Skip to content
SFWD StudiosStraight Forward
StudioProductsLabContact
/

Privacy / com.partilha

com.partilha — Privacy Policy

com.partilha organizes expenses between people and therefore needs to maintain accounts, groups, and shared splits. This policy distinguishes what stays on the device, what goes to service infrastructure, and what other members can see.

Version 1.0 · Last updated: August 31, 2026View legal center
01Accounts and groups
02On-device OCR
03Contextual visibility
04No sale of data

Product data map

Local, remote, or shared — clearly separated.

This map describes the current beta and shows when information leaves the device or may be visible to another person.

com.partilha data and feature inventory
CategoryInformation involvedWhere it stays or movesPurposeYour control
Account and authenticationInternal UUID, sign-in method, required email or Apple identifier, session, and SDK tokens.Supabase, Apple for Sign in with Apple, and the email provider when used.Create and protect the session.Sign out and request rights from the studio; the sign-in method is not editable in the current App.
ProfileDisplay name and @ handle.Remote service; any authenticated account with a complete profile may search an exact @ handle.Identify participants and invitations without an open directory.Edit the display name; the current @ handle is not editable in the App. Request correction where applicable.
Groups and invitationsTitle, type, emoji, owner, members, roles, invitations, dates, and status.Supabase and authorized members; invitees receive needed context.Organize participation and access.Accept or decline invitations; an authorized inviter may revoke them. Roles and members do not yet have remote editing in the App.
Shared events and expensesParticipants, items, quantities, amounts, claims, fees, discounts, adjustments, payers, and revisions.Supabase and authorized members in the context.Calculate and maintain a common reference.Review before saving and avoid unnecessary data.
Local storage and draftsPix, local messages, goals, settlements, reported payments, installments, reminders, drafts, and cached loaded data.Protected file and recovery copy on the device; loaded groups and expenses may have a separate remote version.Maintain features and local recovery.Edit, clear in the App, or remove the app, subject to remote layers.
Receipt and OCRSelected image, detected text, suggested items, indicators, and partial entries.On-device Apple Vision; image and raw text discarded. Suggestions may enter a local draft; saved data may become a remote expense.Prepare a draft for review.Choose the image, review, and decide what to save or share.
Shared PixKey, beneficiary, city, amount, and generated text or QR code.Pix profile on device; content passes through the share sheet or local clipboard, which expires within ten minutes and does not use Handoff.Facilitate a payment instruction outside the App.Review, edit, and choose where to paste or send; com.partilha does not move money.
Technical logs and supportMay include IP, requests, and authentication and security events; email and message when sent.Supabase and necessary subprocessors; studio and email for support.Operate, protect, and support.Avoid unnecessary data and exercise rights through the published contact.

1. Scope, controller, and beta version

This policy applies to the current beta version of com.partilha (the “App”), controlled by SFWD STUDIOS LTDA, registered in Brazil under CNPJ 68.097.694/0001-60, in São Paulo, Brazil, under the SFWD Studios brand. It does not cover the website, Ultimate Truco, or Ultimate Mahjong.

com.partilha must process certain information to authenticate people, maintain groups, and synchronize expenses. We do not sell personal data. Material changes to features or processing will receive a new policy version and, where needed, an in-App notice.

2. Account, authentication, and profile

You may sign in with Apple or with a code or link sent by email. The service processes an internal account identifier, session state, and tokens managed by the authentication SDK, together with the email address or Apple identifier required by the selected method.

Your profile includes a display name and public @ handle. These fields let members recognize one another, find someone by an exact @ handle, and present invitations. We do not publish your profile in an open user directory.

3. Groups, invitations, events, and expenses

To operate groups, we store title, type, emoji, owner, members, roles, invitations, dates, and relevant status. Events may include a title, participants, and their relationship to the group.

Shared splits may contain title, method and status, participants, items, quantities, amounts, item claims or consumption, fees, discounts, adjustments, payer contributions, and revision or history metadata. This data is used to calculate and maintain a shared reference between participants.

Before entering information about another person, confirm that you have a legitimate reason and authority appropriate to the context. Avoid unnecessary details, sensitive information, and anything you should not share with group members.

4. What is also kept on the device

The App maintains a system-protected local snapshot and recovery copy. Depending on the features used, this file may include profile, Pix details, loaded groups and splits, on-device messages, savings goals, settlements, reported payments, installments, reminders, and recoverable drafts.

In the current version, messages, goals, reported payments, installments, settlements, standalone splits outside a group, and certain drafts remain local and should not be understood as synchronized between devices. Loaded profile, group, event, and shared-expense data may also appear in this file as a cache of information with a separate remote layer.

5. Visibility, search, and sharing

Authenticated and authorized members can see group, event, and split information needed for participation. This includes names, handles, roles, items, amounts, contributions, and status within the shared context. Database access controls restrict queries to authorized contexts, but other members can still see, copy, or record information legitimately displayed to them.

Any authenticated account with a complete profile may search an exact @ handle and receive the matching name and handle to confirm the person; there is no open directory or approximate search. An invitation may show the inviter’s name and handle and the group name. When you use the system share sheet, selected content passes to the application or person you choose and then follows that destination’s rules.

6. Receipts, camera, and local OCR

If you photograph or select a receipt, the image is processed locally with Apple Vision to suggest text, items, and amounts. The original image bytes are discarded after reading: the photo and raw recognized text are not sent to the server or stored by com.partilha.

You must review the result. Suggested names and amounts, structured indicators, and partial entries may be saved automatically in a recoverable local draft even before final confirmation. When you save or share reviewed items as an expense, they are processed under the relevant category. Free-form comments about reading issues are not automatically persisted.

7. Pix and payment information

You may optionally store a Pix key — CPF, CNPJ, phone, email, or random key — and beneficiary name and city on the device to generate a QR code and copy-and-paste text. These details are not part of the public profile and, in the current version, are not sent to the remote service by the Pix-profile feature.

When you share Pix details, selected data may pass through the system share sheet or be copied to the local clipboard, configured to expire within ten minutes and without Handoff. com.partilha is not a bank, payment institution, or wallet; it does not hold balances, move money, query banks, or independently confirm payment or receipt. Check everything in the financial institution’s application before authorizing.

8. Reminders and local notifications

Installment reminders use local notifications scheduled on the device. Identifiers and dates are used to schedule them, with reduced content to avoid displaying names, amounts, Pix keys, or bank details on the lock screen.

The current version does not register a push token with a server for this feature. You can deny or revoke permission in system Settings; cancelling the corresponding plan in the App removes its scheduled notices.

9. Technical data, support, and infrastructure logs

The App currently integrates no advertising, behavioral analytics, or crash-reporting SDK. Necessary infrastructure may nevertheless process IP address, timestamps, request data, technical identifiers, authentication events, and security and operational logs to deliver and protect the service.

When you send email support, we receive the address, name or signature, message, and chosen attachments. Do not send passwords, access codes, full card numbers, Pix keys, or another person’s information unless necessary for the request.

10. Providers and international operations

Supabase provides authentication, database, and infrastructure components necessary for the service and may use authorized subprocessors. Apple processes Sign in with Apple and provides system features such as camera, photo selection, Vision, local notifications, and sharing. Email providers participate in login and support according to the chosen method or message.

The country of processing depends on the configured project region, technical routing, and current subprocessors. Processing outside Brazil may occur. We apply available contractual documentation, minimization, access control, and valid mechanisms for the applicable operation; upon request, we will provide available information, subject to commercial and industrial confidentiality.

Supabase Data Processing Addendum ↗Supabase security ↗Apple Privacy Policy ↗

11. Purposes and legal grounds

We process account, profile, session, group, invitation, event, and split information to provide requested features and perform the user relationship. We may also process the minimum necessary under legitimate interests, assessed in context, for security, abuse prevention, support, correction, and defense of the service.

Legal or regulatory obligations and the establishment, exercise, or defense of legal claims may justify specific records. System permissions are requested in context and may be revoked in Settings. Where consent is the legal ground for a purpose, it will be requested specifically and may be withdrawn without affecting earlier lawful processing. Participants must have a legitimate reason and appropriate authority to enter another person’s data; SFWD Studios remains responsible for the applicable ground for processing it controls.

12. Retention

The local file remains until replaced or cleared by the App or system. Removing the App normally clears its container, but copies managed through iOS or Apple-account backups may follow system controls and reappear during restoration. Remote data remains while the account and service are active and for the period needed to preserve the integrity of groups and shared history, meet obligations, prevent abuse, and establish, exercise, or defend claims.

Security and operational logs and backups follow provider technical cycles and are not necessarily deleted at the same instant as active data. The beta has no automatic time-based deletion routine covering every category, so we do not publish one fixed period that would be inaccurate. Requests are assessed through the published contact, considering what can be deleted, anonymized, detached, or must be retained on a legitimate ground.

13. Correction, access, portability, and deletion

You can correct certain details in the App and request confirmation, access, correction, sharing information, anonymization, blocking, deletion where applicable, portability within regulatory limits, objection, and other rights under Brazil’s LGPD.

In the current version, “Delete profile and data” removes the on-device snapshot and recovery copy and signs you out. That command does not by itself delete the authentication account or all remote data. To request remote-account deletion, a copy, or another right, email contact@sfwdstudios.com. We may request the minimum needed to verify identity, account, and scope.

A request does not automatically erase content that also belongs to other members’ context or records required for an obligation, shared-history integrity, fraud prevention, or legal claims. We will assess what can be deleted, anonymized, detached, or retained and explain the applicable response; we do not promise immediate deletion from every layer.

Data-subject rights — ANPD ↗

14. Security

We use HTTPS connections, authenticated sessions, row-level database access rules, context separation, and complete file protection for the local copy.

No system is infallible. com.partilha content is not advertised as end-to-end encrypted: authorized members and necessary infrastructure must process it to operate features. Protect your device and email, review group members, and report suspected unauthorized access.

15. Children, contact, and changes

The App is not directed specifically to children. Anyone unable to validly provide information or accept applicable conditions should use the service with appropriate authorization and supervision. If we identify child or teenager data processed without an appropriate ground, we will take proportionate steps considering best interests.

Questions, rights requests, and security reports may be sent to contact@sfwdstudios.com. You may also petition Brazil’s National Data Protection Authority. Material changes will receive a new date and, where needed, an in-App notice or renewed consent.

Related documents

The product’s complete context.

ProductsProduct terms↗Ultimate TrucoUltimate Truco privacy↗Ultimate MahjongUltimate Mahjong privacy↗

SFWD Studios

Original ideas. Complete products.

contact@sfwdstudios.com
StudioStudioProductsLabPrinciples
LegalLegalPrivacyCookies & StorageWebsite Terms
© 2026 SFWD StudiosRio de Janeiro, Brazil · São Paulo, Brazil
CNPJ · 68.097.694/0001-60