DividirContas
RecursosComo funcionaGuiaPrivacidadeDúvidas
Entrar Web
← Back to home

Privacy and LGPD

Privacy Policy

This Policy explains, in plain language, how DividirContas processes personal data. It also explains the choices and rights protected by Brazil’s General Data Protection Law (LGPD).

Last updated: 12 August 2026

Prefer Portuguese? Leia a versão em português.

This is a complete English convenience translation of the Brazilian Portuguese Privacy Policy. It is not legal advice. For the current Portuguese text and in case of a difference in interpretation, please consult the Portuguese version or contact us before relying on this translation.

1. Who is responsible for the data

DividirContas is the controller of personal data processed directly to operate the app and website. For questions, requests, or to exercise privacy rights, contact us at [email protected].

In groups, other people may enter information about you — for example, your name, your participation in an expense, or a payment. DividirContas provides the tool, while each person is also responsible for the legitimacy of the data they record and share.

2. Data we may process

Account, profile, and authentication data

First name, last name, display name, email address, internal account identifier, and information needed for authentication by email, Google, or Apple. We do not receive your Google or Apple password.

A profile photo is optional. It may be provided by the authentication provider or selected and uploaded directly by you in the app. When you upload a photo, the file is stored in the avatar storage service and associated with your account through a public URL. This lets us show the avatar in your profile and in DividirContas shared features; anyone who has the direct file address can also view it. Do not use an image as an avatar if you do not want it to be visible.

Group and expense data

Group names, participants, descriptions, dates, amounts, payers, split criteria, balances, settlements, confirmations, and activity history. If you choose to attach proof of payment or receipts, we also process those files and the information contained in them.

Settlement proof is optional and selected from the gallery. We accept JPEG, PNG, or WebP images up to 2 MB. The file is sent over an encrypted connection to a private bucket and associated with the settlement through an internal path, not a public URL. Active group participants can view it through a signed URL valid for one hour. We do not run OCR or extract financial fields from the image.

An expense invoice or receipt is also optional. You may take a photo, choose an image, or select a PDF. We accept JPEG, PNG, WebP, or PDF files up to 10 MB, validate their type from file content, and upload the attachment only when you save the expense. These files are subject to the group’s access controls. We do not run OCR or extract fields from the document.

Group comments are user-generated content. We process the text, the identifier and display name of the person who posted it, the date, and the related group so the conversation is shown only to active participants in that group. Comments may be reported and reviewed under the moderation rules described in this Policy and the Terms of Use.

Email provided when adding participants

A group member may enter another participant’s name and, optionally, email address. We use the normalized address to connect that person to an existing profile or, if they do not have an account yet, keep a private reference that allows the connection after that person signs in with the same email. The address entered in this form is not shown in the participant list.

Settlement data

Pix key and its key type, only when provided voluntarily. DividirContas does not access your bank balance, statement, bank password, card, or bank credentials.

When you register a key to receive money during onboarding or in Settings, it is sent over an encrypted connection, stored encrypted, and tied to your account. Authorized participants receive the key only when they need to generate a payment to you. You can replace or remove it in Settings.

When a payer pastes a key or complete Pix code to generate a QR code, that content is processed only in the device’s memory during that operation and is not persisted by DividirContas.

Technical and security data

IP address, device and operating system type and version, app version, access records, error events, and information needed to detect abuse, investigate failures, and keep sessions secure.

Optional usage metrics

If you enable Help improve the app in Settings, we record categorical technical events, such as a screen viewed, login method, group creation, expense entry, and settlement completion. Google Analytics for Firebase may also process a random installation identifier, app version, platform, general device model, and approximate network-derived location.

We do not send Analytics names or emails, group names, descriptions, comments, amounts, Pix keys or codes, bank identifiers, invitation tokens, proofs, or the actual URL you are visiting. Collection starts turned off, does not use advertising identifiers, and can be revoked at any time through the same Settings control.

Optional notifications

Notifications also start turned off. Only after you enable at least one topic in Settings and grant the system permission does the app obtain an APNs or FCM token from the device and associate it with your account to deliver the notices you chose. This token is a technical device identifier for app functionality; it is not used for advertising or tracking.

When you turn off the final topic, sign out, or delete your account, the app removes the link to the registered token and deletes the copy kept in secure storage. Once the server confirms the removal, Android disables FCM auto-initialization and deletes the token, iOS cancels remote registration without changing your permission, and the web cancels the push subscription. If any of these steps fails, we retain the identifier needed to retry; we do not generate a new token during removal. This choice is independent of Help improve the app: accepting notifications does not enable Analytics, and accepting Analytics does not enable notifications.

Communications

Content and contact details sent when you request support, report a problem, or exercise a right.

In-app reports

When you use the contextual report option, we process the selected reason, any extra details you decide to send, information necessary to identify the person, content, or context reported, as well as the review status and any measures adopted. Please include only the information needed for us to understand and assess the situation.

Blocks between participants

When you block someone, we process the identifiers of both accounts, the blocking date, and information needed to apply your choice. Your block list is private: it is not shown to the blocked person or to other participants. Blocking reduces future social interactions, but preserves shared expenses, splits, balances, settlements, and other financial records.

To list and undo a block, the app receives only a random relationship identifier called block_id. It does not receive the profile identifier of the blocked person. The relationship table does not allow direct reading by the app, and the former paginated route that exposed that data has been removed.

3. Why we use data and our legal bases

PurposeExamplesLegal basis
Provide the serviceCreate an account, connect participants through a provided email, synchronize groups, show comments, apply blocks, calculate splits, display balances, and generate the export requested by the userPerformance of a contract
Protect accounts and infrastructureAuthenticate access; prevent fraud, abuse, and incidentsLegitimate interest and compliance with a legal obligation
Receive and assess reportsPromote trust and safety; prevent fraud and abuse; investigate possible violations; and comply with legal dutiesLegitimate interest, exercise of rights, and compliance with a legal obligation
Respond to requestsSupport, fixes, data subject rights, and communicationPerformance of a contract, legal obligation, and legitimate interest
Comply with legal dutiesRespond to valid orders and preserve mandatory recordsCompliance with a legal or regulatory obligation
Optional featuresUsage metrics to understand the most-used screens and features, always after a specific and prominent choiceConsent, where applicable

When we rely on legitimate interest, we consider the necessity of the processing, the impact on data subjects, and the reasonable expectations of people who use the service.

4. Pix, banks, and WhatsApp

DividirContas does not initiate payments and does not connect to your bank account. When you use a Pix key or code, the transaction occurs in the environment of the financial institution you choose. We do not receive automatic confirmation from the Pix system; receipt is confirmed manually in the app.

A key or complete Pix code pasted by the payer is used only in the device’s memory to generate the QR code. The full content is not sent to our database or stored by DividirContas.

This local-processing rule applies to a key entered manually by the payer during that checkout. A key you choose to register to receive money is stored encrypted as explained in section 2 and can be removed in Settings.

Sharing through WhatsApp occurs through a user action using the device’s sharing features. We do not read your conversations, contacts, or WhatsApp content. Once the third-party app is opened, processing is also governed by that service’s policies.

5. Who we may share data with

We may share data only when necessary with:

  • your group participants: to display group-related expenses, splits, balances, confirmations, optional proof images, and comments;
  • infrastructure providers: hosting, database, storage, email delivery, and security;
  • authentication providers: Google and Apple, when you choose to sign in through one of those services;
  • Google Analytics for Firebase: only if you enable optional metrics, as the product measurement operator, without advertising or combination with third-party profiles;
  • public authorities: when there is a legal or regulatory obligation, or a valid order;
  • advisors and successors: in audits, defense of rights, or a possible service reorganization, with appropriate confidentiality and transparency measures.

Within the service, reports and their details are accessible only to the authorized moderation team, with access limited to what is necessary for review, prevention of fraud and abuse, community protection, exercise of rights, and compliance with law. The report content is not shown to the reported person or other participants. Information may be supplied to authorities only when there is a legal or regulatory obligation, or a valid order.

A block relationship is also not shown to the blocked person. For the person who blocked, the service may stop showing optional comments from the other person and suppress related social notifications, as well as prevent a new shared participation. Financial information already part of the group remains available where needed to preserve the history and correct calculations.

DividirContas does not sell personal data or share expense data, balances, participants, Pix keys or codes, proofs, or settlement history with advertisers for targeting. We also do not use this data to offer credit or trade advertising profiles.

6. Storage and international transfers

Some technology suppliers may operate infrastructure or teams outside Brazil. When that happens, we will adopt mechanisms compatible with the LGPD and require appropriate protection by contract, provider policy, or another applicable legal instrument.

Locations and suppliers may change as the service evolves. We remain responsible for assessing safeguards and limiting sharing to what is necessary.

7. How long we keep data

We retain data while your account is active and for the period needed to provide the service. After a deletion request, we delete or anonymize data that does not need to be retained.

Certain information may remain for an additional period to meet legal obligations, prevent fraud, resolve disputes, exercise rights, or preserve shared group records. Protected backups may take a technical period to be overwritten and are not reused for other purposes.

For incident recovery, we keep a daily logical backup and an encrypted copy outside the main server. Because this is not continuous recovery, the restorable point may differ by up to 24 hours. A copy is accepted only after it is decrypted and read in full; the restore test is stopped and marked failed if there is an error or inconsistency in the financial history.

After the 1 August 2026 security migrations, we validated a server backup with 486926 bytes and an encrypted offsite copy with 487238 bytes. The exercise restored 8 profiles and 5 migrations with zero errors and no group with a ledger outside zero.

Report data is kept only for the time needed to assess the situation, apply or review measures, prevent repeat incidents and fraud, meet legal obligations, and exercise rights. We limit collection and access to what is relevant for these purposes and, when retention is no longer necessary, delete or anonymize the data unless another retention is required or allowed by law.

An email provided for a person who does not yet have an account is kept as a private reference while needed to connect the participant to the correct profile. The reference is removed after the connection or when the corresponding participant record is deleted, subject to retention required or permitted by law.

You may replace or remove the optional photo in Settings. When you save the removal, we delete the active avatar file you uploaded and remove its association with the profile. Residual copies may remain temporarily in protected caches or backups until their technical expiry or overwrite cycle.

8. Security

We adopt technical and organizational measures proportionate to the risk, such as encrypted communications in transit, access controls, separated permissions, session protection, records of relevant events, encrypted backups outside the main server, and restore tests that fail safely when there is an error or inconsistency.

No system is completely invulnerable. If an incident may create a relevant risk or harm, we will follow the investigation, mitigation, and communication measures set out in law and the guidance of the Brazilian National Data Protection Authority (ANPD).

9. Your rights under the LGPD

You may request, as applicable:

  • confirmation that processing exists and access to data;
  • correction of incomplete, inaccurate, or outdated information;
  • anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data;
  • portability, subject to regulation and technical feasibility;
  • information about sharing and the possibility of refusing consent;
  • withdrawal of consent where consent is the legal basis;
  • objection to unlawful processing and review of solely automated decisions, where applicable;
  • filing a petition with the ANPD and consumer-protection bodies.

To protect your account, we may ask for additional information to confirm your identity. We will respond within legal time limits and explain any inability to fulfill a request in full.

10. Export, deletion, and in-app controls

Optional metrics

In Settings → Privacy and security, the Help improve the app control lets you give or withdraw your choice. It starts turned off. When you turn it off, the app stops new measurement events and resets local SDK data; the withdrawal does not retroactively delete events already received and processed in aggregate before the change.

Portability and export

In Settings → Export my data, you can generate a JSON file with a structured copy of data your account is allowed to view. The file uses schema v2 and is assembled by the server in one authenticated operation and one consistent database snapshot. Its sections therefore reflect the same point in time; if the operation fails, no partial file is delivered.

The copy includes profile and preferences, groups, participants, expenses, payers, splits, recurrences, settlements, and comments. The activity section shows group, action, type and entity identifier, and date, but not the actor, profile identifier, or internal payload. Notices and notifications are in a separate section with title, text, and creation and read dates. The blocked-people list shows only display name and block date, without internal identifiers,block_id, profile identifier, or email.

The file does not include passwords, sessions, tokens, Pix keys, BR Codes, proof images, or private file paths. It is created on the device and is saved or sent only when you choose a destination in the browser or system sharing menu. From that point, you must protect the file and consider the privacy rules of the chosen destination. Exporting a copy does not delete records held by the service.

Deletion and correction

You may start account deletion in DividirContas settings. Depending on your role in groups and the existence of shared records, you may need to resolve pending issues before it can be completed. This prevents deletion of information that also affects the rights and histories of other people.

You may also correct profile data and edit or remove entries when group and service rules allow it.

If you cannot access the app, see the public Delete account and data page to send a request using the email linked to the account.

11. Children and teenagers

DividirContas is not directed to children. If a minor uses the service, processing must occur in accordance with their best interests and with the authorization or participation of a parent or guardian where required by law. If you believe a child’s data was entered improperly, contact us.

12. Website, cookies, and records

In this version, the institutional website does not use advertising cookies or create advertising profiles. Hosting infrastructure may generate essential technical records, such as IP address, time, and request information, for delivery, security, and diagnosis.

The institutional website and web app use Google Analytics only after you agree. The technical tag starts with storage denied: it neither creates cookies nor sends a page view before the choice. We do not send the complete URL — including invitation token, callback, query, or fragment — and do not use advertising cookies, ad signals, or personalization. You can change this choice in Metrics preferences in the site footer or in app Settings.

13. Future changes to advertising and measurement

If a future commercial model involves processing personal data for advertising or measurement, we will start it only after defining an appropriate legal basis, updating this Policy in advance, and implementing the information, choices, and consent mechanisms required for the specific case.

14. Updates to this Policy

We may update this document to reflect changes in the app, suppliers, or law. The current version will remain available on this page with its update date. Material changes will be communicated through an appropriate channel before taking effect, where required.

15. Contact us

For privacy questions or to exercise rights, email [email protected]. Include only the information needed for us to understand the request, and do not send passwords or authentication codes.

DividirContas

Despesas em grupo organizadas com clareza, do primeiro gasto ao último acerto.

ProdutoRecursosComo funcionaGuia do aplicativoEntrar no appBaixar para AndroidBaixar para iPhone e iPadPerguntas frequentes
LegalTermos de UsoPolítica de PrivacidadeExcluir conta e dadosContato
© 2026 DividirContas.Feito para contas mais leves.
Podemos medir o uso deste site?

Métricas opcionais e sem publicidade nos ajudam a melhorar o DividirContas. Você pode continuar sem aceitar e mudar a escolha depois no rodapé.