
Privacy Policy
Last updated:
This is a translation for convenience. The Portuguese (Brazil) version prevails.
This Policy explains which personal data Tobbo Finanças ("Tobbo", "we") processes when you use the app, the server behind it and the tobbofin.com website; for what purpose and on which legal basis; who we share it with; how long we keep it; and how you exercise your rights under Brazil’s General Personal Data Protection Law (Law No. 13,709/2018, "LGPD").
In short: we use your data to make the app work for you. We do not sell data, we show no ads and we do not use your financial information for advertising. You can download a copy of your data or delete your account in the app at any time.
1. Data controller
| Item | Information |
|---|---|
| Controller | Caotec Serviços em Tecnologia Ltda, developer of and responsible for Tobbo Finanças |
| CNPJ (Brazilian company ID) | 25.171.456/0001-45 |
| Address | Rua Doutor Procópio Toledo Malta, 750, Loteamento Habitacional São Carlos 1, São Carlos/SP, CEP 13563-002 |
| Privacy and Data Protection Officer (DPO) | privacidade@tobbofin.com |
| General contact | contato@tobbofin.com |
This Policy covers the Tobbo Finanças app (Android and, once launched, iPhone), the server behind it and the tobbofin.com website.
2. Data we process
| Category | Data | Source |
|---|---|---|
| Account | Name, email, profile photo (when you sign in with Google), Google or Apple account identifier (the email may be an Apple relay address), notification preferences | You, Google Sign-In or Sign in with Apple |
| Sign-in and sessions | Email sign-in code and link (we keep only a hashed version, which expires in 15 minutes) and active sessions with the device name | Generated when you sign in |
| Optional identification | Brazilian CPF and CNPJ you add in Settings to separate personal (PF) and business (PJ) finances | You |
| Open Finance data | Institutions, accounts, balances, cards and limits, bills, investments and transactions (date, amount, description, merchant and counterparty) | Your financial institutions, with your consent, via the Malvo aggregator |
| Bank notifications (optional, Android only) | Title and text of notifications from the bank apps you choose from a closed list. Notifications from any other app are discarded on the device without reading their content | Your device, only if you enable it |
| Content you create | Manual entries, categories, rules, budgets, goals and savings, pasted bank slips and imported CSV/XLSX spreadsheets | You |
| Conversations with Tobbo | Questions to the chat and to "Can I spend?", generated answers and history | You |
| Group and couple | Invitations, group members and what each person chose to share, account by account | You and group members |
| Integrations you create | Personal access tokens for external AI agents (MCP): name, permission (read or write) and last-used date; the token itself is stored only as a hash. The home-screen widget uses its own read-only token, stored on the device | You |
| Device and push notifications | Notification token (Firebase or Expo) and device platform | Your device, if you allow notifications |
| Technical and security records | Server logs (request method, route, status and duration, with no IP address, headers, parameters or content), AI model usage per group (amount of processing and errors) and a trail of actions taken in the group | Generated automatically |
| Contact | Emails and messages you send us | You |
What we do not collect: bank passwords, full card numbers, location, contacts, photos, audio, notifications from apps outside the bank list, credit scores or advertising identifiers. The app uses no advertising, analytics or crash-reporting SDKs.
Sensitive data: we do not process sensitive personal data (LGPD art. 5, II, and art. 11). Fingerprint, face or PIN unlock is handled by your device’s operating system; Tobbo only receives the result (unlocked or not) and never accesses or stores biometric data. Financial data is not "sensitive" under the LGPD, but it is protected by secrecy rules and we treat it with the same care.
Transaction descriptions and notification texts may contain other people’s names (for example, who sent or received a Pix transfer). We process this data only to organize your finances.
3. Purposes and legal bases
Each use has a specific purpose and a legal basis under LGPD art. 7:
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and maintain your account, authenticate access (email link or code, Google or Apple) and provide support | Account, sign-in and sessions, contact | Performance of contract (art. 7, V) |
| Show your financial picture: dashboard, categorization, transfer reconciliation, budgets, goals, subscriptions, upcoming payments, alerts, chat and "Can I spend?" | Financial data, content you create, conversations | Performance of contract (art. 7, V) |
| Import data from your institutions via Open Finance | Open Finance data | Consent (art. 7, I), given by you at your institution under Open Finance Brasil rules and revocable at any time |
| Read bank app notifications on Android to record purchases and Pix right away | Bank notifications | Consent (art. 7, I): an optional feature you turn on, revocable at any time by switching off the permission |
| Show group members what you decided to share | Accounts and entries you mark as shared | Performance of contract (art. 7, V), according to your choices |
| Send service notices (bill due, budget, security, data deletion and export) | Email, push token, alert data | Performance of contract (art. 7, V); you adjust alerts in the app or on the device |
| Serve integrations you create (MCP agents and widget) | Tokens and the data the agent or widget queries | Performance of contract (art. 7, V), at your request |
| Security: authentication, rate limiting against abuse, fraud prevention and a trail of group actions | Sign-in and sessions, technical records | Legitimate interest (art. 7, IX) |
| Fix bugs, control AI cost and quality and understand app usage in aggregate | Technical records and AI usage, without conversation content | Legitimate interest (art. 7, IX) |
| Send marketing communications (we currently send none) | Consent (art. 7, I), only if you opt in, with unsubscribe at any time | |
| Comply with legal obligations and exercise rights in proceedings | The minimum needed in each case | Legal obligation (art. 7, II) and regular exercise of rights (art. 7, VI) |
Consent: when we ask for your consent, it is free, informed, specific to each purpose and can be withdrawn at any time, free of charge and as easily as it was given. Withdrawal does not affect what was done before it. If you do not consent to Open Finance or notification reading, you can still use Tobbo with manual entries and spreadsheet imports.
Legitimate interest: before relying on this basis, we run a balancing test (legitimate purpose, necessity of the data and balance against your rights and expectations), use the minimum data and never use it for advertising. You can object through the DPO channel.
4. Artificial intelligence
Tobbo uses third-party AI models, acting as processors on our behalf, to: categorize entries; decide whether a bank notification represents money that actually moved; check whether a chat question is within the app’s topic; answer in the chat (including charts); and compute the "Can I spend?" answer.
| Provider | Use |
|---|---|
| Google (Gemini API) | Main provider: categorization, notifications, chat, "Can I spend?" and analyses |
| Anthropic (Claude API) | Alternative provider, used when configured instead of Gemini |
| TypeSafe (Jev model) | Classifiers: whether a notification is a transaction, category suggestion and question topic check |
What we send: only what each task needs, such as the transaction’s description, merchant, counterparty, amount, date and account type; totals and categories; the captured notification text; your question and the conversation history; and your first name and those of group members, to personalize the answer. We do not send passwords, bank credentials, access tokens or your email.
Use by providers: each provider processes data under its own terms, which may vary with the plan used (for Gemini, Google’s terms treat free and paid usage differently, including the use of content to improve Google’s services). That is why we do not claim that the data will never be used to improve third-party models, and we keep what we send to a minimum.
Automated decisions: the AI classifies entries and notifications and generates answers and suggestions. The criteria are the text, merchant, amount, account type and your previous rules and choices; "Can I spend?" considers balances, upcoming bills, budgets and goals. None of these decisions denies you service, credit or rights, and you can correct any category or delete an entry created from a notification (Tobbo learns from it). You can ask for a human review of decisions made solely by automated processing and for information on the criteria used (LGPD art. 20) through the DPO channel.
AI answers are educational, may contain errors and are not investment advice or financial, accounting, legal or tax advice.
5. Who we share data with
We share data only with processors that help us provide the service, each limited to its role and bound to protect the data. As controller, we remain responsible for what they do with the data on our behalf:
| Processor | Purpose | Data | Country |
|---|---|---|---|
| Malvo | Open Finance aggregation: connecting to institutions and collecting what you authorize | Connection identifier and authorized financial data | Brazil |
| Railway | Hosting of the server, database and queues | All service data | United States (East region, Virginia) |
| Google (Gemini API) | AI (see section 4) | Transaction data, notifications, questions and first name | United States and other countries in Google’s infrastructure |
| Anthropic | Alternative AI (see section 4) | Same as the row above, when used | United States |
| TypeSafe | AI classifiers (see section 4) | Transaction data, notification text and questions | United States |
| Resend | Service emails (sign-in, export, deletion) | Name, email and message content | United States |
| Expo and Google Firebase Cloud Messaging | Push notification delivery on Android | Device token and notice content | United States |
| Apple (APNs and Sign in with Apple) | iPhone notifications and Apple sign-in, when applicable | Device token, Apple identifier | United States |
| Google (Sign-In) | Sign-in with a Google account | Name, email, photo and Google identifier | United States |
| Railway and Cloudflare | Hosting of the tobbofin.com website (Railway) and DNS (Cloudflare) | Technical website access data (such as IP and browser) | United States and global network |
| Google (Analytics 4 and Tag Manager) | Website audience measurement, only if you accept analytics cookies | Pages viewed, clicks and scrolling on the website, browser and device data and approximate location (city); no app or financial data | United States |
We also share: with members of your group, only what you choose, account by account; with external AI agents you connect through an MCP token, the data they query with the permission you granted (the agent’s use of that data follows the terms of the service you chose, and you can revoke the token in the app at any time); with authorities, when required by law or court order; and with a possible successor in a reorganization of the service, keeping the safeguards of this Policy.
The app is distributed through Google Play, which processes installation and rating data under Google’s privacy policy; we only receive aggregate statistics from it.
We do not sell, rent or give your data to advertisers, credit bureaus or data brokers. You can ask for the current list of who we share your data with (art. 18, VII) through the DPO channel.
6. International transfers
Some processors (hosting, AI, email, notifications, sign-in and the website) store or process data outside Brazil, mainly in the United States, as shown in the "Country" column of section 5.
These transfers rely on LGPD art. 33, IX, as they are necessary to perform the service you requested (art. 7, V), and on the data protection obligations the providers undertake in their terms. Notification reading and Open Finance also depend on your consent. You can ask for more information about the safeguards for each transfer through the DPO channel.
Website audience measurement with Google Analytics (United States) only happens with your specific and prominent consent, given in the cookie notice, which also grounds that transfer (LGPD art. 33, VIII).
7. How long we keep data
| Data | Period |
|---|---|
| Account, bank accounts, cards, categories, rules, budgets, goals, bank slips, CPF/CNPJ and integrations | While the account exists or until you delete the item |
| Transactions, net worth history and generated alerts | Up to 730 days. Anything older is deleted automatically every day |
| Conversations with Tobbo | Until you delete the conversation or the account |
| Captured bank notifications | While the account exists. Turning off capture stops new readings |
| Email sign-in link and code | 15 minutes (we keep only the hash) |
| Internal alert-detection events | 90 days after processing |
| AI usage records | 365 days |
| Group action trail | 730 days |
| Server logs | For the hosting provider’s retention period, with no IP or content |
| Data export link | 7 days; the file is generated at download time and is not stored |
Account deletion: access is cut off immediately and all your data is permanently deleted within 30 days (usually within minutes). Only an anonymous record that a deletion took place remains (dates and counts), with no name, email or financial data.
Exceptions (LGPD art. 16): we may keep the minimum needed to comply with a legal or regulatory obligation, to exercise rights in judicial, administrative or arbitration proceedings, or in anonymized form, for the period required. If that happens, we will tell you.
You can disconnect a bank at any time; the connection is revoked at the aggregator. See how to delete your account.
8. Your rights
Under LGPD art. 18, you may, free of charge and at any time:
- confirm whether we process your data and access it;
- correct incomplete, inaccurate or outdated data (mostly right in the app);
- request anonymization, blocking or deletion of unnecessary or excessive data or data processed unlawfully;
- request portability of your data in a structured format;
- request deletion of data processed on the basis of consent;
- know which public and private entities we share your data with;
- be informed about the possibility of not consenting and its consequences;
- withdraw consent (Open Finance, notification reading, marketing);
- request review of automated decisions (art. 20) and object to processing based on legitimate interest;
- petition Brazil’s National Data Protection Authority (ANPD) against us, at gov.br/anpd.
In the app: Settings → Privacy and data → Download my data (we email you a link, valid for 7 days, to a ZIP file with your data in JSON and transactions as a CSV spreadsheet) or Delete my account. Also in the app you can edit your profile, disconnect banks, turn off notification capture, delete conversations and revoke agent (MCP) tokens.
By email, no sign-in needed: write to privacidade@tobbofin.com. We acknowledge receipt immediately (simplified response) and send the full response within 15 days (art. 19, II). To protect you, we may ask you to confirm your identity, preferably from your registered email. If we cannot fulfil a request, we will explain why.
9. Children and adolescents
Tobbo is not intended for anyone under 13, and children (12 or younger) may not create an account or use the app on their own. We do not knowingly collect data from anyone under 13 outside Tobbo Kids; if we learn of such an account, it will be deleted.
Adolescents aged 13 to 17 should only use Tobbo with the knowledge and supervision of their parents or legal guardians, who may exercise the rights in this Policy on their behalf. We always process this data in the adolescent’s best interest (LGPD art. 14), only to provide the service, and we do not build marketing profiles of, or send advertising to, minors.
Tobbo Kids (children’s data). Tobbo Kids is an optional mode to teach money to children aged 4 to 12. The child has no account, e-mail or login: a guardian (owner or admin of the group) creates the profile and gives the specific, prominent consent required by LGPD art. 14 §1, which we record with the date, time and who authorized it.
- Minimal data: nickname, birth year (to adapt content to the age) and an avatar picked from a list (no photo), plus progress in the mode: virtual coins, dreams, chores, lessons and connected devices. The child only taps ready-made options and does not type free text. Real bank data is never shown.
- No ads, no external links and no artificial intelligence on the child’s data; nothing is shared with third parties or used for profiling or marketing.
- Access on the child’s device uses a token limited to Tobbo Kids, which the guardian can disconnect at any time; leaving the mode on an adult’s device requires that adult’s biometrics or PIN.
- Deletion: the guardian can delete the child and all their data at any time in the app; the data is also deleted when the group is deleted, or when the guardian who consented leaves the group or deletes their account. The data is included in the guardian’s "Download my data" copy.
10. Security
- Encrypted traffic (HTTPS/TLS) between the app, the server and providers.
- Isolation of each group’s data in the database (Row-Level Security).
- Session tokens, sign-in links and agent (MCP) tokens stored on the server only as hashes.
- On the device, tokens in the system’s secure storage, biometric or PIN lock and automatic app backup disabled.
- Read-only Open Finance access: Tobbo does not move money and never receives your bank password.
- Aggregator notices validated by signature (HMAC) and server logs without financial data.
- Internal access restricted to the minimum necessary.
No system is 100% secure. If a security incident occurs that may cause relevant risk or harm, we will notify the ANPD and the people affected within 3 business days, as required by the Incident Reporting Regulation (CD/ANPD Resolution No. 15/2024), describing what happened, the data involved, the risks and the measures taken.
11. Website, cookies and marketing
The website uses what is essential and, only with your prior consent, Google Analytics 4 to measure visits in aggregate. Without consent (or with your browser's Global Privacy Control signal), no Google script is loaded. Details in the Cookie Policy.
What we do (and never do) with communications and marketing is in Communications and marketing.
A structured summary of this Policy, in the lgpd.md format, is at tobbofin.com/lgpd.md (in Portuguese).
12. Data Protection Officer (DPO) and contact
Our Data Protection Officer (encarregado) is Cendy Andreoli de Oliveira. They receive complaints and communications from data subjects and from the ANPD at privacidade@tobbofin.com.
If you are not satisfied with our answer, you can petition the ANPD at gov.br/anpd.
13. Changes to this Policy
We may update this Policy to reflect changes in the app or the law. The date at the top shows the current version. Material changes will be announced in the app or by email before they take effect and, where the basis is consent, we will ask again.