1. Who we are

This Policy explains how César processes personal data under Brazil's LGPD (Law 13.709/2018) and complements the Terms of Use. César is the controller of personal accounts' data. In company workspaces, the company is the controller of its customers' data and César is the processor (section 5). Data protection officer: [email protected].

2. Data we process

  • Account and device — name, email, picture, language, time zone, password hash, Google/Apple identifiers, WhatsApp number or Telegram chat, push token.
  • Conversations and content — messages, audio (transcribed), attachments, and what you keep in César: notes, tasks, contacts and facts about them, finances, files, apps. César also learns style preferences from conversations.
  • Integrations — data from the accounts you connect (Google, Microsoft 365, Dropbox, Zoho, Strava, X, Instagram, TikTok, iPhone contacts). Tokens are encrypted. From email we extract only bills, purchases, tickets, trips and parcels, without keeping the message text.
  • Third parties — messages and calls with people César contacts at your request (transcript, summary and, if you turn it on, recording) and data from contacts you sync.
  • Computer and browser — screenshots and files from allowed folders, during tasks you request.
  • Health (sensitive data) — wellness measurements taken with the camera (video never leaves the device), lab results you send, weight, meals, training and, on iOS, Apple Health data you authorize.
  • Location — from the device, browser or estimated from IP, if you allow it.
  • Payments and usage — confirmation, amount and transaction ID (never card details) and credit consumption.
  • Technical — IP, browser, logs and sessions recorded by Microsoft Clarity on the website and the app.

3. Why we use it

  • Contract: provide the Service, run actions and routines, billing.
  • Legitimate interest: security, fraud prevention and usage metrics.
  • Consent: health, location, device contacts, Apple Health and call recording. You can withdraw it and delete that data at any time.
  • Legal obligation: fiscal and payment records.

We do not use your data to train artificial-intelligence models and we do not sell it.

4. Who we share it with

  • Artificial intelligence — Google (Gemini), OpenAI, Anthropic and DeepSeek. They receive the request, the context needed, audio, images and screenshots. Some answers combine several models. We use paid APIs whose terms prohibit training on the data; providers may retain it briefly for abuse prevention.
  • Search and information — Perplexity, Tavily, SearchApi, Google Maps, IPRoyal (page access), Travelpayouts, AeroDataBox, AviationStack, 17TRACK, Infosimples, Anycar, Open-Meteo and the Central Bank of Brazil. They receive only the query.
  • Services you connect — Google, Microsoft, Dropbox, Zoho, Strava, X, Meta (Instagram and WhatsApp), TikTok and Telegram.
  • Operations — Twilio (calls), Resend (email), Mercado Pago and Apple (payments and push), DigitalOcean (servers, database and files) and Cloudflare (network).
  • Analytics and ads — Microsoft Clarity and Google Ads (conversion measurement).

We also share data when required by law.

International transfer: our servers are in the US, and some providers process data in other countries, such as China (DeepSeek and 17TRACK). Transfers follow article 33 of the LGPD.

Google data: use of information received from Google APIs adheres to the Google API Services User Data Policy, including Limited Use. This data serves only the features you request and is not used for advertising.

5. César for Companies

When a company uses César with its customers (attendant, data sources, orders, charges, fiscal invoices, apps and tools), César processes that data as processor, only for the company and for no other purpose. If you talked to a company's support, direct requests about your data to that company; any we receive will be forwarded. Data of a deleted company stays restorable for 30 days and is then erased, except fiscal documents kept for the legal period.

6. Retention

We keep data while the account exists. On deletion:

  • identification, tokens and devices are removed immediately;
  • conversations, files, contacts, health, location and other content are erased within 30 days;
  • payment and fiscal records are kept for the legal period.

Disconnecting an integration ends access to it.

7. Your rights and security

You can access, correct, export and delete data and withdraw consent in your profile or at [email protected], and complain to the ANPD.

We use HTTPS, encryption of tokens and certificates, and access control. Authorized staff may view an account in read-only mode, with logging, only for support, security or legal obligations. Relevant incidents will be reported as required by law.

8. Cookies, children and changes

We use necessary cookies (session, language, theme) and analytics and measurement cookies (Clarity, Google Ads). The Service is not intended for people under 18. Material changes to this Policy will be announced in the Service or by email.