Legal

Privacy Policy

Last updated: August 30, 2026Applies to the Quem Deve app (iOS and Android) and the quemdeve.com website.

This Privacy Policy describes how Artcode (“Artcode”, “we”), developer and operator of the Quem Deve app (“Who Owes”), handles personal data in the app (iOS and Android) and on the quemdeve.com website. It was drafted in accordance with the Brazilian General Data Protection Law — Law No. 13,709/2018 (“LGPD”) — and the Brazilian Internet Civil Framework — Law No. 12,965/2014. By creating an account or using Quem Deve, you confirm that you have read and understood this Policy, which is part of the Terms of Use.

Plain-language summary

  • We collect the minimum needed: your email and name for the account, and the records you create in the app yourself.
  • Data about the people you add stays private in your account. Nothing is published or reported to credit bureaus.
  • We do not sell your personal data. Ever.
  • We do not import your address book: you pick one contact at a time, and their photo is only used with your specific consent.
  • On the free plan we show Google ads. On iPhone, ad personalization depends on your permission (ATT).
  • You can delete your account inside the app. After the 30-day grace period, your data enters permanent deletion.

This summary is provided as a courtesy to make reading easier. It does not replace the full document — in case of doubt or conflict, the complete text below prevails.

On this page

Who we are and the role we play

Quem Deve is developed and operated by Artcode. For the data processed through the app and the website, Artcode acts, as a rule, as the controller under Article 5, VI of the LGPD — that is, the party that makes the decisions about the processing.

There is an important distinction regarding the data you record about other people (your list of “People” and the entries associated with them). When you use the app in a professional or business context — for example, tracking customers’ store credit —, you act as the controller of that data and we act as the processor, handling it exclusively to provide the service to you. For strictly personal and household use, the LGPD does not apply to the processing you carry out (Article 4, I of the LGPD); even so, we protect that data as described in this Policy.

Data Protection Officer (DPO)

The official channel for data protection matters — including contact with our data protection officer (Article 41 of the LGPD) — is the email contato@quemdeve.com.

Data you provide to us

Account and sign-in

  • Email: used to create the account and receive the access code. Quem Deve does not use passwords — access happens through a temporary code sent to your email.
  • Sign in with Apple: we receive the name and email provided by Apple (which may be a private relay address, if you prefer).
  • Sign in with Google: we receive your name, email and Google account identifier.
  • Your session is stored on your device in encrypted form (AES-256), with the key protected by the Keychain (iOS) or Keystore (Android).

Profile

  • Display name: how you appear in the app and, if accounts are linked, to the user linked to you.
  • Pix key (optional): used only so you can include it in your payment-request messages and to show it to linked users. Note: a Pix key can itself be personal data (a national ID number, phone or email) — add it only if you want to.
  • Notification token: a technical device identifier used to deliver push notifications.
  • Internal usage counters (for example, how many entries you have created and the date of the last in-app review prompt), used to decide when to show the store review request.
  • Language and currency preferences, stored on the device itself.

Content you record

  • People: name, phone number (optional), notes (optional) and, if you consent, the contact’s photo — see the section on device contacts.
  • Entries: amounts, type (to receive or to pay), description, category, due and payment dates, status, installments, recurrences and splits.
  • Events and expense splits, when you use those features.
  • Suggestions: free-text messages sent through the suggestion channel, together with the app version and platform.

Description, category and notes are free-text fields. Avoid recording sensitive data in them (such as health, religion or political opinion) — they are not needed for the app to work.

Data about third parties and the reliability indicator

The core purpose of Quem Deve is to let you privately record amounts to receive and to pay between you and other people. When you add a Person, you are entering personal data of a third party who is usually not an app user.

  • That data stays restricted to your account: it is not public, does not appear in searches, is not shown to other users (except through account linking, described below) and is never reported to credit bureaus such as SPC and Serasa.
  • You are responsible for ensuring you have a legitimate relationship with the people you add and that their data was obtained lawfully, as set out in the Terms of Use.
  • The reliability indicator is calculated automatically from your own records only (payments marked on time or late). It is a purely informational, private feature: it is not a credit score, has no external validity and is not shared with third parties.

If you were added by a Quem Deve user and want information about, or deletion of, your data, write to contato@quemdeve.com. We will review the request under the LGPD and, where appropriate, remove the data or instruct the user responsible for the record.

Data collected automatically

Diagnostics and stability (Sentry)

We collect crash and performance reports to identify and fix failures. These reports may include your account identifier, email, IP address, device and system data, and a screenshot of the screen displayed at the moment of the failure — which may contain information visible in the app, such as names and amounts from your records. This data is used exclusively for diagnostics, with restricted access and limited retention.

Usage metrics (Firebase Analytics)

We log usage events — screens visited, sign-in method and general actions such as “entry created” — associated with a user identifier, to understand how the app is used and improve it. We do not send Firebase the amounts of your entries, the names of your People or your Pix key.

Performance and updates (Expo)

We collect technical startup and navigation metrics and, on each launch, check for app updates (over-the-air), which involves exchanging basic technical device data with Expo’s servers.

Remote configuration and testing (Firebase Remote Config)

We use remote configuration parameters to adjust features and free-plan limits and to run A/B tests — some users may see variations of the interface or of features.

Advertising (Google AdMob)

  • On the free plan, we display banner ads served by Google AdMob.
  • On iOS, we ask for your permission through App Tracking Transparency (ATT) before using the advertising identifier. If you decline, ads are shown without personalization based on that identifier.
  • On Android, the advertising identifier is used according to your device’s privacy settings, where you can reset it or turn off personalization.
  • Google processes data under the Google privacy policy.
  • Quem Deve Pro subscribers do not see ads.

Subscriptions (RevenueCat, Apple and Google)

Purchases are processed by the App Store or Google Play — we never have access to your card details. To manage access to the Pro plan we use RevenueCat, which receives your account identifier, email, display name and subscription status.

Device contacts

  • Contacts access is optional and only used to make adding a Person easier.
  • You pick one contact at a time in the system’s native picker; we import only the chosen contact’s name and phone number.
  • We never import, copy or store your full contact list on our servers.
  • The contact’s photo is only uploaded to our servers with a specific, separately requested consent — which you can revoke at any time in your Profile.
  • We keep the contact’s internal identifier so that, with your permission, we can locate their phone number on your device again when needed (for example, when preparing a payment request).

Purposes and legal bases (LGPD)

We process personal data based on the following grounds of Article 7 of the LGPD:

  • Performance of a contract (Art. 7, V): creating and maintaining your account, storing and syncing your records, sending access codes, due-date reminders and activity notifications, operating the Pro plan and providing support.
  • Legitimate interest (Art. 7, IX): measuring usage, improving the product, ensuring security, preventing fraud and abuse and keeping operational communications — always with the least possible impact on you.
  • Consent (Art. 7, I): use of contact photos, personalized ads on iOS (ATT) and push notifications. Consent can be revoked at any time.
  • Compliance with a legal obligation (Art. 7, II): keeping application access logs for 6 months, as required by Article 15 of the Brazilian Internet Civil Framework, and other legal and regulatory obligations.
  • Regular exercise of rights (Art. 7, VI): defense in administrative, judicial or arbitration proceedings.

Who we share data with

We do not sell personal data. We share data only with providers that help us operate the service (processors), with the app stores and in the other situations described below:

  • Supabase — service infrastructure: authentication, database and image storage.
  • Google (Firebase) — usage metrics, remote configuration and notification delivery on Android.
  • Sentry — error and performance monitoring.
  • RevenueCat — subscription management and Pro plan access.
  • Google AdMob — ad delivery on the free plan.
  • Expo — app updates, push notification delivery and performance telemetry.
  • ChottuLink — creation and resolution of invite links.
  • Apple and Google — authentication (Sign in with Apple/Google) and purchase processing.

We may also share data: (a) to comply with a legal obligation, court order or request from a competent authority; (b) to protect the rights, safety and property of Artcode, users or third parties; and (c) in corporate transactions — such as a merger, acquisition or sale of assets —, in which case the data will remain protected by this Policy and you will be notified of any relevant changes.

WhatsApp

Quem Deve does not send messages and does not transmit your data to WhatsApp. When you use the payment-request feature, the app simply opens WhatsApp on your device with a pre-filled message — sending it (or not) is entirely your decision, and the conversation is then governed by WhatsApp’s terms and privacy policy. The same applies to the support channel: the pre-filled message includes your name, email and app version, and you can edit it before sending.

Account linking and mirrored records

Quem Deve lets you link your account to that of another person who also uses the app, through an invite. Linking is always voluntary and has important effects on your data:

  • When you create an invite, a link is generated. Any signed-in person who has that link can see your display name and the invited contact’s name before accepting. Share the link only with its intended recipient. Invites expire in 7 days.
  • Once the link is accepted, the entries between you become mirrored: the history recorded by one is copied to the other’s account (with the type flipped) and kept in sync — creation, editing and deletion by the author of a record are reflected in the mirrored copy.
  • Linked users can see each other’s display name, photo, subscriber status and Pix key (if added).
  • Push notifications about new entries may show a name and an amount — including on the device lock screen. You can restrict this in your system settings.
  • Records mirrored from the other user remain under their control: they can change or delete them at any time, including through the permanent deletion of their account.

International data transfers

Our infrastructure and service providers (such as Supabase, Google, Sentry, RevenueCat and Expo) may store and process data outside Brazil, especially in the United States. In those cases, we adopt the safeguards of Article 33 of the LGPD, including data processing agreements (DPAs) and contractual clauses that ensure a level of protection compatible with Brazilian law.

Data retention and deletion

  • Active account: we keep your data for as long as your account exists, to provide the service.
  • Account deletion: you can delete your account in the app, under Profile → Account → Delete account. The account is deactivated immediately and becomes inaccessible; for 30 days, you can change your mind and reactivate it.
  • After the 30 days, the account’s data enters permanent deletion from our active systems, completed within an operational window of up to 90 days, including backups.
  • Mirrored records: the permanent deletion of your account also removes the copies your records mirrored into linked accounts; likewise, copies mirrored to you cease to exist when their author deletes them.
  • Mandatory retention: access logs are kept for 6 months (Article 15 of the Brazilian Internet Civil Framework), and certain data may be retained in the situations allowed by Article 16 of the LGPD (compliance with legal or regulatory obligations and the regular exercise of rights).
  • Suggestions and communications may be kept in aggregated or anonymized form for product history.

Your rights as a data subject (Article 18 of the LGPD)

You may exercise, at any time and free of charge, the rights provided by the LGPD:

  • Confirmation that processing exists and access to your data;
  • Correction of incomplete, inaccurate or outdated data (much of it can be done in the app itself);
  • Anonymization, blocking or deletion of unnecessary or excessive data;
  • Portability of your data, as regulated;
  • Information about who we share your data with;
  • Withdrawal of consent and information about the consequences of refusing it;
  • Review of automated decisions that affect your interests, where applicable;
  • Deletion of data processed on the basis of consent.

To exercise any right, write to contato@quemdeve.com. We will respond within the timeframes set by law and may request information to confirm your identity. You may also lodge a complaint with the Brazilian National Data Protection Authority (ANPD).

Information security

  • Encrypted communication (TLS) between the app and our servers;
  • Encryption at rest on our providers’ infrastructure;
  • Locally encrypted session (AES-256), with the key protected by the device Keychain/Keystore;
  • Per-account isolation: database access rules restrict each record to its owner;
  • Restricted internal access, under the principle of least privilege;
  • On Android, local app preferences may be included in the device backup (Google), depending on your system backup settings.

No system is absolutely secure. If a security incident occurs that may create relevant risk or harm to you, we will report it in accordance with Article 48 of the LGPD. Protect your side too: keep access to your email secure — it is how your account is accessed.

Children and adolescents

Quem Deve is not intended for people under 18, and we do not knowingly collect data from children or adolescents. If we identify an account in breach of this rule, it will be closed and its data deleted. Parents and guardians may contact us to request removal.

Website and cookies

The quemdeve.com website is informational. We use only one essential cookie, to remember your chosen language; we do not use tracking or advertising cookies on the website. The app stores (App Store and Google Play) have their own privacy policies, which apply to browsing and purchases made there.

Changes to this Policy

We may update this Policy to reflect changes in the product or in the law. The date of the last update appears at the top of the page. For relevant changes, we will give reasonable advance notice through the app or the website. Using Quem Deve after the changes take effect means you agree with the updated version.

Contact

Artcode, developer and operator of the Quem Deve app.

Privacy channel and data protection officer (DPO): contato@quemdeve.com.

This Policy was drafted in Portuguese. Translations are provided for convenience and, in case of conflict, the Portuguese version prevails.

Legal

Terms of Use

The rules of the service: what Quem Deve is (and is not), plans, subscriptions and responsibilities.

Read document

Still have questions?

Reach out about privacy, personal data or these documents. We reply through our official email.

Send an email