Skip to content
SFWD StudiosStraight Forward
StudioProductsLabSupport
/

Privacy / Com.partilha

Com.partilha — Privacy Policy

Com.partilha organizes expenses between people and therefore needs to maintain accounts, groups, and shared splits. This policy distinguishes what stays on the device, what goes to service infrastructure, and what other members can see.

Version 1.0 · Last updated: September 12, 2026View legal center
01Accounts and groups
02On-device OCR
03Contextual visibility
04No sale of data

Product data map

Local, remote, or shared — clearly separated.

This map describes the current beta and shows when information leaves the device or may be visible to another person.

Com.partilha data and feature inventory
CategoryInformation involvedWhere it stays or movesPurposeYour control
Account and authenticationInternal UUID, email, protected credentials, session, and SDK tokens.Supabase and Resend for transactional access messages.Create and protect the session.Sign out, recover access by email, and request rights from the studio.
ProfileName, @ handle, bio, photo, and visibility choice.Remote service; any authenticated account with a complete profile may search an exact @ handle.Identify participants and invitations without an open directory.Edit available fields and choose Restricted or Open visibility. Request correction where applicable.
Groups and invitationsTitle, type, emoji, owner, members, roles, invitations, dates, and status.Supabase and authorized members; invitees receive needed context.Organize participation and access.Accept or decline invitations; an authorized inviter may revoke them. Roles and members do not yet have remote editing in the App.
Shared events and expensesParticipants, items, quantities, amounts, fees, discounts, payers, revisions, approvals, closing, and partial settlements.Supabase and authorized members in the context.Calculate and maintain a common reference.Review before saving and avoid unnecessary data.
Local storage and draftsPix, local messages, goals, settlements, reported payments, installments, reminders, drafts, and cached loaded data.Protected file and recovery copy on the device; loaded groups, expenses, and settlements may have a separate remote version.Maintain features and local recovery.Edit, clear in the App, or remove the app, subject to remote layers.
Receipt and OCRSelected image, detected text, suggested items, indicators, and partial entries.On-device Apple Vision; image and raw text discarded. Suggestions may enter a local draft; saved data may become a remote expense.Prepare a draft for review.Choose the image, review, and decide what to save or share.
Shared PixKey, beneficiary, city, amount, and generated text or QR code.Pix profile on device; content passes through the share sheet or local clipboard, which expires within ten minutes and does not use Handoff.Facilitate a payment instruction outside the App.Review, edit, and choose where to paste or send; Com.partilha does not move money.
Technical logs and supportMay include IP, requests, and authentication and security events; email and message when sent.Supabase and necessary subprocessors; studio and email for support.Operate, protect, and support.Avoid unnecessary data and exercise rights through the published contact.

1. Scope, controller, and beta version

This policy applies to the current beta version of Com.partilha (the “App”), controlled by SFWD STUDIOS LTDA, registered in Brazil under CNPJ 68.097.694/0001-60, in São Paulo, Brazil, under the SFWD Studios brand. It does not cover the website, Ultimate Truco, or Ultimate Mahjong.

Com.partilha must process certain information to authenticate people, maintain groups, and synchronize expenses. We do not sell personal data. Material changes to features or processing will receive a new policy version and, where needed, an in-App notice.

2. Account, authentication, and profile

Registration and sign-in use email and password, with emailed codes for confirmation and recovery. Authentication infrastructure processes email, an internal identifier, protected credentials, session state, and tokens. Never share passwords or codes with support. Sign in with Apple is not an available sign-in method in the current version.

Profiles include a display name, @ handle, and optional bio and photo. Profile and group photos are resized and re-encoded on device to remove metadata such as location before upload to private service storage. Temporary URLs and authorization controls limit access; these photos do not follow the local receipt workflow.

3. Groups, invitations, events, and expenses

To operate groups, we store title, type, emoji, owner, members, roles, invitations, dates, and relevant status. Events may include a title, participants, and their relationship to the group.

Shared splits may contain title, method and status, participants, items, quantities, amounts, item claims or consumption, fees, discounts, adjustments, payer contributions, and revision or history metadata. This data is used to calculate and maintain a shared reference between participants.

Before entering information about another person, confirm that you have a legitimate reason and authority appropriate to the context. Avoid unnecessary details, sensitive information, and anything you should not share with group members.

4. What is also kept on the device

The App maintains a system-protected local snapshot and recovery copy. Depending on the features used, this file may include profile, Pix details, loaded groups and splits, on-device messages, savings goals, settlements, reported payments, installments, reminders, and recoverable drafts.

Messages, goals, installments, standalone splits outside groups, and certain drafts remain local. Group expenses, revisions, confirmations, and partial settlement records have a shared remote layer. Payers report payments and recipients confirm, decline, or follow their status; this is not bank verification. The local file can also cache remote information.

5. Visibility, search, and sharing

Authenticated and authorized members can see group, event, and split information needed for participation. This includes names, handles, roles, items, amounts, contributions, and status within the shared context. Database access controls restrict queries to authorized contexts, but other members can still see, copy, or record information legitimately displayed to them.

Authenticated accounts with complete profiles can search an exact @ handle and receive a name and handle. Restricted visibility, the default, limits bio and photo to authorized member contexts; Open visibility allows authenticated accounts to view them. A pending invitation alone does not unlock a restricted bio or photo. There is no public web directory. Changing visibility cannot recall copies already received. System sharing follows the chosen destination’s rules.

6. Receipts, camera, and local OCR

If you photograph or select a receipt, the image is processed locally with Apple Vision to suggest text, items, and amounts. The original image bytes are discarded after reading: the photo and raw recognized text are not sent to the server or stored by Com.partilha.

You must review the result. Suggested names and amounts, structured indicators, and partial entries may be saved automatically in a recoverable local draft even before final confirmation. When you save or share reviewed items as an expense, they are processed under the relevant category. Free-form comments about reading issues are not automatically persisted.

7. Pix and payment information

You may optionally store a Pix key — CPF, CNPJ, phone, email, or random key — and beneficiary name and city on the device to generate a QR code and copy-and-paste text. These details are not part of the public profile and, in the current version, are not sent to the remote service by the Pix-profile feature.

When you share Pix details, selected data may pass through the system share sheet or be copied to the local clipboard, configured to expire within ten minutes and without Handoff. Com.partilha is not a bank, payment institution, or wallet; it does not hold balances, move money, query banks, or independently confirm payment or receipt. Check everything in the financial institution’s application before authorizing.

8. Reminders and local notifications

Installment reminders use local notifications scheduled on the device. Identifiers and dates are used to schedule them, with reduced content to avoid displaying names, amounts, Pix keys, or bank details on the lock screen.

The current version does not register a push token with a server for this feature. You can deny or revoke permission in system Settings; cancelling the corresponding plan in the App removes its scheduled notices.

9. Technical data, support, and infrastructure logs

The App currently integrates no advertising, behavioral analytics, or crash-reporting SDK. Necessary infrastructure may nevertheless process IP address, timestamps, request data, technical identifiers, authentication events, and security and operational logs to deliver and protect the service.

When you send email support, we receive the address, name or signature, message, and chosen attachments. Do not send passwords, access codes, full card numbers, Pix keys, or another person’s information unless necessary for the request.

10. Providers and international operations

Supabase provides authentication, a database, and private photo storage, with authorized subprocessors. Resend sends transactional confirmation and account-recovery messages. Apple provides camera, photo selection, Vision, local notifications, and sharing. Other email providers participate when you contact support.

The country of processing depends on the configured project region, technical routing, and current subprocessors. Processing outside Brazil may occur. We apply available contractual documentation, minimization, access control, and valid mechanisms for the applicable operation; upon request, we will provide available information, subject to commercial and industrial confidentiality.

Supabase Data Processing Addendum ↗Supabase security ↗Apple Privacy Policy ↗

11. Purposes and legal grounds

We process account, profile, session, group, invitation, event, and split information to provide requested features and perform the user relationship. We may also process the minimum necessary under legitimate interests, assessed in context, for security, abuse prevention, support, correction, and defense of the service.

Legal or regulatory obligations and the establishment, exercise, or defense of legal claims may justify specific records. System permissions are requested in context and may be revoked in Settings. Where consent is the legal ground for a purpose, it will be requested specifically and may be withdrawn without affecting earlier lawful processing. Participants must have a legitimate reason and appropriate authority to enter another person’s data; SFWD Studios remains responsible for the applicable ground for processing it controls.

12. Retention

The local file remains until replaced or cleared by the App or system. Removing the App normally clears its container, but copies managed through iOS or Apple-account backups may follow system controls and reappear during restoration. Remote data remains while the account and service are active and for the period needed to preserve the integrity of groups and shared history, meet obligations, prevent abuse, and establish, exercise, or defend claims.

When a photo is removed or replaced, the app removes its reference and attempts to delete the old file. Failures may leave unreferenced private files, and the current version does not automatically clean up every such file. Requests can be sent to the studio.

Security and operational logs and backups follow provider technical cycles and are not necessarily deleted at the same instant as active data. The beta has no automatic time-based deletion routine covering every category, so we do not publish one fixed period that would be inaccurate. Requests are assessed through the published contact, considering what can be deleted, anonymized, detached, or must be retained on a legitimate ground.

13. Correction, access, portability, and deletion

You can correct certain details in the App and request confirmation, access, correction, sharing information, anonymization, blocking, deletion where applicable, portability within regulatory limits, objection, and other rights under Brazil’s LGPD.

In the current version, “Delete profile and data” removes the on-device snapshot and recovery copy and signs you out. That command does not by itself delete the authentication account or all remote data. To request remote-account deletion, a copy, or another right, email [email protected]. We may request the minimum needed to verify identity, account, and scope.

A request does not automatically erase content that also belongs to other members’ context or records required for an obligation, shared-history integrity, fraud prevention, or legal claims. We will assess what can be deleted, anonymized, detached, or retained and explain the applicable response; we do not promise immediate deletion from every layer.

Data-subject rights — ANPD ↗

14. Security

We use HTTPS connections, authenticated sessions, row-level database access rules, context separation, and complete file protection for the local copy.

No system is infallible. Com.partilha content is not advertised as end-to-end encrypted: authorized members and necessary infrastructure must process it to operate features. Protect your device and email, review group members, and report suspected unauthorized access.

15. Children, contact, and changes

The App is not directed specifically to children. Anyone unable to validly provide information or accept applicable conditions should use the service with appropriate authorization and supervision. If we identify child or teenager data processed without an appropriate ground, we will take proportionate steps considering best interests.

Questions, rights requests, and security reports may be sent to [email protected]. You may also petition Brazil’s National Data Protection Authority. Material changes will receive a new date and, where needed, an in-App notice or renewed consent.

Related documents

The product’s complete context.

ProductsProduct terms↗Ultimate TrucoUltimate Truco privacy↗Ultimate MahjongUltimate Mahjong privacy↗

SFWD Studios

Original ideas. Complete products.

[email protected]
StudioStudioProductsLabPrinciplesSupport
LegalLegalPrivacyCookies & StorageWebsite Terms
© 2026 SFWD StudiosRio de Janeiro, Brazil · São Paulo, Brazil
CNPJ · 68.097.694/0001-60