Privacy Policy

Last updated 2026-09-01

This policy explains what EasyBI collects, why, and who else sees it. The controller is FOAD MOBINI KESHEH CONSULTORIA EM TECNOLOGIA DA INFORMACAO LTDA (CNPJ 43.405.391/0001-37), Rua Astor Toniolo, 103, Casa 02, Cond. Alto da Colina I, Santa Felicidade, Curitiba – PR, 82410-050, Brazil. For any privacy question or request, write to foad@fmktech.com.br.

1. The short version

You upload files; we send parts of them to AI providers to answer your questions; we store them so you can ask again later. We do not sell your data and we do not train AI models on it. The one thing worth reading in full is section 3 — because using this product necessarily means your file content leaves our systems.

2. What we collect

  • Account: name, email address, and a hashed password. We never store your password itself.
  • Your content: the files you upload, the structured data extracted from them, your questions, our answers, the analysis code generated for you, and its results.
  • Usage: counts of questions, uploads, document pages and analysis runs, plus the cost each request incurred. We use this to enforce plan limits and to understand what the service costs to run.
  • Technical: IP address and browser user-agent attached to your login session, and server logs of requests and errors.
  • Billing: your Stripe customer and subscription identifiers. Card details go directly to Stripe — they never reach our servers.

3. Your files are processed by AI providers

This is the part people are usually surprised by, so it is stated plainly:

  • PDF and Word documents are sent in fullto Google’s Gemini model so the tables inside them can be extracted.
  • Spreadsheets (CSV, XLSX) are parsed on our own servers. Their raw rows are not sent to a language model. What is sent is the file name, the column names, a short generated summary, and a preview of at most 20 rows of each analysis result.
  • Analysis code generated for you runs in an isolated sandbox with no network access. Your data is mounted into it and destroyed with the sandbox.

What those providers may do with it is contractually limited. Every model request we send carries two flags: zero data retention, so the provider keeps nothing once the response is returned, and no prompt training, so your content is never used to train a model. Requests are routed only to providers that honour both.

Even so: if a document is confidential enough that no third party may ever process it, do not upload it as a PDF or Word file.

4. Why we may process your data

To perform our contract with you (running the service, billing); for our legitimate interests (security, abuse prevention, understanding cost); and to meet legal obligations (tax and accounting records). Where consent is the basis, you may withdraw it at any time.

5. How long we keep it

  • Files and chats: until you delete them, or your account closes.
  • Files belonging to a trial that expired without becoming a paid plan: deleted 60 days after expiry.
  • Billing and usage records: retained as long as tax and accounting law requires, even after account closure.

6. Who else receives your data

We use the processors below. We do not sell personal data, none of these may use your content for their own purposes, and the AI providers additionally operate under zero data retention and no-training terms (section 3).

  • VercelApplication hosting, file storage, sandboxed code execution, AI gateway. Receives: Account data, uploaded files, analysis code and results, request logs.
  • NeonManaged PostgreSQL database. Receives: Account data, chat history, file metadata, usage counters.
  • DeepSeekLanguage model that answers questions and writes analysis code. Receives: Your questions, file names, column names, dataset summaries, result previews (zero retention, no training).
  • GoogleExtracting tables from PDF and Word documents (Gemini). Receives: The full contents of any PDF or Word document you upload (zero retention, no training).
  • StripeSubscription payments. Receives: Email, billing details, payment method (we never see full card numbers).
  • ResendTransactional email (verification, password reset). Receives: Email address.

These providers operate outside Brazil and the EEA, so your data is transferred internationally under the safeguards in their respective data-processing agreements.

7. Your rights

Under the LGPD (Brazil) and the GDPR (EEA/UK) you can ask us to confirm what we hold, give you a copy, correct it, delete it, restrict or object to processing, or provide it in a portable format. You can delete individual files yourself at any time from the Files page. For anything else — including deleting your whole account — write to foad@fmktech.com.brand we will respond within 30 days. You may also complain to Brazil’s ANPD or your local supervisory authority.

8. Security

Data is encrypted in transit and at rest by our infrastructure providers. Every file, chat and analysis result is scoped to its owner and access is checked on every request. Passwords are hashed. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authority as the law requires.

9. Children

EasyBI is not intended for anyone under 18. We do not knowingly collect data from children; if you believe we have, contact us and we will delete it.

10. Cookies

We set only what the service needs: a session cookie to keep you signed in, and a preference cookie remembering your chosen language. No advertising or cross-site tracking cookies.

11. Changes

If we change this policy materially we will email you before it takes effect. The date at the top always reflects the current version.