Privacy Policy
Last updated: September 10, 2026 · Effective from September 10, 2026
This is a translation of the Portuguese version of this Policy. In case of any divergence, the Portuguese version prevails.
1. Introduction
This Privacy Policy describes how reWork (the "Platform") processes personal data in compliance with Brazil's General Data Protection Law (Law No. 13,709/2018 — "LGPD"). By using the Platform, you acknowledge that you have read and understood how your data is collected, used, shared and protected.
2. Data Controller
The controller of the personal data processed on this Platform is Andrigo Luís Oliveira dos Santos, an individual operating the service in a personal capacity.
Single channel for privacy questions, exercising data subject rights and other matters relating to personal data: [email protected].
Data Protection Officer (DPO). As a small-scale processing agent (under the criteria of ANPD Resolution CD/ANPD No. 2/2022), the operation is exempt from formally appointing a DPO. The communication channel above fulfills the role provided for in art. 41, § 4 of the LGPD.
3. Data We Collect
3.1. Data provided by you or your organization
- Registration: name, username, email, position or area;
- Optional contact: phone, Discord name, Discord ID;
- Profile photo: when uploaded by you;
- Content produced: tasks, comments, attached files, time entries, checklists, forms and other records created while using the Platform.
3.2. Data collected automatically
- Session: HTTP-only authentication cookie (
kastor_session) — not accessible to scripts; - Access metadata: IP address, browser agent (User-Agent), sign-in and last access times, timestamps of actions taken;
- Technical logs: request records (route, status, latency) kept for security and debugging;
- Local preferences: theme (light/dark), language, applied filters, active workspace — stored only in your browser's localStorage.
3.3. Usage analytics
We use Microsoft Clarity to generate aggregated heatmaps and session recordings, in order to improve the user experience. Clarity collects interactions (clicks, cursor movements, scrolling), screen size and browser. Password fields and sensitive content are masked by default.
3.4. Data from optional integrations
If you enable integrations (Google Calendar, Discord), we process the access tokens they need to work and the minimum profile data returned by the provider (for example, Discord ID and username in the identification OAuth). We never have access to your password on those services.
4. How We Use Your Data
- Provide, maintain and improve the Platform's features;
- Authenticate you and protect your account;
- Send operational notifications about tasks, mentions and relevant events;
- Detect, investigate and prevent misuse, abuse or security incidents;
- Comply with legal obligations and respond to requests from competent authorities.
We do not use your data for behavioral advertising, nor do we make automated decisions with legal effects or significant impacts on you (art. 20 of the LGPD).
5. Legal Bases (art. 7 of the LGPD)
- Performance of a contract (art. 7, V): operation of the Platform and provision of the service contracted by your organization;
- Consent (art. 7, I): for optional integrations you enable and for any non-essential communications;
- Legitimate interest (art. 7, IX): security, fraud prevention, usage analysis and continuous improvement of the service, always respecting your legitimate expectations;
- Compliance with a legal obligation (art. 7, II): when required by law or by a competent authority.
6. Sharing and Subprocessors
We share personal data only in the following cases:
- With your organization: members of the same team have access to the collaborative content you create within the scope authorized by the administrator;
- With subprocessors that support the operation of the service (listed below);
- By legal obligation: when required by law, court order or competent authority;
- We never sell your data to third parties.
Current list of subprocessors:
- Hostinger (Portainer/VPS): hosting of the application and the database;
- Microsoft (Clarity): usage analytics and aggregated heatmaps;
- Google (Calendar API / OAuth): optional calendar integration;
- Discord Inc. (OAuth and Bot API): optional sign-in with Discord and notifications via bot;
- Transactional email provider: sending system messages (password reset and similar).
7. Cookies and Similar Technologies
- Session cookie (essential):
kastor_session, HTTP-only, SameSite=Lax — keeps you signed in; the Platform doesn't work without it; - LocalStorage (essential): stores theme, language, filter and active workspace preferences only in your browser. It isn't sent with requests;
- Analytics (Microsoft Clarity): anonymized heatmaps and session recordings for UX improvements. You can object to this processing by contacting us through the channel in section 2.
8. Your Rights (art. 18 of the LGPD)
As a data subject, you may at any time:
- Confirm whether your data is being processed;
- Access your data;
- Correct incomplete, inaccurate or outdated data;
- Request anonymization, blocking or deletion of unnecessary or excessive data, or data processed in breach of the LGPD;
- Request portability of your data to another provider;
- Request deletion of data processed on the basis of consent;
- Be informed about who we share your data with;
- Be informed about the possibility of not giving consent and the consequences of refusing;
- Revoke consent at any time.
To exercise any of these rights, send a request to [email protected]. We will reply within 15 calendar days, and this period may be extended with justification.
You also have the right to petition Brazil's National Data Protection Authority (ANPD) directly when you believe your rights have not been respected: gov.br/anpd.
9. Data Retention
- While your account is active — we keep the data needed to operate the Platform;
- Deletion request — data is anonymized or deleted within 30 calendar days of the request;
- Backups — backup copies may keep data for up to 7 days (daily) and are overwritten in the regular cycle;
- Technical and security logs — retained for up to 6 months for incident investigation;
- Records required by law — kept for the applicable periods (for example, art. 15 of Brazil's Internet Civil Framework — 6 months of access logs).
10. Security and Incident Notification
We adopt technical and administrative measures to protect your data:
- Encrypted communication in transit (HTTPS/TLS);
- Passwords stored with irreversible cryptographic hashing;
- HTTP-only session cookie, protected against browser scripts;
- Role-based access control (admin, moderator, team member, freelancer);
- Regular, encrypted database backups;
- Audit records of relevant changes.
No system is 100% secure. In the event of a security incident that may entail relevant risk or damage to data subjects, we will notify those affected and the ANPD under art. 48 of the LGPD.
11. International Transfer
Some of the subprocessors listed in section 6 (Microsoft, Google, Discord) may store or process data outside Brazil. The transfer takes place in compliance with art. 33 of the LGPD, supported by these providers' contractual commitments (standard clauses or equivalent instruments) that ensure an adequate level of protection.
12. Children and Adolescents
The Platform is not intended for children (under 12). Accounts of adolescents (12 to 18) are only allowed with specific and prominent consent from at least one parent or legal guardian, under art. 14 of the LGPD.
13. Changes to this Policy
We may update this policy from time to time. Material changes will be announced within the Platform at least 15 days in advance. The "Last updated" date at the top always shows the current version.
14. Contact
Controller: Andrigo Luís Oliveira dos Santos
Email: [email protected]