Last updated: August 14, 2026.
This Privacy Policy describes how Reversa collects, uses, and protects your personal data, in accordance with Brazil's General Data Protection Law (LGPD — Law 13.709/2018). Reversa is the data controller.
Account data (via email/password, Google, or Apple login): email, display name, profile photo (when provided by the login provider), and login method used.
App usage data generated as you use the features: saved favorites (food, calculation mode, and value entered), food diary entries (food, amount, calories, and macros at the time logged), marketing communication preference (opt-in in your profile), and your account plan (Free/PRO). Your language and theme (light/dark) preferences are saved only on your device — they're not sent to our servers.
Push notification token, generated by your device when you allow notifications, used to send app alerts (like diary reminders).
Technical and diagnostic data, collected automatically via Firebase Analytics and Firebase Crashlytics (Google): app usage events (e.g., screens visited, actions taken), device/install identifiers, and crash reports for bug diagnosis.
Website waitlist data: if you leave your email in the waitlist form on reversa.io, we store that email and the language of the page it was submitted from. To block automated submissions, the form uses Cloudflare Turnstile, which processes your IP address at that moment. This collection is independent of the app: you can join the waitlist without having a Reversa account.
We process your data based on: contract performance (data needed for the app you signed up to use), consent (marketing communications, revocable anytime in your profile; and the email left in the website waitlist, revocable via the contact email below), and legitimate interest (technical diagnostics for app stability, and protecting the waitlist form against automated abuse).
We don't sell your data. We share data only with service providers that run the app's infrastructure, acting as data processors (LGPD art. 5, VII):
These providers process data under their own security and privacy policies, and only have access to what's necessary to provide the service we've contracted from them.
Your data is stored while your account is active. When you delete your account from the app, your profile, favorites, diary, and notification token data tied to the account are permanently removed. Aggregated diagnostic reports (Crashlytics/Analytics) may retain non-directly- identifiable data for an additional period, per Firebase's own policy.
The email left in the website waitlist is kept until the app launches or until you ask us to remove it, whichever comes first.
Access to each user's data is restricted via Row Level Security at the database level: each account can only access its own favorites, diary, and profile. Communication between the app and our servers uses encrypted connections (HTTPS/TLS).
Under LGPD, you can at any time:
To exercise these rights, use the options in the app or contact us at the email below.
Reversa is not directed at children under 13 and does not knowingly collect data from children outside that age range.
We may update this Policy periodically. Material changes will be communicated in the app or by email.
Questions or requests about your personal data: contato@reversa.io.