Privacy Policy
Version: 2.0
Effective date: in force since 10/08/2026 (October 8, 2026) for new users; for those who already used the Platform before that date, from 10/22/2026 (October 22, 2026).
This is a translation for convenience. The Portuguese version prevails.
Introduction
This Privacy Policy describes how Café em Dia collects, uses, shares, stores and protects the personal data of those who use the Café em Dia platform and the Jorge assistant ("Platform"), in compliance with the LGPD — Brazilian General Data Protection Law, Law No. 13,709/2018.
It applies to all channels of the Platform: the dashboard on the website, the Jorge assistant through WhatsApp and the website chat, and the Café em Dia app in ChatGPT.
By using the Platform, the User declares that they have read and understood this Policy.
Data Controller
The controller of the personal data processed by this Platform is:
CAFE EM DIA TECNOLOGIA LTDA ("Café em Dia")
CNPJ: 64.856.383/0001-87
Data Protection Officer (DPO): Edvânio Cristóvão da Cunha
DPO / Privacy e-mail: contato@cafeemdia.com
Address: R. Braulio Brasileiro, 38, Letra A Sala C — Jardim do Trevo — Alpinópolis/MG — CEP 37.940-000
Data Collected
3.1 Data provided directly by the User
- Full name
- E-mail address
- Phone number (required at sign-up; used for WhatsApp access and for commercial contact)
- CPF or CNPJ, when provided at sign-up or required for billing the subscription
- Coffee area of the farm, when provided at sign-up
- Farm data: name, location, area, crops and plots, workers, harvests, payments, inventory, field operations and cash records
- Content of conversations with the Jorge assistant, including audio, photos and documents sent (for example, invoices)
Data about workers and third parties (name, daily wages, amounts paid) is provided by the User, who is responsible for holding it lawfully, and is processed only for the management of their own farm.
3.2 Data collected automatically
- IP address and information about the access device
- Access logs (date, time, session)
- Usage and interaction data on the Platform (pages visited, features used)
- Cookies, as described in section 11
3.3 Data received by the Café em Dia app in ChatGPT
When the User connects the Café em Dia app to ChatGPT (a service of OpenAI), we receive only:
- the data that ChatGPT sends to the app's tools in each request (for example: worker, plot, quantity, amount, date);
- a short sentence, written by ChatGPT, that summarizes the request, used only for logging and diagnostics;
- anonymous technical identifiers sent by ChatGPT (of the user and of the conversation in ChatGPT) and the Café em Dia account identifier, coming from the login.
We neither receive nor ask for the text of the conversation in ChatGPT, previous messages or the profile data of the User's OpenAI account. What the User writes in ChatGPT is processed by OpenAI according to its own privacy policy.
The app login is done on the Café em Dia screen, through the WorkOS authentication service, which receives the account identifier and e-mail to issue ChatGPT access.
3.4 Data we do NOT collect
- Credit card data or payment instruments (processed exclusively by the payment provider, Asaas)
- Bank passwords, bank data or financial account data
- Health data or other sensitive personal data
- Identity documents (unless voluntarily sent by the User in the chat)
Purposes of Processing
The data collected is used for:
| Purpose | Legal Basis (LGPD) |
|---|---|
| Providing the contracted services | Performance of a contract (Art. 7, V) |
| Authentication and access control | Performance of a contract (Art. 7, V) |
| Operation of the AI assistant (Jorge) | Performance of a contract (Art. 7, V) |
| Operation of the Café em Dia app in ChatGPT (records and queries requested by the User) | Performance of a contract (Art. 7, V) |
| Payment processing | Performance of a contract (Art. 7, V) |
| Communications about the service (updates, alerts, account notices) | Performance of a contract (Art. 7, V) |
| Commercial contact with those who sign up (presenting the Platform and the subscription) | Legitimate interest (Art. 7, IX) |
| Security, fraud prevention and error diagnostics | Legitimate interest (Art. 7, IX) |
| Improvement of the Platform and the assistant | Legitimate interest (Art. 7, IX) |
| Measurement of visits and ads on the corporate website | Consent (Art. 7, I) |
| Compliance with legal obligations | Legal obligation (Art. 7, II) |
| Marketing communications (optional) | Consent (Art. 7, I) |
The User may withdraw consent to marketing communications at any time without affecting access to the Platform.
We do not use the User's data to build behavioral profiles, sell advertising or train our own artificial intelligence models.
Artificial Intelligence Processing
The User must be aware that:
Data Sharing
The User's data may be shared with the following suppliers, exclusively for the purposes described in this Policy:
| Supplier | Purpose | Country of Processing |
|---|---|---|
| Supabase | Data storage and authentication | USA |
| Render | Application server hosting | USA |
| Vercel | Website and dashboard hosting | USA |
| OpenAI | Processing of assistant messages, audio transcription and document reading; ChatGPT platform, from which the app's requests come | USA |
| DeepSeek | Processing of AI assistant messages | China |
| TypeSafe AI, Inc. | Automatic verification of the assistant's responses | USA |
| WorkOS | Login for the Café em Dia app in ChatGPT | USA |
| Meta (WhatsApp) | Sending and receiving messages through WhatsApp | USA |
| Meta (Pixel) | Measurement of visits and ads on the corporate website, only after "Accept" on the cookie banner | USA |
| Microsoft (Clarity) | Measurement of corporate website usage, only after "Accept" on the cookie banner | USA |
| Asaas | Processing of subscription payments | Brazil |
| Resend | Sending e-mails (invitations, account notices) | USA |
| Slack | Internal notices to the team (name, e-mail, phone and farm name of those who sign up) | USA |
Café em Dia does not sell, rent or trade Users' personal data.
Data may also be provided to public authorities when there is a legal obligation or court order.
Aggregated and anonymized data (individual re-identification being impossible) may be used for internal analysis and improvement of the Platform, without sharing with third parties.
International Data Transfer
Some suppliers listed in section 6 process data outside Brazil (USA and China). These transfers are carried out on the basis of:
- Contractual clauses and data protection terms of the suppliers
- Suppliers' compliance with international privacy regulations (GDPR, CCPA)
- The User's consent to sending messages to the artificial intelligence providers (section 5.1)
In the case of DeepSeek (China), there is no data protection agreement beyond the supplier's own API terms of use. For this reason, this transfer relies on the User's specific consent (LGPD, Art. 33, VIII), given when using the Jorge assistant (section 5.1). The User may withdraw this consent by ceasing to use the assistant and requesting deletion of the history (section 10).
Data Retention
| Type of data | Retention period |
|---|---|
| Registration data | While the account is active + 5 years after closure |
| Farm data (crops, harvests, etc.) | While the account is active. Deleted immediately after the account is closed. |
| History of conversations with Jorge | While the account is active (deletable on request) |
| Records of the app's calls in ChatGPT (tool, request data, summary, result, date) | While the account is active. Deleted with the account. |
| Account created through ChatGPT that did not subscribe | After the free-use period ends, the account remains available for viewing only. 12 months after the end of that period, the account, the farm and its data are deleted, with e-mail notice at least 30 days beforehand. Subscribing before then keeps everything. |
| Commercial contact (name, phone, e-mail, farm name) | While there is a commercial relationship or until the User requests deletion. When the account is deleted, a contact that never reached a negotiation is erased; if there was already a proposal or a subscription, the record is anonymized: name, phone, e-mail, city, farm name and notes are removed, leaving only the commercial history, without identification. |
| Access logs | 6 months (under the Marco Civil da Internet, Brazil's Internet Civil Framework) |
| Payment data (references) | 5 years (tax obligation) |
After the periods above, data is deleted or irreversibly anonymized.
Data Security
Café em Dia adopts the following measures to protect Users' data:
- Authentication by e-mail and password or by a one-time code (OTP) sent by e-mail
- Access tokens with configured expiration; ChatGPT access uses a short-lived token, issued only after login on the Café em Dia screen
- Data isolation per farm (Row-Level Security in the database)
- Storage on cloud infrastructure with encryption at rest and in transit (HTTPS/TLS)
- Access control based on permissions per user and per entity: someone who can only view a farm cannot write data to it, on any channel
No system is 100% secure. In the event of a security incident affecting personal data, the User will be notified as required by the LGPD.
User Rights and Controls (LGPD)
The User has the following rights and controls regarding their personal data:
| Right | How to exercise |
|---|---|
| Confirmation of processing | Request by e-mail |
| Access to data | Request by e-mail |
| Correction of incomplete or incorrect data | Directly on the Platform or by e-mail |
| Anonymization, blocking or deletion | Request by e-mail |
| Deletion of the account and farm data | In the dashboard, under Settings → Delete my account, or by e-mail |
| Data portability | Request by e-mail (CSV or JSON format) |
| Disconnecting the app from ChatGPT | In the ChatGPT app settings; from then on ChatGPT stops sending requests to Café em Dia |
| Withdrawal of consent | Directly on the Platform or by e-mail |
| Information about sharing | This Policy (section 6) |
| Objection to processing | Request by e-mail with justification |
Requests will be answered within 15 (fifteen) business days.
Contact for exercising rights:
E-mail: contato@cafeemdia.com
Cookies
The Platform's dashboard uses only cookies strictly necessary for operation (authentication session).
The corporate website (cafeemdia.com) shows a cookie banner on the first visit. The Meta Pixel, loaded through Google Tag Manager, and website usage measurement (Microsoft Clarity) are only loaded after the User clicks "Accept". These cookies serve to measure visits and contacts coming from ads and are not used in the dashboard or in the app in ChatGPT.
When "Not now" is clicked, the website keeps only what is necessary for operation. The choice is stored in the browser and can be changed at any time by clearing the site data in the browser settings.
The User may configure their browser to block cookies; blocking session cookies may prevent the dashboard from working correctly.
Age
The Platform's content concerns agricultural management and is suitable for any audience. The Platform is not directed to children under 13 and does not intentionally collect their data; if we identify a child's data, we will delete it immediately.
Subscribing and holding the account of a farm require legal capacity (18 years of age or emancipation).
Changes to this Policy
This Policy may be updated periodically. The version and effective date appear at the top of this document. Relevant changes will be communicated to the User by e-mail at least 15 (fifteen) days in advance. Continued use of the Platform after the new conditions take effect implies acceptance.
Contact and Data Protection Officer (DPO)
For questions, requests or complaints related to privacy:
Data Protection Officer (DPO): Edvânio Cristóvão da Cunha
E-mail: contato@cafeemdia.com
Support: https://www.cafeemdia.com/suporte
Website: https://www.cafeemdia.com/
The User may also file a complaint with the National Data Protection Authority (ANPD) through its website gov.br/anpd.