1.Who we are — the Controller
The Modo Vitta app (available for Android) is operated by an individual under the trade name Modo Vitta, based in Brazil.
For the purposes of the Brazilian General Data Protection Law (LGPD — Law No. 13,709/2018), the data Controller is the operator of Modo Vitta, reachable through the official channel:
2.Data we collect
We collect only the data strictly necessary to run the app and to provide the services you sign up for. Each category is detailed below:
2.1 Account and identity data
- Full name
- E-mail address
- Gender
- Age range (used to confirm that you are 18 or older)
- CPF (the Brazilian individual taxpayer number) — asked only of people who take part in the referral program: when you type a referral code while signing up, or when you apply a code under MyVitta → Refer & Earn. If you never use a referral code, the field is never shown and no CPF is ever sent. When it is provided, it is stored only as an irreversible cryptographic hash, never in plain text, and it is used for fraud prevention and for the integrity of the referral program
- Password (stored as an irreversible hash — never in plain text)
- Restoration credential — created when you sign in and also, when this device does not have one yet, when you open the app with your session already validated, if your device offers the Android feature that gives your access back when you move to a new handset without asking for your password again. On our server we keep only the public half of that credential, its identifier, the model of the component that generated it, a usage counter, the creation and last-use dates and the revocation flag. On its own, none of that opens your account. The half that actually opens it is held by the Android Credential Manager and never reaches us — see sections 4 and 7
2.2 Usage and productivity data
- Tasks you create, their states (Resolve, Resolving and Resolved — with Completed and Cancelled as the two outcomes within Resolved) and the pillars they belong to
- Weekly goals and the balance of hours across your pillars (VittaBalance™) — how many hours of the week you plan to devote to each area of life, and the balance within the 168 hours
- VittaFocus™ focus sessions (Timer and Cycle)
- Scores, streaks and unlocked achievements
- Método Vitta settings (VittaFlow™, personalized pillars)
- App usage markers: dates only, with no content whatsoever — the day this device first saw your account, the dates on which we already showed you each referral and each app-rating invitation, the day you dismissed a prompt bubble (the VittaCheck™ check-in, the weekly report), the moment you marked the bell notifications as read, and the week each pillar was celebrated. They do not record what you did in the app: they record what the app has already shown you, so we do not repeat invitations and prompts you have already seen
- Free text you write: the notes on each task, your VittaNotes™ notepad, the content of your VittaTarget™ goals (Vision, Intention, Trajectory and Action) and the comments you write when you log progress on a goal. In Google Play Data Safety terms, this is Other user-generated content. This text is yours, it stays tied to your account and it is deleted in full when you delete your account
- VittaPartner™ (Partner Mode) comments: the text of the comments you write — including on your partner’s tasks — and the marker of how far you have read theirs. In Google Play Data Safety terms, this is Other in-app messages
Contact Us: when you send a support message from the app, the subject, the text of your report and any image you attach are sent by e-mail to our support inbox, together with your name, your registered e-mail address and your internal account identifier (so that we can reply). Those messages stay in that mailbox — they are not written to the app database and are therefore not removed by the automatic deletion of your account. To have them deleted as well, ask us at contato@modovitta.com.
2.3 Technical device data (Device or other IDs)
- Device identifier — a random code generated by the app itself on first launch, with no relation whatsoever to the serial number, the IMEI or any other factory identifier of the handset. It exists so that we can recognize the devices on which you have already confirmed your access code (and therefore not ask for the code every time)
- Operating system and version
- Version of the installed app
- Crash reports: when the app crashes or hits an error, Google Crashlytics records the error type, the screen and the feature in use at that moment or shortly before — including the wellbeing features — and the technical state of the device at that moment, so that we can fix the problem. These reports never carry the content you write — see the details in section 4 and how to switch it off in section 12
- Usage data (Google Analytics for Firebase): the name of the screen opened inside the app, the language, the approximate country and a random identifier generated by the installation. It tells us which screens and features are actually used and where people give up, so we can prioritise improvements. This collection is a navigation count: it does not carry the content you record, nor your wellbeing and health data — see the details in section 4 and how to switch it off in section 12
We do not check for root or jailbreak. That check was removed from the app and no information of that kind is collected, transmitted or stored. What the app still evaluates — only in order to show you a warning — is whether the device is in developer mode or is an emulator. The result of that evaluation is stored on the device only: it does not reach our servers or any third party.
2.4 Biometric data
Processed locally only: biometric authentication (fingerprint / Face ID) is processed entirely on the device by the operating system. Modo Vitta never receives, transmits or stores biometric data on external servers.
2.5 Payment and subscription data (Purchase history)
- Plan status (Free, Premium or VIP)
- Subscription transaction history
- Payment data is processed directly by the app store (Google Play) or by RevenueCat — Modo Vitta does not store card numbers or bank details
2.6 Notification tokens
- FCM token (Firebase Cloud Messaging), used to deliver push notifications to the registered device
2.7 Advertising data
- Device advertising identifier (GAID on Android)
- Ad interaction data (impressions, clicks)
How this works in practice, without mincing words: the Google ads SDK (AdMob) starts on every launch of the app on every Android device — regardless of your plan and before you make any choice — and from that point on it can access the device’s advertising identifier. That identifier is managed by the operating system, and you can reset it or disable it at any time in your device settings.
To fill the ad slots, AdMob also calls on mediation partners — today, Unity Ads — which receive the request from Google and can likewise access that identifier. That partner’s SDK is started together with Google’s when the app opens. Your consent choice is recorded with it beforehand, so that it applies from the very first ad; from then on, it only comes into play when there is an ad request.
Ads are shown on the Free plan only. Premium and VIP users see no advertising.
Personalization is opt-in. Until you turn on the Marketing consent, ads are requested as non-personalized — and that is the default state for anyone who installs the app. Turning that consent on or off takes effect immediately, and the same choice is passed on to the mediation partners, so that it applies to the ads they deliver as well. In the regions where Google requires its consent form (European Economic Area and United Kingdom), refusing it makes the app request no ads at all; in Brazil that form is not shown, and the control is the Marketing consent inside the app.
2.8 VittaPartner™ (Partner Mode) data, when enabled
- The link between two Vitta accounts (anonymized internal identifiers)
- The partnership invites you send and receive. If you invite someone who does not have an account yet, we store the e-mail address you typed in order to send the invite and to recognize that person if they later sign up
- While the partnership is active, your task schedule and your goal collection become visible to your partner — the exact scope is detailed below
What your partner sees and can do — plainly. The partnership is voluntary: it only exists after one person invites and the other accepts, and either of you can end it at any time from inside the app.
They see your entire schedule. There is no such thing as marking a single task as shared: while the partnership is active, all of your tasks are visible to them — title, pillar, dates, times, duration, state, priority, the timestamp of when you completed each one, the recurrence rule of your routines (for example, “every Monday at 8am”) and the day-by-day record of each routine, that is, which days you kept it and which days you did not.
What they do NOT see: the notes you write inside each task — that text never leaves your account — and your e-mail address. From your profile they only see your picture, your plan and your name. ⚠️ The name shown across most of the app is the display name you chose, but your registered name is what appears on comments.
They also write in your schedule. Your partner can create new tasks in your schedule, edit existing ones, mark them as completed, reopen them and comment on them. They only delete tasks they created themselves in your schedule — and only while nobody has written in them: a note from you, or any comment, is enough for the deletion to be refused. They never delete a task you created, and no repeating task can be deleted by them — not even one they created themselves. On repeating tasks, they can create them, but cannot change the repetition rule of one that already exists — and they can mark one day of the routine as done and reopen it. When they do delete a task, the app notifies you on your device, provided your notifications are on.
VittaTarget™ goals become shared by both of you. Each of you sees all of the other’s goals, with all the text you wrote in them (Vision, Intention, Time, Trajectory and Action) and with the comments from every progress entry. Both of you can edit, log progress on and close any goal. Only the goal’s owner can delete it, and only the owner can reopen it once it has been closed.
Your nights are part of that visibility. VittaSleep™ records each night as a task in your schedule, so your partner sees what time you went to sleep and for how long. They cannot edit or complete those tasks — they are read-only to them. If you would rather not share that, end the partnership or turn VittaSleep™ off under MyVitta → Features.
When the partnership ends, your former partner’s access to your data is cut off immediately on our servers: they stop receiving any new information about you and can no longer write anything into your account. Whatever had already been downloaded to their device is erased on that device’s next sync. The comments each of you wrote stay associated with whoever wrote them, and are erased when that account is deleted (section 6).
2.9 Wellbeing and health data (sensitive — Health info)
When you use certain features, you record information that the LGPD classifies as sensitive personal data (Art. 11). There are exactly three such features: VittaCheck™ (mood, check-ins, gratitude and the weekly report reflections), VittaSleep™ (sleep hours) and VittaHydratta™ (water intake).
The pillar hour balance (VittaBalance™) does not fall into this category, even when the pillar is called Physical Health or Mental Health: there you simply spread the hours of your week across areas of life — that is schedule planning, not health measurement. It is treated as usage and productivity data (item 2.2) and remains available to anyone who declines the consent described below.
This sensitive data is processed only with your specific and highlighted consent (LGPD Art. 11, I), asked for when you first open the app — or later, if you turn one of those three features on under MyVitta → Features. Declining does not stop you from using the app: those three features simply start out turned off. And the data is used exclusively to show your own metrics back to you: we never use it for advertising and we never share it for that purpose.
One important caveat, and it is your call: if you turn on Partner Mode (VittaPartner™), your partner comes to see what time you went to sleep and for how long, because VittaSleep™ records each night as a task in your schedule — and they see your entire schedule. This applies to sleep only: your mood and check-ins from VittaCheck™ and your water intake from VittaHydratta™ are not shared with anyone. You are the one who creates that visibility, by accepting the partnership, and it ends when the partnership ends — the details are in item 2.8.
You may withdraw this consent at any time inside the app, without deleting your account: under MyVitta → MY ACCOUNT → Manage Data, on the wellbeing and health data item. When you withdraw it, VittaCheck™, VittaSleep™ and VittaHydratta™ are switched off and stop recording anything new — and what you already recorded is not erased: it stays stored and comes back if you grant the consent again. To erase the history as well, use Erase My Data or delete your account (section 6).
2.10 Approximate location
- The state and city you enter in your profile, used to personalize your experience. We do not use GPS and we do not track your position. In Google Play Data Safety terms, this is Approximate location — literally “the city the user is in”.
2.11 Photos you send us
- Profile picture (avatar): if you choose one, the image is uploaded to our servers and stays tied to your account until you replace it or delete your account. It is optional — the app works without it.
- Contact Us attachment: if you attach an image to a support message, it travels by e-mail to our support inbox together with your report.
- We never access your camera or your gallery on our own: we only receive the image that you select and send.
2.12 Website waiting list (iPhone and iPad)
This is the only collection made outside the app, and it does not require an account. Anyone who fills in the "Coming to iPhone and iPad" form at modovitta.com — opened by the Waiting List button or by the Apple icon on the home page — sends us:
- the e-mail address you typed
- the IP address the submission came from and its date and time
- a cryptographic digest (hash) of the IP, kept for 1 hour, used only to limit repeated submissions from the same point
Filling it in is voluntary: browsing the pages of the website without using that form sends no data at all. Joining the list does not create an account in Modo Vitta™ and has no connection to the app data described above. The purpose and the legal basis are in item 3, the retention period in item 6, and how to leave the list in item 10.2.
2.13 Screen time in social apps (VittaScroll™)
Processed locally only: if you turn VittaScroll™ on, the app asks Android itself how long a few social and video apps were open on your screen, today and over the last 7 days, and shows that time on a home screen card. That number is read at the moment you open the screen, never leaves the device, is not stored by us, is not sent to any server and is not shared with anyone.
- The list of apps is fixed and defined by us, inside the application. We do not read and do not receive the list of applications installed on your device.
- We do not see what you do inside those apps: no content, no accounts, no messages, no browsing history. The only data point is how long each of them was in the foreground.
- Only time with the app open on screen counts. Music, podcasts and video playing in the background are not included.
- It is optional and reversible. The feature only works after you authorise Modo Vitta™ under "Usage access" in Android’s own settings, and you can switch it off at any time in the same place. Without that authorisation, nothing is read.
- Because the data is neither stored nor transmitted, there is no retention period to observe: switching the authorisation off ends the reading, and nothing is left behind on our side.
3.Purposes and legal bases (LGPD)
Every processing operation carried out by Modo Vitta has a specific, explicit and legitimate purpose, grounded in at least one of the legal bases set out in Arts. 7 and 11 of the LGPD:
| Data / Category | Purpose | Legal basis (LGPD) |
|---|---|---|
| Account data (name, e-mail, gender) | Create and maintain the user account; authentication via OTP | Performance of a contract (Art. 7, V) |
| Restoration credential (section 2.1) | Give your access back when you move to a new device without requiring your password again, and reduce the risk of being locked out of your account | Performance of a contract (Art. 7, V) — the same basis as OTP authentication just above: without access to the account there is no service to perform. It is invalidated when you remove the key under MyVitta → MY ACCOUNT → Trusted Devices (Automatic Sign-In list), when you change your password or use End All Sessions |
| Age range | Confirmation of legal age — access restricted to people aged 18 and over | Legitimate interest (Art. 7, IX) |
| CPF — asked only of people who take part in the referral program (stored as an irreversible hash) | Fraud prevention and integrity of the referral program | Legitimate interest (Art. 7, IX) |
| Usage / productivity data | Deliver the features of the Método Vitta; personalize your experience | Performance of a contract (Art. 7, V) |
| App usage markers (section 2.2) | Avoid repeating invitations, prompts and celebrations you have already seen, and cap how often they appear | Legitimate interest (Art. 7, IX) |
| Wellbeing and health data (sensitive) | Show you, and only you, your personal wellbeing metrics (mood and check-ins, sleep, hydration) | Specific consent (Art. 11, I) |
| Technical device data | Security, error debugging and improvement of the app | Legitimate interest (Art. 7, IX) |
| FCM token | Delivery of the notifications and reminders configured by the user | Consent (Art. 7, I) — requested at install time |
| Subscription data | Validate the active plan; unlock Premium/VIP features | Performance of a contract (Art. 7, V) |
| Password, at the moment you set it | Check the chosen password against a public database of already-leaked passwords and refuse it if it is known. Only a scrambled fragment of it is queried, and nothing that identifies you goes with the query (see section 7) | Legitimate interest (Art. 7, IX) — protecting your account against break-in with an already-known password |
| Advertising data (Free) | Display of Google AdMob ads and those of its mediation partners (Unity Ads), and age-range targeting to sustain the free plan | Consent (Art. 7, I) — LGPD/GDPR ConsentManager |
| E-mail data (announcements) | Sending relevant communications about the service | Consent (Art. 7, I) — opt-in in settings |
| Website waiting list e-mail (item 2.12) | To notify you once when the iPhone and iPad version launches — we do not use that address for any other communication | Consent (Art. 7, I) — you provide it in the form itself, for that purpose |
| Website waiting list IP, date/time and IP hash (item 2.12) | To limit abusive submissions of the form, which sends e-mail, and to record the request to join the list | Legitimate interest (Art. 7, IX) |
4.Sharing with third parties
Modo Vitta does not sell personal data. Apart from Partner Mode — where you are the one who decides to give another person access, as described in item 2.8 — sharing happens only with the essential providers listed below, all of which have their own privacy policies and contractual data protection obligations. There is one exception, and it is declared in the table: the Android Credential Manager. It is not a provider we contracted — the restoration credential is kept in your own Google account, under the terms you already have with Google, so there is no contract of ours to invoke over it. We list it all the same, because the data leaves our reach and you have to know:
| Provider | Purpose | Data transferred | Policy |
|---|---|---|---|
| Google Firebase (FCM) | Push notifications | Device token, notification content | firebase.google.com |
| Google Crashlytics | Diagnosing and fixing crashes | Technical crash diagnostic data (Crash logs and Diagnostics), without the content you record (international transfer to the USA) | firebase.google.com |
| Google Analytics for Firebase | App usage metrics | Name of the screen opened, language, approximate country and a random installation identifier, without the content you record (international transfer to the United States) | firebase.google.com |
| Google AdMob | Advertising (Free plan) | Advertising ID, interaction data (with consent) | policies.google.com |
| Unity Ads | Advertising (Free plan) — mediation partner called on by Google AdMob | Advertising ID, ad interaction data and technical device data, without the content you record (with consent; international transfer) | unity.com |
| RevenueCat | Subscription management | Plan status, anonymized purchase history | revenuecat.com |
| Hostinger | Backend infrastructure (servers in Brazil) | Account and productivity data (encrypted traffic) | hostinger.com.br |
| Google Play | Distribution and payment processing | Purchase data (managed by the store) | The respective store |
| Android Credential Manager (not a contracted provider — see the paragraph above and the box below) |
Give your access back when you move to a new device, without asking for your password again | Your account's restoration credential, kept in your own Google account (international transfer to the United States) | policies.google.com |
We may also share personal data when required by law, by court order or by a competent authority, limited to what is strictly necessary.
5.International data transfers
The main Modo Vitta server is located in Brazil (Hostinger). However, some of the providers listed in the previous section (Google Firebase, Crashlytics, AdMob, Unity Ads, RevenueCat) have global infrastructure and may process data in other countries, including the United States. The restoration credential also leaves Brazil: it is held in your own Google account, whose infrastructure is global.
In those cases, we ensure that the transfer takes place under the mechanisms set out in Art. 33 of the LGPD and under the Data Processing Agreements signed with each provider, which include clauses equivalent to the European Union Standard Contractual Clauses (GDPR Standard Contractual Clauses).
The restoration credential is the exception, for the same reason as in the previous section: it does not go to a provider we hired, but to your own Google account — the transfer is governed by the terms you already have with Google, not by any contract of ours, and we have no way of bringing it back to Brazil. What supports this transfer is Art. 33, IX combined with Art. 7, V of the LGPD: it is necessary in order to perform what you signed up for — getting back into your account.
6.Data retention and deletion
| Category | Retention period | Justification |
|---|---|---|
| Active account and usage data | For as long as the account is active | Performance of the contracted service |
| App usage markers (section 2.2) | While the account is active — they are not erased by "Erase My Data" | Legitimate interest (Art. 7, IX) — without them, the invitations and prompts you already dismissed would start over |
| Data after account deletion | Up to 30 days (backups) + permanent purge | Operational security and error recovery |
| CPF (the irreversible hash only, where one exists) | For as long as the referral program is active — including after account deletion | Fraud prevention — legitimate interest (Art. 7, IX) |
| Terms of Use acceptance record (date and time) | For as long as it may be required as evidence — including after account deletion | Regular exercise of rights in judicial, administrative or arbitration proceedings (Art. 7, VI) |
| Privacy notice response record — the version and date on which you responded, without the content of the response | For as long as it may be required as evidence — including after account deletion | Regular exercise of rights in judicial, administrative or arbitration proceedings (Art. 7, VI) |
| Access logs (Marco Civil) | 6 months | Legal obligation — Art. 15 of Law 12,965/2014 |
| Transaction records | 5 years | Legal obligation — Brazilian Civil Code, Art. 205 |
| Advertising data (Free) | As per the Google AdMob policy and that of the mediation partner (Unity Ads) | Managed by the provider, with consent |
| Website waiting list — the whole record (e-mail, IP and date/time) | Until the launch notice is sent, or until you ask for removal — whichever comes first. The IP hash, 1 hour | End of the purpose that justified the collection. This record is distinct from the access logs listed in this same table, which follow the Marco Civil period |
Erasing only your data, without deleting your account
If you want to get rid of the content you created without losing your account, the app offers a separate path — Erase My Data. You stay signed in, with the same login, and start over from scratch:
- Open the Modo Vitta™ app with your account signed in
- Go to MyVitta → MY ACCOUNT → Manage Data → Erase My Data
- Type “ERASE” to confirm and tap Send confirmation code
- Enter the 6-digit code sent to your registered e-mail address (valid for 5 minutes) and confirm
What stays: your account remains active — name, e-mail, password, plan, gender, age range, state/city, streak, your privacy consents, your trusted devices, the restoration credential described in section 2.1, the anti-fraud referral record, the delivery address for this device's notifications and the anti-fraud CPF hash (where one exists) are not affected, and you stay signed in without having to log in again.
The app usage markers described in section 2.2 also stay: the dates on which we already showed you each referral and each app-rating invitation, the day this device first saw your account, the day you dismissed a prompt bubble, the moment you marked notifications as read, and the week each pillar was celebrated. They are dates only, they describe nothing you recorded, and they are what keeps invitations and prompts you already dismissed from starting over after this operation. They are erased when you delete your account.
This is permanent too. There is no undo and we cannot recover the content afterwards. If you want a copy first, use Request data portability on the same Manage Data page. Note that support messages sent through Contact Us — and any image attached to them — live in our support mailbox, outside the app database, so they are not reached by this operation; to have those deleted too, ask us at contato@modovitta.com.
How to delete your account and your data
You can delete your account and all of your data at any time, free of charge, by following the steps below:
- Open the Modo Vitta™ app with your account signed in
- Go to MyVitta → MY ACCOUNT → Manage Account → Delete account
- Type “DELETE” to confirm and tap Send confirmation code
- Enter the 6-digit code sent to your registered e-mail address (valid for 5 minutes) and confirm
The same deletion is also available under MyVitta → MY ACCOUNT → Manage Data, at the bottom of the page.
No access to your account or to your registered e-mail address? Send a request to contato@modovitta.com from the e-mail address associated with your account.
Full step-by-step: the page modovitta.com/excluir-conta-en.html (in Portuguese) details the process, the alternative e-mail channel and the complete list of what is deleted and what is kept.
- Security audit records — date and time, IP address, type of action, the internal account identifier and, for some access events, the e-mail address used in the attempt. They are kept in pseudonymized (not anonymized) form for the period stated in the table above, after which they are deleted automatically, in compliance with a legal obligation — Art. 15 of Law 12,965/2014 (Brazilian Internet Civil Rights Framework, the Marco Civil da Internet).
- The account record, already anonymized — the account record is not physically deleted: name, e-mail, gender, age range, city, picture and all remaining data are replaced with anonymous values and the account is flagged as deleted. This preserves the integrity of the audit trail and of the referral records already granted.
- The hash of your CPF, where you provided one — the CPF itself is never stored; what remains is only the irreversible cryptographic hash, with no name, e-mail or any other data attached to it. It is kept for as long as the referral program is active, on the legal basis of legitimate interest in fraud prevention (Art. 7, IX): it is what stops the same person from deleting and recreating accounts in order to collect referral benefits over and over. What this does and does not mean: it does not stop you from creating a new account — the CPF is only ever asked of people who use the referral program. What it does stop is that same CPF earning the referral bonus again. If you need that CPF released for the referral program, write to contato@modovitta.com.
When deletion happens. The moment you confirm, the account is deactivated right away: every session is ended, the data held on the device you asked from is wiped, and nobody can reach the account any more — neither you, nor anyone who shared an agenda with you. The permanent deletion on the server runs 7 days later.
If you used Modo Vitta™ on more than one device, the others lose access as soon as they reconnect and return to the login screen; until then, with no connection, whatever was already downloaded may keep showing up on them. The copy left on those devices is erased when the app is uninstalled, or when someone signs in on them with a different account.
Those 7 days are yours, to change your mind. If you sign back in with the same email and password within that window, the account is restored with everything that was in it and the deletion is cancelled. After the 7 days there is no way back. While the window is open, your email stays reserved for that account and cannot be used to create another one.
Backup copies may retain the data for up to 30 days after the permanent deletion, before the final purge, as stated in the table above.
7.Data security
We apply technical and organizational measures in line with the state of the art to protect personal data against unauthorized access, loss, alteration or destruction:
- Encryption in transit: all communication between the app and the server uses HTTPS with TLS 1.2 or higher
- Encryption at rest: the local database is encrypted with SQLCipher (AES-256)
- Secure storage: credentials and tokens stored in the Android Keystore
- Multi-factor authentication: e-mail OTP available to every user
- Risky environment warning: the app detects whether the device is in developer mode or is an emulator and shows you a warning. It is informational only — it does not block access, it does not check for root/jailbreak and the result never leaves the device
- Password: stored exclusively as an irreversible hash (bcrypt/argon2)
- Leaked password: whenever you set a new password, the server checks whether it has already appeared in public breaches and refuses one that is already circulating on the internet — without your password going anywhere beyond our server (see the box just below)
- CPF: stored exclusively as an irreversible cryptographic hash, with a secret salt kept on the server — never in plain text
- Restoration credential: of the key pair that gives your access back on a new device, our server keeps only the public half. The private half — the one that actually signs and opens the account — is generated and held by the Android Credential Manager, is never transmitted to us and does not exist on any server of ours. It is invalidated when you remove the key under MyVitta → MY ACCOUNT → Trusted Devices (Automatic Sign-In list), when you change your password or use End All Sessions, and fully deleted when you delete your account
- Least privilege: internal staff access personal data only on a need-to-know basis and with an audit record
- Periodic testing: security reviews before every version published to the stores
In the event of a security incident that may create relevant risk or damage to data subjects, Modo Vitta will notify the ANPD and the affected users within the legally prescribed period, under Art. 48 of the LGPD.
8.Minimum age — 18 and over
Modo Vitta is intended exclusively for people aged 18 and over. During sign-up, the user confirms their age range and declares being of legal age; there is no sign-up flow for people under 18.
We do not knowingly collect data from people under 18. If we identify an account belonging to a minor, that account will be removed and the data deleted.
Parents or guardians who identify the use of the app by a minor can request deletion at contato@modovitta.com.
9.Your rights as a data subject
The LGPD (Art. 18) grants data subjects the following rights, which may be exercised at any time through the contact channel given in section 13:
We answer requests within 15 business days, extendable by a further 15 days with justification, as provided for by the ANPD.
11.Ads and personalization
Users on the Free plan see ads served by Google AdMob, which may call on mediation partners to fill those slots — today, Unity Ads. Your consent choice is passed on to them and applies just the same. In the regions where regulation requires it (European Economic Area and United Kingdom), the app shows the Google consent form (UMP) on launch, before requesting any ad; in Brazil that form is not shown, and control sits with the Marketing consent inside the app.
What each choice does:
- Marketing consent on — personalized, interest-based ads, using the device advertising ID
- Marketing consent off (the default state on install) — non-personalized ads, including those delivered by the mediation partners: they are still shown on the Free plan, but they are not based on your interests and may be less relevant
- Refusing the Google form, where it is required (European Economic Area and United Kingdom) — the app requests no ads at all
That choice takes effect immediately and can be changed whenever you want under MyVitta → MY ACCOUNT → Manage Data.
To sustain the free plan, ads may be targeted by age range (adult audience, 18 and over), always respecting the consent choice made by the user.
Users on the Premium and VIP plans are not subject to any form of advertising inside the app.
12.Consent and withdrawal
Where processing is based on consent (LGPD Art. 7, I), the user may withdraw it at any time, free of charge and without difficulty, without affecting the lawfulness of the processing carried out before the withdrawal.
Channels for withdrawing specific consents — and, in the case of crash reports and usage metrics, for objecting to processing based on legitimate interest (Art. 18, § 2):
- Push notifications: device settings or MyVitta → PREFERENCES
- Personalized advertising: MyVitta → MY ACCOUNT → Manage Data — Marketing switch
- Crash reports (Crashlytics): collection starts out on, based on our legitimate interest in keeping the app stable (Art. 7, IX), and does not rely on consent — but you can switch it off at any time inside the app, under MyVitta → MY ACCOUNT → Manage Data; once you do, Crashlytics stops collecting and sending crash reports
- Usage metrics (Analytics): collection starts out on, based on our legitimate interest in understanding how the app is used so that we can improve it (Art. 7, IX), and does not rely on consent — but you can switch it off at any time under MyVitta → MY ACCOUNT → Manage Data; once you do, Analytics stops collecting and sending usage metrics
- Wellbeing and health data (Art. 11): MyVitta → MY ACCOUNT → Manage Data — the wellbeing and health data item; withdrawing switches VittaCheck™, VittaSleep™ and VittaHydratta™ off and stops any new recording, without erasing what has already been recorded (see item 2.9)
- E-mail communications: the unsubscribe link present in every e-mail, or contato@modovitta.com
- All consents / account deletion: MyVitta → MY ACCOUNT → Manage Account → Delete Account, or by e-mail — see modovitta.com/excluir-conta-en.html
13.Data Protection Officer (DPO)
The Modo Vitta Data Protection Officer is responsible for receiving communications from data subjects, from the ANPD and from interested parties on privacy matters.
Data Protection Officer — Modo Vitta
E-mail: contato@modovitta.com
Subject: LGPD — [your request]
Answered within 15 business days of receipt of the request.
14.Brazilian National Data Protection Authority — ANPD
If you believe that your rights as a data subject have not been properly addressed by Modo Vitta, you have the right to file a complaint directly with the Brazilian National Data Protection Authority (ANPD):
- Website: www.gov.br/anpd
- Electronic filing: through Consumidor.gov.br or the ANPD portal
15.Updates to this Policy
This Privacy Policy may be updated from time to time to reflect changes in the app, in legislation or in our data processing practices. Material changes will be communicated to the user through:
- A notice inside the app (banner or informational modal)
- An e-mail to the registered address (when the change is relevant)
The version in force is always available at modovitta.com/privacy-en.html (English) and at modovitta.com/privacy.html (Portuguese), with the date of the last update shown at the top of the document.
Continued use of the app after the effective date of a new version constitutes acceptance of the changes.