Forgile Privacy Policy
Last updated: [publication date]
This is an English translation provided for convenience. The official text is the Portuguese version, which prevails in case of any discrepancy.
Forgile is a platform for learning to code by practicing: you study, write code, run it and get explanations about the result. This policy explains what personal data we process, why, who we share it with, how long we keep it and how you can exercise your rights. It follows Brazil's General Data Protection Law (Law No. 13,709/2018, the "LGPD").
1. Who is responsible for your data
The data controller is LBA TECNOLOGIA LTDA, CNPJ 41.450.516/0001-15, headquartered at [address] ("Forgile", "we", "us").
Data Protection Officer (DPO): [name], email marketing@forgile.com.
2. What data we process
2.1 Data you give us
- Sign-up: name, email and password. The password is stored only as a cryptographic digest (bcrypt hash); not even we can read it.
- Sign in with Google: when you choose this option, Google sends us an identifier for your Google account, your email (and whether it is verified) and your name. We do not receive your Google password or access to your contacts, files or emails.
- Code and answers: the code you write in the exercises and the answers you submit.
- Problem reports: when you report a problem with an exercise, we keep the reason, the comment you wrote and the link to your account (so the same report isn't repeated). Whoever reviews the reports sees only the exercise, the reason and the comment, without knowing who sent it.
- Payment (PRO plan): when you subscribe, your card or Pix details are given directly to Stripe, which processes the charge. We do not receive or store your card number. From Stripe we receive and store the plan, the subscription status, dates, amounts and paid periods, and Stripe identifiers (customer, subscription and charge), to unlock PRO, show it to you and handle refund requests. We do not store any card data (not even the last digits) or Pix data. This data is included in the export of your data (Me page).
- Contact: whatever you write to us when asking for help or exercising your rights.
2.2 Data generated by your use
- Progress and results: exercises completed, the result of each run (for example, "different output" or "compilation error"), time and memory used.
- Gamification: XP, level, consecutive days of practice (ember), daily goal, your browser's time zone (to know what "today" is for you), daily orders, daily challenge, achievements and practice sessions.
- Friends league (optional): if you join the league, we keep your invite code and the list of friends you added or who added you. Your friends in the league see only your first name and your XP for the week; never your email, full name or what you answered. When you leave the league, you stop appearing to your friends.
- Account security: session records (tokens stored only as a cryptographic digest), dates of creation and email confirmation, one-time links to confirm your email and change your password.
- Abuse protection: IP address, email typed at login and counts of attempts to log in, sign up, recover a password and run code. These counters live only in the server's memory, for at most one hour, and are not written to a database.
- Technical logs: the server logs requests (date and time, IP address, address accessed, browser and request result) to keep the service running and to investigate failures and attacks.
2.3 What we don't do
- We do not sell personal data.
- We do not use third-party advertising or tracking tools.
- We do not keep your login in the browser's
localStorageorsessionStorage.
3. What we use data for and on which legal basis
| Purpose | Data | Legal basis (LGPD, art. 7) |
|---|---|---|
| Create and maintain your account, allow you to log in | sign-up, Google data, account security | performance of a contract (V) |
| Run your code and show the result | code, results | performance of a contract (V) |
| Save your progress | progress and results | performance of a contract (V) |
| Gamification (XP, ember, goals, orders, challenges, achievements) | progress, results, time zone | performance of a contract (V) |
| Friends league, only for those who join | first name, weekly XP, friendships | consent (I), which you can withdraw by leaving the league |
| Send account emails (email confirmation, password change, billing and renewal notices) | name, email | performance of a contract (V) |
| Charge and manage the PRO subscription, refunds and cancellations | payment data, name, email | performance of a contract (V) |
| Keep payment records and tax documents | payment data | compliance with a legal obligation (II) |
| Protect accounts and the service against abuse and fraud | IP, attempts, technical logs | legitimate interest (IX) and fraud prevention (art. 11, II, "g", where applicable) |
| Keep access logs required by law | technical logs | compliance with a legal obligation (II) — Brazilian Internet Civil Framework (Marco Civil da Internet), art. 15 |
| Improve exercises and explanations based on aggregated data | aggregated results | legitimate interest (IX) |
| Forgy's help with artificial intelligence, when you ask (section 5) | the attempt's code, the exercise statement and the grading result | performance of a contract (V) |
Whenever we rely on legitimate interest, you may object (section 8).
4. Running your code
The code you submit runs on a separate, isolated server with no internet access, only to produce the exercise output. It does not run on your computer or on the server that stores your data. Treat exercise code as something the Forgile team may read to fix failures and improve the exercises; do not put passwords, documents or personal data in it.
5. Artificial intelligence
When your code doesn't pass, you can ask Forgy for a hint. Only at that moment, and only because you asked, we send to an artificial intelligence provider (Anthropic, which makes the Claude models):
- the exercise statement;
- the code of that attempt;
- the grading result you already see on screen (the compiler message or the failed test).
We do not send your name, email, password or any other account data. The generated hint is stored with the attempt, so you can see it again without sending anything new. We also store how many hints you used that day, to apply your plan's limit.
The AI explains and gives hints, but it never decides whether your code is correct: the tests decide. [Confirm in the contract with the provider: data sent through the API is not used to train models, and the provider's retention period.]
6. Who we share data with
We share data only with companies that help us run Forgile (processors), under contract and only for these purposes:
| Company | What for | Where |
|---|---|---|
| Amazon Web Services (AWS) | servers, database and code execution | Brazil (São Paulo) |
| Cloudflare | website delivery, DNS and attack protection | global network |
| Resend | sending account emails | Brazil (São Paulo), company headquartered in the US |
| sign in with Google, when you choose that option | US and other countries | |
| Stripe | payment for the PRO plan (card and Pix), when you subscribe | US and other countries |
| Anthropic | Forgy's help with AI, when you ask | US |
We may also share data when required by law, by court order or to defend Forgile's rights in legal proceedings.
7. International transfers
Some processors (Cloudflare, Resend, Google, Stripe and Anthropic) may process data outside Brazil. In these cases, we adopt the safeguards set out in art. 33 of the LGPD, such as [ANPD-approved standard] contractual clauses.
8. Your rights
You can, at any time and free of charge:
- confirm whether we process your data and access it;
- correct incomplete or outdated data;
- request the anonymization, blocking or deletion of unnecessary data or data processed in breach of the LGPD;
- request the portability of your data;
- request the deletion of your account and of the data processed based on your consent;
- find out who we share your data with;
- object to processing based on legitimate interest;
- request a review of decisions made solely on the basis of automated processing.
Two of these rights you can exercise on your own, on the Me page, under "Your account and your data":
- Download my data: a file with everything we store about you (account, progress, attempts with the submitted code, AI hints, reports and league). Passwords and access tokens are not included in the file.
- Delete my account: you confirm by typing your account email, and the account and all data linked to it are deleted immediately. This cannot be undone.
For the other rights, write to marketing@forgile.com from your account email. We reply within 15 days. You can also file a complaint with Brazil's National Data Protection Authority (ANPD).
9. How long we keep data
| Data | Period |
|---|---|
| Account, progress and submitted code | while the account exists; deleted as soon as you delete your account. Database backups are replaced within [30] days |
| Login sessions | up to 14 days after last use |
| Email confirmation and password change links | up to [48 hours] and [30 minutes], respectively; after that they no longer work |
| Attempt counters (abuse protection) | up to 1 hour, only in the server's memory |
| Access logs | 6 months (Marco Civil da Internet, art. 15) |
| Payment records and tax documents | [5] years, for the period set by tax law, even after the account is deleted |
| Backups | up to [7] days, then replaced |
We may keep data for longer when the law requires it or to defend rights in legal proceedings.
10. Cookies
We only use cookies needed for login to work and to keep it secure, plus two interface preference cookies (theme and language) that hold no personal data. We do not use advertising or analytics cookies.
| Cookie | What for | Duration |
|---|---|---|
forgile_refresh | keep you signed in securely (cannot be read by the page's scripts) | up to 14 days |
forgile_csrf | protect the login and sign-up forms against attacks from other sites | session |
JSESSIONID | complete sign in with Google | up to 10 minutes |
forgile_theme | remember the theme you chose (light or dark) on the website and the app, across the forgile.com domain; interface preference, not sensitive | 1 year |
forgile_lang | remember the language you chose (Portuguese, English or Spanish) on the website and the app, across the forgile.com domain; interface preference, not sensitive | 1 year |
If you block the login cookies, you won't be able to log in to your account. Without the preference cookies, Forgile follows your device's theme and language.
11. Security
We use encrypted connections (HTTPS), passwords hashed with bcrypt, tokens stored only as cryptographic digests, attempt limits, isolated code execution and restricted access to the servers. No system is completely secure: if an incident may cause you relevant risk or harm, we will notify you and the ANPD, as the LGPD requires.
12. Children and teenagers
[Forgile is intended for people aged [13] or older. Teenagers between [13] and 18 must use Forgile with the knowledge and permission of their parents or guardians. We do not knowingly collect data from children under 12; if we identify such an account, it will be deleted.]
13. Changes to this policy
We may update this policy. When the change is relevant, we will let you know by email or within Forgile before it takes effect. The date at the top shows the last update.
14. Contact
Questions about this policy or about your data: marketing@forgile.com.