Privacy Policy

Last updated: 20/02/2026


This Privacy Policy describes how Desviados.net (hereinafter "Platform", "we", or "our") collects, uses, stores, shares, and protects your personal data, in compliance with Brazil's General Data Protection Law (LGPD) and the European General Data Protection Regulation (GDPR).

1. Data Controller

Desviados.net acts as the data controller for LGPD and GDPR purposes and is responsible for decisions regarding the processing of personal data collected through the Platform.

Controller Contact: [email protected]

2. Personal Data Collected

We collect the following categories of personal data:

2.1. Registration and Identification Data

  • Username;
  • Email address;
  • Password (stored with secure encryption - bcrypt hash);
  • Date of birth (optional, for personalization and curation);
  • Location (optional, provided voluntarily);
  • Profile picture (optional);
  • Biography and personal preferences (optional).

2.2. User-Generated Content

  • Texts and published narratives;
  • Comments and interactions on publications;
  • Uploaded images and clips;
  • Private messages between users;
  • Meetups and events.

2.3. Technical and Browsing Data

  • IP address;
  • Access logs (date, time, pages visited);
  • Device information (type, operating system, browser);
  • Cookies and similar technologies;
  • Session and authentication data.

2.4. Social Interaction Data

  • Likes (upvotes) on content;
  • List of followers and followed profiles;
  • Badges and unlocked achievements;
  • Content view history.

2.5. Sensitive Data

We do not request sensitive data by default. If you include sensitive data in content or in your profile, processing will occur based on your consent and in accordance with the LGPD.

3. Purposes of Processing

We use your personal data for the following purposes:

  • Create and manage your user account;
  • Authenticate access and ensure account security;
  • Allow the publication, sharing, and viewing of content;
  • Process password recovery via email;
  • Display rankings, badges, and social features;
  • Apply privacy settings (private profile, content visibility);
  • Moderate content and prevent abuse;
  • Comply with legal obligations and respond to authority requests;
  • Improve user experience and develop new features;
  • Send service-related notifications (account activity, messages);
  • Prevent fraud, spam, and malicious activity.

4. Legal Bases for Processing

Personal data is processed based on the following legal grounds (Art. 7 and 11 of the LGPD):

  • Performance of contract: To provide Platform services according to the Terms of Use;
  • Legitimate interest: For security, fraud prevention, and service improvements;
  • Consent: For optional data and submitted content;
  • Compliance with legal obligation: To comply with legal and regulatory requests;
  • Credit protection: For payment processing, when applicable.

5. Data Sharing

Your personal data may be shared in the following situations:

5.1. Service Providers

We share data with third parties that provide essential services, including:

  • Hosting and infrastructure providers;
  • Email services (for password recovery and notifications);
  • CDN (Content Delivery Network) for media distribution;
  • Analytics and performance monitoring tools;
  • Payment processing services (when applicable).

All providers are contractually required to protect your data and use it only for authorized purposes.

5.2. Legal Requests

We may disclose personal data when required by law or by court order, including criminal investigations or legal proceedings.

5.3. Public Content

Content configured as "Public" is accessible to all Platform visitors. You control visibility through privacy settings.

6. User Privacy Controls

6.1. Content Visibility

You control who can view each piece of published content:

  • Public: Visible to all;
  • Logged-in Users Only: Visible only to authenticated users;
  • Followers Only: Visible only to people who follow you;
  • Private: Visible only to you.

6.2. Private Profile

When enabling the "Private Profile" option in settings:

  • Your profile does not appear in public lists (rankings, badges, searches);
  • Third parties cannot access your profile via direct link;
  • Your content does not appear in public lists and feeds;
  • You and administrators continue to have normal access.

6.3. Temporary Account Deactivation

You can deactivate your account at any time in profile settings. When deactivated:

  • All your content becomes hidden;
  • Your profile stops appearing in public lists;
  • Your data remains securely stored;
  • The account can be reactivated instantly by logging in again, restoring all content and visibility.

7. Data Retention and Deletion

7.1. Retention Period

We keep your personal data while:

  • Your account is active (including temporarily deactivated accounts);
  • Necessary for compliance with legal obligations;
  • It is necessary for security, fraud prevention, and dispute resolution.

7.2. Permanent Deletion

To request permanent deletion of your account and personal data, send a request to [email protected] with the subject "Data Deletion - LGPD".

After identity verification, we will proceed with deletion within the legal deadline. Note that:

  • Deletion is irreversible;
  • Some data may be kept in anonymized form for statistical purposes;
  • Data required to comply with legal obligations will be retained as required by law.

7.3. Difference Between Deactivation and Deletion

Feature Temporary Deactivation Permanent Deletion
Content Hidden, can be restored Permanently deleted
Personal data Stored securely Deleted in accordance with LGPD
Reactivation Instant upon login Not possible
How to do it Profile settings Contact via email

8. Information Security

We implement technical and organizational measures to protect your personal data, including:

  • Password encryption (bcrypt hashing);
  • HTTPS/TLS connections for secure data transmission;
  • Access and authentication controls;
  • Security monitoring and access logs;
  • Regular encrypted backups;
  • Security policies and team training.

Despite all efforts, no system is 100% secure. We recommend using strong, unique passwords.

9. Cookies and Similar Technologies

We use cookies to:

  • Remember browsing preferences and settings;
  • Keep your login session active;
  • Remember language and theme preferences;
  • Platform usage analytics (optional).

For full details, see our Cookie Policy.

10. International Data Transfer

If there is an international transfer of personal data, we will adopt appropriate safeguards under the LGPD (Art. 33) and GDPR, including standard contractual clauses and equivalent protection guarantees.

11. Data Subject Rights

Under the LGPD (Art. 18) and GDPR, you have the following rights:

  • Confirmation and Access: Confirm the existence of processing and access your data;
  • Correction: Correct incomplete, inaccurate, or outdated data;
  • Anonymization, Blocking, or Deletion: For unnecessary, excessive, or non-compliant data;
  • Portability: Receive data in a structured and interoperable format;
  • Deletion: Request permanent data deletion (except where there is a legal retention obligation);
  • Information About Sharing: Know with whom we share your data;
  • Withdrawal of Consent: Withdraw previously provided consent;
  • Objection: Object to processing in cases permitted by law.

How to exercise your rights: Send a request to [email protected] with the subject "LGPD/GDPR Rights". We will respond within 15 days.

12. Password Recovery and Email Communications

We use your email address to:

  • Send password recovery links (valid for 24 hours);
  • Notify about important account activity;
  • Communications related to the Terms and Policies.

We do not send promotional emails without explicit consent.

13. Minors

This Platform is exclusively for adults over 18. We do not intentionally collect data from minors. If we become aware of inadvertent collection, we will delete the data immediately.

If you identify improper use by minors, report it immediately to [email protected].

14. Changes to this Policy

We may update this Policy periodically. Significant changes will be communicated through the Platform or by email. The date of the last update is shown at the top of this document.

15. Applicable Law and Supervisory Authority

This Policy is governed by Brazilian law, especially the LGPD (Law 13.709/2018). For GDPR-related matters, you may contact European data protection authorities.

Brazilian National Data Protection Authority (ANPD): www.gov.br/anpd

16. Contact

For privacy questions, rights requests, or security incidents:

Email: [email protected]
Suggested subject: [LGPD/GDPR Privacy] or [Exercise of Rights]


Terms of Use · Cookie Policy