This Privacy Policy explains how JEFFERSON TEIXEIRA DA SILVA LTDA (CNPJ 49.180.596/0001-48), trading as Behind Solutions TI and operating as NativeBlade ("NativeBlade", "we", "us"), collects, uses and protects personal data when you use our Website and Services, as defined in our Terms of Service.
We follow the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados, Law 13,709/2018, "LGPD") and, where it applies to you, the EU General Data Protection Regulation (GDPR).
1. Who is responsible
NativeBlade is the controller of the personal data described in this policy.
When your apps, repositories or configuration contain personal data about other people, you are the controller of that data and we process it on your behalf as your processor (operador), only to provide the Services. See section 9.
For any privacy question or request, contact our data protection channel (Encarregado) at privacy@nativeblade.dev.
2. What we collect
Information you give us
- Account: name, email address, password (stored only as a secure hash), profile photo if you upload one.
- GitHub sign-in and access: if you sign in with GitHub or connect a repository, your GitHub user ID and username, and access to the repositories you choose when installing the NativeBlade GitHub App.
- Team: the email addresses of people you invite, and their roles.
- Billing: your plan, subscription status and billing history. Payments are processed by Stripe. We do not receive or store your full card number.
- Project content: repositories, build settings, environment variables, signing credentials, certificates, keystores, configuration files (such as Google services files), Studio uploads, build logs and artifacts.
- Integrations: webhooks you configure and their delivery history, and API tokens (we store only a hash of each token).
- Communications: messages you send us, including contact and sales requests.
Information collected automatically
- Security and access logs: IP address, browser and device information (user agent), date and time of access, and the devices you have signed in from.
- Usage: builds you run, their status and duration, and how you use features of the Services.
- Website analytics: pages visited, referring site, approximate location derived from IP, device and browser type.
- Errors and performance: technical information when something fails, which may include the page, request and account involved.
Information from other sources
- GitHub, when you sign in with it or connect repositories.
- Stripe, about the status of your payments.
- Email verification: when you create an account or change your email, we check with a verification provider whether the address can receive email.
3. Why we use it and our legal bases
| Purpose | Legal basis (LGPD, art. 7) |
|---|---|
| Create and manage your account, run builds, sign and store your apps, submit them to stores at your request, process payments and provide support | Performance of a contract (V) |
| Keep the Services secure: verify email addresses, detect fraud and abuse, send alerts about new sign-ins, enforce plan limits | Legitimate interest (IX) and performance of a contract (V) |
| Keep access logs, invoices and records required by law, including the Brazilian Internet Civil Framework (Law 12,965/2014) and tax law | Compliance with a legal obligation (II) |
| Understand how the Website and Services are used, fix errors and improve the product | Legitimate interest (IX) |
| Send product news and tips by email | Legitimate interest (IX), and you can opt out at any time in your notification settings |
| Establish, exercise or defend legal claims | Regular exercise of rights (VI) |
Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect processing done before it.
4. Who we share it with
We do not sell your personal data. We share it only with the service providers we need to run NativeBlade, under contracts that limit their use to providing their service to us:
| Provider | What they do for us |
|---|---|
| Laravel Cloud | Hosts the Website, the NativeBlade Cloud portal and its database |
| Amazon Web Services | Runs build servers and stores build artifacts and uploads |
| Stripe | Processes payments and manages subscriptions |
| Resend | Sends transactional and account emails |
| GitHub | Sign-in with GitHub and access to repositories you connect |
| NeverBounce | Verifies that an email address can receive email |
| Sentry | Error monitoring |
| Google Analytics | Website and portal usage analytics |
We may also share personal data:
- With Apple, Google or other stores, when you instruct us to submit a build on your behalf;
- With your team, who can see the projects, builds and activity of the teams you belong to;
- To comply with the law, a court order or a request from a competent authority, or to protect the rights and safety of NativeBlade, our users or others;
- In a corporate transaction, such as a merger or acquisition, in which case the new owner will remain bound by this policy.
5. International transfers
Some of our providers store or process data outside Brazil, mainly in the United States. We only transfer personal data in the situations allowed by article 33 of the LGPD, including when the transfer is necessary to perform our contract with you, and we choose providers that commit to appropriate data protection safeguards.
6. How long we keep it
| Data | How long |
|---|---|
| Account and project data | While your account is active |
| Builds, build logs and artifacts | Deleted automatically after your plan's retention period, currently 7 days |
| Access logs (IP address, date and time) | At least 6 months, as required by article 15 of the Brazilian Internet Civil Framework |
| Invoices and payment records | For the period required by tax and accounting law, generally 5 years |
| Data needed for legal claims | Until the claim is resolved or can no longer be brought |
When the retention period ends, we delete or anonymize the data.
7. Your rights
Under the LGPD you have the right to:
- confirm whether we process your personal data and access it;
- correct incomplete, inaccurate or outdated data;
- request anonymization, blocking or deletion of unnecessary or excessive data, or data processed in violation of the law;
- request portability of your data to another provider;
- request deletion of data processed based on consent;
- know which third parties we share your data with;
- be informed about the possibility of not giving consent and its consequences, and withdraw consent;
- object to processing carried out in violation of the law.
You can update your name, email, password, photo and notification preferences directly in your account settings.
For any other request, including deleting your account, email privacy@nativeblade.dev from the email address registered on your account, so we can confirm it is you. We may ask for additional confirmation. We will reply within 15 days. When your account is deleted, we delete your projects, secrets, builds and account data, except the records we are required by law to keep (see section 6).
If you are not satisfied with our response, you can file a complaint with the Brazilian National Data Protection Authority (ANPD), or with the data protection authority where you live.
8. Cookies
We use a small number of cookies:
- Essential cookies keep you signed in, protect forms against cross-site request forgery and remember your session. The Services do not work without them.
- Analytics cookies from Google Analytics help us understand how the Website and portal are used. They do not identify you by name.
We do not use advertising cookies.
You can block or delete cookies in your browser settings, and you can opt out of Google Analytics with the Google Analytics Opt-out Browser Add-on. Blocking essential cookies will prevent you from signing in.
9. Your app's end users
NativeBlade Cloud builds and signs your apps. It does not run inside your published apps and does not receive data about the people who use them. Over-the-air updates are hosted by you, not by us.
The Framework is open-source software that runs on your users' devices under your control. You are responsible for your app's own privacy policy and for how your app handles your users' data.
If Your Content (for example, environment variables or configuration files) contains personal data of others, we process it only to build and deliver your app, as your processor.
10. Security
We use HTTPS for all data in transit, encrypt secrets such as signing credentials and environment variables at rest, and offer two-factor authentication and alerts for new sign-ins. Read more on our Security page.
No system is completely secure. If we become aware of a security incident that may create a relevant risk or damage to you, we will notify you and the ANPD as required by the LGPD.
11. Children
The Services are intended for people 18 years of age or older. We do not knowingly collect personal data from children or adolescents. If you believe a minor has provided us personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy. If a change is significant, we will notify you by email or in the Services before it takes effect. The date at the top of this page shows when it was last updated.
13. Contact
JEFFERSON TEIXEIRA DA SILVA LTDA
CNPJ 49.180.596/0001-48
Rua Visconde de Pirajá, Sala 718, Rio de Janeiro, RJ, 22410-002, Brazil
Data protection channel (Encarregado): privacy@nativeblade.dev