Privacy Policy
Health data is sensitive personal data under Brazil's LGPD (art. 5, II). This page explains, plainly, what we do with yours.
Last updated on September 10, 2026.
Who is responsible for your data
The data controller is Hatching Code LTDA, registered in Brazil under CNPJ 54.934.111/0001-02. For any privacy matter, including requests for access, correction or deletion, write to privacidade@acalento.ai. We reply within 15 days.
What data we collect
We only collect what you type or upload. We do not buy databases, we do not import your history from anywhere and we do not track you outside the app.
- Account data: name, email and a password, which we store only as a hash (we cannot read your password)
- Health data you record: tests, vaccines, appointments, medications, symptoms and measurements, with dates, values and notes
- Documents you upload: photos and PDFs of tests, reports and vaccination cards
- Record profile: date of birth and biological sex, used to compute preventive reminders
- Dependents' records you create, with the same types of data as above
- Technical logs: date and time of access, IP address and the audit trail of who accessed whose data
Why we process this data
The legal basis is your consent, given explicitly at sign-up and recorded with date and version (LGPD, art. 7, I and art. 11, I). You can withdraw it at any time by deleting your account.
- Organize your health history in one place and show how your test results evolve
- Read the documents you upload and propose structured records from them
- Show preventive reminders applicable to your age and sex, based on public guidelines
- Keep the service secure and maintain the audit trail the LGPD itself requires
Artificial intelligence: it proposes, you decide
When you upload a document, its content (the photo or PDF, which may contain your name and health data) is sent to an artificial intelligence model to extract the data. The model runs on Magalu Cloud (MGC), the Brazilian cloud provider that hosts all of acalento's infrastructure, under contract and with no right to use the data for any other purpose; your document does not leave the country for this. The app asks your permission before the first upload, and you can simply not use automatic reading: everything can be recorded by hand.
What the AI returns is always a proposal. Nothing becomes a record in your history until you review and accept it. The AI does not diagnose, does not confirm diseases, does not recommend treatments and does not prescribe.
We do not use the content of your documents to train artificial intelligence models.
Who we share it with
No one, by default. We do not sell or hand over identifiable personal data, and we have no advertising. There are only three situations in which data leaves here:
- When you authorize it: when you grant access to a family member, caregiver or health professional, you define the role, the scope and the duration, and you can revoke it whenever you want (the cutoff applies on the next request)
- With vendors that operate the infrastructure on our behalf, under contract and with no right to use the data for anything else: Magalu Cloud (MGC), the Brazilian cloud that hosts the application, the database and the AI model that reads your documents
- When the law or a court order requires it
Aggregate, anonymous statistics
We may produce and commercialize aggregated, anonymized statistics, of the kind public health already uses: screening coverage, vaccination delays and gaps by age group and by region.
Aggregated means the number describes a group, never a person. Anonymized means it went through a process that prevents tracing it back to you, considering the technical means reasonably available (LGPD, art. 12). We do not publish slices small enough to allow anyone to be identified.
Your identifiable history is never sold, handed over or published. Ever.
Where the data lives and how it is protected
- Application, database and backups in a Brazilian cloud
- Traffic always encrypted in transit, and the database encrypted at rest
- Your documents never have a public link: downloading requires your authenticated session
- Every read and change of health data is recorded in an audit trail
- Passwords stored only as a hash, never in plain text
How long we keep it
For as long as your account exists. When you delete your account, the data is truly erased, right away, not frozen. Deletion takes effect immediately: a session open on another device stops working on the very next request.
Your rights
The LGPD (art. 18) gives you rights over your data, and they live inside the app, with no need to ask anyone:
- Access everything we have about you and export it in a single file, in the Account tab
- Correct wrong data by editing the record
- Delete your account and your whole history, in the Account tab, confirming with your password
- Know who has access to your record, and revoke it
- Withdraw consent, which in practice means deleting your account
Other people's data
You can create a record for a dependent, such as a child or a family member under your care. By doing so, you declare that you have the authority to handle that person's health data and you take responsibility for that declaration. A dependent's record has the same rights and the same protection as yours.
Children and teenagers
The app is for people aged 18 or over. A child's or teenager's record exists only as a dependent, created and managed by whoever is responsible for them, in their best interest (LGPD, art. 14).
Changes to this policy
If we change what we do with your data, we update this page and the version of the terms inside the app, and we ask for your acceptance again before you continue. This version is from September 10, 2026.