Privacy Policy - Rufi
Last updated: November 8, 2025
1. Introduction
This Privacy Policy describes how Rufi collects, uses, stores and protects your personal information.
We take your privacy seriously and are committed to protecting your data in accordance with the LGPD (Brazilian General Data Protection Law).
2. Information We Collect
2.1 Information You Provide
- Registration Data: Name, email, password (encrypted)
- Pantry Data: Items, categories, quantities
- Shopping Lists: Products, preferences
2.2 Information Collected Automatically
- Usage Data: Features used, time of use
- Device Data: Model, operating system
2.3 Payment Information
IMPORTANT: We do not store credit card data. All payments are processed by certified providers (PagSeguro, Apple Pay, Google Pay).
3. How We Use Your Information
- Provide and improve the service
- Personalize your experience
- Process payments and subscriptions
- Send important notifications
- Ensure security and prevent fraud
4. Sharing of Information
4.1 We Do NOT Sell Your Data
We never sell, rent or trade your personal information.
4.2 Necessary Sharing
- Payment Processors: PagSeguro, Stripe
- Infrastructure: Secure servers
5. Data Security
- Encryption: HTTPS/TLS in transit and at rest
- Passwords: bcrypt hash
- Tokens: OAuth 2.0
- Compliance: PCI-DSS via gateways
6. Your Rights (LGPD)
- Access your data
- Correct inaccurate information
- Request account deletion
- Export your data
- Revoke consents
7. Data Retention
- Active Account: As long as you use the app
- Inactive Account: 12 months
- Tax Records: 5 years
8. Contact
For privacy questions:
- Email: privacidade@rufi.app
- DPO: dpo@rufi.app