Privacy Policy
Welcome to Smart Blocks Lab.
Our platform was developed following
Privacy by Design principles, aiming to collect
and store only the data strictly necessary for the system to operate.
This Privacy Policy explains how personal data is processed
when using the Smart Blocks Lab platform, in accordance with
the Brazilian General Data Protection Law (LGPD),
the Brazilian Internet Civil Framework (Marco Civil da Internet),
the UK GDPR, and the EU GDPR.
1. Data Controller
Smart Blocks Lab is responsible for the processing
of personal data described in this policy.
Questions, requests, and privacy-related inquiries
may be submitted through the support area available within the platform.
2. What data we collect
To provide authentication, platform functionality,
and access to available resources, the following data may be processed:
Data stored on our servers
-
Name:
voluntarily provided by the user when contacting support.
-
Email address:
used as the account authentication and access identifier.
-
Password:
stored using secure hashing algorithms.
The original password is not accessible in plain text.
-
Saved projects:
blocks, files, and content voluntarily created by the user.
-
Support information:
data voluntarily submitted by the user through the platform support area.
-
Technical records and security logs:
information used for authentication, platform stability,
fraud prevention, and security purposes.
Data stored locally in the browser
-
API keys:
stored locally in the user's browser and not intentionally
stored on our servers.
-
Preferences and session data:
technical data required to maintain the user experience,
authentication, and platform preferences.
The platform may use local browser storage mechanisms
for technical operation, authentication, and session maintenance.
3. Purpose and legal basis for processing
Personal data is processed based on the following legal grounds:
-
Performance of Terms of Use:
authentication, account access, and project storage.
-
Legitimate interest:
platform security, fraud prevention,
and system stability.
-
Communication and support:
handling requests voluntarily submitted
by users through the support area.
-
Legal obligation compliance:
when required to comply with applicable laws.
4. Sharing and international data transfers
-
The platform infrastructure may be located
in the United Kingdom or other countries with hosting services
compatible with appropriate information security standards.
-
We do not sell, rent, or share personal data
with third parties for commercial purposes.
-
Integrations configured by users with AI/LLM providers
may establish direct communication between the user's browser
and the respective external providers.
-
The voice input feature, when used, relies on the speech recognition
service of the user's browser. In some browsers, captured audio may be
transmitted to third-party services (for example, the browser provider)
for conversion into text. This processing occurs outside our control,
according to the policies of the browser and the respective provider.
Audio is not stored on our servers; only the resulting text is processed
by the platform.
5. Data retention and deletion
Account data remains stored while the account is active.
Users may request account deletion at any time through the platform.
After account deletion, associated personal data
will be removed or anonymized, except for technical records
and information whose temporary retention is necessary
for legal compliance, platform security,
or fraud prevention purposes.
Technical records and security logs may be temporarily retained
after account deletion for the minimum period necessary
to comply with legal obligations and platform security requirements.
6. User rights
Users may request information regarding data associated with their account,
as well as request correction or deletion of personal data, when applicable.
Privacy and data protection requests may be submitted
through the platform support area.
We currently do not provide an automated feature
for changing the account email address,
as it is used as the primary identifier
within the platform authentication structure.
7. Information security
We adopt reasonable technical and organizational measures
to protect data against unauthorized access,
loss, alteration, or destruction.
- Use of HTTPS (SSL/TLS);
- Secure password storage using hashing;
- Authentication and session protections;
- Security measures applied to the application environment.
8. Use by minors
The platform is not intended for use by minors
without appropriate legal supervision.
9. Changes to this policy
This Privacy Policy may be updated periodically.
The most recent version will always be available on this page.