Privacy Policy — Loa
Last updated: August 13, 2026
This policy explains how the app Loa — Leia, Ouça e Anote handles information. The principle is simple: we collect the minimum necessary, and your documents are yours.
Controller and contact
This policy is maintained by islogicdev, an independent developer profile. For any privacy or data protection matter, write to islogicdev@gmail.com.
Who this policy applies to
This policy applies to the app "Loa — Leia, Ouça e Anote" (package com.islogicdev.reader), currently available through open testing on Google Play. The islogicdev site has its own policy, available on the Privacy page.
How the app works
Loa is a tool to import, organize, read and listen to the user’s own documents. It was built local-first:
- It works without an account: imported documents and notes stay only on your device.
- Read-aloud is processed on the device itself, using the system voice engine. The content you read is not sent to our servers for this feature.
- You pick files through the system picker. The app does not scan your storage for files.
- There is no book catalog, no distribution or sale of third-party content, and no encouragement of piracy. The content is always provided by you.
- The Pro Web Reader only opens public HTTPS pages you choose: the page is fetched directly from the source site, the text is extracted on the device and nothing is sent to islogicdev servers.
Data we process and why
Processing depends on the features you choose to use:
- Use without an account: documents, extracted text, notes, bookmarks, categories, progress and preferences stay on the device and are not sent to islogicdev servers. The system voice engine you choose may process text under that provider’s settings and policy.
- Optional account: we process your e-mail, internal user ID, sign-in provider and technical authentication data. Plain-text passwords are never available to islogicdev.
- Current public offer: documents, extracted text, notes, bookmarks, categories, progress and preferences stay on the device and are not uploaded for backup or sync. Continuity data created during closed testing remains protected and inaccessible from the app while the feature is paused, until account deletion or applicable operational handling.
- Subscription: Google Play and RevenueCat process purchase history, product and base plan, transaction identifiers, dates, environment and subscription status. islogicdev never receives your card number or full payment details.
- Security and operation: infrastructure providers may process IP address, network headers and limited technical logs for authentication, fraud prevention, diagnostics, availability and incident response.
- Support: if you contact us, we process your e-mail, message and any attachments you choose to send in order to handle the request.
- Web Reader (Pro): visited addresses, extracted text, cookies and cache stay only in the private on-device session and are erased when you leave. No browsing history is created. Only sites you explicitly save remain stored, on this device only. If Pro expires while the Web Reader is open, reading stops and temporary session data is erased immediately.
- Product metrics: this option is enabled by default and sends only content-free events about feature interactions and permitted technical context. They are aggregated in memory and kept on the server only as daily counts by event, allowed dimension and app version. We never send documents, extracted text, titles or file names, notes, bookmarks, searches, audio, email, account identifier, advertising identifier or a persistent device identifier.
- Metrics security: the IP address may be processed transiently by Supabase and other infrastructure providers during a request to limit abuse and protect the service. islogicdev does not include it in the metrics or store it in raw form in the analytics database; the derived technical scope expires within ten minutes and is not used to identify, locate or profile people.
- Crash diagnostics: if the app closes unexpectedly or hits an error, technical diagnostic data (error type, stack trace, device model, OS and app versions) may be sent to the Sentry monitoring service to identify and fix the problem. These reports do not include name, email, documents, notes or reading content.
Purposes and legal bases
- Performance of the service and contract: authenticate, restore purchases and deliver requested Free and Pro features.
- Consent or user choice where applicable: select local files and send content to support.
- Legitimate interests, after assessing necessity, proportionality and safeguards: protect accounts, prevent fraud, maintain availability, understand feature adoption, prioritize improvements and improve subscription operations.
- Compliance with legal or regulatory obligations and establishment, exercise or defence of rights.
What we do not do
- We show no ads and do not sell or rent personal data.
- We do not use documents, notes or voice for advertising, behavioral profiling or AI model training.
- We do not use an advertising identifier or behavioral tracking SDKs.
- Product metrics are limited to aggregate counts about features and permitted technical context; they do not reveal reading content, create individual profiles, or include screen recording or session replay.
App permissions
On Android, we use only what is necessary:
- Notifications and playback service: to keep read-aloud running with the screen locked and show the controls.
- File access: only through system pickers, to import what you choose.
- Google Play billing: to process subscriptions, if you choose to subscribe.
- Internet: used when you open pages in the Web Reader, use account and subscription features or, according to your app settings, send crash diagnostics and product metrics.
Sharing with processors and third parties
We use only necessary services and limit data to each integration’s purpose:
- Google Play and Google identity services: distribution, billing, purchase restore and Google sign-in.
- Supabase: authentication, database, backend functions, temporary protection of historical closed-test records, and receipt, abuse limiting and aggregation of product metrics.
- RevenueCat: purchase validation, Pro entitlement status, restore support and operational subscription metrics.
- The Android text-to-speech engine you select: voice generation under the settings and policy of the provider installed on the device.
- E-mail provider: delivery of authentication and support messages when needed.
- Authorities or third parties only when required by law, a valid order, or to protect rights and safety.
- Sentry (Functional Software, Inc.): receives technical crash and diagnostic reports to keep the app stable, without direct personal identifiers.
- Resend: delivers the daily operational summary to the team, containing only aggregate counts and no reading content or persistent identifiers.
Google, Supabase, RevenueCat, Sentry and Resend may process data outside Brazil. We use applicable contracts and safeguards for international transfers and remain responsible for selecting and supervising the processors.
Security and integrity
- Backend communications use encrypted connections in transit.
- The local database is encrypted and the session is stored in the system’s secure storage.
- The backend uses per-user isolation, Row Level Security, private storage, server credentials outside the app and server-side Pro validation.
- We apply data minimization, least privilege, logs without sensitive content and regular dependency updates.
- No system is invulnerable. If a relevant incident occurs, we will assess its impact and make the notices required by law.
Retention and deletion
- Local data remains on the device until you delete it or uninstall the app.
- The account remains while it exists. Historical closed-test continuity records, where present, remain protected and are deleted with the account or under the applicable operational process, except for minimum legal, antifraud or rights-related retention.
- Protected residual copies may remain for limited processor backup cycles and are deleted or overwritten under their respective processes.
- Google Play and RevenueCat may retain transaction records for periods required by their own obligations and terms.
- Support messages are kept only as long as necessary for the request, security and compliance records.
- Technical crash reports in Sentry are kept for up to 90 days and then automatically deleted, with no link to your account or identity.
- Before sending, the limited local metrics queue remains for no more than seven days and is cleared after server acknowledgement or when you turn the option off. The server keeps no individual events, only daily aggregate counts retained for up to 180 days to compare product evolution and plan improvements. Technical scopes used to limit abuse stop being used after ten minutes and are removed by the routine in the following minute.
Account and data deletion
You can request deletion of your account and associated data at any time. The step-by-step guide is on the dedicated page:
Your rights
Under the LGPD, you may request confirmation of processing, access, correction, anonymization, portability and deletion of your data, plus information about sharing and withdrawal of consent. To exercise any right, write to islogicdev@gmail.com. We reply as quickly as possible.
Product metrics are enabled by default. You can turn them off at any time under Settings > Privacy > Share usage metrics. Loa works normally without them. Turning them off stops new events from being sent and clears the pending local queue.
Teenagers and protection of minors
Loa is intended for people aged 13 or older and is not designed for children under 13. Minors must use accounts and online features with parental authorization where local law requires it. We process minors’ data in their best interests, without ads, chat, behavioral profiling or data sales. If we learn of use below the minimum age without valid authorization, we will take steps to restrict the account and delete applicable data.
Changes to this policy
This policy may be updated to reflect changes in the app or in legislation. When that happens, the date at the top will be revised. Relevant changes in data processing will be highlighted with reasonable notice.