Legality & Transparency

Privacy Policy

We built Bodivo to help you feel at home in your body. Your wellness journey is deeply personal, and we treat your personal data with rigorous care, total transparency, and unwavering respect for your privacy.

Effective: September 12, 2026
GDPR, CCPA & LGPD Aligned
~6 min read

Zero Data Selling

We never sell, rent, or trade your personal health records to data brokers or advertising networks.

You Own Your Data

You have the absolute right to export, correct, or permanently erase your data whenever you choose.

Purpose-Driven Only

We collect only what is strictly necessary to deliver meaningful wellness signals and keep your app secure.

Multi-Layer Security

Protected through physical, electronic, and procedural safeguards conforming to modern standards.

01

Overview & Scope

This privacy policy applies to the Bodivo app for mobile devices, together with any related services operated by RAFAEL RODRIGUES MARQUES DESENVOLVIMENTO DE SOFTWARE LTDA (DBA Dissociative Dreams St.), CNPJ 67.645.372/0001-46 (collectively, the "Application").

Throughout this document, Dissociative Dreams St. is referred to as the "Service Provider", "we", "us", or "our". This policy outlines the principles governing how personal data is collected, processed, retained, and safeguarded when you interact with the Application.

Fundamental Principle

Bodivo was designed under the principles of Privacy by Design and data minimization. Your fitness metrics and physical records remain under your absolute control, securely stored on your device.

02

Information Collection and Use

The Application collects information when you download and use it. For a better experience while using the Application, the Service Provider may require you to provide certain personally identifiable information.

User-Provided Data

Information you voluntarily provide when creating your profile or interacting with the app:

  • Email address
  • First name and last name
  • Age and gender
  • App usage and wellness preference data
Automatically Collected Data

Technical data recorded automatically to ensure operational stability:

  • Device Internet Protocol (IP) address
  • Pages visited inside the Application
  • Time and date of your visit
  • Time spent on specific pages and features
  • Device model, manufacturer, and operating system version

The information the Service Provider requests will be retained and used as described in this privacy policy.

Workout, physical evolution, and water intake information are stored locally on the user's device and are not transmitted to, collected, or stored on our servers.

The Service Provider may use the information you provide to send important information, required notices, and, where permitted by law, marketing communications.

03

Cookies & Tracking Technologies

The mobile Application does not use cookies in its native operation.

In our institutional and support web pages (dissociativedreams.com), only essential technical cookies are used to allow for safe navigation, load balancing, and language preferences.

We do not employ third party cookies for publicity behavioral monitoring or unsolicited tracking.

04

Your Rights

Under global privacy standards, including the General Data Protection Regulation (GDPR), you possess comprehensive legal rights over your personal data:

Right of Access

Request a copy of the personal data held by the Service Provider concerning you.

Right to Rectification

Request correction of any inaccurate, incomplete, or outdated personal data.

Right to Deletion

Request permanent erasure of your personal data from all active systems and backups.

Withdrawal of Consent

Withdraw previously granted consent at any time without affecting prior lawful processing.

To exercise any of these rights, contact the Service Provider directly at contact@dissociativedreams.com.

05

Regional Privacy Rights (LGPD & CCPA)

Depending on your place of residence or jurisdiction, specific statutory regulations afford you designated rights regarding your personal information. This section details our compliance with Brazil's Lei Geral de Proteção de Dados (LGPD, Lei Federal nº 13.709/2018) and the California Consumer Privacy Act (CCPA).

Lei Geral de Proteção de Dados (LGPD – Lei nº 13.709/2018)

If you are located in Brazil or if your personal data is processed in connection with the offering of services in Brazil, your data is protected under Brazil's Lei Geral de Proteção de Dados (LGPD, Lei Federal nº 13.709/2018). Data processing activities are conducted under the responsibility of the controller: RAFAEL RODRIGUES MARQUES DESENVOLVIMENTO DE SOFTWARE LTDA (DBA Dissociative Dreams St.), CNPJ 67.645.372/0001-46.

Sensitive Health Data & Local Storage (Art. 11 of LGPD)

Data relating to workout routines, measurements, and physical body composition constitute sensitive personal data related to health under Art. 5, II and Art. 11 of the LGPD. Bodivo was developed with a strict privacy architecture: this data remains exclusively in your device's local memory, without any transmission, collection, or retention on external or cloud servers by the controller.

Pursuant to Article 18 of the LGPD, you have the following rights as a data subject (titular de dados):

  • Confirmação e Acesso (Art. 18, I e II): Confirmation of the existence of processing and full access to your personal data.
  • Correção (Art. 18, III): Rectification of incomplete, inaccurate, or outdated information.
  • Anonimização, Bloqueio ou Eliminação (Art. 18, IV): Anonymization, blocking, or erasure of unnecessary, excessive, or unlawfully processed data.
  • Portabilidade (Art. 18, V): Portability of your data to another service provider upon express request, subject to commercial and industrial secrets.
  • Eliminação de Dados com Consentimento (Art. 18, VI): Deletion of personal data processed based on consent, except in cases where retention is legally authorized (Art. 16).
  • Informação sobre Compartilhamento (Art. 18, VII): Information regarding public and private entities with which the controller has shared personal data.
  • Informação e Revogação do Consentimento (Art. 18, VIII e IX): Information regarding the option to withhold consent and the associated consequences, as well as the right to revoke consent at any time through a free and facilitated procedure.
  • Revisão de Decisões Automatizadas (Art. 20): Right to request the review of decisions carried out solely by automated processing that affect your interests.

California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), affords you specific statutory protections:

  • Right to Know: The right to request disclosure of the categories and specific pieces of personal information collected, used, disclosed, or shared.
  • Right to Delete: The right to request the deletion of personal information collected from you, subject to statutory exceptions.
  • Right to Correct: The right to request rectification of inaccurate personal information maintained about you.
  • Right to Opt-Out of Sale / Sharing: The right to opt out of the sale or sharing of personal information for cross-context behavioral advertising. (Note: We do not sell or share your personal data).
  • Right to Limit Use of Sensitive Personal Information: The right to limit the use and disclosure of sensitive personal data strictly to what is necessary for delivering the Application's core functionality.
  • Right to Non-Discrimination: You have the right to receive equal service and pricing without discrimination for exercising any of your CCPA/CPRA rights.
Exercising Regional Rights & Encarregado (DPO)

To exercise your CCPA/CPRA or LGPD rights, submit your request to our Encarregado pelo Tratamento de Dados Pessoais (Data Protection Officer) at contact@dissociativedreams.com. Requests under the LGPD are answered immediately in simplified format, or within 15 (fifteen) business days for detailed declarations as provided by Art. 19, II. You also have the right to file a petition before the Brazilian Data Protection Authority (Autoridade Nacional de Proteção de Dados – ANPD) at gov.br/anpd ↗.

06

Third-Party Access & Infrastructure

Only aggregated, anonymized data is periodically transmitted to external services to help the Service Provider improve the Application and service quality.

The Application utilizes third-party services that possess their own independent Privacy Policies governing data processing. Below are the links to the privacy policies of the third-party service providers utilized by the Application:

The Service Provider strongly advises you to review the privacy policies of each external service provider linked above. The Service Provider has no control over and assumes no responsibility for the content, privacy policies, or practices of any third-party sites or services.

07

International Data Transfers

The Service Provider or its third-party service providers may transfer personal data to countries outside your country of residence, including outside the European Economic Area (EEA). Where applicable law requires safeguards for international transfers, the Service Provider will use appropriate mechanisms:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions or other legally recognized transfer mechanisms
  • Your consent, where required and legally permitted

Data protection laws in other countries may differ from those in your jurisdiction. Where required by law, the Service Provider will apply appropriate safeguards and obtain any consent required for the transfer.

08

Information Disclosure

The Service Provider may disclose User Provided and Automatically Collected Information:

  • As required by law: Such as to comply with a subpoena, court order, or similar legal process.
  • To protect rights and safety: When the Service Provider believes in good faith that disclosure is necessary to protect their rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
  • With trusted service providers: Who work on their behalf, do not have an independent use of the information disclosed to them, and have agreed to adhere to the rules set forth in this privacy statement.
09

Opt-Out Rights

You can stop all further collection of information by the Application by uninstalling it from your mobile device. You may use the standard uninstall processes as may be available as part of your mobile device or via the mobile application marketplace or network.

Important Note on Uninstalling

Uninstalling stops the Application from collecting new data from your device, but it does not automatically delete information that has already been transmitted to the Service Provider or to authorized third parties.

To request permanent deletion of your historical personal data, to withdraw consent, or to exercise any of your statutory rights, please contact the Service Provider at contact@dissociativedreams.com.

10

Data Retention Policy

The Service Provider retains personal data based on its necessity for the stated purposes and in strict accordance with statutory limitations:

Data Category Retention Duration Purpose & Rationale
User Provided Data Name, email, age, gender, habits Active use + 12 months Duration of your active use of the Application plus 12 months thereafter, unless a longer retention duration is mandated by law.
Automatically Collected Data IP address, visit logs, device telemetry Up to 24 months Retained for diagnostics, bug resolution, and security analysis from the date of collection.
Aggregated & Anonymized Data De-identified statistical data Indefinite Retained indefinitely for longitudinal trend analysis as it no longer identifies or links to you.
Legal Compliance Records Transaction logs, regulatory notices As required by law Retained for the period required to satisfy statutory, tax, audit, or legal dispute obligations.

You may request deletion of your personal data at any time, subject to any overriding legal obligation to retain it. If you want the Service Provider to delete User Provided Data submitted through the Application, please contact them at contact@dissociativedreams.com. Please note that some User Provided Data may be required for the Application to function properly.

11

Data Deletion Process

You can request complete deletion of your personal data or your entire account by contacting the Service Provider at contact@dissociativedreams.com. The Service Provider will process your request within the statutory timeframes required by applicable law (typically 30 days under GDPR/CCPA, or 15 business days under Brazilian LGPD).

Upon verification of your identity, the Service Provider will permanently delete your personal data from its active systems and associated database backups, except where retention is required for legal compliance or legitimate business purposes.

Submit an Instant Privacy Request

Click either button below to draft a pre-filled request directly to our data protection team from your email client:

12

Children's Privacy

The Application is not intended for children under 16 years of age, or such higher age as required by applicable law in your jurisdiction. The Service Provider does not knowingly solicit data from children or market the Application to them.

Where parental or guardian consent is required under applicable law, the Application is not intended for use without that consent. The Service Provider does not knowingly collect personally identifiable information from children under 16 years of age in violation of applicable law.

Notice to Parents & Guardians

In the event the Service Provider discovers that a child has provided personal information, the Service Provider will immediately delete this from their servers. If you are a parent or guardian and you are aware that your child has provided the Service Provider with personal information, please contact the Service Provider immediately at contact@dissociativedreams.com so that they will be able to take prompt corrective action.

13

Security Safeguards

The Service Provider is concerned about safeguarding the confidentiality of your information. The Service Provider provides physical, electronic, and procedural safeguards to protect information the Service Provider processes and maintains.

These protections include encrypted data transmission through TLS/SSL (Transport Layer Security), restricted internal access controls, regular vulnerability reviews, and secure server hosting environments.

Transparency Commitment

While we strive to maintain protections aligned with the highest industry standards, no method of electronic transmission or storage is 100% infallible. We encourage you to adopt secure, unique passwords and keep your device's operating system up to date.

14

Data Breach Notification

If a data security incident or breach occurs that affects your personal data, the Service Provider will notify you and relevant supervisory authorities in accordance with applicable legal requirements.

Where required, this notification will provide detailed information regarding the nature of the breach, the scope of data involved, likely consequences, and the immediate corrective measures taken to mitigate potential risks.

15

Changes to this Policy

The Service Provider may update this Privacy Policy from time to time. The Service Provider will notify you of material changes by posting the updated Privacy Policy with an updated effective date. Where required by law, the Service Provider will seek your consent to material changes before they take effect.

Previous versions of this Privacy Policy will be maintained and made available upon request by contacting the Service Provider at contact@dissociativedreams.com.

Effective Date: This privacy policy is effective as of 2026-09-12.

17

Contact Us

If you have any questions regarding privacy while using the Application, or have questions about our data practices, please contact the Service Provider:

Data Protection Officer (DPO) Privacy & Data Governance Team
Direct Contact Email contact@dissociativedreams.com
Data Controller Entity RAFAEL RODRIGUES MARQUES DESENVOLVIMENTO DE SOFTWARE LTDA
Trading Name & CNPJ Dissociative Dreams St. (CNPJ 67.645.372/0001-46)
Application Bodivo for Mobile
Response Timeframe Within 15 business days (LGPD) / 30 calendar days