Privacy

Privacy Policy

v1 Published August 1, 2026 · Effective since August 1, 2026 · Terms of Use

This is the English version of a Policy whose original text is in Portuguese. Where the law of your country entitles you to rely on the version in the language you contracted in, that version prevails for you — see section 1 — read the original (Política de Privacidade).

1. Who we are, scope and territory

This Privacy Policy describes how Epdex — a series and movie tracking app, available at epdex.app and in the app stores — handles personal data.

Controller (art. 5, VI of the Lei Geral de Proteção de Dados, Law No. 13,709/2018 — LGPD, Brazil's General Data Protection Law; also controller within the meaning of art. 4(7) of Regulation (EU) 2016/679 — GDPR): iVidal Soluções Digitais, registered under CNPJ (Brazilian corporate taxpayer ID) No. 12.100.698/0001-04, with mailing address in Itapetininga/SP, Brazil — P.O. Box (Caixa Postal) No. 2.

Territory. Epdex is offered globally. The controller is Brazilian, and the service is made available to people in any country where the app stores distribute it, except where local law forbids it. Depending on where you live, the following regimes apply to this processing:

RegimeWhen it applies to you
LGPD — Law No. 13,709/2018 (Brazil)To processing carried out in Brazil, to offering the service to people in Brazil and, because we are a Brazilian controller, to our activity as a whole
GDPR — Regulation (EU) 2016/679To you if you are in the European Union or the European Economic Area, because we offer the service to people in that territory (art. 3(2)(a))
UK GDPR and the Data Protection Act 2018To you if you are in the United Kingdom
CCPA/CPRA and equivalent U.S. state lawsTo you if you are a California resident, or a resident of another U.S. state with equivalent privacy legislation

The greater protection always wins. Where one of these regimes gives you more protection than the others, the greater one is what applies to you. Nothing in this Policy reduces a right that the law of your country of residence grants you and that cannot be waived by contract.

Because we are based in Brazil, our operation also remains subject to the Marco Civil da Internet (Law No. 12,965/2014, Brazil's Internet Civil Framework) and the Código de Defesa do Consumidor (Brazil's Consumer Protection Code) — including the duties they impose on us regarding you, such as the retention of access logs covered in section 7.

Languages. This Policy is published in Portuguese (Brazil) and English, and the app interface is available in those same two languages. The Portuguese version is the original text. Where the law of your country requires that the document be presented to you in another language, or entitles you to rely on the version in the language you contracted in, that version prevails for you. The Portuguese original is at epdex.app/politica-de-privacidade.html.

2. Data we collect

We collect the minimum necessary. Data minimization is a design premise, not a statement of intent.

Where this data comes from. Most of it comes from you — what you type, mark and upload. The rest comes from your device and your connection (IP address, model, system version), from the login provider you choose, when you sign in through one, and from other users, in two situations only: when someone accepts your friend invite (or you accept theirs) and when someone reports content of yours. We do not buy data from anyone and we do not receive data about you from data brokers or advertising networks.

a) Data you provide

  • Name — optional.
  • E-mail — required when signing up with e-mail and password; optional when you sign in through an external provider that does not supply it, as is the case with TikTok. Without an e-mail your account works normally, but we cannot send password recovery or e-mail notices.
  • Password — only when signing up with e-mail. We never store your password: we keep an irreversible cryptographic hash.
  • Login provider identifier — when you sign in through an external provider (currently Google or TikTok), we receive an identifier for your account on that service, and your name when available. If we offer other providers — such as Sign in with Apple, once the app is available on the App Store — exactly the same rules of this Policy apply.
  • Your usage content — titles on your watchlist, marked episodes, ratings, reactions, lists and your language, theme and privacy preferences.
  • Date of birth — provided at sign-up, or later, under Settings (see section 10). We use it exclusively to (i) verify the minimum age of 16 and (ii) apply the safeguards for teenagers described in sections 5 and 10. It is never shown to anyone.
  • Handle and display name — a handle is created automatically when your account is born and can be edited at any time. It is part of your Public Profile Information (see section 5). Your e-mail always stays private.
  • Profile photo — optional, uploaded by you and cropped within the app itself. It is part of your Public Profile Information; you can change or remove it at any time.
  • Comments and public interactions — comments you write about titles and episodes (with an image or GIF, when you attach one), and comments and reactions on other users' posts. They are content posted in a community space — see section 5 — and can be deleted by you.
  • Friends and invites — the personal invite link you can generate, and the friendships created when someone opens that link (or when you open someone else's), with a record of who invited whom and since when. You can generate a new link — the previous one stops working — and undo any friendship at any time.
  • Imported history — when importing a file from another service, we read only the tracking data. Credentials, access tokens, IP addresses, device data and advertising identifiers that may be present in the file are discarded without being stored.
  • Share links — when you share a title, episode or list, we create a short link and record what you shared, when, and an aggregate count of how many times the link was opened. We do not identify whoever opens the link — we only count the opening.
  • What you write in the Help Center — when you open an issue or an idea on the public Help board, we store the title, the description, the area you indicated, your votes on other people's posts and the replies our team publishes. If you check post anonymously, your handle is not shown to anyone on the board — but the post remains linked to your account, so that you can see it under "My reports" and be notified when we reply. Tell us only what is necessary: the form warns you, and we reinforce it here, that you should not write personal data (yours or anyone else's) in the body of the post.
  • Reports you file — what was reported, the reasons chosen, the details you wrote, when, and what our team decided. This history is visible only to you, under "My reports" in the Help Center, and to the moderation team.
  • E-mail left on the waiting list — if you signed up for the site's waiting list before launch, we keep that e-mail for a single purpose: to let you know when Epdex opens. Once that purpose is fulfilled, it is deleted (see section 7).
  • Acceptance record — date, time and version of the documents you accepted (see section 12).

b) Data collected automatically

  • IP address, device type and version, operating system and app version.
  • Approximate location, inferred from the IP address — country, state and, temporarily, city. This inference is made within our own servers, by looking up a local database: your IP address is not sent to any third-party geolocation service. We never use GPS. We also record whether the connection appears to come from a VPN, so as not to distort regional statistics.
  • Configured language.
  • Technical access logs and error events.
  • App telemetry events — only if you authorize it (see section 4).

About the city: we keep little, and for a short time. The city stays linked to your tracking record only until the statistical week closes; after that it is deleted automatically, leaving only country and state. We use this data to understand, in aggregate, what is being watched in each region of Brazil — never to identify or locate you. See section 3.

c) What we deliberately do not collect

  • Advertising identifiers and cross-app tracking.
  • Precise location (GPS).
  • The list of apps installed on your device.
  • Sensitive data (art. 5, II of the LGPD) and payment data.

d) What you must provide, and what happens if you do not

Nothing here is asked out of curiosity. This table says, item by item, whether providing the data is a contractual or statutory requirement, and what the concrete consequence of not providing it is:

DataIs it required?If you do not provide it
E-mail and passwordYes, if you choose to sign up with e-mail — it is a contractual requirement: without them there is no way to authenticate you through that routeYou do not create the account by e-mail, but you can sign in through an external provider. Signing in through a provider that does not supply an e-mail, the account works normally — only without password recovery and without e-mail notices
Date of birthYes, at sign-up — it is how we verify the minimum age of 16 and apply the safeguards for teenagersThe account is not created. Accounts from the testing period, predating this collection, are not required to provide it and stay under the most protective regime, with a private profile (section 10)
Name, profile photo and a custom handleNoNothing changes: your account is born with an automatically generated handle, and the whole service works without a name and without a photo
IP address, device data and technical access logsThey are not asked of you — they exist because the connection exists, and keeping access logs is a legal obligation (section 7)There is no way to use an online service without your connection generating that record; what we do is keep the minimum, for the minimum period
App telemetry and analytics cookiesNo — they depend on your consentNothing changes for you: declining does not limit any part of the service (section 4)
Promotional communicationsNo — they depend on your consentYou stop receiving that kind of message. Service notices and release notifications continue, because they are part of what you signed up for
Content you post — comments, Help Center posts, reportsNoNothing: the whole of Epdex works without you posting anything

3. Legal bases and purposes

Every processing activity has a specific purpose and an identified legal basis — under art. 7 of the LGPD and, for those in the EU/EEA, under art. 6(1) of the GDPR. For those in the United Kingdom, the corresponding provisions of the UK GDPR apply.

PurposeLegal basis (LGPD)Legal basis (GDPR)
Create and maintain your account, authenticate accessPerformance of a contract (art. 7, V)Performance of a contract — art. 6(1)(b)
Record and sync your tracking historyPerformance of a contract (art. 7, V)Performance of a contract — art. 6(1)(b)
Import history from another service, when you request itPerformance of a contract (art. 7, V)Performance of a contract — art. 6(1)(b)
Release notifications and service noticesPerformance of a contract (art. 7, V)Performance of a contract — art. 6(1)(b)
Promotional communicationsConsent (art. 7, I)Consent — art. 6(1)(a)
Display your Public Profile Information — handle/display name, photo and public activity — to other users, when your profile is public (see section 5)Performance of a contract (art. 7, V)Performance of a contract — art. 6(1)(b)
Operate community features — comments, reactions and conversations between users — including moderation and abuse preventionPerformance of a contract (art. 7, V) and legitimate interest (art. 7, IX)Performance of a contract — art. 6(1)(b) — and legitimate interest — art. 6(1)(f)
Display the profile of teenagers (16 to 17 years old) to other users — requires the data subject to make the profile public through an affirmative actionConsent (art. 7, I), with regard to their best interests (art. 14)Consent — art. 6(1)(a) — subject to art. 8
Security, fraud and abuse prevention, stabilityLegitimate interest (art. 7, IX)Legitimate interest — art. 6(1)(f)
Aggregate audience statistics by region and week, to guide the catalog, translations and product prioritiesLegitimate interest (art. 7, IX)Legitimate interest — art. 6(1)(f)
Product metrics, analytics cookies and prioritization of languages and regionsConsent (art. 7, I)Consent — art. 6(1)(a) — and art. 5(3) of Directive 2002/58/EC (ePrivacy)
Record of document acceptanceCompliance with a legal obligation (art. 7, II) and regular exercise of rights (art. 7, VI)Legal obligation — art. 6(1)(c) — and legitimate interest — art. 6(1)(f)
Respond to authorities and comply with the lawLegal obligation (art. 7, II)Legal obligation — art. 6(1)(c)

Why a public profile is performance of a contract, not consent. Epdex is, by nature, a service with a community dimension: tracking series and movies together with other people — seeing what friends watch, commenting, reacting — is part of the product you sign up for when you create the account, just as displaying your profile is part of using a social network. That is why the display of your Public Profile Information relies on art. 7, V of the LGPD and on art. 6(1)(b) of the GDPR — performance of the contract entered into with you, under both regimes —, with the following safeguards: (i) the set of what is public is closed and listed in section 5 — everything else remains private; (ii) you can make your profile private at any time, with immediate effect and without losing any other feature of the service — or, if you prefer a middle ground, hide specific parts of the profile (ratings, list, activity, friends or individual titles) without making it private; (iii) teenagers have their profile private by default; and (iv) for processing based on legitimate interest, we keep a documented balancing report — the test that weighs our interest against your rights and reasonable expectations (art. 10, § 3 of the LGPD and recital 47 of the GDPR) —, and you can object to any of it through dpo@epdex.app (art. 18, § 2 of the LGPD and art. 21 of the GDPR).

Which "legitimate interests", exactly, the table refers to. Where the legal basis is legitimate interest (art. 7, IX of the LGPD and art. 6(1)(f) of the GDPR), the interest we pursue is always one of these four, and no other: keeping the service up, stable and secure; preventing fraud, abuse and automated misuse, including by moderating what is posted; understanding in aggregate what is being watched, so as to decide the catalog, translations and product priorities; and being able to prove which version of the documents applied to our relationship with you at each moment. None of them is advertising, data selling or commercial profiling. For each one we keep the balancing report mentioned above, and you can object to any of them through dpo@epdex.app — see section 6.

How we use aggregate data to improve the service

We analyze aggregate patterns, never individual behavior. These are two different things, with different legal bases:

Audience statistics by region (legitimate interest — do not depend on authorization)

How many people watched each title, in each region of Brazil, in each week. These numbers are built in such a way that it is not possible to trace them back to you:

  • the statistic stores no user identifier at all — not your id, not your handle, not any code derived from them;
  • a slice only comes into existence once it gathers at least 5 distinct people. Below that it is not stored — a group of one is not a statistic, it is personal data under another name;
  • the finer the geographic slice, the more people it requires to exist: if a neighborhood or city does not gather enough people, the number only exists at the state or country level.

You can object to this processing at any time through dpo@epdex.app (art. 18, § 2 of the LGPD).

Product telemetry (consent — only if you authorize it)

  • Languages and translations: concentration of use by language and region tells us what to translate next.
  • Catalog by region: which regions demand which "where to watch" data.
  • Catalog failures: titles the import could not match and searches with no results reveal gaps to fix.
  • Performance by device: model and system version guide where to optimize.
  • Login methods: which provider is actually used.
  • Stability: error reports to fix crashes.

Automated decisions

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (art. 20 of the LGPD and art. 22 of the GDPR). Catalog recommendations, list ordering and what shows up in your feed are personalization: they help you find something to watch and decide nothing about your life, your access to the service or your rights. The decisions that do carry weight — closing an account, permanently removing reported content — are reviewed by a person on our team. Even so, the right to request review provided for in art. 20 of the LGPD is recorded here and can be exercised through dpo@epdex.app.

What feeds personalization. It is not an automated decision, but it is still a calculated result you are shown — so it is worth saying how it is calculated. Recommendations, Surprise me and the ordering of lists use your own history inside Epdex: the genres and languages of the titles you finished and rated well (what you abandoned counts as a negative signal), what is on your list, and what you accepted or declined among earlier suggestions — weighted towards what is recent, because taste moves. What does not go into it: data bought from third parties, your behavior outside Epdex, or any sensitive characteristic — we do not use your age, gender, origin, religion or orientation to decide what to show you. And you hold the controls: marking, rating, abandoning or declining a suggestion feeds straight back into the calculation.

4. Cookies, analytics and consent

No analytics happens before you choose. Not on the site, not in the app.

On the site. When you visit epdex.app for the first time, you will see a notice with three equivalent options: accept all, reject non-essential and manage. No non-essential cookie is activated before you choose, and Google Analytics is only loaded if you accept analytics cookies. You can review or withdraw your choice at any time through the Cookie preferences link, in the footer.

In the app. Telemetry is off by default. No telemetry event is sent until you turn it on under Settings → Privacy. You can turn it off whenever you want, with immediate effect. We do not use advertising SDKs, advertising identifiers or cross-app tracking.

What this does not affect. Your tracking history — the episodes and movies you mark — keeps being saved with or without telemetry: it is the service you signed up for, not usage measurement. The same goes for the aggregate audience statistics described in section 3, which do not depend on this choice and which you can object to through dpo@epdex.app.

Cookies we use on the site

CategoryPurposeLegal basisCan you decline?
EssentialAuthenticated session, security, language, theme and the record of your cookie choicePerformance of a contract / legitimate interestNo — without them the service does not work
AnalyticsMeasure audience and aggregate usage (Google Analytics: _ga, _ga_<ID> cookies, with a pseudonymous identifier)ConsentYes
AdvertisingNot used

Declining analytics cookies does not limit your access to any part of the service.

We do not sell your data and we do not share it for targeted advertising.

5. Who we share with

We do not sell personal data. We do not share it with third parties for advertising.

With other Epdex users — your public profile

Your e-mail is never shown to anyone else, anywhere, under any circumstances. The same goes for your date of birth and your password.

What is public has a name and a closed list. We call Public Profile Information the following set — and only this set:

  • your handle or display name and your profile photo;
  • your public tracking activity: titles and episodes you marked as watched, titles you added to your list, titles you started rewatching, and the ratings you gave them;
  • your comments on titles and episodes (with an image or GIF, when you attach one) and your comments and reactions on posts by other users.

This information is visible to other authenticated Epdex users. Since 17 September 2026, your profile page can also be opened by someone who does not have an account, through a direct link — that is what lets a profile you shared be seen by whoever received the link. In that case, the visitor sees less than an authenticated user would:

  • they see your handle, your photo, your cover and a summary of your collection (counters and highlights);
  • they do not see the ratings you gave anything — neither the average nor how many;
  • they cannot open your followers, who you follow, your achievements or your full collection — only how many there are; opening any of those lists requires an account;
  • they neither read nor write comments: they only see how many people commented.

We still block indexing and scraping of that content: the page exists for whoever has the link, not for search engines. And all of this applies to public profiles only — if your profile is private, a visitor sees the same neutral label every other user sees.

What is never public, even with a public profile: your e-mail; your date of birth; your searches; your emotion reactions to titles ("how you felt" — that is your diary, not a showcase); the titles you mark as hidden, one by one; and any content whose visibility you have restricted.

Public by default, private by choice — with immediate effect. The profile of adults is public by default: that is how the community dimension of Epdex works. You can make your profile private at any time, under Settings → Privacy, with immediate effect: your name and photo stop being displayed (other users see a neutral label, with name and photo blurred) and your activity leaves everyone else's view. No other feature of the service is lost by making that choice. Accounts with no date of birth on record remain under the most protective regime — private profile — until the account holder provides it.

You do not have to choose between all or nothing. Keeping your profile public, you can hide specific parts of it, one by one, under Settings → Privacy: the ratings you give titles; your watchlist; your recent activity of episodes and check-ins; your friends list; and any individual title, one by one, from the title's own page. What you hide leaves everyone else's view immediately. When you show it again, that information reappears on your profile — but the period during which it was hidden does not retroactively enter anyone's updates.

You see this choice before anything is displayed. The visibility setting is presented during sign-up itself, for new accounts — and, for accounts from the testing period (with no date of birth on record), at the moment the account holder provides the date under Settings (section 10). In both cases, you confirm the public default or make your profile private right there, before any of your information is shown to anyone else. And it is made clear what confirming exposes: by confirming the public default, your library — watched titles, watchlist and ratings — becomes visible on your profile, and your activity starts feeding everyone else's updates from that point on; what you recorded before does not retroactively enter anyone's feed.

Teenagers (16 to 17 years old): private by default. With regard to their best interests (art. 14 of the LGPD), a teenager's profile is born private and only becomes public through an affirmative action by the account holder, reversible at any time.

When you turn 18. Your age is recalculated from the date you provided — it is not frozen on the day you signed up. When you turn 18, your profile does not become public on its own: what happens is that the option to adopt the adult default appears under Settings, and it only applies if you choose it. If you do, the visibility applies from that moment on: the activity you recorded while you were a teenager stays out of everyone else's view.

Spoiler protection remains. Activity about episodes ahead of the viewer's own progress arrives protected — the other user decides whether to reveal it.

Invites and friendships. Your personal invite link shows your display name to whoever opens it. You can, at any time, generate a new link (the previous one stops working) or undo a friendship. "Friends" are users connected through an accepted invite; each person's friends list is visible according to the visibility of their profile — and can be hidden separately, without making the profile private, through the specific option described above.

Moderation. Content posted in a community space is subject to the conduct rules of the Terms of Use and to the reporting channel: reported content is taken down immediately until reviewed by our team, and every moderation decision is logged.

The Help Center board. What you post under Help → Issues and ideas is visible to anyone with an Epdex account who opens the Help Center — not to the open internet: the area requires you to be signed in through the app, and the pages are served with a no-index instruction for search engines. Your handle appears next to your post, unless you choose to post anonymously. There are no comments from other users on the board: the only public reply is our team's, signed as "Epdex Team" — the name or e-mail of whoever replies is never shown. The board is also subject to the moderation described above: a post may be taken down, and its author keeps seeing its status under "My reports".

With companies that support us

We share only what is strictly necessary, with the following categories:

  • Infrastructure processors — hosting, database and e-mail delivery, which process data on our behalf and under contract.
  • Error monitoring — technical failure reports, which may contain an IP address and an account identifier, used for diagnostics.
  • Analytics — only with your consent, as described in section 4.
  • Login providers — the provider you choose (currently Google or TikTok; also Apple, once the app is on the App Store) receives only what is needed to authenticate you.
  • Authorities — under a court order or legal obligation.
  • Successors — in the event of a reorganization or transfer of the service, with prior notice to you.

Who answers for what. The controller is Epdex: we are the ones who decide why and how your data is processed, and we are the ones you hold to account — through dpo@epdex.app, under any of the regimes in section 1. Hosting, database, e-mail delivery, error monitoring and analytics act as processors (operadores, in the LGPD's vocabulary): they process data on our behalf, within what we contracted, and may not use it for purposes of their own. The login providers you choose and — when your device loads a catalog image or an audio preview directly from them — TMDB and Apple are independent controllers of what they see in that contact: on that point their own privacy policies apply, not this one.

Catalog sources. Information about series and movies comes from TMDB and Watchmode, with streaming availability data attributed to JustWatch via TMDB. A title's original soundtrack, when available, comes from Apple (iTunes Search API). These lookups are made by our servers — your identity and your IP address are not transmitted to those services.

Catalog images. Posters and other title images are loaded directly from TMDB's content delivery network (image.tmdb.org). During that loading, your IP address and the characteristics of your browser or device are visible to TMDB.

Soundtrack cover art and audio preview. When you open a title's soundtrack and play the 30-second preview of a track, the album cover and the audio are loaded directly from Apple's servers by your device — they do not pass through our servers, because Apple's terms prohibit audio previews from being saved or stored by us at any point along the way. During that loading, your IP address and the characteristics of your device are visible to Apple. The screen always shows, next to the play button, a link to the track's page on Apple's store.

6. Your rights as a data subject

The rights below come from different regimes, depending on where you live (see section 1) — but most of them we give to everyone, without asking where you are from: exporting, correcting, going private and deleting are all inside the app, for any user. Where one regime gives you more than another, the greater one applies.

Directly in Epdex, without talking to anyone

  • Close your account and delete your data: Settings → Account → Close account. We ask you to sign in again to confirm it is you. Deletion is immediate and cannot be undone — export your data first if you want to keep it. See section 7.
  • Make your profile private, or hide parts of it: Settings → Privacy, with immediate effect (section 5).
  • Turn telemetry on or off: Settings → Privacy, with immediate effect.
  • Review cookie consent on the site: the Cookie preferences link, in the footer.
  • Withdraw a consent: telemetry and cookies, through the routes above; promotional communications, through the same route by which you authorized them or by writing to dpo@epdex.app. Withdrawal takes effect from then on and is as easy as giving the consent was — it does not make unlawful the processing already carried out before.
  • Correct your name or e-mail: on the profile screen.
  • Export your data: Settings → Privacy → Export data — a complete file, in a readable and reusable format. It also includes what you posted on the Help Center board (with our team's replies), your votes and the reports you filed, with the status of each.
  • See what you reported: Settings → Help → My reports — your posts on the board and your reports, with the status of each. It is a private page: no one but you can see it.

Your rights under the LGPD (art. 18)

If the LGPD applies to you, it guarantees you, free of charge and at any time: confirmation of the existence of processing; access to the data; correction of incomplete, inaccurate or outdated data; anonymization, blocking or deletion of unnecessary data or data processed in non-compliance; portability; deletion of data processed on the basis of consent; information about who we share with; information about the possibility of not consenting and its consequences; withdrawal of consent; and objection to processing based on legitimate interest.

Your rights under the GDPR and the UK GDPR

If you are in the European Union, the European Economic Area or the United Kingdom, you have the right to:

  • access your data and this information (art. 15);
  • rectification of inaccurate or incomplete data (art. 16);
  • erasure, the so-called "right to be forgotten" (art. 17) — in Epdex it is immediate and in your own hands, under Settings → Account → Close account;
  • restriction of processing (art. 18), while we sort out the accuracy of a piece of data or the grounds of an objection you raised;
  • data portability (art. 20) — the Export data feature above hands you a file in a machine-readable format that you can take to another service;
  • object (art. 21), including to any processing we carry out on the basis of legitimate interest — such as the aggregate audience statistics in section 3;
  • not be subject to a decision based solely on automated processing with legal or similarly significant effects (art. 22). As stated in section 3, we make no such decisions: a catalog recommendation is personalization, it produces no legal effect and does not significantly affect anyone;
  • withdraw your consent at any time (art. 7(3)), as easily as you gave it — without affecting the lawfulness of processing carried out before the withdrawal.

One right the law requires us to point out separately: the right to object. You can object to processing we carry out on the basis of legitimate interest — including the aggregate audience statistics in section 3 — on grounds relating to your particular situation; where promotional communications are concerned, the objection is unconditional: just ask, and we stop, without asking why. Write to dpo@epdex.app. Once we receive the objection we cease the processing — unless there are compelling legitimate grounds that override your rights, in which case we tell you what they are (art. 21 of the GDPR and art. 18, § 2 of the LGPD).

Your rights in California (CCPA/CPRA)

If you are a California resident — or a resident of another U.S. state with equivalent legislation — you have the right to know what personal information we collect, where it comes from, what it is used for and who we share it with; to delete your data; to correct inaccurate data; to obtain a portable copy; to opt out of the sale or sharing of personal information; to limit the use of sensitive personal information; and to not be discriminated against for exercising any of them — Epdex does not charge a different price or deliver a worse service to anyone who exercises a right.

We do not sell personal information and we do not share it for behavioral advertising — neither for money nor for any other valuable consideration, in the sense the CCPA/CPRA gives to "sale" and "sharing". In the preceding twelve months there has been no sale and no such sharing, and that is not how Epdex makes money. We also do not collect sensitive personal information (see section 2c), so there is no use to limit — and no sale or sharing to opt out of, because no processing of that nature is taking place. The account of what we collect, where it comes from, what it is for and who it is shared with is in sections 2 and 5, and stands as the disclosure for the preceding twelve months required by the CCPA/CPRA.

How to exercise them, and how long we take

For anything not available in the app, write to dpo@epdex.app — the same channel serves every regime above. We respond within 15 days. That is our commitment and the LGPD's deadline; for those in the EU/EEA or the United Kingdom, the statutory deadline is one month, extendable by a further two months for genuinely complex requests, with notice to you within the first month (art. 12(3) of the GDPR) — in practice, we work to the 15 days. We may ask for information to confirm your identity, solely to prevent someone from accessing or deleting data that is not theirs.

Complaining to an authority

You do not have to come to us first. You can complain directly to:

  • Brazil — the ANPD, Autoridade Nacional de Proteção de Dados (Brazil's National Data Protection Authority, gov.br/anpd);
  • European Union / EEA — the supervisory authority of your country of residence, of your place of work, or of the place where the alleged infringement took place (art. 77 of the GDPR); the list is at edpb.europa.eu;
  • United Kingdom — the Information Commissioner's Office (ICO, ico.org.uk);
  • California — the California Privacy Protection Agency (cppa.ca.gov) and the California Attorney General (oag.ca.gov).

7. Retention, account closure and deletion

We keep your data for as long as your account exists. When you close your account, we actually delete your data — we do not deactivate it, we do not keep it in a reversible way.

How long we keep each thing

The general rule is a single one: for as long as your account exists. Whatever has a period of its own, shorter or longer, has it because there is an objective criterion behind it — never "just in case":

DataHow longCriterion
Registration, tracking history, lists, ratings, friendships, preferences and content you postedAs long as the account existsThey are the service itself. When you close the account they go in the same act — save only for the emptying out described below
Technical access logs6 monthsThe period set by art. 15 of the Marco Civil da Internet. It is an obligation on us, not a choice
City inferred from the IP addressUntil the statistical week closesOnce the week's statistic is consolidated the city serves no purpose and is deleted automatically — only country and state remain
Record of Surprise me suggestions (what we showed and how you responded)210 daysIt is what the longest of the usage windows requires — the memory of your refusals runs to 180 days. Once the period is up, the record serves no purpose and is deleted automatically
The file generated when you export your data5 days after it is readyTime for you to download it. After that the file is destroyed, and only the record that a request was made remains
An import awaiting your confirmation48 hoursAn unconfirmed preview is discarded: without confirmation there is no purpose that justifies keeping it
E-mail left on the site's waiting listUp to 90 days after launchThe purpose of the list is to announce the launch; once that purpose is fulfilled, the data does not stay
Record of document acceptanceAs long as the account existsIt serves to prove which text applied at each moment of our relationship. It is deleted along with the account
Aggregate audience statisticsIndefinitelyThey are not personal data (art. 12 of the LGPD): they contain no identifier that leads back to you
Data needed for a legal obligation or to defend rights in legal proceedingsFor the applicable statutory period, and only for itWe retain strictly what is necessary, only for as long as the obligation or the proceedings last

How closing the account works, under Settings → Account → Close account:

  1. We confirm it is you. We ask you to sign in again with your password or login provider and confirm the closure on a dedicated screen. This is the protection against someone who has gotten hold of your device closing your account.
  2. We notify you by e-mail first. If there is an e-mail on file, we send the closure notice before any data is deleted.
  3. Access ends immediately. Your credentials and all active sessions are revoked immediately, on every device.
  4. The data is deleted next. We remove your registration — name, e-mail, credentials and links to login providers — and all of your content: tracking history, progress, watchlist, lists, ratings, reactions, favorite characters, recent searches, imports, share links you generated, your handle, your invite link, your friendships (which also disappear from the lists of whoever was your friend), notification tokens and the record of the documents you accepted. For accounts with an extensive history, this removal completes in the background right after the previous step.

What stays standing, without you in it. Comments you wrote and posts you opened on the Help Center board are not deleted as rows, but rather emptied out: the text and the link to your account disappear, and only a "removed account" marker remains. The reason is concrete — deleting the whole row would take with it what belongs to other people: the replies someone wrote in your conversation, the votes others cast on your post and the public reply our team gave there. Your votes on other people's posts, on the other hand, are deleted, and each post's count is recalculated.

Closure is irreversible. There is no grace period and no way to recover the account once confirmed — that is why steps 1 and 2 exist. If you want to keep your history, export your data first (section 6).

We may retain, exclusively for the period and to the extent required, information necessary to comply with a legal or regulatory obligation, for the regular exercise of rights in legal proceedings, and internet application access logs, under art. 15 of the Marco Civil da Internet.

Where that exception comes from. Keeping access logs is not our choice: it is an obligation of Brazilian law — art. 15 of the Marco Civil da Internet requires an application provider to keep those logs for six months, under confidentiality and in a controlled environment. It applies because we are based in Brazil, and therefore it reaches people using Epdex from outside the country too. These are technical access records (date, time and origin of the connection), not your content: nothing of your tracking history survives account closure because of this rule.

The aggregate audience statistics described in section 3 also remain. They contain no identifier that leads back to you and, under art. 12 of the LGPD, are not considered personal data — which is why they are not affected by closure.

8. Information security

We adopt technical and administrative measures to protect your data (art. 46 of the LGPD). Among them:

  • Encryption in transit — all traffic between you and our servers uses HTTPS/TLS, with mandatory redirection of insecure connections.
  • Passwords never stored — we keep only a hash generated by a purpose-built password algorithm, designed to be slow and resistant to brute force. Not even we can recover your password.
  • Token-based authentication with expiration and renewal, with immediate revocation of all sessions when the account is closed.
  • Request rate limiting against abuse and automated attempts.
  • Audit logs of progress changes and document acceptance, and error monitoring to detect anomalous behavior.
  • Minimization as a security control — data that is not collected cannot leak. Our importer discards, by design, credentials, tokens, IP addresses and advertising identifiers present in files from other services.
  • Security review in the development process, before sensitive changes are merged.

No system is immune. We cannot guarantee absolute security and recommend that you use a unique password for Epdex.

Incidents. If there is a personal data breach, we tell you what happened, which data was affected and what you should do. The deadlines and recipients differ according to the regime that applies to you:

  • LGPD (art. 48): where there is relevant risk or damage to your rights, we notify you and the ANPD within a reasonable time.
  • GDPR (art. 33): we notify the competent supervisory authority within 72 hours of becoming aware of the breach, unless it is unlikely to result in a risk to the rights and freedoms of the people affected; if notification goes beyond 72 hours, it comes with the reasons for the delay. Where the breach is likely to result in a high risk to you, we communicate it to you directly, without undue delay (art. 34).
  • UK GDPR: the same regime, with notification made to the ICO.

9. International transfer

Where your data sits. Our infrastructure is operated from servers located in the United States, and the controller is based in Brazil. Because Epdex is offered globally, there is an international transfer in more than one direction — which of them reaches you depends on where you are.

If you are in Brazil. Your data is transferred to the United States, which is not the subject of an adequacy decision by the ANPD. The transfer relies on the necessity of performing the contract entered into with you (art. 33, IX, read together with art. 7, V of the LGPD): that is the hosting where the service you signed up for runs — without it there is no account, no history and no app. On top of that ground come the technical safeguards described in section 8, which hold wherever the data sits: encryption in transit, a password kept only as a hash, immediate session revocation and minimization — data that is not collected crosses no border at all.

If you are in the EU/EEA or the United Kingdom. Your data is transferred to the United States and to Brazil. Neither country is the subject of a European Commission adequacy decision applicable to this operation — the law requires us to tell you that, and we are telling you. The transfer is necessary for the performance of the contract you entered into with us (art. 49(1)(b) of the GDPR and the corresponding provision of the UK GDPR): creating your account and syncing your history is, quite literally, writing that data onto the infrastructure Epdex runs on. Here too the technical safeguards of section 8 apply in addition.

What that means in practice. You acknowledge that authorities in the destination country may, under the law there, request access to data stored in their territory — that is a consequence of where the servers are, not a permission we grant anyone. We select providers whose terms provide for security and confidentiality obligations over what they process on our behalf, and we share with each one only what its function requires (section 5). If you want to know, concretely, where a piece of your data sits and on what ground the transfer relies, ask through dpo@epdex.app — we answer within the deadlines in section 6.

10. Minimum age and teenagers

Epdex is intended for people 16 years of age or older. The catalog filters adult-themed content by default, on every screen of the app — it does not depend on self-declared age for that — and also has a community reporting channel: anyone can flag a title as inappropriate, which removes it from the catalog immediately until reviewed by our team. We do not knowingly collect personal data from children (art. 14 of the LGPD).

Why 16, and not 13. Sixteen is the highest floor that art. 8 of the GDPR allows Member States to set for a teenager to consent on their own to information society services. By adopting 16 for everyone, a single number satisfies every country where Epdex is offered — without having to geolocate you at sign-up to know which age to require.

Date of birth at sign-up. We ask for your date of birth when you create the account, for two exclusive purposes: to refuse sign-ups below the minimum age and to apply the teenager regime below. It is not shown to anyone and is not used for any other purpose.

Accounts with no date of birth on record — created during the testing period, before this was collected at sign-up — are not required to provide it: they remain under the most protective regime, with a private profile, until the account holder provides the date under Settings. Once adulthood is confirmed, the public default of section 5 applies, with the visibility choice presented to the account holder at that same moment — nothing is displayed before it. The record is made once; corrections are handled through dpo@epdex.app.

Teenagers (16 to 17 years old) use Epdex with their own safeguards, with regard to their best interests (art. 14, caput, of the LGPD and ANPD Board Statement (Enunciado CD/ANPD) No. 1/2023):

  • the profile is born private — name, photo and activity are not shown to other users;
  • making the profile public requires an affirmative action by the account holder, reversible at any time;
  • upon turning 18, nothing changes automatically: the option to adopt the adult default appears under Settings, and visibility only applies if the person chooses it — from then on, keeping out of view the activity recorded during adolescence (section 5);
  • we do not show personalized advertising or perform behavioral tracking — for any user, of any age (sections 2c and 4).

If we become aware that an account belongs to someone under 16, it will be closed and the data deleted. If you are responsible for a child or a teenager under 16 and believe they have created an account on Epdex, write to dpo@epdex.app — we will handle it as a priority, and we will not ask for anything beyond the minimum needed to locate the account.

11. Data Protection Officer, contact and changes

Data Protection Officer (DPO — Encarregado). Requests regarding personal data and privacy must be sent to dpo@epdex.app, the official channel for data subjects under art. 41 of the LGPD. It is the same channel for every regime in this Policy — LGPD, GDPR, UK GDPR and CCPA/CPRA — and for every country: you do not need to work out which regime covers you, nor look for a different address depending on where you live, in order to reach us. Write in Portuguese or in English; we answer within the deadlines in section 6, whether the request is for access, rectification, erasure, portability, restriction, objection, withdrawal of consent or simply a question about this Policy.

General contact: contact@epdex.app.

Authorities. You can complain to the competent authority in your country without coming to us first — the list is in section 6.

Changes to this policy. We may update it. Material changes will be communicated in the app and by e-mail, when there is an e-mail on file, at least 15 days before they take effect. We will keep the date of the last update at the top of the document, and the history of previous versions will remain available for consultation.

12. Acceptance record and versioning

We record your acceptance. When you accept this Policy and the Terms of Use, we store the date, time and version of the document accepted, linked to your account. We do this for two reasons: to prove which text applied to your relationship with us at each moment, and to allow you to look up what you accepted.

When we publish a new version with material changes, we will ask for your acceptance again after the 15-day prior notice. Each acceptance generates its own record, without erasing the previous ones.

You can view your acceptance history under Settings → Account and request it through dpo@epdex.app. If you close your account, that record is deleted along with the rest of your data (section 7).