1. Responsible person and contact
Matheus Gerlach de Moraes is responsible for the Badsite project and decisions about data processed to provide the service. Contact info@gerla.com.br for support and privacy requests.
This version describes the current product foundation and identifies planned integrations. Operational and legal review must be completed before commercial launch; publishing this document does not certify compliance.
2. Information we process
We process information needed for the features you use. Do not send sensitive data, identity documents or client information through profile fields or messages unnecessarily.
- Interest list: required name and email, selected project types and tools, details you enter in “other”, your choice to receive updates and the signup date. Joining the list does not create an account.
- Account: email, user identifier, display name if provided, preferred language and plan access status.
- Authentication: information needed for login, sessions, email confirmation and account recovery, processed with Supabase.
- Operation and security: technical request and error records, which may include IP address, time, route and browser details depending on the infrastructure services used.
- Preferences: language saved in your browser and favorites stored locally on your device.
- Support: content and contact details you choose to send when asking for help.
3. Why we use this information
We use interest-list information to understand demand for Badsite and, if you choose to hear from us, to tell you about testing and launch. Joining the list does not grant platform access. A new entry may trigger an operational notification to the project owner; that destination is not the public privacy contact.
Account information is used to authenticate you, maintain your profile and check feature access; preferences remember your choices; technical records help investigate failures and protect the service. Support messages help us respond to and follow up on requests.
Legal grounds must match each purpose: performance of a contract or steps you request, legal obligations and, where applicable, legitimate interests subject to a necessity and impact assessment. Contact about testing and launch depends on your specific choice, which you can withdraw through the privacy contact. Browsing alone is not treated as consent to advertising.
4. Cookies and browser preferences
Authentication uses session cookies needed to maintain account access. The badsite_locale cookie remembers your language selection. Favorites use browser localStorage and are not synchronized between devices in this version.
You can clear this data in browser settings. Doing so may sign you out, remove local favorites and forget your language preference.
This version does not install advertising tools or marketing pixels. To guide library curation, the server records fulfilled code requests with the account identifier, piece, obtainment channel (source, download or MCP), day and time. Repeated requests count once per account, piece, channel and UTC day. The administrative dashboard shows totals per piece without identifying people; this metric does not prove use in a website. These records do not include prompts, client code, IP addresses or browser details.
5. Providers and sharing
Badsite uses Vercel to host and deliver the application, and Supabase for authentication, database and storage. The interest list is kept in Supabase and can only be viewed by authorized administrators. These services may process the technical and account data needed for their roles.
The platform may also load fonts from Google Fonts; requesting those files connects your browser to that provider. Replacing these with files hosted on the site itself must be checked during production review.
When configured, Resend sends the project owner an alert about new list entries, including the information submitted in the form. Sending launch notices to list members will require a separate process and a way to unsubscribe. Stripe is planned for payments; this policy does not imply an active checkout.
We do not sell personal data. Necessary information may be shared with operational providers, to meet a legal obligation or to investigate abuse, within the relevant purpose and need.
6. Payments, MCP and AI
When checkout is active, full card details should be entered in the payment processor’s environment. Badsite should receive only the information needed to link a purchase and manage access, such as identifiers and subscription status.
MCP connections and expanded AI features still require configuration and release. Permissions, revocation options and information shared with the chosen tool will be explained before activation.
This version does not automatically collect client social media profiles or generate complete sites from that information. Those features require a separate assessment of data, providers and permissions.
7. Location and transfers
Infrastructure may process data outside Brazil. The current Supabase project uses a region in the United States, and Vercel content delivery may involve its international infrastructure.
The inventory of countries, subprocessors, contracts and mechanisms for international transfers must be completed before commercial launch. You can request information about how your account data is handled through the privacy contact.
8. Retention, deletion and security
Data is retained according to the purpose’s needs and applicable legal duties. Interest-list entries are kept while the list is used for testing and launch or until you withdraw your choice to be contacted, subject to legal obligations and the need to document a fulfilled request. An automatic disposal period for this list has not yet been set; one must be defined before a bulk-message campaign. An account closure request requires assessing what can be deleted and what must be retained, with justification, for legal obligations or the exercise of rights.
Library obtainment records have a 90-day retention window in the active database. A scheduled process periodically deletes expired records in batches; failures or backlogs require operational monitoring and correction. Effective account deletion also removes its obtainment records from the active database. Retention periods for other categories, logs and backup disposal are still under operational review. We do not promise immediate deletion across all systems. Relevant limitations and retention will be explained when handling a request.
Access controls and separation of public content from restricted files are part of the application. No environment is risk-free; incidents must be assessed and reported according to applicable requirements.
9. Your rights and requests
You can request confirmation and access, correction and information on sharing, and, where applicable, portability, anonymization, blocking or deletion. You can also withdraw your choice to receive launch and testing messages or challenge unlawful processing.
Send requests to info@gerla.com.br. We may ask for proportionate identity confirmation to protect your account or waitlist entry. Do not send your password. If a request cannot be fulfilled, we will explain why and the next steps.
You may also contact Brazil’s ANPD or the relevant consumer protection authorities.
10. Audience and updates
Badsite is intended for adults. If you become aware of a child or teenager’s account in this version, contact us so we can review it and take appropriate action.
Relevant new purposes or integrations will require an updated policy and, where needed, advance information or a choice. The date and version at the top identify the text you are reading.