Privacy policy

Brognoli BI is the brand responsible for the brognolibi.com website and the BROGNOLI Studio software, focused on content, digital products, and productivity tools for Power BI, Excel, and analytics.

Privacy policy

1. Who we are

Brognoli BI is the brand responsible for the brognolibi.com website and the BROGNOLI Studio software, focused on content, digital products, and productivity tools for Power BI, Excel, and analytics.

This policy explains how we handle personal data when you browse the website, create an account, subscribe to a plan, use BROGNOLI Studio, or contact us.

Last updated: September 28, 2026. Version: 2026-09-28.

2. What data we collect

We collect only the data needed to operate the website, the account, and BROGNOLI Studio, such as name, email address, login credentials, or third-party social login identifiers when you authenticate through external providers.

We may also process subscription data, plan information, trial status, credits, transaction identifiers, and billing metadata handled by payment providers.

For security, synchronization, and license enforcement, we may record technical and operational data such as device identifiers, active sessions, app version, basic preferences, and usage logs required for support and stability.

We also process information voluntarily submitted through forms, commercial inquiries, support requests, and communications sent to Brognoli BI.

3. How we use your data

We use your data to create and maintain your account, authenticate access, process subscriptions, unlock features according to your plan, and enable the secure use of BROGNOLI Studio.

We also use data to send operational communications, provide support, prevent fraud, enforce plan-based licensing limits, keep minimum technical logs, and improve the stability of our products and services.

Where appropriate, we may use aggregated and non-identifiable information for internal metrics, usage analysis, and product improvement.

4. Legal basis

Your data may be processed based on contract performance, compliance with legal obligations, legitimate interest related to service operation and security, the regular exercise of rights, and, where required, your consent.

We seek to rely on the most appropriate legal basis for each processing activity and to comply with the Brazilian General Data Protection Law (LGPD) and other applicable rules.

5. Who can access your data

You may access your own account data and the information made available inside the website and BROGNOLI Studio according to your usage profile.

The Brognoli BI team may access data strictly necessary for support, customer service, abuse prevention, billing, and operational maintenance, always on a limited need-to-know basis.

We use Supabase for authentication and database services; Stripe for billing and payments; Resend for operational email; and Vercel for hosting and storage of published materials. Google or Microsoft receive the data required when you choose social sign-in.

When you use managed AI in BROGNOLI Studio, your prompt and any files you submit are sent to the provider selected for that feature (OpenAI, Anthropic, or Google) to generate a response. In bring-your-own-key mode, the app sends the request directly to the selected provider using the key configured on your device. Avoid submitting third-party personal data or confidential information unless you have appropriate authorization and a legal basis.

The primary Supabase project is in Oregon, United States (us-west-2). The website's Vercel Functions execute in N. Virginia, United States (iad1), and the Blob region identified for published materials is São Paulo, Brazil (GRU1). Vercel log location and retention may differ and have not been confirmed.

Stripe may process data in different countries; retention periods depend on data type, service, law, fraud-prevention needs, and legal claims. Stripe says that in many jurisdictions it generally keeps personal data from Business Users for five or more years after the relationship ends or the last transaction. Resend says it stores data in the United States, retains email and log data for 30 days on Free, Pro, and Scale plans, and deletes remaining customer data within 90 days after account termination.

For managed AI in Studio, OpenAI says API data is not used for training by default and content may be retained in abuse-monitoring logs for up to 30 days; Anthropic says commercial API inputs and outputs are not used for training by default and are deleted within 30 days, subject to exceptions. The Gemini API project used by Brognoli is paid: Google says prompts and responses are not used to improve products, but content may be logged for a limited period for abuse prevention and processed or temporarily stored in countries where Google operates. We have not confirmed special zero-retention or regional data-residency controls for these provider projects. Provider policies and exceptions may change; avoid submitting unnecessary personal or confidential information.

We do not sell, rent, or monetize your personal data with third parties.

6. How long we keep data

We keep your data while your account is active or for as long as necessary to provide the service, comply with legal obligations, resolve disputes, perform contracts, and protect Brognoli BI rights.

Billing, payment, and legal compliance records may be retained for the periods required by applicable law, even after account closure.

When deletion is possible and no retention obligation applies, data will be removed or anonymized within a reasonable period.

7. Your rights

You may request confirmation of processing, access, correction of incomplete or outdated data, anonymization, blocking, deletion, portability, and information about data sharing, where applicable.

You may also revoke consent when consent is the applicable legal basis and request account deletion, subject to legal and operational limitations.

If you have an account, you can download a copy of its associated data or submit an account deletion request for review in My account. Staff will review the request before any deletion; records that must be retained for legal obligations, billing, or fraud prevention may be preserved or anonymized. If you cannot access your account, contact support@brognolibi.com.

8. Security

We adopt reasonable technical and administrative measures to protect your data against unauthorized access, loss, alteration, disclosure, or improper destruction.

This includes access controls, authentication, permission segregation, specialized providers, and protection of data in transit and within infrastructure aligned with modern market standards.

Even so, no environment is completely risk-free, which is why safe password, access, and device practices also depend on the user.

9. Cookies and tracking

We may use cookies and similar technologies that are strictly necessary for website operation, authentication, language preferences, session continuity, and basic usage measurement.

We do not sell your data to third parties and, as a rule, we do not use invasive behavioral tracking for external commercialization purposes.

10. Changes to this policy

This policy may be updated from time to time to reflect legal, operational, contractual, or product changes.

When relevant changes occur, we may update the date on this page and, where appropriate, adopt additional communication measures.

11. Contact and data privacy requests

For questions, personal data requests, or the exercise of privacy rights, please contact support@brognolibi.com.

We will make reasonable efforts to respond within an appropriate timeframe and in accordance with applicable law.

Request access, export, or deletion of your data

If you can sign in, use My account to download your data or submit a deletion request for review. If you cannot access your account, email the address below. We may verify your identity; do not send passwords, API keys, or unnecessary identity documents.