Skip to content
Lectorium
Homepage Terms
EN
  • Português
  • English
  • Español
  • Français
  • 中文
Open Lectorium
Baroque ceiling fresco with figures in glory

Legal document

Privacy Policy

Effective: June 5, 2026

← Homepage Terms of Service →

This is a courtesy translation. In case of divergence, the Brazilian Portuguese version prevails.

Lectorium is local-first: your documents live on your device and in your Google Drive or Dropbox account. We do not operate servers that store your working files.

Quick summary

What we collect

Why

Legal basis (LGPD)

Name, email, profile photo (Google OAuth)

Identify and authenticate your session

Contract performance — art. 7, V

Google OAuth token

Operate Google Drive on your behalf

Contract performance — art. 7, V

File metadata (name, size, type)

Display your library and sync

Contract performance — art. 7, V

Connection logs (IP, timestamp)

Security and legal compliance

Legal obligation — art. 7, II (Marco Civil, art. 13)

Aggregated technical metrics (Cloudflare Web Analytics)

Understand traffic and performance, without cookies, advertising or profiling

Legitimate interest — art. 7, IX

Billing data (identifier, amount, product, date)

Grant access to purchased content and process refunds

Contract performance — art. 7, V

1Who we are

Data controller: Lectorium, operated by the party responsible for the service and for decisions on the processing of personal data in this application.

Data Protection Officer (DPO): to exercise your rights or ask privacy questions, write to [email protected]. We respond within 15 business days, as required by LGPD art. 18 §5.

2Data we collect and why

2.1 Google account (optional, for using Google Drive)

When you sign in with Google, Lectorium receives from Google OAuth:

  • Display name, email address and profile photo — to create and identify your account.
  • OAuth access token — to perform Google Drive operations on your behalf during the session.

Legal basis: contract performance (art. 7, V of Law 13,709/2018). This data is necessary only for authentication and Google Drive-connected features; the local workspace can be used without connecting a Google account.

Retention: while your account remains active. The OAuth token is stored locally, encrypted on your device, and deleted when you sign out.

Google Drive scopes: drive.file (only files created or opened by the app) and drive.appdata (the library's private manifest).

2.2 Files and content

Editing, annotation and document storage happen locally on your device. For AI features — including OCR of scanned PDFs — content travels directly from the app to Google's APIs (Gemini); it does not pass through Lectorium servers and we have no access to it.

Retention: the local cache stays in the app's storage until you clear the data or sign out.

2.3 Dropbox (optional integration)

If you connect Dropbox, Lectorium accesses only the files you explicitly select. The token is stored locally, encrypted. No Dropbox data is transmitted to our servers.

2.4 Connection logs

Our infrastructure (Supabase) records access logs with IP address and timestamp, as required by art. 13 of Brazil's Marco Civil da Internet (Law 12,965/2014). These logs are kept for 12 months and are only disclosed to third parties under court order.

2.5 Payment data

When you make a purchase (theme or Pro plan), we record the payment identifier, amount, product and date. This data is kept on secure infrastructure (Supabase with RLS) and is necessary to grant access to the product and to process any refunds.

Payment processing is handled entirely by Mercado Pago — Lectorium does not store card data, bank details or payment-instrument information.

Retention: 5 years, for tax and support purposes, as required by applicable Brazilian law.

2.6 Technical metrics and telemetry

We use Cloudflare Web Analytics for aggregated traffic and performance metrics on public pages — without cookies, localStorage or user identifiers. We do not use Google Analytics, behavioral advertising, retargeting or profiling.

Internal technical events used for in-app diagnostics are not sent to Lectorium servers.

3Who we share data with

We do not sell, rent or pass on your data to data brokers or advertisers. We share data only with the subprocessors necessary to operate the service:

  • Google LLC (USA) — OAuth authentication and the Google Drive API. Transfer backed by Standard Contractual Clauses (SCCs).
  • Supabase Inc. (USA / EU) — database and authentication, under Supabase's SCCs and DPA.
  • Cloudflare Inc. (global network) — hosting, security, CDN and aggregated metrics for public pages.
  • Dropbox Inc. (USA) — only if you voluntarily connect Dropbox.
  • Mercado Pago S.A. (Brazil / Argentina) — payment processing. Card data travels directly between you and Mercado Pago, subject to their privacy policy.

4International transfers

Our subprocessors are based in the United States, in Brazil, or operate global infrastructure. International transfers rely on Standard Contractual Clauses (SCCs), a mechanism recognized under art. 33 et seq. of the LGPD as an adequate safeguard. Each provider maintains public DPAs on their websites.

5Automated decisions

Lectorium does not use automated decisions that produce legal effects or significantly affect you (LGPD art. 20). AI features generate suggestions that always depend on human review and action.

6Security

  • Access tokens are stored encrypted on your device (AES-GCM via the WebCrypto API).
  • All communication with external APIs uses HTTPS/TLS.
  • Supabase infrastructure operates with RLS — each user only accesses their own data.
  • In the event of a security incident, we will notify you and the ANPD within the timeframes set by LGPD art. 48.

7Your rights (LGPD, art. 18)

  • Confirmation and access: know whether we process your data and obtain a copy.
  • Correction: correct incomplete, inaccurate or outdated data.
  • Anonymization or deletion: of data processed on the basis of consent or legitimate interest.
  • Portability: receive your data in a structured format.
  • Objection: object to processing based on legitimate interest.
  • Information about sharing: know who we share your data with.
  • Withdrawal of consent: at any time, without prejudice to prior processing.

To exercise any right, write to [email protected]. We respond within 15 business days.

8How to revoke Google access

  • Sign out of your account in the app's settings — this erases the local token.
  • Revoke authorization on the permissions page of your Google Account.
  • Clear the app's local data in your system settings.

Your files in Drive remain in your Google account. Only you can delete them there.

9Cookies and local storage

We do not use tracking or advertising cookies. Local storage keeps your session and offline work cache. Local workspace data stays on your device and is not accessed remotely by us.

10Children and teenagers

Lectorium may be used in educational contexts, including by minor students, under the guidance of guardians, teachers or institutions. Processing of children's and teenagers' data must observe the student's best interest and the authorizations required by law.

If you believe a child used Lectorium without the necessary authorization, write to [email protected].

11Changes to this Policy

We will announce material changes at least 30 days in advance, through the app's interface or by email. The effective date at the top indicates the current version; continued use after that date constitutes acceptance.

12Contact and Data Protection Officer (DPO)

General questions and privacy matters: [email protected]

Lectorium

Homepage Terms [email protected]

© 2026 Lectorium