public guidelines
  • Keep the service secure and maintain the audit trail the LGPD itself requires

Artificial intelligence: it proposes, you decide

When you upload a document, its content (the photo or PDF, which may contain your name and health data) is sent to an artificial intelligence model to extract the data. The model runs on Magalu Cloud (MGC), the Brazilian cloud provider that hosts all of acalento's infrastructure, under contract and with no right to use the data for any other purpose; your document does not leave the country for this. The app asks your permission before the first upload, and you can simply not use automatic reading: everything can be recorded by hand.

What the AI returns is always a proposal. Nothing becomes a record in your history until you review and accept it. The AI does not diagnose, does not confirm diseases, does not recommend treatments and does not prescribe.

We do not use the content of your documents to train artificial intelligence models.

Who we share it with

No one, by default. We do not sell or hand over identifiable personal data, and we have no advertising. There are only three situations in which data leaves here:

  • When you authorize it: when you grant access to a family member, caregiver or health professional, you define the role, the scope and the duration, and you can revoke it whenever you want (the cutoff applies on the next request)
  • With vendors that operate the infrastructure on our behalf, under contract and with no right to use the data for anything else: Magalu Cloud (MGC), the Brazilian cloud that hosts the application, the database and the AI model that reads your documents
  • When the law or a court order requires it

Aggregate, anonymous statistics

We may produce and commercialize aggregated, anonymized statistics, of the kind public health already uses: screening coverage, vaccination delays and gaps by age group and by region.

Aggregated means the number describes a group, never a person. Anonymized means it went through a process that prevents tracing it back to you, considering the technical means reasonably available (LGPD, art. 12). We do not publish slices small enough to allow anyone to be identified.

Your identifiable history is never sold, handed over or published. Ever.

Where the data lives and how it is protected

  • Application, database and backups in a Brazilian cloud
  • Traffic always encrypted in transit, and the database encrypted at rest
  • Your documents never have a public link: downloading requires your authenticated session
  • Every read and change of health data is recorded in an audit trail
  • Passwords stored only as a hash, never in plain text

How long we keep it

For as long as your account exists. When you delete your account, the data is truly erased, right away, not frozen. Deletion takes effect immediately: a session open on another device stops working on the very next request.

Your rights

The LGPD (art. 18) gives you rights over your data, and they live inside the app, with no need to ask anyone:

  • Access everything we have about you and export it in a single file, in the Account tab
  • Correct wrong data by editing the record
  • Delete your account and your whole history, in the Account tab, confirming with your password
  • Know who has access to your record, and revoke it
  • Withdraw consent, which in practice means deleting your account

Other people's data

You can create a record for a dependent, such as a child or a family member under your care. By doing so, you declare that you have the authority to handle that person's health data and you take responsibility for that declaration. A dependent's record has the same rights and the same protection as yours.

Children and teenagers

The app is for people aged 18 or over. A child's or teenager's record exists only as a dependent, created and managed by whoever is responsible for them, in their best interest (LGPD, art. 14).

Changes to this policy

If we change what we do with your data, we update this page and the version of the terms inside the app, and we ask for your acceptance again before you continue. This version is from September 10, 2026.

Back to the home page