Privacy Policy
This policy describes what we collect, why, and the choices you have, in plain language.
Who we are
This Privacy Policy explains how personal data is handled in Decide It (the “App”) and on this website. The controller (controlador under the Brazilian LGPD) is Decide It, Brazil. Contact: contact.decideit@gmail.com.
Privacy contact / data protection officer (encarregado): Decide It Privacy Team, contact.decideit@gmail.com.
In short: no ads, no analytics and no tracking SDKs in the App. We don’t sell your personal data. You sign in only with Apple or Google; we never ask for your phone number or your contacts, and your email is never shown to other users. You can delete everything in Settings.
Data we collect
Data you give us
- Sign-in account (Apple or Google)
- When you continue with Apple or Google, the provider confirms who you are and we receive your email, your user ID at that provider and, if it shares it, your name. With Apple, the email may be a private relay address that forwards messages to you. We never receive your Apple or Google password. This data is kept by our authentication system.
- Used for contact, account recovery and to confirm requests about your data. It stays private: no other user can see your email.
- Profile
- Display name (it may come prefilled from your Apple or Google account, and you can edit it), @username and an optional profile photo that you upload yourself; we don’t import your Apple or Google photo. Name, @username and photo are visible to other users in the App. Profile photos are stored in a public file location: anyone who has the exact image address can open it.
- Questions
- The question, the options (text and optional photos), whether votes are public or anonymous, the deadline, the S.O.S. flag, the share code and the verdict.
- Votes and takes
- Your vote, and optionally your take as text or as an audio recording (up to 30 seconds). Audio may contain your voice and anything audible around you.
- Reactions
- The emoji reactions (🔥 😂 🤡 💯) you add to takes.
- Friends, blocks, reports
- Friend requests and friendships, people you block, and reports you file (what was reported, the reason you pick or write, and when).
- S.O.S. usage
- Which week you used your weekly S.O.S., and your setting for receiving S.O.S. alerts.
Data collected through permissions you grant
- Camera and photos
- Used only when you choose to take or pick a picture for an option or for your profile. Pictures are resized and compressed on your device before upload. Photo-library access uses the system picker.
- Microphone
- Used only while you record an audio take.
- Notifications
- If you allow them, we store your Expo push token and platform (iOS or Android) to send you notifications, and we keep a short queue of the notifications we send (title, text and the question they refer to).
- Last activity (“Active now”)
- We store the time of your last activity in the App to show “Active now” to your friends, only if you also turn the feature on. You can turn it off in Settings.
Data created automatically
- Language
- Your language (Portuguese, English or Spanish) is saved to your profile so notifications arrive in your language.
- Technical data
- Our hosting providers process technical data such as IP address and request logs to deliver and secure the service. We don’t use it for advertising.
- On your device
- The App stores your login session and a few settings (such as language, appearance and whether it already asked about notifications) in the app’s local storage.
What we don’t collect: we don’t collect your location, an advertising ID, your phone number or your contacts. The App contains no advertising or analytics tools.
Why we use data and our legal bases
Legal bases refer to the EU/UK GDPR and the Brazilian LGPD.
- Run the service
- Create your account, sign you in, show questions, votes and takes, and keep the Golden Rule and vote privacy working. Contract (GDPR 6(1)(b)); performance of a contract (LGPD art. 7, V).
- Find friends
- Let you find people by @username and invitation link. Contract (GDPR 6(1)(b)); performance of a contract (LGPD art. 7, V).
- Notifications
- Tell you about new questions, S.O.S., verdicts and friend requests. Contract and, for push permission, consent.
- Safety and abuse prevention
- Handle reports and blocks, enforce the Terms, apply usage limits. Legitimate interests (GDPR 6(1)(f); LGPD art. 7, IX).
- Legal obligations
- Respond to valid legal requests and keep records the law requires. Legal obligation (GDPR 6(1)(c); LGPD art. 7, II).
You can withdraw consent at any time by turning off the permission in your phone’s settings, without affecting what happened before.
International transfers
Our providers may process data in countries other than yours. Our main database is hosted in São Paulo (Brazil). When data is transferred out of your country, we rely on safeguards recognized by law, such as standard contractual clauses or adequacy decisions (GDPR Chapter V; LGPD art. 33).
How long we keep data
- Account, profile, questions, votes, takes, reactions, friends
- Until you delete your account. We don’t automatically delete older questions.
- Sign-in data (email, provider ID)
- Kept with your account and erased with it.
- Notification queue
- Notifications already sent or failed are removed after 7 days.
- Reports
- Kept as long as needed for safety and legal reasons: up to 12 months after the report is reviewed. When an account is deleted, the link between a report and the reporter is removed.
- Backups and logs
- Provider backups and logs may keep copies for a limited time (up to 30 days) before they expire.
See Delete account and data for what happens when you delete your account.
Your rights
Depending on where you live (for example under the LGPD, the GDPR, the UK GDPR, or the CCPA/CPRA in California), you may have the right to:
- Access the personal data we hold about you and get a copy.
- Correct inaccurate data. You can edit your name, @username and photo in the App.
- Delete your data. Use Settings → Delete account and data, or this page.
- Portability: receive your data in a structured, commonly used, machine-readable format. The App has no self-service export yet, so ask us by email.
- Object to or restrict certain processing, and withdraw consent (for example, turn off microphone, camera or notifications in your phone’s settings).
- Know who we share data with, and not be discriminated against for using your rights.
- Complain to your data protection authority (in Brazil, the ANPD; in the EU/UK, your local supervisory authority).
How to exercise them: email contact.decideit@gmail.com from the email address registered on your account (the one from your Apple or Google sign-in), so we can confirm it is you. We reply within 30 days, or sooner where the law requires.
California (CCPA/CPRA). In the last 12 months we collected identifiers (email, name, provider user ID, username), audio and photos, content you create, and device and network data, for the purposes described above. We don’t sell personal information or share it for cross-context behavioral advertising, and we don’t use or disclose sensitive personal information to infer characteristics about you. You can use an authorized agent to make a request.
Children
Decide It is not for children under 13, and where the law sets a higher age (for example 16 in some countries) it is not for people below that age. We don’t knowingly collect personal data from children under the minimum age. If you believe a child has an account, write to contact.decideit@gmail.com and we will delete it.
Security
- Data travels over encrypted connections (HTTPS/TLS).
- Access rules in the database decide who can read what. For example, audio takes and option photos are only available to people allowed to see them.
Content in Decide It is not end-to-end encrypted. No system is completely secure; if a breach affects you we will notify you and the authorities as the law requires.
This website
This website uses no cookies, no analytics and no third-party fonts. The only third-party script is the anti-bot check (Cloudflare Turnstile), loaded on the guest voting pages; Cloudflare receives technical signals from your browser (such as IP address and browser characteristics) solely to tell people from bots, under its own privacy terms. Our hosting provider (Cloudflare, Inc.) may keep standard server logs. Invitation pages (/p/…) read the invite code from the address in your browser to show the question and to try to open the App.
Voting as a guest. If you vote on an invitation page without an account, we store your choice together with a random identifier that your browser keeps in local storage (no name or email) and a salted hash of your IP address, used only to limit abuse (for example, many votes from one connection). Your guest vote counts in the total shown to the person who asked. It is not linked to any profile, and nobody sees who you are. Clear your browser data to remove the identifier; to ask us to remove a guest vote, contact us with the invite link.
Changes to this policy
We may update this policy. If the change is material we will tell you in the App or by other appropriate means. The “Last updated” date at the top shows the current version.
Contact
Decide It
Brazil
contact.decideit@gmail.com