Privacy Policy
Last updated: 2026-07-10
This Policy explains how Cool collects, uses, shares and protects your personal data, and what your rights are. We take your privacy seriously and process your data in line with the LGPD and the GDPR.
Notice: this is a template document
This text is a standard template provided by the Cool platform to help communities and creators get started. It reflects the spirit of Brazil's LGPD (Law No. 13,709/2018) and the GDPR (EU Regulation 2016/679), but it does NOT constitute legal advice. Before publishing, review it with a qualified lawyer to tailor it to your business, country and way of operating.
Who the controller is
The controller of the personal data processed on this platform is Cool ("we"), operator of the community service. For any privacy question or to exercise your rights, contact our data protection officer (DPO) at the email address at the end of this document.
What data we collect
We collect: (a) account data — name, email, password (stored encrypted); (b) profile data — photo, bio and other information you choose to provide; (c) payment data — processed by payment gateways/partners (we do not store your full card number); (d) usage and cookie data — pages visited, device, IP address, identifiers; (e) community content — posts, comments, messages and materials you submit; (f) city-level location — when provided, to show you on the members map.
Legal bases and purposes
We process your data based on the LGPD (art. 7) and the GDPR (art. 6): performance of a contract (to run your account and the community), consent (non-essential cookies, marketing communications), legitimate interest (security, fraud prevention, service improvement) and compliance with a legal obligation (tax, accounting).
Purposes include: creating and maintaining your account, processing payments and subscriptions, displaying and moderating community content, personalizing your experience, sending communications you have authorized, and keeping the platform secure.
Who we share with
We share data only when necessary: with payment processors (to charge subscriptions and products), with hosting and database providers (for example, Supabase), with transactional and marketing email providers, and with authorities when required by law. We also share, within each community, the content you post with other members and with the owner/administrators of that community. We do not sell your personal data.
International transfer
Some of our providers may process data outside your country (for example, on servers in the United States or the European Union). When this happens, we adopt appropriate safeguards — such as standard contractual clauses — to ensure a level of protection consistent with the LGPD and the GDPR.
Use of artificial intelligence (AI)
Cool uses AI features (the Sophia assistant, the tutor and automated support) to help owners and members: suggesting replies and actions, summarizing lives, organizing the CRM and answering questions. To do so, certain content you provide (for example, posts, comments, support messages and aggregated community data) may be sent to an AI provider (Anthropic, based in the United States) acting as a processor/subprocessor, under a contractual obligation of confidentiality and use restricted to providing the service. This is an international transfer, with the safeguards described above. The AI does NOT take critical actions (such as sending campaigns or charging) without human confirmation, and we do not use your content to train third-party models. Contact our DPO with questions about this processing.
Data retention
We keep your data only for as long as necessary for the purposes described or as required by law (for example, tax obligations). When you close your account, we delete or anonymize your personal data within a reasonable period, except where the law requires longer retention.
Security
We adopt technical and organizational measures to protect your data: encryption in transit (HTTPS), hashed passwords, access control and monitoring. No system is 100% invulnerable, but we work continuously to reduce risks. In the event of a relevant security incident, we will notify you and the authorities as required by law.
Your rights as a data subject
You have the right to: access your data; rectify incomplete or outdated data; delete it (erasure); port it to another provider; object to processing based on legitimate interest; and revoke consent at any time (without affecting processing already carried out).
To exercise any of these rights, send a request to the contact email at the end of this document, stating which right you wish to exercise. We will respond within the legal timeframes. You may also complain to the competent data protection authority (in Brazil, the ANPD).
Children
Cool is not intended for people under 18 (or the applicable legal minimum age, such as 16 under the GDPR). We do not knowingly collect data from children. If we learn that we created an account for a minor without proper consent, we will delete the data.
Data protection officer (DPO) and contact
For questions about this Policy, to exercise your rights or for privacy matters, contact our data protection officer (DPO) at privacidade@cool.app.
Changes to this Policy
We may update this Policy from time to time. When we make relevant changes, we will notify you by appropriate means (for example, a notice on the platform or email). The date of the last update is shown at the top of this document.