Privacy Policy
Last updated: July 19, 2026
Kasual was designed so you can exist in here without leaving a trace out there. Privacy is not an appendix to the product — it is the product. This policy explains, in plain language, which data we process, why, and what your rights are under Brazil's General Data Protection Law (LGPD, law 13.709/2018).
1. Who we are
Kasual is operated by [legal entity name, CNPJ and address] ("Kasual", "we"), the controller of personal data processed in the app and on this website. For any privacy matter, contact our Data Protection Officer (DPO) at privacidade@kasual.app.br.
2. What we collect
Account and authentication
- Your phone number (if you sign in via SMS) or your Apple or Google account identifier. Your number and e-mail are never shown to anyone — they only prove you are one person, and one person only.
Your mask and profile
- Nickname and avatar. We don't ask for — and don't want — your real name.
- Profile photos. Private by default; shown only to people you allow, according to the reveal mode you choose.
- Self-declared information, such as who you are and who you're looking for, plus anything you write on your profile.
Liveness check (biometric — sensitive data)
- The facial verification ("liveness check") confirms you are a real person and that the verification face matches your profile photos. Processing is done by a specialized partner (Amazon Web Services — Rekognition Face Liveness).
- The liveness video is not stored by us. We keep only the verification result and the technical references needed to keep your account verified.
- Biometric data is sensitive data (LGPD art. 11) and is only processed with your specific, highlighted consent, requested before the camera opens. You may revoke consent at any time — without verification, however, your profile doesn't join the ball.
Age confirmation (18+ app)
- Kasual is restricted to adults 18+ and complies with Brazilian law on the protection of minors in digital environments (law 15.211/2025). Age is confirmed through operating-system signals (such as the declared age range on your Apple or Google account) and/or your stated date of birth.
- In edge cases we may request additional confirmation (such as CPF or an ID document), processed by a verification partner. We do not store your CPF or document images.
Conversations and media
- Messages and media exchanged in chat are processed only to deliver the feature. Chat images expire after being opened (view-once or twice) and screenshots are blocked by the app.
Usage and device data
- Technical and usage data (device model, OS, usage events, crash reports) through Firebase Analytics and Crashlytics, to keep the app running and improve it.
3. Why we use your data
- Creating and authenticating your account;
- Verifying you are a real, unique person over 18;
- Operating the product: profiles, matches, chat, reveal and discretion modes;
- Safety, fraud prevention and moderation — including handling reports;
- Improving the app with aggregated usage metrics;
- Complying with legal obligations.
4. Legal bases
- Consent (art. 7, I and art. 11, I): biometric liveness data;
- Contract performance (art. 7, V): account, profile, chat and other features;
- Legal obligation (art. 7, II): age verification and legally required record-keeping;
- Legitimate interest (art. 7, IX): safety, fraud prevention and moderation, always with the minimum data necessary.
5. Who we share with
We never sell your data. We share it only with processors that help us deliver the service, under contract and our instructions:
- Google (Firebase) — authentication, infrastructure, metrics and crash reports;
- Amazon Web Services — liveness processing and face comparison;
- Apple and Google — social sign-in and age signals.
We may also share data with public authorities under legal obligation or court order.
6. International transfers
Some of our processors handle data outside Brazil. In those cases the transfer follows the safeguards of LGPD art. 33, such as contractual clauses ensuring an equivalent level of protection.
7. How long we keep data
- Account and profile data: for as long as the account exists;
- Delete the account, delete everything — including the biometric references from the liveness check;
- Access logs may be retained for the legal period (art. 15 of the Brazilian Internet Framework — 6 months), and records tied to reports or legal obligations for as long as the law requires.
See the step by step at Account deletion.
8. Your rights (LGPD art. 18)
At any time, you may request:
- Confirmation that we process your data, and access to it;
- Correction of incomplete or outdated data;
- Anonymization, blocking or deletion of unnecessary data;
- Portability;
- Deletion of data processed under consent;
- Information about sharing;
- Revocation of consent.
Just write to privacidade@kasual.app.br. We reply within the LGPD deadlines. You may also petition Brazil's National Data Protection Authority (ANPD).
9. Security
We apply appropriate technical and organizational measures: encryption in transit, restricted access control, in-app screenshot blocking and view-once media. No system is infallible, but data minimization is our first defense: what we don't collect can't leak.
10. Children and teenagers
Kasual is strictly forbidden for anyone under 18. We actively verify age and remove accounts suspected of belonging to minors. Learn more on our Child safety page.
11. Changes to this policy
If we change anything relevant, we'll notify you through the app before the change takes effect. The current version will always live on this page.
12. Contact
Data Protection Officer (DPO): [DPO name] — privacidade@kasual.app.br