← Back to Home

Privacy Policy

Last update: 04/11/2025

✓ LGPD Compliant - This Privacy Policy is compliant with the General Data Protection Law (Law nº 13.709/2018)

Introduction

The Oki Creator ("we", "our" or "platform") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store and share your information when you use our services.

By using our platform, you consent to the practices described in this policy.

1. Definitions (LGPD)

  • Personal Data: Information related to a natural person identified or identifiable
  • Treatment: Every operation performed with personal data (collection, storage, use, sharing, deletion)
  • Controller: Oki Creator - who makes decisions about the treatment
  • Operator: Third parties who treat data in our name (ex: Supabase, Stripe)

2. Personal Data We Collect

2.1. Data Provided Directly by You

  • Registration: Name, email, password (encrypted)
  • Profile: Profile picture, professional information (optional)
  • Payment: Card information is processed by Stripe (we do not store it)
  • Content: Generated images, prompts, avatars, created projects

2.2. Automatically Collected Data

  • Technical: IP address, browser type, operating system
  • Usage: Visited pages, usage time, accessed features
  • Cookies: Session identifiers, preferences (see our Cookies Policy)
  • Device: Device type, screen resolution

2.3. Third Party Data

  • Social Authentication: If you use login via Google/Facebook (name, email, photo)
  • AI APIs: Image generation metadata

3. How We Use Your Data (Purpose and Legal Basis LGPD)

PurposeBase Legal (LGPD Art. 7)Used Data
Create and manage your accountExecution of contract (Art. 7, V)Name, email, password
Process paymentsExecution of contract (Art. 7, V)Dados de pagamento (via Stripe)
Provide AI servicesExecution of contract (Art. 7, V)Prompts, images, preferences
Improve the platformLegitimate interest (Art. 7, IX)Usage data, analytics
Send communicationsConsent (Art. 7, I)Email, preferences
Comply with legal obligationsLegal obligation (Art. 7, II)Tax data, logs
Prevent fraudLegitimate interest (Art. 7, IX)IP, usage patterns

4. Sharing of Data

4.1. Service Providers (Operators)

We share data with third parties that help us provide services:

Supabase (Database and Authentication)

Location: USA (Privacy Shield certified) | Data: Account, profile, content

Stripe (Payment Processing)

Location: USA/Global (PCI-DSS compliant) | Data: Payment information

MinIO (File Storage)

Location: Own servers | Data: Images, avatars, assets

AI APIs (OpenAI, Google AI)

Location: USA | Data: Prompts, generation metadata

4.2. International Transfer

Some of our providers are located in the United States. We ensure that these transfers are compliant with the LGPD through:

  • Standard contractual clauses approved by the ANPD (National Data Protection Authority)
  • Security certifications (SOC 2, ISO 27001)
  • Contractual commitments to protect data

4.3. Exceptional Situations

We can disclose data without consent when:

  • Required by law or judicial order
  • To protect rights, property or security
  • In case of merger, acquisition or sale of assets (with prior notice)

5. Data Retention Period

Data TypeRetention Period
Registration dataWhile the account is active + 5 years (legal obligation fiscal)
Payment data5 years (legal obligation fiscal)
Generated contentWhile the account is active or until deletion request
Access logs6 months (Internet Civil Code)
Anonymous analyticsIndefinitely (anonymous data)

6. Your Rights (LGPD Art. 18)

According to the LGPD, you have the following rights over your data:

✓ Confirmation and Access

Confirm if we are treating your data and access it

✓ Correction

Correct incomplete, inaccurate or outdated data

✓ Anonymization/Blocking

Anonymize or block unnecessary data

✓ Deletion

Delete data treated with your consent

✓ Portability

Export your data in structured format

✓ Information about Sharing

Know with whom we share your data

✓ Revocation of Consent

Revoke consent at any time

✓ Opposition

Oppose treatments performed without consent

How to Exercise Your Rights

To exercise any of these rights, contact:

  • Email: privacidade@oki.com ou dpo@oki.com
  • Response Period: 15 days (LGPD Art. 18, §5º)
  • Format: Free, in simplified or complete format (via electronic report)

7. Security Measures

We implement technical and organizational measures to protect your data:

7.1. Technical

  • Data encryption in transit (HTTPS/TLS)
  • Password encryption (bcrypt/Argon2)
  • Data encryption at rest (AES-256)
  • Firewall and DDoS protection
  • Multi-factor authentication (optional)
  • Security monitoring 24/7

7.2. Organizational

  • Restricted access to data (minimum privilege)
  • Team training in security
  • Confidentiality contracts with employees
  • Security audits periodically
  • Incident response plan

7.3. Incident Notification

In case of security incident that may generate significant risk or damage, we will notify:

  • The ANPD (National Data Protection Authority) - reasonable period
  • You (affected subject) - in reasonable period

8. Cookies and Similar Technologies

We use cookies and similar technologies. For more information, see our Cookies Policy.

9. Minors

Our platform is not intended for minors. We do not intentionally collect data from minors. If we become aware that we are collecting data from a minor, we will immediately delete that information.

10. Changes to this Policy

We may update this Policy periodically. We will notify about significant changes through:

  • Email to the registered address
  • Highlighted notice on the platform
  • Update of the date at the top of this page

11. Applicable Legislation

This Policy is governed by Brazilian legislation, especially:

  • General Data Protection Law (LGPD - Law 13.709/2018)
  • Internet Civil Code (Law 12.965/2014)
  • Consumer Defense Code (Law 8.078/1990)

12. Data Protection Officer (DPO)

Our Data Protection Officer (DPO) is available to clarify doubts and receive communications:

Data Protection Officer (DPO)
Email: dpo@oki.com ou privacidade@oki.com
Website: https://loophid.com
Response Period: 15 days (according to LGPD)

13. Data Protection Authority

If you are not satisfied with our privacy practices, you can contact the supervisory authority:

ANPD - National Data Protection Authority
Website: https://www.gov.br/anpd/
Contact Channel: https://www.gov.br/anpd/pt-br/canais_atendimento

This Privacy Policy was prepared in accordance with the General Data Protection Law (LGPD) and represents our commitment to transparency and protection of your personal data.