Privacy Policy
Effective date:
The short version: we keep what is needed to run your account, sign you in to our apps and bill you. Your AI hub vault is end-to-end encrypted and we cannot read the secrets in it. OTPBox messages are encrypted with a key specific to your account and deleted when your plan's retention ends. Card data stays with Stripe. Google Analytics and Google Ads measurement run only if you accept them in the cookie banner, and we do not sell personal data.
1. Who is responsible
The controller of your personal data is ZODO SOLUCOES EM TECNOLOGIA LTDA ("Zodo", "we"), CNPJ 35.403.783/0001-39, Av. Felisberto, 22, Vila Nova, Cocal do Sul, SC, 88845-000, Brazil.
Contact, including our data protection officer (encarregado): contact@zodo.dev.
This policy covers rc.center (the website, the account center, sign-in for our apps and billing) and the apps sold through it: AI hub (ai-hub.rc.center) and OTPBox (otpbox.rc.center). AI hub also has its own privacy policy with the full detail of its vault; for AI hub, where that policy is more specific, it applies.
2. Data about your account
Account
Your e-mail address, when you confirmed it, when the account was created, and the version of these terms and this policy you accepted and when. Your password is never stored: we keep only an Argon2id hash of it. We also count failed sign-ins to lock the account for 15 minutes after repeated failures.
Two-step verification
If you turn it on, we store the authenticator secret encrypted (AES-GCM, with a key kept outside the database) and your recovery codes only as keyed hashes. Recovery codes are shown to you once and cannot be read back.
Sessions
Each sign-in creates a session. Your browser keeps a random token in a cookie; we store only a hash of it, with when it was created, last used and expires (after 30 days), and the IP address and browser (user agent) it was opened from. You can see and end your sessions in your account page.
Sign-in activity
For every attempt to sign up, sign in, enter a two-step code, reset a password or confirm an e-mail, and for every sign-out and every sign-in to an app through rc.center, we record the time, the kind of event, the result (for example success or wrong password, or the app you signed in to), the account when known, a one-way hash of the address typed, the IP address and the user agent. Passwords and codes are never recorded. This log protects accounts against password guessing and abuse, and it is also the record of access to our application (IP address, date and time) that the Brazilian Internet Civil Framework (Law 12.965/2014, art. 15) requires us to keep for 6 months.
E-mail links
Confirmation, password reset and e-mail change links are single-use and stored only as hashes. They expire (24 hours for confirmation, 30 minutes for a reset, 1 hour for an e-mail change). While an e-mail change is pending we keep the new address with it.
Apps you sign in to
When you sign in to an app with rc.center, we record your consent (which app, which permissions, when) and the tokens we issue to that app, stored as identifiers or hashes. The app receives your account identifier, your e-mail address, whether it is confirmed, and your plan and what it includes for that app. Apps are also told, by signed messages, when your plan changes or your account is disabled or deleted. You can see and disconnect apps in your account page.
Plan and billing
Your plan, its status and dates, whether a cancellation is scheduled, any discount running (percent, end date, code and partner name), your currency and the Stripe customer and subscription identifiers. You enter payment details on Stripe's page: we never receive your card number. Stripe processes your name, billing address, tax id if you give one, payment method and invoices as described in its own privacy policy.
Operator records
When one of our operators acts on an account (for example grants a courtesy plan, disables an account or creates a promotion code), the action is recorded with what changed. Operators are told when a new account is created, with the domain of its e-mail address and the time, not the full address.
E-mails we send
Transactional messages only: confirmation, password reset, e-mail change, security notices (password, two-step verification or recovery codes changed or used) and the confirmation that your account was deleted. We do not send marketing e-mail.
Technical logs
Our servers log each request's method, path (never query strings, which can carry codes), status, duration and IP address. These logs are kept by our hosting provider for 20 days.
Visitor analytics and ad measurement, only with your consent
On our public pages we use Google Analytics 4 and the conversion measurement of Google Ads, both from Google, to learn how visitors find and use the sites and whether our ad campaigns work. They run only if you choose Accept in the cookie banner. Until then, and if you choose Reject, the Google tag is not loaded at all and nothing is sent to Google for this purpose.
- Where: the home pages of rc.center, AI hub (ai-hub.rc.center) and OTPBox (otpbox.rc.center), the pricing section, these legal pages, the rc.center sign-up page and the page you return to after Stripe's checkout. Never on your account page, the admin pages, or the signed-in pages of AI hub and OTPBox.
- What is collected: the pages you view and the site that sent you there, clicks on our buttons and links, your browser, operating system, device type and screen size, an approximate location (country, region and city) that Google derives from your IP address, random identifiers stored in cookies to tell visits apart, and, when you arrive from a Google ad, the ad click identifier.
- Events: a completed sign-up form (method "email"), the start of a checkout for Pro, and a completed subscription with the Stripe checkout identifier, the plan, the amount and the currency. We never send your e-mail address, name, account identifier or payment details to Google.
- Retention: Google keeps this data for 14 months, then deletes it.
- Your choice: it is stored in the
rc_consentcookie for 12 months and covers rc.center, AI hub and OTPBox. To withdraw or give consent at any time, use Cookie settings at the bottom of the pages and choose Reject or Accept. Rejecting stops measurement and removes the Google cookies from the site's domain.
The public pages also load their typeface from Google Fonts, which receives your IP address and browser details (see Service providers).
3. Data in the apps
AI hub
The vault is end-to-end encrypted. The key that opens it is derived on your device from your master password, which never leaves your device. We store your secrets only as ciphertext and cannot decrypt them. We do see metadata needed to run the service: the names of your secrets, devices and machines, the requests AI sessions make (name requested, reason, client, time, result) and the audit trail of every access. One exception: a remote AI client that does not provide its own encryption key can only receive a secret in "transparent mode", where the value passes through our service readable (over TLS) and is erased as soon as the grant ends; the approval screen warns you. AI hub's own privacy policy lists all of this in detail, including the providers used for push notifications on Android.
OTPBox
- Your inboxes have addresses on a subdomain specific to your account. That subdomain is a random identifier, not your rc.center account identifier.
- Messages your inboxes receive (the full message, and the text, links, codes and attachment list we extract from it) are encrypted with AES-256-GCM using a data key specific to your account, which is itself protected by a key in Oracle Cloud Vault. They are stored in Oracle Cloud Object Storage in the us-ashburn-1 region (Ashburn, Virginia, United States). The index we use to list messages (subject, sender, extracted codes and verification link) is stored encrypted in the same way.
- With each message we also keep delivery metadata: the sending server's IP address and the results of the SPF, DKIM and DMARC checks.
- Messages are deleted automatically when your plan's retention ends (30 days on Pro). You can delete a message or an inbox earlier. Deleting your rc.center account destroys your data key, which makes all your stored messages unreadable at once; the encrypted files then expire.
- Our mail server logs record the sending server's IP address, internal identifiers, sizes and the delivery result. They never record sender or recipient addresses, subjects or message content.
- If you set a webhook on an inbox, we send the message identifier, sender, subject, extracted codes and verification link to the address you chose.
- Messages can contain personal data of the people and services that send them. We process that content only to deliver it to you, under your instructions, and you are responsible for receiving it lawfully.
4. Why we process it
| Purpose | Data | Legal basis |
|---|---|---|
| Provide your account, sign-in, apps and the plan you chose | Account, sessions, two-step verification, app consents, app data | Performance of a contract (LGPD art. 7, V; GDPR art. 6(1)(b)) |
| Charge for paid plans, issue invoices, handle refunds and taxes | Plan and billing data | Performance of a contract and legal obligation (LGPD art. 7, II and V; GDPR art. 6(1)(b) and (c)) |
| Keep accounts and the services secure, prevent fraud and abuse | Sign-in activity, sessions, logs, operator records, OTPBox delivery metadata | Legitimate interest (LGPD art. 7, IX; GDPR art. 6(1)(f)) |
| Keep access records required by the Brazilian Internet Civil Framework | IP address, date and time of access | Legal obligation (Law 12.965/2014, art. 15; LGPD art. 7, II) |
| Answer you when you write to us | Your message and e-mail address | Performance of a contract or legitimate interest |
| Measure visits to our public pages and the results of our ad campaigns (Google Analytics and Google Ads) | Pages viewed, clicks, device and browser, approximate location, cookie identifiers, ad click identifier, sign-up and subscription events | Consent, which you can withdraw at any time (LGPD art. 7, I; GDPR art. 6(1)(a)) |
We do not make decisions about you based solely on automated processing, and we do not sell or rent personal data. Only if you accept cookies, measurement data is shared with Google to measure and improve our ads, as described in section 2.
5. Service providers
We share personal data only with providers that run part of the services for us, and only what each one needs:
| Provider | What it does for us | Data it receives | Where |
|---|---|---|---|
| Quave ONE | Hosting of rc.center, AI hub and the OTPBox service, and their databases | All the data described above, as stored on our servers | Brazil (São Paulo) |
| Stripe | Payments, subscriptions, invoices and the billing portal | E-mail address, billing name and address, tax id, payment method, payments and invoices | United States and other countries |
| Postmark (ActiveCampaign, LLC) | Sending our transactional e-mail | Your e-mail address and the content of the messages we send you | United States |
| Oracle Cloud Infrastructure | OTPBox mail servers and encrypted message storage, and the key that protects your OTPBox data key | Encrypted OTPBox messages; the sending server's IP address at delivery | United States (us-ashburn-1) |
| Cloudflare | DNS for the rc.center domain | Domain name lookups only; traffic to our pages does not pass through Cloudflare | United States and other countries |
| Google Analytics and Google Ads (Google LLC) | Visitor analytics and ad conversion measurement, only after you accept cookies | Pages viewed, clicks, device and browser, IP address (used for an approximate location), cookie identifiers, ad click identifier, sign-up and subscription events (checkout identifier, plan, amount and currency) | United States |
| Google Fonts (Google LLC) | The typeface of the website's public pages (home and legal pages) | Your IP address and browser details when the page loads | United States |
AI hub uses additional providers for push notifications and app distribution on Android; they are listed in its own policy. We may also disclose data when required by law or by an order from a competent authority, and to protect our rights in legal proceedings.
6. Cookies and local storage
The cookies needed for signing in are always used. Analytics and advertising cookies are set only if you accept them in the cookie banner; rejecting them changes nothing else on the sites. You can change your choice at any time with Cookie settings at the bottom of the pages.
| Name | Purpose | Duration |
|---|---|---|
__Host-rc_session | Keeps you signed in to rc.center. The protection against cross-site requests is derived from it, not stored in another cookie. | 30 days, or until you sign out |
__Host-rc_mfa | Holds the step between your password and your two-step code | 5 minutes |
rc_consent | Remembers your cookie choice (accept or reject) for rc.center, AI hub and OTPBox | 12 months |
_ga, _ga_<id> | Google Analytics, only with your consent: tells visits and visitors apart | 13 months |
_gcl_au | Google Ads conversion measurement, only with your consent: links a sign-up or subscription to the ad that brought you | 90 days |
| Local storage: currency | Remembers whether you chose US$ or R$ on the plan page | Until you clear your browser data |
Local storage: rc_ga_once | Only with your consent: keeps a subscription from being counted twice in analytics when the page is reloaded | Until you clear your browser data |
Stripe's checkout and billing pages, and the apps on their own domains, set their own cookies under their own policies.
7. How long we keep it
| Data | Kept for |
|---|---|
| Account, two-step verification, sessions, app consents | While the account exists; deleted or revoked when you delete it (see below). Expired sessions and links are removed after a day. |
| Operator records | 365 days |
| Records of processed Stripe events | 90 days |
| Billing records (subscriptions, invoices) | 5 years, also after the account is deleted, as Brazilian tax and accounting law requires. Stripe keeps invoices under the same rules. |
| Sign-in activity, which is also the access record (IP address, date and time) | 6 months, as required by Law 12.965/2014, art. 15, then deleted automatically (after 190 days) |
| Request logs at our hosting provider | 20 days |
| Analytics and ad measurement data at Google (only with your consent) | 14 months |
| OTPBox messages | Your plan's retention (30 days on Pro), or less if you delete them |
| AI hub data | As described in AI hub's own policy |
| Database backups | Up to 7 days |
8. International transfers
We are in Brazil, and our servers and databases are hosted in Brazil (São Paulo). Your data is also processed by the other service providers listed in section 5, some of which are outside Brazil, for example in the United States: Stripe, Postmark, Oracle Cloud (us-ashburn-1) for OTPBox message storage, and Google for analytics and ad measurement when you accept cookies.
9. Your rights
Under the Brazilian General Data Protection Law (LGPD, Law 13.709/2018, art. 18) you can:
- confirm whether we process your data and access it;
- correct incomplete, inaccurate or outdated data;
- ask for anonymization, blocking or deletion of unnecessary or excessive data, or data processed against the law;
- ask for portability of your data to another provider;
- ask for deletion of data processed with your consent, and withdraw consent;
- know with whom we share your data;
- object to processing based on legitimate interest, and ask for a review of automated decisions;
- complain to the Brazilian data protection authority (ANPD).
If you are in the European Economic Area, the United Kingdom or Switzerland, you have equivalent rights under the GDPR: access, rectification, erasure, restriction, portability, objection, and a complaint to your local supervisory authority. If you are in the United States, you can ask to know, correct and delete your personal data. We do not sell it, and we share data with Google for ad measurement only when you accept cookies; you can opt out at any time with Cookie settings. We will not treat you differently for exercising any of these rights.
How to exercise them
- In your account page you can, yourself: see your e-mail and change it, change your password, manage two-step verification and recovery codes, see and end sessions, see and disconnect apps, and delete your account. Manage billing (Stripe) shows and updates your billing details and invoices.
- For anything else, write to contact@zodo.dev from your account's e-mail address. We may ask you to confirm it is you. We answer within 15 days.
10. Deleting your account
In your account page, under Delete account, confirm with your password and the phrase shown. Deletion is immediate and cannot be undone:
- any paid subscription is cancelled in Stripe at once (see the refund rules);
- every session and every app token is revoked, and the apps are told the account was deleted;
- your e-mail address, password hash, two-step verification secrets, recovery codes and app consents are erased, and the address can be registered again;
- OTPBox destroys your data key, which makes all your stored messages unreadable;
- we send a last e-mail confirming the deletion.
What remains is an internal record without your e-mail address, linked to billing records we must keep, the logs described above until they expire, and a count of deleted accounts with no identifier. While AI hub keeps its own accounts, delete your AI hub account separately, as explained at ai-hub.rc.center/delete-account.
11. Security
All traffic uses TLS. Passwords are hashed with Argon2id; sessions, tokens, links and codes are stored only as hashes; secrets we must keep are encrypted with keys held outside the database. Operator access requires two-step verification and every operator change is recorded. AI hub's vault is end-to-end encrypted, and OTPBox encrypts each account's messages with its own key. No system is perfectly secure: if an incident may cause you relevant risk or harm, we will tell you and the authorities as the law requires (LGPD art. 48).
12. Children
The services are for people aged 18 or older and are not directed to children. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, write to us and we will delete it.
13. Changes to this policy
We update this policy when the services change what they collect or how they use it. The effective date at the top shows the current version. We tell you about material changes by e-mail before they take effect.
14. Contact
ZODO SOLUCOES EM TECNOLOGIA LTDA, CNPJ 35.403.783/0001-39, Av. Felisberto, 22, Vila Nova, Cocal do Sul, SC, 88845-000, Brazil. Data protection officer (encarregado) and general contact: contact@zodo.dev.