Privacy Policy
Plain-language summary (the full text below prevails)
- Who is responsible for your data: F99 E-SPORTS LTDA (Brazil). This is the "Data Fiduciary" under Indian law and the "controller" under EU law. Contact: brazilsensilegends@gmail.com.
- What we collect:
- your account, your phone model and quiz answers, your sensis and how you use classes;
- the purchase details our payment partners send us: name, e-mail, mobile number, amount and status.
- Checkout: the Meta and Utmify pixels measure which ads bring sales, only with your consent. We also report every order to Utmify, paid or not, to see which campaign brought it.
- Messages from us: WhatsApp messages and e-mails about your order and our offers only if you tick the box at checkout. You can stop them at any time.
- We never sell your data. Service providers process it for us, many of them in the United States. Our team is in Brazil.
- Under 18: a parent must agree. We don't track or target ads at children.
- Your rights: access, correction, erasure, withdrawing consent, and naming someone to act for you. We reply within 30 days and never later than the law allows.
- Complaints: first contact our Grievance Officer. In India you can then go to the Data Protection Board.
1. Who we are
1.1. This Privacy Policy explains how F99 E-SPORTS LTDA, a company incorporated in Brazil (CNPJ 47.491.284/0001-20), with its office at Av. General Ataliba Leonel, 1223, Room 43, Santana, São Paulo – SP, 02033-000, Brazil ("BSL", "we", "us"), handles personal data. It covers Brazil Sensi Legends and the BSL Sensi Generator, including:
- generator.brazilsensilegends.com;
- brazilsensilegends.com;
- the India checkout at checkout.brazilsensilegends.com;
- our support and community channels.
1.2. Our role under the law:
- India (Digital Personal Data Protection Act, 2023, the "DPDP Act"): we are the Data Fiduciary for your personal data.
- European Union and United Kingdom (GDPR / UK GDPR): we are the controller.
1.3. Contact:
- Privacy team: brazilsensilegends@gmail.com
- Grievance Officer (India): Felipe, Customer Support Manager, brazilsensilegends@gmail.com, +91 86380 23511
1.4. The same company also runs Hashira Sensix, a Portuguese-language product for Brazil, with a separate user database. Our internal management panel receives payment notifications for both brands and grants access to both apps. It is used only by our authorised team.
2. Scope
2.1. This Policy applies to you if you:
- (a) visit our websites;
- (b) create an Account or use the Generator and our Content;
- (c) buy a Plan through the India checkout (Transact Bridge) or through Hotmart, or start a checkout and do not finish it;
- (d) contact our support or join our Community;
- (e) are the parent or guardian of a User under 18.
2.2. Capitalised terms such as Account, Plan, Generator and Content have the meaning given in our Terms of Service.
3. Personal data we collect
| Category | What we collect | Source |
|---|---|---|
| Account | Display name or nickname; e-mail; password (stored by our authentication provider only in hashed form, so our team can never read it); profile photo, if you upload one; account creation date; e-mail confirmation status; date of birth, to check your age, and, if you are under 18, your confirmation that a parent or guardian allowed you to use the Service; records of your acceptance of our Terms and this Policy (date, time, version, IP address and browser) | You |
| Google sign-in | Your Google name, e-mail, photo and account identifier. We never receive your Google password | Google, if you choose it |
| Plan and access | Plan, type, start and end dates, status (active, expiring, grace period, blocked), block reason (for example "refund in progress"), approval status, usage of limits | Us and our management panel |
| India checkout | Full name, e-mail, mobile number, the offer and plan, amount, currency, GST, payment status, payment method type (for example UPI or card), and Transact Bridge session and transaction IDs. If you arrive from an ad, we also collect the campaign parameters (UTM, campaign and ad identifiers). If you come from the app for an upgrade price, the checkout also receives a signed token with your Account e-mail, your current plan and the offer | You and Transact Bridge |
| Payment notifications | The raw notices our payment partners send us. Transact Bridge's notices can include your IP address, your billing city, state and postal code, and the payment method. Hotmart's notices can include your phone, address and a document number when Hotmart collects them. Before we store a notice, we remove any document number, address details and IP address from it. We never receive your full card number or UPI PIN | Transact Bridge, Hotmart |
| Unfinished checkouts | Name, e-mail, mobile number, offer, amount and campaign parameters of people who start a payment but do not finish it | You, when you press "proceed to payment" |
| Generator use | Phone model; your questionnaire answers (fingers, profile, game mode, button size, screen film, drag style, DPI limit, interface issues); the text you type when your phone is not found; questionnaire steps; generated and saved Sensis; Tweaks | You, when you use the Generator |
| Classes | Classes and modules opened, video position, completion, minutes watched, time spent in the classes area (excluding idle time), star ratings | You, when you use Classes |
| Technical data | IP address, date and time of access, browser and operating system, cookie and pixel identifiers, pages visited, bot-check signals | Your browser and our providers |
| Support and Community | Messages you send by e-mail, WhatsApp or Discord; your phone number or username on those services; your requests (refund, deletion and so on) | You |
| Parents | Parent's name, contact details and the information needed to verify parental consent where the law requires it | The parent |
3.1. Phone detection. To suggest your phone model, your browser may read on-device information, such as the model reported by your system and your screen size. This happens on your device. We store only the model you confirm in the questionnaire.
3.2. What we don't collect:
- sensitive data such as health, biometrics, religion or political views;
- your precise GPS location;
- your contacts;
- files from your phone, other than a photo you choose to upload;
- card numbers;
- your Game or Google passwords.
4. Why we use your data and on what legal basis
| Purpose | Main data | Legal basis |
|---|---|---|
| Create and run your Account, sign-in, password reset | Account, Google sign-in, technical | Performance of our contract with you (GDPR art. 6(1)(b)). India: data you voluntarily provide for this purpose (DPDP Act s. 7(a)), or your consent |
| Calculate, save and tweak Sensis; deliver classes, HUDs and Downloads; apply Plan limits | Generator use, Classes, Plan | Contract; India: s. 7(a) or consent |
| Process your purchase, grant access to the e-mail used at checkout, send access and welcome e-mails | Checkout, payment notifications, Account | Contract; India: s. 7(a) or consent |
| Handle cancellations, refunds, chargebacks and your support requests | Checkout, payment notifications, Plan, support | Contract; legal obligation (consumer laws); establishing or defending legal claims |
| Keep security logs and prevent fraud, duplicate accounts and abuse (bot checks, approval step, rate limits) | Technical, Account | Legitimate interests (GDPR art. 6(1)(f)); legal obligation (DPDP Rules, security safeguards) |
| Understand how the product is used, to improve it (which phones to calibrate, which classes work), using aggregated data where possible | Generator use, Classes | Legitimate interests; India: consent where required |
| Measure website traffic with Google Analytics | Cookies, technical | Consent |
| Measure which ads lead to sales with the Meta Pixel and the Utmify pixel on the checkout | Checkout events, campaign parameters, cookie identifiers | Consent (cookie banner) |
| Report every order to Utmify, paid or not, to know which campaign brought it | Name, e-mail, order status and value, campaign parameters | Legitimate interests in measuring our advertising (GDPR art. 6(1)(f)); India: your consent when you accept this Policy at checkout |
| Send you WhatsApp messages and e-mails about your order, including one you started and did not finish, and our offers | Name, e-mail, mobile, order | Consent: the optional box at checkout, never ticked in advance |
| Give you Community access at your request | Phone, username | Contract / your request |
| Comply with the law and valid requests from authorities | As required | Legal obligation |
4.1. Withdrawing consent. Where we rely on consent, you can withdraw it at any time, as easily as you gave it, from:
- the cookie settings link in the footer;
- the "unsubscribe" link in our e-mails;
- a message to brazilsensilegends@gmail.com.
Withdrawing consent does not affect processing carried out before it. After you withdraw, we stop that processing within a reasonable time.
5. Children and parental consent
5.1. Minimum age:
- You must be at least 13 (or the higher minimum age in your country) to create an Account.
- Purchases must be made by an adult. Under-18s may not buy a Plan (Terms, section 4).
5.2. Under 18. Under the DPDP Act, anyone under 18 is a child. If you are under 18, you may use the Platform only with your parent's or guardian's permission, which we ask you to confirm when you sign up. When the DPDP Rules start to require it, we will also obtain verifiable consent from a parent or guardian before processing a child's personal data.
5.3. For every User under 18, wherever they live:
- (a) we do not carry out tracking, behavioural monitoring or targeted advertising directed at children;
- (b) inside the app, we do not load analytics for Accounts that told us they are under 18;
- (c) we collect only what is needed to provide the Service. The profile photo is optional, and no public profiles are shown;
- (d) a parent can exercise the rights in section 9 on the child's behalf.
5.4. Under 13. We do not knowingly collect personal data from children under 13, or below the minimum age where you live. If we learn that we have, we delete it. Parents can contact us at brazilsensilegends@gmail.com.
6. Who we share data with
6.1. We do not sell personal data. We share it only as described below, and only as much as needed:
| Recipient | Why | Where |
|---|---|---|
| Supabase (Supabase Inc.) | Database, authentication and file storage, including profile photos | United States and other countries |
| Vercel (Vercel Inc.) | Hosting of our websites and server functions; technical logs | United States |
| Transact Bridge | Our payment partner in India: payment processing, GST, refunds and chargebacks. It receives your e-mail, the order details and the campaign parameters, and it collects your payment details directly | India |
| Hotmart | Payments, refunds and chargebacks for purchases outside India | Brazil / Netherlands / other |
| Utmify | Sales attribution: which ad or campaign led to a checkout or a sale. It receives the name, e-mail, status and value of every order, paid or not, and the campaign parameters, but not your mobile number or IP address. Its pixel on the checkout pages loads only with your consent | Brazil |
| Meta Platforms | Meta Pixel on the checkout: page views, checkout start, purchase value and currency, and cookie identifiers. Only with your consent | United States / Ireland |
| Google (Google LLC) | Google sign-in (if you choose it); Google Analytics (only with consent); Google Fonts, which receives your IP address when a page loads | United States |
| Cloudflare (Cloudflare, Inc.) | Storage and delivery of videos, images and files (R2); bot protection (Turnstile) | Global / United States |
| Upstash | Temporary order store for the India checkout: name, e-mail, mobile, plan and campaign parameters, kept for 45 days | United States and other countries |
| Resend | Sending welcome and notice e-mails | United States |
| Adobe Fonts | Web fonts on the checkout. It receives your IP address when the page loads | United States |
| WhatsApp (Meta) and Discord | Support and Community, when you use them | Global |
| Banks and payment networks | Responding to chargebacks and disputes: purchase, acceptance and usage records | India / your country |
| Authorities and courts | When required by law or a valid order | As applicable |
6.2. Processors and independent controllers:
- Our service providers act as our processors (Data Processors under the DPDP Act) under contracts that require them to protect your data and use it only on our instructions.
- Transact Bridge, Hotmart, Google (for sign-in), Meta and WhatsApp also act as independent controllers for their own purposes, under their own privacy policies.
6.3. Our team. Our team in Brazil accesses personal data through a management panel with these safeguards:
- role-based permissions, so that support staff see only what they need;
- two-factor authentication;
- a tamper-proof audit log that records every action.
Raw payment notices can be opened only by specifically authorised staff, and every opening is logged.
6.4. Business transfers. If our business is reorganised, sold or merged, personal data may pass to the successor. The successor must honour this Policy.
7. International transfers
7.1. We are based in Brazil, and several providers process data in the United States and other countries. Your personal data will therefore be transferred outside your country, including outside India.
7.2. India. The DPDP Act allows these transfers, except to countries the Government of India restricts by notification (s. 16). We do not transfer data to any restricted country.
7.3. EU and UK. For personal data from the EU or the UK, we use the European Commission's Standard Contractual Clauses (with the UK Addendum) or another valid safeguard. You can ask us for a copy.
8. How long we keep data
| Data | How long | Why |
|---|---|---|
| Account, Sensis, generation history, class progress and ratings | While your Account exists. Deleted within 30 days after you delete the Account; your generation history is anonymised | Contract |
| Profile photo | Until you change or remove it, or delete your Account | Contract |
| Security and access logs (IP, date, time) | At least 1 year | DPDP Rules (security safeguards); fraud prevention |
| Purchase, subscription, refund and chargeback records | 5 years after the end of our relationship | Tax, accounting and consumer law; legal claims |
| Records of your acceptance of the Terms and this Policy | While your Account exists, plus 5 years | Proof of contract |
| Raw payment notices (document numbers, addresses and IP addresses are removed before storage) | Only while needed to check and fix payment issues; then the content is erased and only a record that the event happened remains | Checking and fixing payment issues |
| Unfinished checkouts (name, e-mail, mobile, offer) | Only while useful to help you finish the purchase. The checkout's temporary order store keeps them for 45 days | Contacting you about the checkout, with consent where required |
| Parental consent records | While the child's Account exists, plus 5 years | Proof of consent |
| Support messages | 2 years | Support and legal claims |
| Staff audit logs | 5 years | Security and accountability |
| Google Analytics | 2 months | Statistics, with consent |
| Checkout browser storage: campaign parameters | 7 days | Attribution of the order to the campaign that brought you (no personal data) |
| Upgrade-price cookie | 6 hours | Applying your upgrade price |
8.1. When the period ends, we delete or anonymise the data. We keep it longer only when:
- the law requires it;
- an authority orders it;
- we need it to establish or defend a legal claim.
8.2. Backups follow our providers' replacement cycle of up to 7 days, after which deleted data disappears from them.
9. Your rights
9.1. Everyone. Wherever you live, you can ask us to:
- (a) confirm whether we process your data, and give you a summary of it and of how we process it;
- (b) correct, complete or update it;
- (c) erase it, unless we must keep it by law;
- (d) tell you who we have shared it with;
- (e) withdraw a consent you gave.
9.2. India (DPDP Act). You also have the right to:
- grievance redressal (s. 13);
- nominate another person to exercise your rights if you die or become incapacitated (s. 14).
If you are not satisfied with our Grievance Officer's answer, you may complain to the Data Protection Board of India.
9.3. EU/UK (GDPR). You also have the rights of:
- restriction;
- portability;
- objection to processing based on legitimate interests.
You may complain to your local supervisory authority.
9.4. US states. Where state privacy laws apply to us, you may request access, deletion and correction. We do not sell personal data. You can opt out of the use of advertising pixels by refusing or withdrawing cookie consent.
9.5. How to make a request:
- from My Account, where you can change your name, photo, e-mail and password, or delete your Account;
- by e-mail to brazilsensilegends@gmail.com;
- through the Grievance Officer (section 1.3).
To protect you, we may verify your identity, for example with a code sent to your Account e-mail.
9.6. When we reply. We reply within 30 days, and never later than the law allows. The DPDP Rules allow up to 90 days for grievances. We do not charge for requests. We will tell you if the law allows or requires us to refuse part of a request, for example because we must keep purchase records.
9.7. Account deletion:
- What we delete: your Account, Sensis, class progress and photo, within the periods in section 8. Your generation history is anonymised, so it can no longer be linked to you.
- What we keep: only what the law requires, and we do not use it for anything else.
- Before you ask: if you have an active Subscription, cancel it first so that you are not charged again.
10. Cookies, pixels and similar technologies
10.1. App (generator.brazilsensilegends.com):
| Name | Set by | Purpose | Duration | Type |
|---|---|---|---|---|
sb-[project]-auth-token (may be split in parts) |
BSL (Supabase) | Keeps you signed in | Up to 30 days, renewed while you use the app | Strictly necessary |
sb-[project]-auth-token-code-verifier |
BSL (Supabase) | Secures Google sign-in | Minutes | Strictly necessary |
bsl-cookie-consent (browser storage) |
BSL | Remembers your choice in the cookie banner | Until you change it | Strictly necessary |
_ga, _ga_3NEXY5RGZF |
Google Analytics | Traffic and usage statistics, with Google signals and ad personalisation turned off | Up to 2 years | Analytics: consent only |
| Turnstile check | Cloudflare | Tells people from bots at sign-up and sign-in | Session | Strictly necessary (security) |
10.2. India checkout (checkout.brazilsensilegends.com):
| Name | Set by | Purpose | Duration | Type |
|---|---|---|---|---|
bsl_upgrade_[offer] |
BSL | Applies your personal upgrade price. It holds your Account e-mail, current plan and offer, is signed against tampering, and is not readable by page scripts | 6 hours | Strictly necessary for that feature |
bsl_timer_end (browser storage) |
BSL | Shows the offer countdown on the checkout pages | Until you clear your browser data | Functional |
bsl_checkout_prefill |
BSL | Carries the name, e-mail and mobile from a checkout link to the checkout page, so they never appear in the page address. Not readable by page scripts | 30 minutes | Strictly necessary for that feature |
bsl-cookie-consent (browser storage) |
BSL | Remembers your choice in the cookie banner | Until you change it | Strictly necessary |
bsl:tracking-parameters (browser storage) |
BSL | Remembers the ad or campaign that brought you, so your order is attributed to it. It holds only the campaign parameters, no personal data | 7 days | First-party attribution |
Meta Pixel (_fbp, _fbc) |
Meta | Measures checkout starts and purchases from ads | Up to 90 days | Advertising measurement: consent only |
| Utmify pixel | Utmify | Ties the visit to the campaign that brought you | Set by Utmify | Measurement: consent only |
| Transact Bridge payment window | Transact Bridge | Processes the payment securely | Set by Transact Bridge | Strictly necessary |
| Turnstile check | Cloudflare | Bot protection before a payment starts | Session | Strictly necessary |
10.3. Choosing what to allow:
- Strictly necessary technologies do not need consent: without them sign-in, payment and security would not work.
- Analytics and advertising-measurement technologies load only after you accept in our cookie banner.
- You can change your choice at any time through Cookie settings in the footer.
11. Automated processing and Marechal 1.0
11.1. Marechal 1.0 calculates your Sensi automatically, using formulas and calibration profiles applied to your phone's specifications and your answers. The questionnaire looks like a chat, but the replies are automated: no person is answering, and Marechal 1.0 is not generative artificial intelligence.
11.2. Some Account decisions are also automated:
- applying Plan limits;
- suspending access while a refund or dispute is open;
- bot checks;
- approving an Account after a confirmed purchase.
None of these decisions has legal effects beyond your contract with us. You can ask a person to review any of them, and we will explain the logic involved.
12. Security
12.1. We take reasonable security safeguards, as required by the DPDP Act s. 8(5) and Rule 6, and by GDPR art. 32. They include:
- encrypted connections (HTTPS/TLS);
- passwords stored only in hashed form;
- row-level access controls in our databases, so each User reaches only their own data;
- integration secrets stored only as hashes;
- role-based staff access with two-factor authentication, session time limits and a tamper-proof audit log;
- masked e-mails and phone numbers in technical logs;
- rate limits and bot checks;
- temporary links for videos and files;
- security headers.
12.2. No system is completely secure. Please use a strong, unique password and never share your Account.
13. Personal data breaches
13.1. If a personal data breach occurs, we will:
- inform affected users without delay, in clear language, explaining what happened, the likely consequences and what we are doing;
- inform the Data Protection Board of India, with a detailed report within 72 hours, as required by Rule 7 of the DPDP Rules;
- inform other authorities within the time limits of the applicable law, for example 72 hours under the GDPR.
14. Marketing, WhatsApp and unfinished checkouts
14.1. Service messages are needed for the Service and do not require marketing consent. They are:
- account confirmation and password resets;
- access and welcome e-mails;
- expiry notices;
- changes to our Terms.
14.2. Messages about your order and our offers. At checkout there is an optional box, never ticked in advance and not needed to pay: "Send me WhatsApp messages and e-mails from Brazil Sensi Legends about my order and offers." If you tick it, we may send you WhatsApp messages and e-mails about that order, including an order you started and did not finish, and about our offers. We record your choice with your order.
14.3. Stopping them. You can stop these messages at any time, and it is as easy as it was to agree:
- reply "STOP" to any WhatsApp message;
- use the unsubscribe link in any marketing e-mail;
- or write to brazilsensilegends@gmail.com.
Stopping them does not affect the service messages in 14.1.
14.4. Your mobile number is used for:
- (a) order support;
- (b) the messages in 14.2, only if you ticked the box;
- (c) Community access, if your Plan includes it and you ask for it.
15. Third-party links
15.1. Our Platform links to services we do not control, each with its own privacy policy, such as:
- the Game (Garena);
- Transact Bridge and Hotmart;
- WhatsApp;
- Discord;
- app stores.
16. Language
16.1. This Policy is published in English. You may ask for this notice in Hindi or another language listed in the Eighth Schedule to the Constitution of India by writing to brazilsensilegends@gmail.com.
17. Changes to this Policy
17.1. We may update this Policy. We will tell you about material changes by e-mail and on the Platform before they take effect. Where a change needs your consent, we will ask for it again. The effective date is shown at the top.
18. Contact and complaints
18.1. Contacts:
- Privacy team: brazilsensilegends@gmail.com.
- Grievance Officer (India): Felipe, Customer Support Manager, brazilsensilegends@gmail.com, +91 86380 23511. We acknowledge within 48 hours.
- Postal address: Av. General Ataliba Leonel, 1223, Room 43, Santana, São Paulo – SP, 02033-000, Brazil.
- India: the Data Protection Board of India, after you have used our grievance process.
- EU/UK: your local data protection supervisory authority.