Rico aos Poucos
Privacy Policy

Privacy Policy

This Policy explains, without beating around the bush, what personal data Rico aos Poucos collects, why it collects it, who it shares it with, how long it keeps it and what you can demand from us. It was written to be read by people who are not lawyers, and it follows Brazil's General Data Protection Law — LGPD (Lei nº 13.709/2018), the Brazilian Internet Civil Framework — Marco Civil da Internet (Lei nº 12.965/2014) and the Brazilian Consumer Protection Code — Código de Defesa do Consumidor (Lei nº 8.078/1990).

1. Who the controller is

Rico aos Poucos (ricoaospoucos.com.br) is an independent financial education project, maintained by an individual, with no ties to brokerages, asset managers, fund administrators or financial institutions. For the purposes of art. 5, VI, of the LGPD, the person responsible for the project is the controller of the personal data processed on the site, in the Android app and in the browser extension.

Official channel for any personal data matter: galera.org@gmail.com.

2. What requires an account and what does not

Most of the site is open: you browse articles, fund and company analyses, quotes, indicators, commodities, sectors, news, calculators and simulators without identifying yourself.

An account (Google sign-in) is required for:

  • The final part of long articles, where the conclusion sits — short articles open in full, and news items are never cut;
  • The Valuation tab on real estate fund pages, with the fair price and the maths behind it — the same tab on stock pages is open;
  • The Portfolio, your dashboard and your watchlist;
  • Price alerts and notifications;
  • Writing: commenting, posting in the forum, sending chat messages, creating or voting in polls, and sending a report through the "Contribute" button. Reading all of that is open — an account is only required to write.

These parts sit behind sign-in either because they depend on knowing whose they are (the portfolio, the alert, the comment) or because that is how the project sustains itself without charging anyone.

Even without an account, the site records technical browsing data (item 3.4) — like any site on the internet.

3. What data we collect

3.1. When you create an account (Google login)

The only way to create an account is Google login (OAuth 2.0). We never create, ask for, see or store your password. When you authorize it, Google hands us — and we store:

  • Display name and profile picture (the URL of the picture hosted at Google);
  • E-mail address;
  • Unique Google account identifier (the sub field), which is what ties your session to your account here;
  • Creation date, date of last login and last access, and the language you chose.

Inside the site you can edit your display name, your bio and the public address (slug) of your profile.

3.2. When you use the Portfolio (your financial information)

As you use it, we may store:

  • Transactions and positions: asset, quantity, price, date, brokerage, income received and the daily history of the portfolio's value;
  • Cash and assets outside the exchange: balance, deposits and withdrawals, real estate, dollars, gold, cryptocurrencies, fixed income, pension plans and personal loans, with issuer, index, rate and amounts;
  • Property: vehicles and real estate, including FIPE code/model, acquisition value, market value and financing details (amount, rate, installments);
  • Debts: type, outstanding balance, rate and monthly installment;
  • Investor profile and onboarding: objective, horizon, risk tolerance, self-declared knowledge and, if you tell us, monthly income, cost of living, monthly contribution, available amount and main bank;
  • Synchronization with B3: if you import the spreadsheet from the Área do Investidor (B3's investor area) or use our browser extension, we store the trades, positions and income that come from there (details in item 3.7);
  • Expense tracking: if you import a bank statement (CSV from Nubank, Inter or a generic one), we store the transactions — date, amount, description, merchant, category and source bank. The file is read inside your browser; only the resulting list of transactions is uploaded to our server. Heads up: the description of a Pix transfer usually carries the name and part of the ID document of whoever sent or received it. That text goes up exactly as it came from the bank, so your statement may contain other people's data — delete the transaction if you don't want it kept;
  • Analyses and plans generated on request: the text of the analysis, the plan and the snapshot of your profile used to produce them (see item 5);
  • Portfolio ledger: the record of each action of yours (entered, edited, deleted), so you can audit your own history;
  • Sharing: if you share a portfolio by link or invite someone, we store the link token and the e-mail address of the invited person.

What the Portfolio does not do: it does not connect to your bank account, does not move money, does not place orders, does not ask for bank or brokerage passwords, does not ask for your CPF (Brazilian taxpayer ID) and does not store card data.

3.3. When you publish something

Comments, forum topics and replies, chat messages, polls and votes, shared links and reports sent through the "Contribua" button are recorded with your text, the page where they were made, the date and your identification. Along with them, for security and abuse prevention, we record the IP address and the browser (user-agent) of the submission.

  • It is public: the text of comments, forum posts, chat and polls, along with your display name and picture. Your e-mail is never displayed publicly.
  • If content of yours goes through moderation, we also keep the original text, the action taken and the reasoning — that is what makes it possible to reverse a wrong moderation;
  • It is not public: the report sent through "Contribua" and the images attached to it (up to 6 files). They go only to whoever maintains the site — including by message on the person in charge's Telegram, so that the problem gets seen quickly.

3.4. When you are just browsing

  • Visit identifier: we generate a random code (rap_visitor_uid) stored in your browser to count visitors without knowing who they are;
  • Pages viewed: which page, when, how many times, where you came from (referrer) and shares, with the IP stored only in scrambled form (hash);
  • Searches made on the site: the term searched for and the result clicked, with a hashed IP, plus the browser, the page you came from and a session identifier;
  • Usage events: when a sign-in invitation appears and what you do with it, and through which channel you shared a page;
  • If you have an account: browsing starts being associated with it, including browsing done in the same browser before you signed up. We keep one record per article or fund opened (retaining the most recent ones) and the page on which your account was born. Out of that comes an interest profile (which funds and topics you follow) — see item 5;
  • Google Analytics 4 metrics (identifier G-6XBNHTHSTW), with aggregated audience data.

You can turn off our own audience tracking at any time — instructions in the Cookie Policy.

3.5. Access logs

The server keeps access logs (date, time, IP, route, response, browser), as required by art. 15 of the Marco Civil da Internet. They serve security, failure diagnosis, abuse control and compliance with court orders — and nothing else.

3.6. Notifications and e-mails

  • Browser push: we store the technical address of the subscription (endpoint) and the encryption keys generated by your browser;
  • Android app: we store the device token in Firebase Cloud Messaging;
  • E-mail: we store the send, the delivery status and — in campaigns — whether you opened it and whether you clicked. We use that to reduce the frequency for those who aren't interested: whoever doesn't open starts receiving less and then stops receiving. You can unsubscribe through the link in the footer of any e-mail of ours;
  • There is a cap of 1 e-mail per day and 3 per week per person, across all campaigns.

3.7. "Sincronizar B3" browser extension

The extension is optional, installed by you, and its purpose is to bring your B3 statement into the Portfolio without typing. How it works, in detail:

  • It only acts on two origins: the B3 Área do Investidor site and Rico aos Poucos;
  • Before the first read it shows a screen with what it will read and what it will do, and only continues after you agree. Every request it makes to B3 is read-only: the extension places no orders, moves no money and changes nothing in your account there;
  • The credential of your B3 session never leaves B3's page and is never sent to us. The extension uses it right there to request your data from B3;
  • What reaches us is the result: trades, positions and income;
  • The pairing between the extension and your account uses its own token, stored only in the extension's local storage; on our server we store only its hash;
  • Automatic synchronization is opt-in and can be turned off in the extension's panel;
  • So that wallets never get mixed when more than one B3 account is used in the same browser, the extension stores on your computer an irreversible cryptographic digest (SHA-256) of the B3 session identifier. It only answers "is this the same account as always?", is never sent to us, and cannot be used to reconstruct your tax ID or any other data about you;
  • The permissions it asks Chrome for are the two origins above and nothing else: it does not ask for access to all sites, does not ask for your cookies and does not ask for the permission that reveals the URL of every tab (the one Chrome describes as "read your browsing history");
  • Uninstalling stops the collection immediately. To revoke the pairing on the server, remove the extension in your account or request the revocation through the channel in item 16.

3.8. What we do not collect

  • Passwords — not your Google one, not your bank's, not your brokerage's;
  • CPF, RG (Brazilian taxpayer and ID numbers), card data, bank accounts or financial access credentials;
  • Sensitive data under art. 5, II, of the LGPD: health, biometrics, religion, political opinion, union membership, sex life, racial or ethnic origin;
  • Precise GPS location.

If you spontaneously write any of these data in a comment, in a bio or in a report, it is yours and you can ask for its removal at any time.

4. What we use it for and on what legal basis

What forWhat data it usesLegal basis (LGPD, art. 7)
Create and maintain your account, authenticate you and keep the session Google account data, session cookie Performance of a contract (art. 7, V)
Store favorites, alerts, preferences and your Portfolio Items 3.1 and 3.2 Performance of a contract (art. 7, V)
Publish and display comments, forum, chat and polls Item 3.3 Performance of a contract (art. 7, V)
Send notifications and e-mails you asked for or can turn off E-mail, push subscription, app token Consent (art. 7, I) and legitimate interest (art. 7, IX)
Understand how the site is used, measure audience and improve the product Item 3.4, in aggregated form Legitimate interest (art. 7, IX)
Sort the content of your dashboard by what interests you Interest profile (item 5) Legitimate interest (art. 7, IX)
Generate the analysis of your portfolio or the contribution suggestion you asked for Portfolio and profile (item 3.2) Performance of a contract and consent (art. 7, V and I)
Prevent spam, fraud, abuse and attacks; moderate content IP, user-agent, logs, published content Legitimate interest (art. 7, IX)
Keep access logs Item 3.5 Compliance with a legal obligation (art. 7, II — Marco Civil, art. 15)
Handle data subject requests, respond to contacts, exercise rights in proceedings Whatever each case requires Legal obligation and regular exercise of rights (art. 7, II and VI)

If one day we want to use any data for a new purpose incompatible with these, we will ask for your consent beforehand — not afterwards.

5. Profiling and artificial intelligence

Two different things happen here, and it is important to keep them apart:

5.1. Interest profile (automatic, no AI)

If you have an account, the pages you open form a profile of the assets and topics that interest you. It serves to sort your dashboard and to decide which asset it makes sense to alert you about. It is arithmetic, with no human decision and no AI model. It does not set prices, does not restrict access and does not produce any legal effect on you.

There is also a reputation score per person, calculated from your activity on the site (what you published and how it was received) and from an automated relevance assessment of each contribution. It sorts highlights and may cause a contribution assessed as being of low relevance not to appear in the public listings. If that happens to something of yours, you can request human review through the channel in item 16.

5.2. Use of artificial intelligence models

Part of the editorial content of the site (articles, fund analyses, translations, narrations) is produced with the support of AI models under automated and human review criteria. That involves no personal data of anyone.

There are, however, situations in which your data may be processed by a third-party AI model (today, models from Anthropic and Google):

  • Analysis of your portfolio and contribution recommendation, when you ask for it: the content of the portfolio and the profile you filled in are sent to the model to generate the text. Without your request, nothing is sent;
  • Moderation and classification of what is published — detecting spam and offense, and assessing the relevance of a contribution (the score in item 5.1);
  • Diagnosis of a problem you reported through the "Contribua" button, including the image you attached;
  • Public reply to a correction you pointed out in content of ours: your comment is analysed in order to establish the error and to draft the reply and the correction notice;
  • Production of the site's content from what is published in public areas of the community.

None of this processing decides on credit, price, access to your account or anything with legal effect on you. Two of them, however, affect what you published: automated moderation may hide or edit a passage that breaks the rules, and the relevance assessment may keep a contribution out of the listings — in both cases without prior notice. That is why we guarantee the right in art. 20 of the LGPD expressly: you can request human review and an explanation of the criteria behind any automated outcome that affects you, through the channel in item 16, and we reassess it.

We do not sell, rent or transfer your data to train third-party AI models, and we do not use the content of your portfolio to train any model.

6. Who we share it with

We do not sell personal data. We share it only with those necessary for the site to work — each one receives only the minimum for its job — and with authorities, when the law requires it.

WhoWhat forWhat reaches them
Google LLC (Sign-In) Authenticate you Nothing of ours goes there beyond the login request. Google is the one who sends us name, e-mail, picture and the account identifier
Google Analytics 4 Measure audience Browsing, IP, browser, usage events
Cloudflare, Inc. Host the pages (Cloudflare Pages), CDN and attack protection IP, browser and the request — as with any CDN
DigitalOcean, LLC Server where the API and the database live Everything you send to the service is stored on that server
Brevo (Sendinblue) Deliver the e-mails Your e-mail, your name and the content of the message
Google Firebase Cloud Messaging and your browser's push services (Google, Mozilla, Apple, as the case may be) Deliver the notification to your device Device token/address and the content of the notification
Telegram Alert the person in charge of a bug report right away The text of your report, the page, your identification and the first attached image
Anthropic and Google (AI models) The cases listed in item 5.2 Only the content of that case (portfolio, published text or bug report)
Tabela FIPE (parallelum.com.br) and the FipeZap index, through an intermediary server of ours Look up vehicle make, model and price, and real estate price variation, in "Meus Bens" (My Property) Only the terms of the query (vehicle model, city/type of property), with no identification of you
Market data providers (Yahoo Finance, brapi.dev, Binance, Tesouro Direto, B3, CVM, FNET, CEPEA) Quotes, indicators and documents that the site publishes Nothing of yours. These are server queries per asset, with no user identification whatsoever
Google Fonts, jsDelivr, cdnjs Deliver the site's fonts and libraries IP and browser, at the moment of download
YouTube (no-cookie mode) Display embedded videos Whatever the YouTube player collects when you hit play
Cloudflare Web Analytics, when active on the hosting Audience counting done by the hosting itself Technical data of the visit (page, browser, country), with no identification cookie
Public and judicial authorities Comply with a valid legal order or defend rights Strictly what the request determines

We do not use Meta/Facebook Pixel, TikTok Pixel, ad networks, data broker platforms or session recording tools.

7. International transfer

Several of the providers above operate servers outside Brazil. By using the site, your data may be processed abroad. We do that on the basis of art. 33 of the LGPD, choosing providers that offer adequate contractual and technical safeguards (standard contractual clauses, certifications and public compliance commitments), and limiting the data sent to the minimum necessary for each service.

8. How long we keep it

DataPeriod
Account, portfolio, favorites and preferencesFor as long as the account exists. You ask for deletion, we erase it (item 10)
Comments, forum, chat and pollsWhile published. You can delete yours at any time
Server access logsThey live in files that rotate by size — the oldest ones are discarded when the reserved space fills up. If there is a court request, we preserve whatever exists for the period determined (Marco Civil, art. 15)
IP and user-agent attached to publicationsWhile the publication exists, as evidence in case of abuse
Images attached to bug reportsDeleted when the case is resolved or archived; there is also a purge of attachments older than 30 days
E-mail sending and unsubscribe recordsFor as long as needed to honor your unsubscribe
Google Analytics metricsThe data stays 14 months in GA4 (default setting); the cookie in your browser lasts up to 24 months
Data the law requires us to keep, or needed for defense in proceedingsFor the legal period or until the end of the proceedings

9. Information security

  • All traffic is encrypted with HTTPS/TLS;
  • Authentication is delegated to Google — there is no password of ours to leak;
  • Session cookies are cryptographically signed and flagged as HttpOnly, Secure and SameSite, which prevents scripts from reading them;
  • The extension's token is stored as a hash on the server;
  • The IP stored in browsing and search statistics is scrambled (salted hash);
  • Security headers at the edge (CSP, HSTS, anti-clickjacking), request limits per origin and administrative panels closed to the public internet;
  • Database access restricted to the minimum necessary.

In the Android application, which is the site itself inside an app, the login is handed over to the app through a session token stored only while the app is open.

No system is immune. If an incident with relevant risk to you happens, we apply item 14.

10. Your rights and how to exercise them

The LGPD (art. 18) gives you, free of charge and at any time, the right to:

  • Confirm whether we process data of yours and access that data;
  • Correct incomplete, inaccurate or outdated data;
  • Anonymize, block or erase unnecessary or excessive data, or data processed unlawfully;
  • Request portability to another provider;
  • Erase data processed on the basis of your consent;
  • Know who we share your data with;
  • Withdraw consent and object to processing carried out on another legal basis;
  • Request review of an automated decision (item 5);
  • File a petition with the ANPD, Brazil's data protection authority (gov.br/anpd).

How to ask, in practice

Write to galera.org@gmail.com with the subject "LGPD — [what you want]", from the same e-mail as your Google account (that's how we confirm it's you). We reply within 15 days.

Deleting the account: ask through the same channel. The deletion runs through a procedure that sweeps the entire database and erases every row linked to your account — registration, portfolio, property, debts, imported transactions, favorites, alerts, preferences, notification subscriptions, interest profile, reputation and what you published in public areas. Only the following remain: the record of your e-mail unsubscribe (precisely so we don't write to you again), the server access logs for as long as they exist, and whatever the law requires us to keep or whatever is necessary for defense in proceedings.

You can also, on your own and at any time, inside the site: delete comments, messages, entries, assets, property, debts, transactions, alerts and favorites; turn off notification categories; and unsubscribe from e-mails through the link in the footer of each campaign. One honest caveat: deleting a comment removes it from display immediately, but the record stays in the database for abuse control — and goes for good when you delete your account.

11. Cookies and browser storage

We use cookies to keep you logged in, remember the language and protect the login against fraud, plus local storage for preferences and for audience measurement. We do not use advertising cookies. The complete list, item by item, with duration and how to turn each one off, is in the Cookie Policy.

12. Children and teenagers

Rico aos Poucos is not intended for people under 18 and does not intentionally collect data from children and teenagers. There is no content directed at that audience. If a minor has created an account, the legal guardian can write to galera.org@gmail.com and we will delete the account and the data.

13. Third-party content and links

The site links to and embeds third-party content (B3, CVM — Brazil's securities regulator —, FNET, news portals, YouTube, social networks). When you click or hit play, you become subject to that third party's privacy policy, over which we have no control. We recommend reading them.

14. Security incident

If a security incident occurs that may bring relevant risk or harm to you, we will notify you and the ANPD, Brazil's National Data Protection Authority within a reasonable period, stating the nature of the incident, the data involved, the measures taken and what you can do to protect yourself, as provided in art. 48 of the LGPD.

15. Changes to this Policy

This Policy may change when the site changes, when the law changes or when we switch providers. The date and version number at the top always show what is in force. Relevant changes are announced prominently on the site and, when they affect processing based on consent, we ask for your consent again. Continued use after publication means you are aware of the version in force.

16. Contact and Data Protection Officer (DPO)

The person responsible for the project also serves as Data Protection Officer (art. 41 of the LGPD). Get in touch:

  • E-mail: galera.org@gmail.com
  • Suggested subject: "LGPD — [your request]"
  • Response time: up to 15 days

This Policy is governed by Brazilian law, was written in Portuguese and, in case of divergence with the translations into other languages, the Portuguese version prevails. The courts of the district of the controller's domicile are elected, except where the data subject is a consumer, in which case the courts of the consumer's domicile prevail.