rc.center

Privacy Policy

Effective date:

The short version: we keep what is needed to run your account, sign you in to our apps and bill you. Your AI hub vault is end-to-end encrypted and we cannot read the secrets in it. OTPBox messages are encrypted with a key specific to your account and deleted when your plan's retention ends. Card data stays with Stripe. Google Analytics and Google Ads measurement run only if you accept them in the cookie banner, and we do not sell personal data.

1. Who is responsible

The controller of your personal data is ZODO SOLUCOES EM TECNOLOGIA LTDA ("Zodo", "we"), CNPJ 35.403.783/0001-39, Av. Felisberto, 22, Vila Nova, Cocal do Sul, SC, 88845-000, Brazil.

Contact, including our data protection officer (encarregado): contact@zodo.dev.

This policy covers rc.center (the website, the account center, sign-in for our apps and billing) and the apps sold through it: AI hub (ai-hub.rc.center) and OTPBox (otpbox.rc.center). AI hub also has its own privacy policy with the full detail of its vault; for AI hub, where that policy is more specific, it applies.

2. Data about your account

Account

Your e-mail address, when you confirmed it, when the account was created, and the version of these terms and this policy you accepted and when. Your password is never stored: we keep only an Argon2id hash of it. We also count failed sign-ins to lock the account for 15 minutes after repeated failures.

Two-step verification

If you turn it on, we store the authenticator secret encrypted (AES-GCM, with a key kept outside the database) and your recovery codes only as keyed hashes. Recovery codes are shown to you once and cannot be read back.

Sessions

Each sign-in creates a session. Your browser keeps a random token in a cookie; we store only a hash of it, with when it was created, last used and expires (after 30 days), and the IP address and browser (user agent) it was opened from. You can see and end your sessions in your account page.

Sign-in activity

For every attempt to sign up, sign in, enter a two-step code, reset a password or confirm an e-mail, and for every sign-out and every sign-in to an app through rc.center, we record the time, the kind of event, the result (for example success or wrong password, or the app you signed in to), the account when known, a one-way hash of the address typed, the IP address and the user agent. Passwords and codes are never recorded. This log protects accounts against password guessing and abuse, and it is also the record of access to our application (IP address, date and time) that the Brazilian Internet Civil Framework (Law 12.965/2014, art. 15) requires us to keep for 6 months.

E-mail links

Confirmation, password reset and e-mail change links are single-use and stored only as hashes. They expire (24 hours for confirmation, 30 minutes for a reset, 1 hour for an e-mail change). While an e-mail change is pending we keep the new address with it.

Apps you sign in to

When you sign in to an app with rc.center, we record your consent (which app, which permissions, when) and the tokens we issue to that app, stored as identifiers or hashes. The app receives your account identifier, your e-mail address, whether it is confirmed, and your plan and what it includes for that app. Apps are also told, by signed messages, when your plan changes or your account is disabled or deleted. You can see and disconnect apps in your account page.

Plan and billing

Your plan, its status and dates, whether a cancellation is scheduled, any discount running (percent, end date, code and partner name), your currency and the Stripe customer and subscription identifiers. You enter payment details on Stripe's page: we never receive your card number. Stripe processes your name, billing address, tax id if you give one, payment method and invoices as described in its own privacy policy.

Operator records

When one of our operators acts on an account (for example grants a courtesy plan, disables an account or creates a promotion code), the action is recorded with what changed. Operators are told when a new account is created, with the domain of its e-mail address and the time, not the full address.

E-mails we send

Transactional messages only: confirmation, password reset, e-mail change, security notices (password, two-step verification or recovery codes changed or used) and the confirmation that your account was deleted. We do not send marketing e-mail.

Technical logs

Our servers log each request's method, path (never query strings, which can carry codes), status, duration and IP address. These logs are kept by our hosting provider for 20 days.

Visitor analytics and ad measurement, only with your consent

On our public pages we use Google Analytics 4 and the conversion measurement of Google Ads, both from Google, to learn how visitors find and use the sites and whether our ad campaigns work. They run only if you choose Accept in the cookie banner. Until then, and if you choose Reject, the Google tag is not loaded at all and nothing is sent to Google for this purpose.

The public pages also load their typeface from Google Fonts, which receives your IP address and browser details (see Service providers).

3. Data in the apps

AI hub

The vault is end-to-end encrypted. The key that opens it is derived on your device from your master password, which never leaves your device. We store your secrets only as ciphertext and cannot decrypt them. We do see metadata needed to run the service: the names of your secrets, devices and machines, the requests AI sessions make (name requested, reason, client, time, result) and the audit trail of every access. One exception: a remote AI client that does not provide its own encryption key can only receive a secret in "transparent mode", where the value passes through our service readable (over TLS) and is erased as soon as the grant ends; the approval screen warns you. AI hub's own privacy policy lists all of this in detail, including the providers used for push notifications on Android.

OTPBox

4. Why we process it

PurposeDataLegal basis
Provide your account, sign-in, apps and the plan you choseAccount, sessions, two-step verification, app consents, app dataPerformance of a contract (LGPD art. 7, V; GDPR art. 6(1)(b))
Charge for paid plans, issue invoices, handle refunds and taxesPlan and billing dataPerformance of a contract and legal obligation (LGPD art. 7, II and V; GDPR art. 6(1)(b) and (c))
Keep accounts and the services secure, prevent fraud and abuseSign-in activity, sessions, logs, operator records, OTPBox delivery metadataLegitimate interest (LGPD art. 7, IX; GDPR art. 6(1)(f))
Keep access records required by the Brazilian Internet Civil FrameworkIP address, date and time of accessLegal obligation (Law 12.965/2014, art. 15; LGPD art. 7, II)
Answer you when you write to usYour message and e-mail addressPerformance of a contract or legitimate interest
Measure visits to our public pages and the results of our ad campaigns (Google Analytics and Google Ads)Pages viewed, clicks, device and browser, approximate location, cookie identifiers, ad click identifier, sign-up and subscription eventsConsent, which you can withdraw at any time (LGPD art. 7, I; GDPR art. 6(1)(a))

We do not make decisions about you based solely on automated processing, and we do not sell or rent personal data. Only if you accept cookies, measurement data is shared with Google to measure and improve our ads, as described in section 2.

5. Service providers

We share personal data only with providers that run part of the services for us, and only what each one needs:

ProviderWhat it does for usData it receivesWhere
Quave ONEHosting of rc.center, AI hub and the OTPBox service, and their databasesAll the data described above, as stored on our serversBrazil (São Paulo)
StripePayments, subscriptions, invoices and the billing portalE-mail address, billing name and address, tax id, payment method, payments and invoicesUnited States and other countries
Postmark (ActiveCampaign, LLC)Sending our transactional e-mailYour e-mail address and the content of the messages we send youUnited States
Oracle Cloud InfrastructureOTPBox mail servers and encrypted message storage, and the key that protects your OTPBox data keyEncrypted OTPBox messages; the sending server's IP address at deliveryUnited States (us-ashburn-1)
CloudflareDNS for the rc.center domainDomain name lookups only; traffic to our pages does not pass through CloudflareUnited States and other countries
Google Analytics and Google Ads (Google LLC)Visitor analytics and ad conversion measurement, only after you accept cookiesPages viewed, clicks, device and browser, IP address (used for an approximate location), cookie identifiers, ad click identifier, sign-up and subscription events (checkout identifier, plan, amount and currency)United States
Google Fonts (Google LLC)The typeface of the website's public pages (home and legal pages)Your IP address and browser details when the page loadsUnited States

AI hub uses additional providers for push notifications and app distribution on Android; they are listed in its own policy. We may also disclose data when required by law or by an order from a competent authority, and to protect our rights in legal proceedings.

6. Cookies and local storage

The cookies needed for signing in are always used. Analytics and advertising cookies are set only if you accept them in the cookie banner; rejecting them changes nothing else on the sites. You can change your choice at any time with Cookie settings at the bottom of the pages.

NamePurposeDuration
__Host-rc_sessionKeeps you signed in to rc.center. The protection against cross-site requests is derived from it, not stored in another cookie.30 days, or until you sign out
__Host-rc_mfaHolds the step between your password and your two-step code5 minutes
rc_consentRemembers your cookie choice (accept or reject) for rc.center, AI hub and OTPBox12 months
_ga, _ga_<id>Google Analytics, only with your consent: tells visits and visitors apart13 months
_gcl_auGoogle Ads conversion measurement, only with your consent: links a sign-up or subscription to the ad that brought you90 days
Local storage: currencyRemembers whether you chose US$ or R$ on the plan pageUntil you clear your browser data
Local storage: rc_ga_onceOnly with your consent: keeps a subscription from being counted twice in analytics when the page is reloadedUntil you clear your browser data

Stripe's checkout and billing pages, and the apps on their own domains, set their own cookies under their own policies.

7. How long we keep it

DataKept for
Account, two-step verification, sessions, app consentsWhile the account exists; deleted or revoked when you delete it (see below). Expired sessions and links are removed after a day.
Operator records365 days
Records of processed Stripe events90 days
Billing records (subscriptions, invoices)5 years, also after the account is deleted, as Brazilian tax and accounting law requires. Stripe keeps invoices under the same rules.
Sign-in activity, which is also the access record (IP address, date and time)6 months, as required by Law 12.965/2014, art. 15, then deleted automatically (after 190 days)
Request logs at our hosting provider20 days
Analytics and ad measurement data at Google (only with your consent)14 months
OTPBox messagesYour plan's retention (30 days on Pro), or less if you delete them
AI hub dataAs described in AI hub's own policy
Database backupsUp to 7 days

8. International transfers

We are in Brazil, and our servers and databases are hosted in Brazil (São Paulo). Your data is also processed by the other service providers listed in section 5, some of which are outside Brazil, for example in the United States: Stripe, Postmark, Oracle Cloud (us-ashburn-1) for OTPBox message storage, and Google for analytics and ad measurement when you accept cookies.

9. Your rights

Under the Brazilian General Data Protection Law (LGPD, Law 13.709/2018, art. 18) you can:

If you are in the European Economic Area, the United Kingdom or Switzerland, you have equivalent rights under the GDPR: access, rectification, erasure, restriction, portability, objection, and a complaint to your local supervisory authority. If you are in the United States, you can ask to know, correct and delete your personal data. We do not sell it, and we share data with Google for ad measurement only when you accept cookies; you can opt out at any time with Cookie settings. We will not treat you differently for exercising any of these rights.

How to exercise them

10. Deleting your account

In your account page, under Delete account, confirm with your password and the phrase shown. Deletion is immediate and cannot be undone:

What remains is an internal record without your e-mail address, linked to billing records we must keep, the logs described above until they expire, and a count of deleted accounts with no identifier. While AI hub keeps its own accounts, delete your AI hub account separately, as explained at ai-hub.rc.center/delete-account.

11. Security

All traffic uses TLS. Passwords are hashed with Argon2id; sessions, tokens, links and codes are stored only as hashes; secrets we must keep are encrypted with keys held outside the database. Operator access requires two-step verification and every operator change is recorded. AI hub's vault is end-to-end encrypted, and OTPBox encrypts each account's messages with its own key. No system is perfectly secure: if an incident may cause you relevant risk or harm, we will tell you and the authorities as the law requires (LGPD art. 48).

12. Children

The services are for people aged 18 or older and are not directed to children. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, write to us and we will delete it.

13. Changes to this policy

We update this policy when the services change what they collect or how they use it. The effective date at the top shows the current version. We tell you about material changes by e-mail before they take effect.

14. Contact

ZODO SOLUCOES EM TECNOLOGIA LTDA, CNPJ 35.403.783/0001-39, Av. Felisberto, 22, Vila Nova, Cocal do Sul, SC, 88845-000, Brazil. Data protection officer (encarregado) and general contact: contact@zodo.dev.