Privacy Policy
In effect from January 2026. Last updated on 26 September 2026.
1. Who we are
eziduo is a finance app for couples. This policy explains how we collect, use and protect the personal and financial data of people who use the app. eziduo is not intended for anyone under 18 and we do not knowingly collect data from children or teenagers.
2. Data we collect
We collect registration data (name, email and, optionally, a profile photo), financial data you enter (spending, income, cards, goals and trips) and files imported in CSV, OFX or PDF. We also collect usage data to improve the service, such as screens accessed and operational events. Data is stored in Supabase (database, authentication and storage, with isolation per household), and the application is hosted on Railway; both handle data only under our instructions. For sending transactional emails (account confirmation, invitations and notices), we use Resend, from Resend Inc., based in the United States, which handles data only under our instructions. Your household's financial data may be sent to Anthropic, our AI subprocessor, in three situations: to read PDF statements, to suggest a category, merchant, instalment and subscription for entries imported in any format, and to answer questions and, once you confirm, create entries through the AI Assistant. On the eziduo.com marketing site we use Google Analytics, from Google, which only runs with the visitor's consent given in the cookie banner and, when active, stores cookies in your browser to measure visits and navigation. This site usage data is not linked to your financial records. At sign-up, we store, a single time, where the person who registered came from: campaign parameters from the URL, the site that referred them, and the entry page. This is not ongoing tracking, it does not repeat on every visit, and it does not store an IP address; it only helps us understand where the people who sign up come from, including when the referral comes from an AI assistant. The eziduo app records, in its own database, the pages visited and the actions taken, without using cookies, to provide support and improve the service. This record is kept for up to 12 months and is deleted once the account deletion is completed.
3. How we handle your data
Imported files are sent to our server for processing. Reading the file itself is direct: CSV and OFX statements are parsed on our server without AI, and only when a new spreadsheet layout appears do the header row and a small sample of lines go through AI, a single time, to identify the columns. PDF reading uses AI to extract transactions from the statement. After that, in every format, each transaction's data goes through AI to suggest a category, merchant name, instalment and recurring subscription; you review and approve everything before any entry is added to your account. The AI Assistant reads your household's financial data to answer questions and, once you confirm, creates new entries; it does not edit or delete anything. This AI processing is carried out by Anthropic, our subprocessor. We process this data under different legal bases of the LGPD: performance of a contract (registration, authentication and the link between the household's two accounts), consent (AI processing of imported statements and use of the AI Assistant), legitimate interest (security, fraud prevention and service quality) and legal obligation (when required for tax or regulatory purposes related to subscription billing). eziduo does not use Open Finance and does not request access to your bank account.
4. Collective, anonymous categorisation
eziduo is building an automatic categorisation feature that learns from the habits of many couples at once; this feature is not live yet. Once it is active, here is how it will work: we learn that a merchant tends to belong to a certain category (for example, that a merchant tends to be categorised as 'Pets') from confirmations by several different couples, and we use that learning to suggest a category for a similar entry for other couples. This database never stores who spent, how much, or when: it only stores the merchant's name, already normalised, the category associated with it, and how many distinct couples confirmed that category. No identifier for a person, a couple, or a household ever enters this database, and it stays separate from your financial entries, which remain isolated by household, as described in the 'Storage and security' section. A pattern only becomes a suggestion once it has been confirmed by a minimum number of distinct couples, which prevents this database from revealing anything about a specific couple, and there is a dedicated filter to keep a natural person's name, such as one from a bank transfer, out of this database as if it were a merchant name. While this feature is not active, none of your real data is part of this collective database; this section will be updated once it goes live.
5. How we track AI Assistant quality
To understand whether the AI Assistant is working well, we record signals about how each conversation went, never what was said in it: how many turns the conversation had, whether an error occurred and which tool failed, whether the person cancelled partway through, how long the reply took, and whether the person confirmed or declined an action the assistant proposed, such as creating an entry. None of this telemetry stores the text of a question or an answer; it is not a way of reading your conversation, only of measuring how the mechanism is doing.
6. When you mark a reply from the assistant as unhelpful
If you mark a reply from the AI Assistant with a thumbs down, we store only that specific question and that specific reply, for our team to review and improve the assistant; nothing else from the conversation is stored along with it. Before confirming, you see a warning explaining what will be stored, and you can undo it at any time, which deletes the record.
7. Review of AI Assistant conversations by our team
In the app's settings there is an option, on by default, that lets our team read that household's AI Assistant conversations, to help us improve its replies. Whoever created the couple's space can turn it off at any time: turning it off revokes the team's access immediately, including for past conversations, which can no longer be read from that moment on. Turning it off does not delete any conversation, it only closes off reading access, so turning it back on also restores access to the previous history. Until 2 September 2026 this option was off by default. From that date it became on by default, and spaces that were off only because of the previous default were switched on; those that had been turned off by explicit choice remained off.
8. Storage and security
Data is stored securely, with access restricted to the couple's account. We adopt technical and organisational measures to protect the data against unauthorised access, loss or improper alteration, including isolation of your financial entries by household via Row Level Security in the database. This isolation has known, always limited exceptions, all already described in this policy: the collective, anonymous categorisation (section 4), which never uses any entry data at all; the record of a reply marked as unhelpful (section 6), which stores only that question and that reply; and review of AI Assistant conversations by our team (section 7), which applies for as long as whoever created the space does not turn that option off. The AI Assistant quality telemetry (section 5) is not an exception to this isolation, because it never stores conversation text. We also use encryption in transit (HTTPS/TLS) across all communication with our servers, secure authentication with no plaintext password storage, and sensitive keys and credentials kept only on the backend, never exposed in the app. We keep data for as long as the account is active and for as long as needed to fulfil the purposes of this policy, including legal and tax obligations; when you request account deletion, personal data is removed or anonymised, unless retention is required by law. As a PWA, eziduo also uses local browser storage (such as localStorage and service worker cache) to keep you signed in, save preferences and allow fast use of the app, including partially offline; within the app, we do not use third-party advertising tracking cookies.
9. Payment
Payment processing for the Plus subscription is handled by Stripe. eziduo does not store full credit card details, which remain Stripe's responsibility.
10. Your rights (LGPD)
Under the LGPD, you may request access, correction, export or deletion of the personal data processed by eziduo, the anonymisation or blocking of unnecessary data, and information about who your data is shared with, as well as withdraw consent where applicable. To exercise these rights, requests can be sent to the data protection officer at privacidade@eziduo.com.
11. Changes to this policy
This policy may be updated periodically to reflect changes to the service or to the law. Material changes are communicated within the app or by email.
12. Contact
Questions about this policy or about data processing can be sent to contato@eziduo.com. Under article 41 of the LGPD, the data protection officer (DPO) is Mauro Fernandes Neto, eziduo's controller, and can be reached by email at privacidade@eziduo.com.
This English version is provided for convenience only. The Portuguese version of this Privacy Policy is the sole legally binding version. In the event of any conflict or inconsistency between the versions, the Portuguese version shall prevail.