Privacy Policy

Last Updated: February 4, 2026

1. Introduction

This Privacy Policy explains how Bouki collects, uses, and protects your personal information. We comply with Brazil's General Data Protection Law (LGPD - Lei nº 13.709/2018).

By using Bouki, you agree to this policy.

2. Information We Collect

Personal Information

  • Account Data: Name, email address, password (encrypted)
  • Profile Data: Language preference, timezone settings
  • Contact Data: WhatsApp number (if you use WhatsApp chat) (soon)

Financial Information

  • Transactions: Amount, category, date, description, payment method
  • Categories: Custom categories you create
  • Budgets: Spending limits and financial goals
  • Reports: Generated financial insights and analysis

Usage Information

  • Device Data: IP address, browser type, operating system
  • Platform Activity: Features used, pages viewed, timestamps
  • Chat History: Conversations with our AI assistant

Cookies & Tracking

We use cookies and similar technologies to:

  • Keep you logged in
  • Remember your preferences
  • Improve platform performance
  • Analyze usage patterns

You can disable cookies in your browser, but some features may not work properly.

3. How We Use Your Information

We use your data to:

1. Provide Services

  • Process and categorize transactions
  • Generate spending reports and insights
  • Send spending alerts and notifications
  • Provide AI chat assistance

2. Improve Platform

  • Analyze usage patterns
  • Fix bugs and technical issues
  • Develop new features
  • Train our AI models

3. Communicate

  • Send monthly reports
  • Provide customer support
  • Send important account updates
  • Notify about policy changes

4. Comply with Law

  • Meet legal obligations
  • Prevent fraud and abuse
  • Enforce our terms of use

4. Legal Basis for Processing

Under LGPD, we process your data based on:

  • Contract Performance: To provide services you've signed up for
  • Consent: For optional features like WhatsApp integration
  • Legitimate Interest: To improve our platform and prevent fraud
  • Legal Obligation: To comply with Brazilian financial regulations

5. Data Sharing

We do not sell your personal information.

We share data only with:

Service Providers

  • Stripe: Payment processing (for subscriptions)
  • Convex: Database and backend infrastructure
  • Resend: Email delivery (for reports and notifications)
  • Google Gemini: AI chat functionality

These providers are contractually required to protect your data.

Legal Requirements

We may disclose data if required by:

  • Court orders or legal processes
  • Law enforcement requests
  • Protection of our legal rights
  • Prevention of fraud or illegal activity

6. Data Storage & Security

Security Measures

  • Encrypted passwords (never stored in plain text)
  • Secure HTTPS connections
  • Regular security audits
  • Access controls and authentication

Data Location

Your data is stored on secure cloud servers. We use industry-standard security practices.

Data Retention

  • Active Accounts: We keep your data as long as your account is active
  • After Deletion: We retain some data for legal compliance (up to 5 years per Brazilian law)
  • Backups: Deleted data may persist in backups for up to 90 days

7. Your Rights (LGPD)

You have the right to:

  • Access: Request a copy of your personal data
  • Correction: Update inaccurate information
  • Deletion: Request account and data deletion
  • Portability: Export your data in a standard format
  • Withdrawal: Revoke consent for data processing
  • Information: Know how we use your data
  • Objection: Object to certain data processing activities

To exercise these rights, contact us at contact@bouki.app.

8. AI & Automated Decisions

Our AI chat assistant:

  • Analyzes your transactions to provide insights
  • Generates spending summaries and recommendations
  • Answers financial questions based on your data
Important: AI may make errors. Always verify important information independently. We don't make automated decisions that significantly affect your rights.

9. Children's Privacy

Bouki is not intended for users under 18. We don't knowingly collect data from children. If we discover we've collected a child's data, we'll delete it promptly.

10. International Users

Our services are primarily for Brazilian users. If you access from outside Brazil:

  • Your data may be transferred to Brazil
  • You consent to data processing under Brazilian law
  • LGPD protections still apply

11. Changes to This Policy

We may update this policy occasionally. Changes take effect immediately upon posting. We'll notify you of significant changes via:

  • Email notification
  • Platform announcement
  • Updated "Last Updated" date

Continued use after changes means you accept the new policy.

12. Contact Us

General Inquiries:

  • Email: contact@bouki.app
  • Website: bouki.app

ANPD (National Data Protection Authority):

If you're not satisfied with our response, you can file a complaint with Brazil's ANPD at https://www.gov.br/anpd

By using Bouki, you acknowledge that you've read and understood this Privacy Policy.