Privacy Policy

Last updated: 2026-08-01

1. Introduction to personal data processing

Convenience translation: the Portuguese version is the binding text. This Privacy Policy describes how Entrela collects, uses, stores, and protects users’ personal data. Commitment to privacy and information security is a fundamental pillar of our work in mental health.

2. Data Collection and Processing

The application collects and processes the following types of data:

  • Account data: Name, age, email, phone, city/state, and basic profile information.
  • Health and mental-health data: Self-reported information, scales, questionnaires, mood records, medication adherence, and other clinical instruments.
  • Technical data: Access logs, session identifiers, days and times of use, needed for system stability and security.
  • Usage data and technical observability: Interaction events, app and operating-system version, device identifier for notifications, and technical stability signals such as failures and performance, used for support, security, and continuous improvement.
  • Support and submitted content: Name, email, subject, message, attachments, and other content the user chooses to share through the application.
  • Billing data: When applicable to a subscription started outside this version of the application, account reference, plan, and history needed for support and legal obligations. Full card details remain with the payment processor.
  • On-device local collection and storage: Some information may be temporarily recorded on the device itself for offline operation, continuity of form completion, and later secure synchronization with the user’s account.

Health app on iOS

Integration with the Health app (HealthKit) is optional and read-only. With express authorization, Entrela reads steps, distance, active energy, heart rate, heart-rate variability, and sleep. Entrela does not add or change data in the Health app and does not use that data for advertising or model training.

3. Sensitive Health Data

Data processed by Entrela is classified as sensitive personal data under Brazil’s Lei Geral de Proteção de Dados (Law No. 13.709/2018 – LGPD).

LGPD compliance

This data is processed on the legal basis of Health Protection, under Art. 7, item VIII, and Art. 11, item II, subitem “f”, of the LGPD, exclusively for follow-up and organization of health information.

Access to HealthKit depends on explicit consent and may be revoked. The Disable and delete data option in Entrela ends synchronization and requests deletion of health data synced to the server. Revoking only in Health app settings prevents new reads; to delete the already synced copy, also use the option in Entrela or request account deletion.

4. Purpose of Data Use

Data is used to enable longitudinal follow-up, generate descriptive visualizations and reports for the linked healthcare professional, and ensure the security and functionality of the platform.

5. Use of Artificial Intelligence

Explicit prohibition

Personal and sensitive health data are NOT used to train, retrain, or improve general-purpose artificial intelligence models.

In this version, clinical AI features are disabled. Personal data, self-reports, and health data are not sent to train proprietary or third-party models.

6. Data Sharing

Functional sharing occurs with the healthcare professional linked by the user and with essential technology operators, limited to what is necessary to provide, protect, and maintain the service.

We use Google/Firebase for authentication, database, cloud functions, abuse protection, usage metrics, and failure observability; Apple for Sign in with Apple and, when authorized, HealthKit; and EmailJS to forward messages submitted through support. Google and Apple receive the metadata needed for authentication, but clinical data is not sent as part of login. Firebase processes data stored in Entrela’s backend.

This version does not offer a paid subscription or start checkout inside the application. Historical billing records, if any, may remain under Stripe processing only for support, fraud prevention, and legal obligations, without clinical self-reports.

We require operators to apply security measures, confidentiality, limited retention, and protection compatible with this Policy and applicable law.

7. Information Security

We adopt advanced technical and organizational measures, including encryption in transit and at rest, strict access control, and continuous audit monitoring to protect the integrity of your data.

8. Retention, revocation, and data-subject rights

Personal data is kept only for the period needed for the described purposes, account maintenance, and legal obligations. Synced health data depends on active consent; deletion requests remove the account and linked data from Entrela’s operational systems, except minimal records that must be retained for legal obligation, fraud prevention, or defense of rights.

Support messages and historical billing records, when they exist, follow timelines limited by support needs and legal obligations. Anonymized data, without a reasonable possibility of association with the data subject, may be retained for security and aggregated metrics.

Under the LGPD, the user may confirm processing, request access, correction, portability, withdrawal of consent, or deletion of their data.

To delete the account and all linked data, visit ladoalado.app/account-deletion. Other requests may be made through the app’s support channels at ladoalado.app/support.

9. Policy Updates

This Privacy Policy may be updated periodically to reflect legal changes or technical improvements. The user will be notified of significant changes.