Piloto do Afiliado

Privacy Policy

Português

Updated on

Texto base, ainda não revisado juridicamente, e com os dados do titular por preencher. Vale como descrição honesta do que o sistema faz — não como parecer.

This policy describes how Piloto do Afiliado handles personal data under Brazil's Law 13.709/2018 (LGPD). In one sentence: we keep the minimum needed to publish your posts and answer your messages, we do not sell any of it, and we delete it when you ask.

1. Data we collect

Account data: name, e-mail, and a password stored as a hash (never in plain text), plus access timestamps used to keep your session alive. Connected profiles: the profile ID and username on Instagram or TikTok, and the access tokens the platform returns. We never receive or ask for your social network password — the connection is OAuth, performed on the platform's own screen. What you publish: the images and videos you upload, the caption, the scheduled time, and the outcome of each publication (success, failure, the post link). People who interact with you: when someone comments on your post or sends you a DM, Meta sends us the message content, that person's username and ID, and — when the platform returns it — their follower count and whether they follow your profile. This exists so you can reply and so the "followers only" gate can work. Site access: Cloudflare, which hosts the service, logs IP address and technical request data for security and abuse prevention.

2. How we use it

  • Publish the content you scheduled, at the time you scheduled it.
  • Deliver automated replies and the replies you write in the inbox.
  • Keep your session, refresh tokens that are about to expire, and warn you when a connection

breaks.

  • Investigate failures, abuse, and fraud.

**We do not use your data or your audience's data for third-party advertising, we do not sell data, and we do not train AI models on your message content.**

3. Legal basis

  • Performance of a contract (LGPD art. 7, V) — account data, connected profiles, and

scheduled content: without them the service cannot do what it was hired to do.

  • Legitimate interest (art. 7, IX) — technical access logs, used for security and abuse

prevention.

  • Consent (art. 7, I) — connecting each profile, granted on Meta's or TikTok's own

screen and revocable at any time there or here.

4. Who we share with

Only with those the service requires, and each receives only what it needs:

  • Cloudflare, Inc. — hosting, database, and media storage.
  • Meta Platforms, Inc. — Instagram publishing and sending/receiving comments and DMs.
  • TikTok / ByteDance — video publishing on TikTok.
  • Google LLC — the site's typeface is loaded from Google Fonts, which exposes the

visitor's IP address to Google. This applies to public pages; the signed-in area does not depend on it. These services process data outside Brazil, mainly in the United States. The international transfer relies on the contractual clauses and safeguards each of them offers. We may also disclose data under a court order or legal requirement.

5. Cookies

We use one cookie: the session cookie, created when you sign in and deleted when you sign out. It is strictly necessary — without it there is no way to know the next page is yours. Your light/dark theme choice lives in your browser's localStorage, never leaves it, and is not a cookie. There are no advertising, social, or third-party analytics cookies on this site.

6. How long we keep it

  • Account and connected profiles: while the account exists.
  • Access tokens: while the profile is connected. Disconnecting deletes the token

immediately.

  • Uploaded media: while the publication exists in your account.
  • Conversations (DMs and comments): while the account exists, so you keep your support

history.

  • Technical access logs: per Cloudflare's retention, typically a few days.

Once the account is deleted, all of the above is erased within 30 days — see Data deletion.

7. Your rights

Under the LGPD you may request confirmation of processing, access, correction, anonymization, blocking, erasure, portability, information about sharing, and withdrawal of consent. To exercise any of them, write to contato@pilotodoafiliado.com.br. We reply within 15 days. A profile connection can be cut at any time without contacting us: here, under Accounts → Remove; or on the social network's side, by revoking the app's access.

8. Security

Social network tokens are stored encrypted (AES-GCM) and are only decrypted, in memory, at the moment of publishing or replying. Every database query is scoped by the owner's identifier — that is what keeps one account's data from surfacing in another. The webhook that receives Meta events validates the cryptographic signature of every call and rejects everything if the key is not configured. Without that, anyone who discovered the URL could send messages on a profile's behalf. No system is infallible. In the event of an incident with relevant risk, we notify the data subjects and the Brazilian DPA (ANPD), as the law requires.

9. Changes

Changes to this policy appear on this page with the update date at the top. Any change that broadens the use of data is announced by e-mail before it takes effect.