Skip to content
OAZE

Privacy policy

Last updated: 15 September 2026

Draft pending legal review. The content describes how the product actually works, but it has not been reviewed by a lawyer and required details are missing.

Before final publication: fill in the controller identification (§1), appoint the data protection officer (§11, required by art. 41 of the LGPD) and review the legal bases in §3.

1. Who is responsible

OAZE is the controller of the personal data processed here, under Brazil's General Data Protection Law (Law 13.709/2018).

You are the data subject. The controller role only changes in a future business contract in which the client decides how to process other people's personal data; that case will have its own contract and annex.

To be completed: legal name, company tax ID (CNPJ) and address.

2. What we collect

Sign-up data. Email, password (stored only as a hash, never in plain text) and, optionally, the name you want to be called by.

Financial data you enter. Accounts, cards, categories, transactions, budgets, goals and investments. We do not fetch this from anywhere: it all arrives because you typed it or imported a file you downloaded from your own bank.

Plan data. Plan, limits and subscription status linked to the account, with the session and subscription identifiers at Stripe.

Payment data. When you subscribe, OAZE sends Stripe your email and the plan and amount chosen. Card details are typed on Stripe's page and never pass through OAZE.

Minimal technical data. Server error logs, with a request identifier and a timestamp. They do not include financial content.

We do not collect: your location, your contact list, your browsing history on other sites, or third-party data. We do not use advertising cookies or social network trackers. We use only storage that is essential for the session, preferences and local operation. If you choose to sign in with Google, Google may use its own cookies during that authentication.

3. What we use it for, and on what legal basis

  • Performing the contract (art. 7, V) — keeping your account, syncing your data between devices, enforcing plan limits and charging the subscription, when there is one.
  • Complying with legal obligations (art. 7, II) — meeting legal obligations applicable to the service.
  • Legitimate interest (art. 7, IX) — security, fraud prevention and fixing defects, always with the minimum data needed.
  • Consent (art. 7, I) — only for sending data to UGLEZ, described in §5. You can choose not to use UGLEZ and the rest of the product works exactly the same.

4. Where the data lives

Records live in a PostgreSQL database managed by Supabase, with per-account isolation enforced in the database itself (Row Level Security): an account only reaches its own rows, and that is enforced by the database, not by a check in the application.

The site is hosted on Hostinger.

International transfer: these services may keep servers outside Brazil. Before each transfer, OAZE must confirm the legal basis, the country, the importer and a valid mechanism under the LGPD and ANPD Resolution 19/2024. To be confirmed: the Supabase project region and the countries used by each supplier.

5. UGLEZ and the use of artificial intelligence

Much of what UGLEZ shows is calculated in your own browser. For that, no data leaves the device.

When you talk to UGLEZ, the question and a summary of your numbers go to a server of ours, which calls OpenAI's Responses API. The screen shows which categories of data go along before you send.

What is not sent: transaction descriptions, merchant names, account or card numbers, and your email.

Your data is not used to train models. It is sent only to generate your answer. The call does not ask the API to store the generated response (store: false).

The provider access key stays on the server. It never reaches your browser, and the browser never talks directly to any AI provider.

6. Who we share with

We share only what is needed for the operation you chose. Each supplier's role may be processor, sub-processor or independent controller:

  • Supabase: PostgreSQL database, authentication, Edge Functions and the backups available on the contracted plan.
  • Hostinger: hosting of the public files and the technical logs needed to deliver and secure the site.
  • Stripe: Checkout, subscription, invoice, cancellation, refund, dispute and fraud prevention.
  • OpenAI: UGLEZ's answer, only when you choose to send a question, within the limits described in §5.
  • Google and Apple: authentication, only when the method is enabled and you choose it.
  • jsDelivr: technical fallback to load the public Supabase library if the local file is unavailable.

Cloudflare Turnstile, hCaptcha, analytics, external SMTP and error monitoring will only be added to this list before being activated and after assessing purpose, data, retention, security and international transfer.

We do not sell your data. We do not hand it over for advertising. We do not cross-reference it with other databases.

We may provide data under a court order. In that case we notify you, except when the law forbids the notice.

7. What stays only on your device

OAZE keeps in the browser's localStorage: display preferences (theme, selected month), a cache of your data so the screen opens quickly, and a queue of what has not been uploaded yet while you are offline.

This is per device and never reaches us. Clearing the browser data erases this part — without affecting what is in your account.

If you use OAZE without an account, your financial records stay on the device, and we have no copy and no way to recover them. Hosting may still generate the technical and access logs described in this policy.

8. Cookies and privacy choices

OAZE uses cookies or equivalent technologies strictly necessary for the session, security, requested preferences and local operation. They are not used for advertising.

The banner lets you accept or refuse optional technologies. They stay off until you choose and, if refused, analytics, marketing, non-essential personalization and optional SDKs cannot start. Today OAZE has none of those categories active.

The decision is kept in oaze.cookies.v2, in your browser, so the banner respects your choice. You can erase this preference in your browser data and choose again.

Refusing optional technologies does not end the session or turn off features needed for the service you asked for. If you do not want the processing required for an account, use the local mode without an account; in that mode, OAZE does not receive your financial records.

9. How long we keep it and how we delete it

Financial records remain for as long as your account exists. When you delete the account, OAZE cancels the renewal, revokes the sessions and removes the data from the active database.

Some records may be kept for the period required by law or needed to exercise rights, including billing, fraud, acceptances and access logs. Where art. 15 of the Brazilian Internet Act applies, access logs are kept for 6 months, under confidentiality and security.

Residual copies may remain in backups protected by the supplier's technical cycle. They are not available for normal use and must return to the deletion queue if a backup is restored. The maximum period will be published after contractual confirmation with Supabase.

Security incident records are kept for at least 5 years. Data retained after deletion will not be reused for marketing or reactivation.

10. Your rights

The LGPD (art. 18) guarantees you: confirmation of processing, access, correction, anonymization or blocking, portability, deletion, information about sharing and withdrawal of consent.

In practice, two of them you exercise on your own, without asking anyone:

  • Portability and access — Settings → Export. Everything comes out, in an open format, right away.
  • Deletion — Settings → Delete account. We ask you to type your own email to confirm, because the operation cannot be undone.

For the rest, write to support. We reply within 15 days.

11. Data protection officer (DPO)

To be completed: name and contact of the data protection officer, as required by art. 41 of the LGPD.

12. Children and teenagers

OAZE is not intended for people under 18 without a legal guardian's permission, and we do not knowingly collect children's data. If that happens, tell support and we delete it.

13. Incidents and responsibilities

OAZE adopts security measures proportional to the risk and may be held liable when it causes harm through unlawful processing, an avoidable failure, unlawful instructions, delay in containment, or negligent choice and oversight of a supplier.

If a processor breaches the LGPD or our lawful instructions, or if an independent controller fails in a decision of its own, it may be held liable for its part in the event. This does not prevent OAZE from cooperating with the investigation and supporting the data subject.

The user may be held liable for fraud, unlawful acts, deliberate sharing of credentials or proven exclusive fault. A common mistake or phishing does not automatically transfer all responsibility.

An incident that may cause relevant risk or harm will be reported to the ANPD and to the affected data subjects within 3 business days, unless a specific legal deadline applies. The notice will state the nature of the data, the risks, the measures taken and the contact channel.

14. Accessibility and privacy

This policy, the cookie choices, rights requests, export and deletion must work with a keyboard, screen readers, zoom and other assistive technologies. OAZE's target is WCAG 2.2 level AA.

If a barrier prevents you from exercising a right, write to suporte@oaze.site. We will offer an equivalent alternative at no cost and with no loss of deadline.

15. Changes to this policy

If something relevant changes, we notify you by email 30 days in advance and update the date at the top of this page.

16. Contact

Support page or suporte@oaze.site.