1. Who processes your data
The controller of your personal data is G DA SILVA C ROCHA DESENVOLVIMENTO DE SOFTWARE & TECNOLOGIA (GROCHA Tech), CNPJ 38.323.551/0001-69.
Data Protection Officer (DPO), under Article 41 of the LGPD: contato@grochatech.com.br — phone +55 (19) 98847-2424.
This Policy explains, in plain terms, what data we process, why, with whom we share it, how long we keep it, and how you exercise your rights. It is part of the Terms of Use.
2. Who this Policy applies to
It applies to anyone using the website www.aiaviator.com.br and the Aviator AI apps for Android and iOS, whether on the free tier, in the trial period, or on a paid plan, in Brazil or abroad.
The Service is not offered to people in Brazil (Terms of Use, clause 3).
3. Data we process
3.1 Data you provide
- Registration: email (in accounts created from a betting house, the login may be the CPF, the Brazilian individual taxpayer number), name, and password. The password is stored only as a hash — we have no access to it.
- Contact and support: contact email, messages written in Support, and files you attach (screenshots, for example).
- Community: public nickname, text messages, images and audio you send, reactions, and reports.
- Betting house connection (optional): when you choose to connect your account at a betting house to play inside the app, we store the credentials needed to keep that session. You may disconnect and remove this data whenever you wish.
- Preferences and gaming profile: settings, chosen alerts, experience level, answers to the initial questionnaire, and bankroll preferences (goals, limits, reality check).
- Bankroll management: balance, deposit, and withdrawal amounts you record, plus any free-form notes you write on those entries. We record money, not individual bets.
3.2 Data collected automatically
- Access and usage logs: date and time of access, IP address, screens visited, actions in the app, game selected, app version, and platform.
- Device identifier: a random identifier generated by the app/browser itself to measure usage and diagnose failures. It is not your device’s serial number.
- Consents: date, time, version accepted, IP address, and browser/app identification at the moment of acceptance — proof that the acceptance took place.
- Notifications: the device’s technical token, needed to deliver push messages.
- Failures and performance: app error and crash reports.
- Subscription and payments: plan, cycle, amount, currency, status, and transaction identifiers at the processor or the store.
- Access control and fraud prevention: daily minute consumption per person, access grants from ads, and — to prevent more than one trial period per person — the normalized email and hashed (irreversible) versions of the IP and browser used at registration.
- AI interactions: the text you send to the AI, the response generated, and your rating (👍/👎), used to measure and improve the quality of support.
- Campaign origin (website): campaign parameters and click identifiers present in the link you arrived through.
3.3 Game data (not personal)
Public round results — multipliers, times, sequences — and the statistics derived from them. They identify no one and are the raw material of the analysis.
3.4 Sensitive data
We do not ask for health, biometric, religious, political opinion, or racial origin data. Do not use the chat, Support, or the notes field to write that kind of information, or third-party documents. We automatically block the posting of CPF numbers and credentials in public areas of the app.
4. Where the data comes from
- From you: registration, forms, messages in Support and in the community, preferences, and settings.
- From your use of the Service: automatic records generated by the app and the website.
- From third parties: payment confirmation (Stripe, Google Play, App Store), verification that an ad was watched (Google AdMob) and, when you choose to link a betting house account, the public data of that game session.
5. What we use it for and on what legal basis
We process data only for the purposes below, each with its legal basis under the LGPD:
- Creating and maintaining your account, authenticating access, and verifying your email — performance of a contract (Article 7, V).
- Delivering what you purchased: signals, statistics, windows, game catalog, bankroll management, and alerts — performance of a contract (Article 7, V).
- Billing, invoicing, and subscription management — performance of a contract and legal obligation (Article 7, V and II).
- Tax document issuance and accounting retention — legal obligation (Article 7, II).
- Verifying the country of access at signup, via IP address and the device’s time zone, to prevent accounts in Brazil, in accordance with the Brazilian Federal Government’s Provisional Measure of September 25, 2026 — legal basis: compliance with a legal obligation (Article 7, II). The country is calculated on our own server, without sending the IP to third parties.
- Support and customer service, including with AI assistance — performance of a contract (Article 7, V).
- Community moderation and user safety — legitimate interest (Article 7, IX).
- Fraud prevention, prevention of trial period abuse, duplicate accounts, and misuse — legitimate interest and fraud prevention (Article 7, IX, and Article 11, II, "g").
- Usage metrics, failure diagnostics, and improvement of the product and the models — legitimate interest (Article 7, IX).
- Notifications and alerts you have enabled — consent (Article 7, I), revocable in the settings.
- In-app advertising — consent, where required by the platform, or legitimate interest (Article 7, I and IX).
- Marketing communications by email — consent (Article 7, I), with an unsubscribe link in every message.
- Retention of records and the regular exercise of rights in judicial, administrative, or arbitration proceedings — Article 7, II and VI.
Whenever the basis is legitimate interest, we assess the impact on you and limit the processing to what is necessary. You may object to such processing through the channels in clause 13.
We do not sell your personal data.
6. Cookies and storage on your device
On the website:
- Strictly necessary cookies: two authentication cookies, protected against reading by scripts, that keep you logged in — one short-lived and one for session renewal. Without them, login does not work.
- Browser local storage: basic account data used to render the interface, the language you chose, screen preferences, a random browser identifier for metrics and diagnostics, and the parameters of the campaign you arrived through.
- Third-party cookies: the campaign measurement tools described in clause 7 may set their own cookies when they are active.
In the app:
- Access tokens are kept in the operating system’s protected storage (Keychain on iOS, encrypted storage on Android).
- Preferences, tour flags, and a random device identifier are kept in the app’s local storage.
How to control this: you can clear cookies and site data in your browser settings, and delete local data by uninstalling the app or using "log out". Blocking the necessary cookies prevents login.
7. Advertising
- We display ads through the Google AdMob network, in the app, for the free tiers — including video ads that grant temporary access to paid features. Paid plan subscribers do not see these ads.
- Where the law requires it (European Economic Area, United Kingdom, and Switzerland), we ask for your consent to personalized advertising through Google’s consent panel before any ad is shown, and you may change your choice afterwards.
- On iOS we do not request cross-app tracking permission and we do not collect Apple’s advertising identifier (IDFA) — ads there are non-personalized.
- On the website, when active, we use campaign measurement tools from Meta and TikTok to learn which ads generate registrations and subscriptions. They record visits and funnel events, associated with the click identifiers present in the link.
- We do not sell your data to advertisers and we do not profile you to set prices.
8. Artificial intelligence and automated decisions
- We use third-party AI models in customer support, in community moderation, and in scenario readings. In these functions, the text of your message and the minimum context needed are sent to the model provider to generate the response.
- We do not send passwords, card data, or identity documents to AI models. Avoid writing sensitive data in the chat.
- Moderation may block, hide, or remove messages and restrict your participation in an automated way. Under Article 20 of the LGPD, you have the right to request review by a natural person of any automated decision that affects your interests — simply write to Support or to the DPO’s email.
- We do not use your personal data to train third-party AI models.
9. Who we share it with
We share only what is necessary, with suppliers acting as processors on our behalf and under our instructions, bound by contract and by a duty of confidentiality:
- Google Cloud Platform — hosting of the application and the database.
- Stripe — card payments. Receives email and transaction data.
- Google Play and Apple App Store — purchases made inside the app. They receive and process the payment under their own policies; we receive back only the confirmation and the subscription identifiers.
- Google Firebase — sending notifications (device token), crash reports, and usage metrics.
- Google AdMob — serving and verifying ads.
- OpenAI — artificial intelligence models used in support, translation, and moderation. Receives the text of your message, the minimum conversation context and, in Support, the account data needed to answer you (plan, subscription status, account age). We do not send passwords, cards, or documents.
- Resend — sending service emails. Receives the address, subject, and content of the message.
- Meta and TikTok — campaign measurement on the website, when active (clause 7).
- Partner tracking network — counting clicks on partner betting house links, by click identifier, with no registration data sent.
- Partner betting houses (Betou, Sortenabet) — when you choose to connect your betting house account to play inside the app, we transmit your credentials and your connection’s IP address to the house, because that is what authenticates the game session. Without that connection, nothing is sent to the house.
Some of these suppliers are located outside Brazil (clause 10).
We may also share data:
- due to a legal or regulatory obligation, or to comply with a court order or a request from a competent authority;
- for the regular exercise of rights in judicial, administrative, or arbitration proceedings;
- in the event of a corporate reorganization, merger, or sale of the operation, in which case the successor is bound by this Policy and you will be notified.
10. International data transfers
Some of our suppliers are located outside Brazil (mainly the United States and the European Union). In those cases, the transfer takes place under Articles 33 to 36 of the LGPD, supported by data protection contractual clauses signed with each supplier and limited to what is necessary to perform the contract.
11. How long we keep it
We keep each piece of data for as long as its purpose requires. The periods currently applied:
- Registration, subscription, and preferences: for as long as the account exists.
- Tax and payment data: 5 years, by legal obligation, even after the account is closed.
- Usage metrics and telemetry: 90 days.
- Crash reports: for the period set by the diagnostics provider.
- Notifications sent: 2 days.
- Balance samples from the connected betting house: 30 days.
- Attachments sent in Support: 90 days after the support case is closed.
- Attachments sent in the community: 30 days.
- Community and Support messages, report and sanction records: for as long as necessary for moderation, user safety, and the defense of rights.
- AI interactions: for as long as necessary for quality control and the security of support.
- Fraud prevention controls (normalized email and hashed versions of IP and browser): for as long as they are necessary to prevent more than one trial period per person.
- Round results and predictions: 14 and 90 days, respectively. These are not personal data.
Account deletion. When you delete your account, we permanently erase your registration, settings, gaming profile, alerts, notifications, device tokens, bankroll entries, balance samples, subscriptions, payments, and sessions, and we unlink your identity from the telemetry records.
The following remain, for the periods stated above: messages already posted in the community and in Support, moderation records, AI interactions, fraud prevention controls, and whatever the law requires us to keep — including tax data. Once those periods end, the data is deleted.
- Accounts of users in Brazil: deleted by October 5, 2026, at 11:59 PM (Brasília time), by their holder or automatically, with the same effects as a deletion request described in section 13.
12. Security
We adopt technical and administrative measures appropriate to the risk:
- the account password is stored only as a hash using the bcrypt algorithm, never in readable text;
- the email verification code is stored only as a hash, with a limit on attempts;
- encrypted connection (HTTPS/TLS) for all communication between you and our servers;
- sessions handled by cookies protected against reading by scripts on the website, and by the operating system’s secure storage in the app, with the option to lock the app with biometrics;
- limits on login attempts and on requests, to contain automated attacks;
- a filter that blocks the posting of CPF numbers and credentials in the public areas of the app;
- attachments served only to those entitled to them, never through a public link;
- the database in a controlled cloud environment, with access restricted to the personnel who need it;
- scheduled automatic deletion of data that has a defined retention period.
Betting house credentials. If you choose to connect your account at a betting house, the credentials are stored on our servers because the game session must be re-authenticated on each access. Use a password at the betting house that is different from the one you use on other services and disconnect the account in the settings when you no longer want to use the game inside the app — removal is immediate.
No system is 100% secure. You have a role too: use a strong, unique password, do not share credentials, and keep your device protected.
13. Your rights and how to exercise them
Under Article 18 of the LGPD, you may at any time request:
- confirmation that we process your data and access to it;
- correction of incomplete, inaccurate, or outdated data;
- anonymization, blocking, or deletion of data that is unnecessary, excessive, or processed in breach of the law;
- portability to another supplier;
- deletion of data processed on the basis of consent;
- information about whom we share your data with;
- information about the possibility of withholding consent and the consequences of doing so;
- withdrawal of consent;
- objection to processing based on legitimate interest;
- review of automated decisions (Article 20).
How to request: write to contato@grochatech.com.br or use Support in the app. We respond within 15 days. We may ask for information to confirm your identity before answering — this protects you against fraudulent requests made in someone else’s name.
Account deletion: you can delete your account and the associated data directly in the app or through the account deletion page on the website, without having to talk to anyone. Deletion is permanent and does not entitle you to a refund of the period already paid for.
If you are not satisfied with our response, you may complain to the Autoridade Nacional de Proteção de Dados (ANPD — Brazilian Data Protection Authority) — gov.br/anpd.
14. People under 18
The Service is prohibited for people under 18. We do not knowingly collect data from children or adolescents. If an account is identified as belonging to a minor, it is closed and the data is deleted, except for what the law requires us to keep. If you are a parent or guardian and suspect that a minor has created an account, write to contato@grochatech.com.br and we will resolve it as a priority.
15. Security incidents
If an incident occurs that may create a relevant risk or harm to you, we will notify you and the ANPD within a reasonable period, describing what happened, the data involved, and the measures taken, in accordance with Article 48 of the LGPD.
16. Users outside Brazil
We operate from Brazil under the LGPD. If you are in another country, we process your data to the same standard described here and we honor the rights provided by your local legislation wherever applicable — including access, correction, and deletion requests — through the same channels set out in this Policy.
17. Changes to this Policy
We may update this Policy. The version in force is always published in the Service, with the date it was updated. Material changes are announced by email, notification, or an in-app notice and, where the change requires it, we will ask for your consent again.
18. Contact
G DA SILVA C ROCHA DESENVOLVIMENTO DE SOFTWARE & TECNOLOGIA — CNPJ 38.323.551/0001-69
Data Protection Officer (DPO) and data subject channel: contato@grochatech.com.br — +55 (19) 98847-2424