Privacy
Privacy Policy
Effective July 10, 2026 · Corrected July 19, 2026 · Privacy Policy version 4
This Privacy Policy explains how Severo handles personal data for the Severo app, support channels, account deletion channels, and public website pages.
Severo is intended for adults 18 and older. Renan Bredariol is the controller responsible for the processing described in this policy. You can contact Severo about privacy, support, and account deletion at support@severofit.app.
Data we collect
Depending on how you use Severo, we may collect or process:
- Account data, such as name, email address, user or account identifiers, authentication state, account status, email verification or password-recovery request state, and legal acceptance versions.
- Profile, health, and fitness data you choose to enter, such as age, sex, height, weight, goals, nutrition, hydration, workout routines, workout history, progress, and preferences.
- Food, barcode, exercise, workout, reminder, notification, and app settings data.
- Privacy choices, analytics consent state, readable export data, deletion requests, and support messages.
- Optional categorical app-interaction analytics and analytics identifiers when analytics is enabled and your choices allow it.
- Crash logs, diagnostics, and app or device identifiers used for reliability.
- Website request metadata, such as IP address, browser or device information, timestamps, and pages requested when processed by the website host.
Some Severo data is health or fitness-related. We use it to provide the features you choose and handle it with extra care.
Passwords, one-time verification or recovery codes, session credentials, and similar authentication material are used to authenticate and protect accounts. Severo does not intentionally include this material in product analytics.
How we use data
We use data to:
- Create, authenticate, secure, and manage accounts.
- Provide fitness, nutrition, hydration, workout, history, export, deletion, privacy, and support features.
- Save preferences and app settings.
- Respond to support, deletion, privacy, and security requests.
- Improve reliability, diagnose crashes or errors, and protect the app and website.
- Comply with legal, security, platform, and operational obligations.
- Analyze product usage only when analytics is enabled and allowed by your choices.
Legal bases and health-related data
Depending on the data and purpose, Severo relies on your consent, steps requested by you or performance of the service agreement, compliance with legal or regulatory obligations, the regular exercise of rights, and legitimate interests for proportionate non-sensitive security and service operations.
Severo treats profile, body, nutrition, hydration, weight, workout, exercise, and progress information that concerns or reveals health as sensitive health data. The Terms include a dedicated sensitive health and fitness data section, and the app records account-level acceptance of the current Terms as your authorization for this health-data processing and, distinctly, for its transfer and storage with Supabase in the United States (Ohio). Accounts without current acceptance evidence may be asked to review and accept updated terms before entering health and fitness areas. This account-level acceptance supports the setup and daily tracking features you choose.
You may refuse or withdraw this consent by not continuing the setup or by contacting support@severofit.app. Refusal or withdrawal may prevent Severo from providing features that require this information. Withdrawal does not affect processing that was lawful before it.
Optional analytics is off unless it is enabled and your choice allows it. You can withdraw analytics consent in the app.
Sharing and service providers
We do not sell personal data. We do not use personal data for targeted advertising.
Severo currently uses Supabase for account authentication, app-data storage, account export, and deletion infrastructure; Resend for transactional authentication emails, including verification and password-recovery codes; and Cloudflare for website delivery and support-email routing.
Severo also uses Google for Google Sign-In when you choose and the option is available in your app version, Mixpanel for optional product analytics only after your consent choice allows it, and Firebase Crashlytics for enabled crash and diagnostic processing used to improve reliability.
These providers process data to support Severo. Their own infrastructure, security, and retention processes may apply to data they process on Severo's behalf.
International processing and transfers
Remote services can involve processing outside Brazil:
- Supabase: the primary production database and authentication project are in the United States (Ohio). Supabase processes account, authentication, app, and user-entered health and fitness data to provide the account-backed service. Sensitive health data collected after acceptance of the current Terms' sensitive health and fitness data section is transferred and stored there under that account-level authorization. Primary account data is kept while the account is active and follows the deletion and lawful-retention rules below.
- Resend: primary processing takes place in the United States. Resend processes the email address, authentication-email content, and delivery metadata needed to send verification and password-recovery messages. Its operational and security records follow its provider terms and applicable law.
- Cloudflare: its global network processes limited website request metadata in the United States, Europe, and other network locations to deliver and protect the website. For support-email routing, it also processes sender and recipient addresses, message content, attachments you choose to send, and routing metadata. Cloudflare states that network metadata is retained for a limited period under its service terms.
- Google Sign-In: Google may process identity information in countries where it or its subprocessors operate when you choose this option. Google account and provider retention rules also apply.
- Mixpanel: United States data residency is used by default. It processes optional categorical product analytics only after you enable analytics consent. Severo excludes raw health or fitness entries, user content, and authentication secrets from these events.
- Firebase Crashlytics: processes crash logs, diagnostics, and app or device identifiers for reliability. Google may process this information in countries where it or its subprocessors maintain facilities.
For sensitive health data collected after acceptance of the current Terms' sensitive health and fitness data section, Severo uses the international-transfer authorization described in those Terms and in this policy as the Article 33, item VIII, mechanism under the LGPD. For account use, authentication emails, support requests, and user-selected Google Sign-In, Severo uses Article 33, item IX, only where the transfer is necessary for a purpose allowed by Article 7, items II, V, or VI. Provider data-processing terms, contractual safeguards, and security measures support these transfers but do not remove Severo's responsibility to use an applicable LGPD mechanism and honor your rights.
Severo is responsible for selecting and configuring providers, limiting disclosed data, maintaining app-side access and consent controls, and responding to rights requests. Providers are responsible for their infrastructure and contractual security, subprocessor, and deletion duties. You may request the current provider list, destination information, retention criteria, and information about applicable contractual clauses or safeguards through support@severofit.app. Provider processing does not remove Severo's responsibilities as controller or your right to petition the ANPD.
Your choices
Mixpanel analytics is configured for production, but collection remains off until you enable analytics consent. You can withdraw that consent in the app, which stops optional analytics collection and resets the analytics identity.
Firebase Crashlytics is enabled for crash and diagnostic processing. It is used for reliability and security, not controlled by optional analytics consent, and does not intentionally receive raw health or fitness entries, user content, or authentication secrets.
The static public website does not include Severo advertising or product-analytics scripts and does not set those cookies through Severo website code. The website host may still process request metadata and use strictly necessary security or delivery mechanisms.
Severo may request camera access for barcode scanning. Severo processes the camera view on the device for barcode reading and does not intentionally upload or store camera images. Severo may request notification permission for local reminders. During an active workout, Android may show an ongoing notification and iOS may show a Live Activity with exercise, progress, elapsed or rest state, and workout controls. These surfaces can be visible on your device or lock screen according to your operating-system settings.
You can request account deletion in Settings > Privacy and data, through the public Account deletion page, or by emailing support@severofit.app.
Your LGPD rights
You may request confirmation of processing, access, correction, information about shared use, anonymization, blocking or deletion where applicable, portability subject to regulation, review of applicable automated decisions, objection, information about the possibility of refusing consent and its consequences, withdrawal of consent, and deletion of data processed on consent subject to lawful retention exceptions. You may also petition the ANPD or consumer-protection bodies as provided by law.
Requests are free through support@severofit.app. We may use proportionate account context to verify the requester, but you should never send a password or one-time code. If a request cannot be fulfilled, Severo will provide the factual or legal reason when required. The in-app readable export is a convenience and does not limit a broader access request.
Retention, export, and deletion
After an authenticated server deletion succeeds, Severo deletes the Supabase Auth account and active app-owned account data. The app then starts account-data cleanup on that device. If a local cleanup step cannot complete, the app reports items to review. An emailed request may require verification before action. If server deletion fails, the app does not present it as completed and you can retry or contact support.
Readable export covers app-owned account data supported by the current export flow. Some processor-held data, support records, diagnostics, and website metadata may not be included in the in-app export. Files you saved or shared outside Severo are not deleted automatically.
We keep account and tracking data while your account is active or while needed for the purposes described in this policy. After deletion or account closure, limited records are retained only where permitted by law, under an applicable legal basis, and for the necessary period. Temporary backup copies are isolated from ordinary use until overwritten or expired under the provider's backup cycle. Support, privacy-request, and legal/security records are retained only as needed to handle the request, comply with obligations, or exercise or defend rights. Provider-held records may not be removed at the same moment as active app-owned data, but provider schedules do not override Severo's controller responsibilities or your rights.
Children and teens
Severo is intended for adults 18 and older. If you believe someone under 18 created an account or provided personal data, contact us so we can review and take appropriate action.
Security
We use technical and organizational measures designed to protect personal data. No app, website, network, or storage system can be guaranteed to be completely secure.
Changes to this policy
We may update this policy when the app, website, providers, legal requirements, or operations change. Material updates will show a new effective date and policy version and may require renewed acceptance in the app. Non-material corrections may keep the same version and effective date while showing a corrected or last-updated date.
Contact
For privacy, support, and account deletion requests, contact support@severofit.app.