Privacy Policy

What data Bora (bora.care) receives, why, who we share it with, how long we keep it and how to delete it. This policy follows the Brazilian General Data Protection Law (LGPD, Lei 13.709/2018) and takes the EU General Data Protection Regulation (GDPR) into account.

Updated 4 October 2026Русская версия

1. Who is responsible for the data

Data controller (controlador under the LGPD): Viktoriya Andreevna Belykh (Белых Виктория Андреевна), a professional income tax payer (self-employed) in Russia, INN 550311898223.

Questions about data, requests for a copy or deletion, and contact with the data protection officer (encarregado under the LGPD): igor.n.tomko@gmail.com.

2. What data we receive

  • Account. When you sign in with Google: your e-mail, name and profile photo link. With Telegram: the account identifier, name and photo that Telegram passes on. With a link from an e-mail: only your e-mail.
  • Technical sign-in data. IP address, browser and sign-in time. The Supabase authentication service stores them to protect your account.
  • Profile. A photo, if you upload your own, and a name, if you give one.
  • Form data. For the CPF step you can fill in names of the mother and father, an address, a phone number and an e-mail for yourself and your family members. We show them to you so you can copy them into the Receita Federal form, and we send them nowhere.
  • Family and steps. Names of family members and how they are related to you, your steps, marks and dates.
  • Documents. Files you upload (up to 25 MB each): passports, certificates, records. They may contain passport details, information about children and other sensitive data (dados sensíveis under the LGPD).
  • Access. Plan, status and period of access, buyer and subscription identifiers at the payment provider. We do not receive card data: lava.top processes it.
  • Analytics. A random browser identifier, linked to your account after you sign in; which sections and guides are opened and which buttons are pressed; where you came from (the site domain, utm tags or a link code). If a search in the reference finds nothing, we save the query (up to six words, without digits) so we can write the missing guide. Your e-mail, names, IP address and the contents of documents do not go into analytics.
  • Search. The text of your query goes to our server at Cloudflare, where a Workers AI model picks suitable guides. The answer to an identical query is kept in the Cloudflare cache, not linked to you.
  • Subscription to changes. If you subscribed to changes in a guide: your e-mail (or your account, if you are signed in), which guide and when you confirmed the subscription.
  • Correspondence. If you write to us, we keep the messages so we can reply and return to the question.

3. Why and on what basis

  • Sign-in, steps, documents and access: so that the service works as promised (performance of a contract, LGPD art. 7, V; GDPR art. 6(1)(b)).
  • Sensitive data in documents: we keep it because you uploaded the file yourself for your own case, and we show it only to you; to sort it into folders, the file is read by the models listed below (consent, LGPD art. 11, I; GDPR art. 9(2)(a)). To withdraw consent, delete the file.
  • E-mails about guide changes: only if you subscribed yourself and confirmed the address (consent, LGPD art. 7, I; GDPR art. 6(1)(a)). You can unsubscribe at any time with the link in every e-mail.
  • Analytics and abuse protection: to understand which sections are useful and where people come from (legitimate interest, LGPD art. 7, IX; GDPR art. 6(1)(f)). You can object by e-mail.
  • Payments, receipts and taxes: because the law requires it (LGPD art. 7, II; GDPR art. 6(1)(c)).
  • Replies to your messages: to help with the question you asked.

We do not sell data, we do not show advertising and we do not make automated decisions that affect you.

4. Who else processes the data

Data goes only to the services without which Bora does not work, and only in the amount they need:

  • Supabase: the database, sign-in and file storage. Storage region: Brazil (São Paulo).
  • Cloudflare: site hosting, search (Workers AI), cache and request logs (IP address, page, browser) to run and protect the site.
  • Google and Telegram: if you sign in through them. They learn that you signed in to Bora and process this under their own rules.
  • Resend: the e-mail with the sign-in link and the e-mails about guide changes.
  • Document recognition and bot replies: Xiaomi (MiMo), DeepSeek, Anthropic (Claude) and Typesafe (Jev). They receive the uploaded file or its text to determine the document type, whose it is and which fields it has, and also your question to the bot and fragments of the guide to answer it. Files stay in Supabase.
  • Vercel: a private analytics panel for the owners of Bora. It reads events without e-mail and names.
  • lava.top: payment processing and refunds.

5. Transfers abroad

The servers of these services may be outside Brazil and your country, for example in the USA, the EU and China. We use services that undertake to protect data in a data processing agreement (standard contractual clauses), as the LGPD (art. 33) and the GDPR require.

6. How long we keep it

  • Account, profile and steps: while your access is active and for one year after it ends. An account without payment: two years after the last sign-in, or until you ask us to delete it.
  • Documents: one year after access ends, so you can renew access or download them; then we delete them. Earlier: delete them yourself in "My documents" or write to us.
  • Subscription to changes: until you unsubscribe. An address that was not confirmed is deleted after 7 days.
  • Analytics: 400 days, to compare year over year.
  • Payment data: as long as tax law requires.
  • Cloudflare and Supabase logs: according to the retention periods of those services.

7. Your rights

Under the LGPD (art. 18) and the GDPR you can:

  • find out whether we process your data and get a copy of it;
  • correct inaccurate or outdated data;
  • delete, anonymize or restrict unnecessary data;
  • get your data in a machine-readable format;
  • find out who we share it with;
  • withdraw consent and object to analytics.

Write to igor.n.tomko@gmail.com from your account address, and we will reply within 15 days. You can delete documents and your profile photo yourself at any time.

If you are not satisfied with the reply, you can contact the ANPD (Brazil) or the data protection authority of your country.

8. Children's data

An adult creates the account. A parent or legal representative adds the child's data (name, documents, CPF form data) for the family's case. We process it only in the best interests of the child (LGPD art. 14). The service is not intended for children who use it on their own.

9. How we protect the data

The connection to the site is encrypted (HTTPS). Documents are kept in private storage: the database gives every record and every file only to your account. Only the owners of Bora have access to the service panels.

If a breach occurs that may harm you, we will notify you and the ANPD.

10. Browser storage and cookies

Bora sets no advertising or third-party cookies. In the browser storage (localStorage) the site saves:

  • the sign-in session, so you do not have to sign in every time;
  • the color theme;
  • a random analytics identifier, the source of the first visit and a visit counter;
  • before sign-in: your steps, people, CPF form data, answers to the "Path to the passport" questionnaire and trips in the days calculator;
  • the last five search queries.

This data stays on your device until you clear the site data in your browser. From it we receive only the analytics identifier and the source of the first visit.

11. Changes to this policy

The update date is at the top of the page. We will announce material changes on the site and by e-mail to those who have an account.