1. Controller and scope
BeMiVe is the controller of the personal data collected through the mobile app (iOS and Android), institutional website, backend APIs, admin panel, corporate portal, Amazon Alexa Skill, the integration gateway for ChatGPT and other AI assistants, the smartwatch module, push and e-mail notifications, and support channels.
BeMiVe is operated by a company established in Brazil. This Policy explains how we handle your information under Brazil's General Data Protection Law (LGPD, Law No. 13,709/2018) — our home legislation — and under the laws that apply where you live. If you reside in the United States, Canada or Australia, the region-specific section at the end of this Policy ("Additional information by region") supplements and, where they conflict, prevails over the general text for you.
The current version is available at bemive.com/en/privacy-policy and inside the app (Settings > Privacy Policy), as required by the app stores.
- Controller: W N P DE MATOS SOLUCOES EM INFORMATICA - ME, Brazilian company registry (CNPJ) 10.234.041/0001-04
- Data Protection Officer (DPO) / Privacy Officer: Weverly Matos (support@bemive.com)
2. Categories of data we collect
We collect only the data needed to provide and improve the services. The main categories are:
- Identification and contact: full name, e-mail, phone, profile photo, language, country, national ID number (CPF, when provided by users in Brazil), gender/biological sex, date of birth.
- Health and wellness data (sensitive data): hydration, weight, body measurements, blood pressure, blood glucose, laboratory and imaging exams, prescriptions, medications (including GLP-1 treatments), allergies, symptoms, habits, vaccines, workouts, goals and personalized plans, attachments (PDFs, images, reports).
- Dependants' and pets' data: name, relationship to the account holder, health information, family history, authorization of use.
- Smartwatch and wearable data: steps, distance, calories, heart rate, heart-rate variability, sleep data (duration, stages), oxygen saturation, physical activity (type, duration, intensity), sensor data.
- AI interaction data: queries made via ChatGPT and AI assistants, exam photos submitted for OCR/AI analysis, generated answers and insights, assistant conversation history.
- Transactional data: subscription history, Apple/Google store receipts and tokens, payment status, redeemed offers, linked corporate plan.
- Support data: tickets, real-time chat messages, voice recordings (Alexa), attachments sent to support, service ratings.
- Technical and usage data: device make and model, app and OS version, language, timezone, push identifiers (Firebase/APNS), IP address, error logs, performance and navigation metrics, saved preferences, analytics and crashlytics events.
- Inferred data and metadata: engagement profile, goal adherence, AI-generated health score, clusters for content campaigns and smart notifications.
- Integration data: social sign-in tokens (Google, Apple), Alexa Skill data, native calendars, Apple HealthKit, Android Health Connect, data imported from smartwatches, e-mail/cloud files.
- Corporate data (business portal): company identification, the employee's employment link, aggregated and anonymized team health data (never individual data).
We do not store credit card information; payment processing happens in the stores (Apple/Google) or in PCI-DSS certified gateways.
3. How data is obtained
- Data you provide directly when signing up, in forms, when uploading exams, answering questionnaires, contacting support and querying ChatGPT.
- Automatic collection performed by SDKs and libraries (Firebase, Google Analytics, Crashlytics, SignalR) for authentication, notifications, statistics, security and performance improvement.
- Sensor data collected automatically by connected smartwatches and wearables, such as heart rate, steps, sleep and physical activity.
- AI-generated data from automated exam analysis (OCR), health summaries and personalized insights.
- Authorized integrations with Alexa, ChatGPT, calendars, Apple HealthKit, Android Health Connect, storage services, app stores and notification providers.
- Corporate portal: employment-link data provided by the contracting company; health data is always provided directly by the employee.
4. Purposes and legal bases
| Purpose | Data examples | Legal basis |
|---|---|---|
| Create and maintain your account, authentication, social login and biometrics | Name, e-mail, password hash, social tokens | Performance of a contract |
| Monitor health, generate reports, plans and reminders | Sensitive health data, metrics, attachments | Express consent |
| Analyze exams with AI, generate the health summary, answer via ChatGPT | Exam photos, health data, queries | Express consent |
| Import smartwatch and wearable data | Heart rate, steps, sleep, activity | Express consent |
| Manage dependants, family and pets | Profile data, family relationships | Guardian's consent + performance of a contract |
| Send notifications, medical alerts and reminders | Push tokens, timezone, indicator name | Performance of a contract + legitimate interest |
| Offer plans, process payments, issue receipts | Transactional data, subscriptions | Performance of a contract + legal obligation |
| Corporate portal: aggregated, anonymized dashboard | Aggregated data (minimum group size), employment link | Legitimate interest + employee consent |
| Technical support, fraud prevention, privacy compliance | Tickets, messages, logs | Performance of a contract + legitimate interest + legal obligation |
| Analyze usage, metrics and app reliability | Analytics, device info, crashlytics | Legitimate interest (product improvement) |
| Display ads and targeted campaigns | Advertising IDs, usage profile | Consent (where required) + legitimate interest |
| Comply with legal, judicial and regulatory requirements | Logs, registration, history | Legal/regulatory obligation |
For sensitive health data we rely on specific, prominent, purpose-bound consent. You may withdraw consent at any time, without affecting the lawfulness of processing already carried out.
5. Sharing with third parties
We share data with processors that support our operation, under contracts requiring confidentiality and equivalent protection:
- Infrastructure and database: Amazon Web Services (AWS): EC2, RDS PostgreSQL and S3.
- File storage: AWS S3 for attachments, exams and reports.
- Authentication: Duende IdentityServer (centralized SSO, PKCE, rotating tokens).
- Notifications and analytics: Firebase (Cloud Messaging, Analytics, Crashlytics), APNS, transactional e-mail provider (Brevo).
- Social sign-in: Google Sign-In, Sign in with Apple.
- Voice assistant: Amazon Alexa Skill.
- AI assistant and insights (app): DeepSeek (api.deepseek.com) processes the text of your health records — assistant questions, exams, blood glucose, blood pressure, weight, medications and questionnaire answers — to generate explanations, summaries and insights. Data is sent only with the express consent you give in the app. DeepSeek's handling of data is governed by the DeepSeek terms and privacy policy.
- Exam reading (OCR): Google Cloud Vision extracts the text of exams and documents (images and PDFs) you upload. See Google Cloud Vision data usage.
- Assistant via ChatGPT (optional integration): OpenAI, when you connect BeMiVe to ChatGPT or other external assistants; queries are processed through a secure gateway, with consent at the moment of use.
- Payments: Apple App Store and Google Play Store for in-app purchases; authorized gateways for corporate subscriptions.
- Advertising: Google Mobile Ads/Ad Manager (free plan).
- Ad campaign measurement: Meta (Facebook App Events SDK) receives install events and aggregated app-usage events to measure acquisition campaigns. Health data is never sent to Meta.
- Smartwatches: manufacturers' APIs for importing sensor data.
- Sharing initiated by you: when you generate a shared-record link or the emergency card, the selected data becomes accessible to anyone holding the link (for example, doctors and family members) during its validity period. The emergency card is accessible without login, by design, for urgent situations. Accesses are logged and you can revoke them at any time in the app.
We do not sell personal data. We only share it when necessary for the purposes described here, with an adequate legal basis or a legal requirement.
6. Artificial intelligence and automated decisions
BeMiVe uses third-party artificial intelligence services to process health data. Before anything is sent, we ask for your express consent in the app, stating which data is sent and to which provider. The providers are:
- DeepSeek (api.deepseek.com): generates exam explanations, health summaries, assistant answers and insights from the text of your records. Data is transmitted encrypted and limited to the context of the request, governed by the DeepSeek terms and privacy policy.
- Google Cloud Vision: performs optical character recognition (OCR) on the exams and documents you upload. Per Google Cloud Vision data usage, submitted content is not used to train the service's models.
- OpenAI (ChatGPT) — optional integration: when you connect BeMiVe to ChatGPT or external assistants, queries are processed via a secure gateway, limited to context and subject to consent.
- Alexa Skill: voice commands are processed by Amazon to perform actions on the platform (checking medications, recording data, receiving reminders).
- Health summary and score: proprietary algorithms combine your data to generate a wellness score and personalized insights.
You can grant or withdraw AI-processing consent at any time in Settings › Privacy › My Consents. Refusing does not block the rest of the app. The AI only organizes and explains information based on public guidelines — it does not diagnose; clinical judgment always belongs to your physician.
What is never sent to AI providers: under no circumstances do we transmit passwords, authentication tokens, national ID numbers, phone, address, payment or card data, biometric data or third-party credentials. Only the content strictly necessary to the request context is sent; unrelated documents are not included. Sending happens exclusively through our backend gateway, with no direct communication between your device and the AI models.
You have the right to request a review of automated decisions, and information about the criteria and procedures used. To exercise this right, contact support@bemive.com.
7. International transfers
Servers and providers may be located in Brazil, the United States, the European Union and other jurisdictions. We adopt standard contractual clauses (SCCs), security policies and compliance requirements to ensure an adequate level of protection.
In particular, data processed by OpenAI (ChatGPT) and Amazon (Alexa) may be transferred to servers in the United States, under those providers' standard contractual clauses and security commitments; data processed by DeepSeek may be transferred to servers in China.
For transfers to countries without a recognized adequate level of protection, we carry out a transfer impact assessment (TIA), identifying the risks of the destination jurisdiction and adopting supplementary measures — encryption, data minimization and purpose restriction to the request context — in addition to standard contractual clauses.
8. Automatic monthly backup
BeMiVe automatically creates a monthly backup of your health data and medical record.
- Frequency: the 1st of every month, at 02:00.
- Location: file saved only on your device (Downloads/bemive/).
- Encryption: AES-256-GCM with HMAC-SHA256 protection.
- Retention: only the 2 most recent backups are kept.
- Control: can be disabled in the app settings at any time.
The file is never automatically sent to our servers. The decryption key is stored only on secure servers and can only be used by authorized administrators for a restoration you request.
9. Retention and disposal
We keep data while your account is active and for as long as needed to meet legal and contractual obligations. After you request account deletion:
- Registration data: anonymized right after the request is processed (7-day grace period).
- General health data (hydration, glucose, blood pressure, weight, symptoms): immediate soft delete + permanent erasure after 180 days.
- Clinical record data (exams, reports, prescriptions, medications, vaccines, appointments): for users in Brazil, retained for 20 years as required by Brazilian Law 13,787/2018 (medical records). For users outside Brazil, see "Additional information by region" below — this Brazilian statutory retention does not apply to you.
- Accounting and tax records: 5 years under tax law.
- Privacy audit logs: sensitive data sanitized after 30 days; structural logs kept for 5 years.
- Tokens and sessions: erased 30 days after account deletion.
After the applicable periods, data is irreversibly anonymized or securely erased, including data held by AI providers and third-party services. Automated erasure runs daily via a retention job.
10. Your rights
You (and, where applicable, your dependants through their guardian) can exercise the following rights:
- confirmation that we process your data;
- easy access to your data;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or erasure of unnecessary or excessive data;
- portability of your data to another provider, in a structured format;
- information about the entities with which your data has been shared;
- withdrawal of consent, at any time;
- objection to processing based on legitimate interest;
- review of decisions made solely on the basis of automated processing;
- erasure of data processed on the basis of consent.
How to exercise them: send your request to support@bemive.com or use "Support > Privacy" in the app. We may ask for additional information to confirm your identity. We respond within 15 days for users in Brazil and within 30 days for users in other regions (see the regional section for specifics).
Data export: you can request a full export of your data in a structured format (JSON/CSV) directly in the app or by the e-mail above.
Account deletion: you can delete your account directly in the app, at Settings > Privacy and Data > Delete account, confirming with your password and the displayed confirmation phrase. The account is immediately blocked on every channel (app, Alexa, ChatGPT, corporate portal) and personal data is anonymized after a 7-day grace period, during which the deletion can be cancelled; after that, the operation is irreversible. Erasure observes mandatory legal retention; where full erasure is not possible due to a legal obligation, data is anonymized. Requests can also be made at support@bemive.com.
11. Security measures
- Encryption in transit (HTTPS/TLS) and at rest (AWS RDS encryption, S3 server-side encryption, Flutter Secure Storage);
- Password hashing and salting (Argon2), rotating tokens and centralized authentication via Duende IdentityServer (SSO);
- Access management with logs, least-privilege principles and environment segregation;
- Vulnerability monitoring, periodic security testing and code review;
- Backup routines, disaster recovery and infrastructure redundancy;
- Encrypted communication with AI providers (ChatGPT, OCR) with no data retention by the provider;
- Anonymization in the corporate portal via k-anonymity (minimum of 5 participants per group) and pseudonymization for aggregated data;
- Incident response policy with timely notification to authorities and data subjects when required by law.
12. Advertising, tracking and cookies
On the free plan we display ads through Google AdMob. Linked SDKs and services (Firebase, Google Analytics, Google Mobile Ads) may collect identifiers for analytics, notifications and advertising. On the institutional website and corporate portal, cookies may be used for authentication, sessions and usage metrics. We do not use traditional cookies inside the mobile app.
Advertising consent: before showing ads, we collect your consent through a consent management platform (Google UMP). Without consent, we show only non-personalized ads (NPA), which do not use your history for targeting.
iOS — App Tracking Transparency (ATT): on iOS we present Apple's tracking prompt. The advertising identifier (IDFA) is only used for personalized ads and measurement if you authorize it; if you decline, we do not use the IDFA to track you and we show only non-personalized ads. The App Store privacy answers and Google Play Data Safety reflect these practices.
We do not sell your personal data and we do not share it with data brokers for targeted advertising. Your health data is never used to target or personalize ads — advertising relies only on advertising identifiers and signals unrelated to health. You can review or withdraw tracking consent at any time in your operating system settings (reset the advertising identifier or adjust tracking/ATT) and, on the website, manage cookie preferences where available.
13. Communications, marketing and notifications
We send essential communications (security, changes to terms, health alerts, medication reminders) on a contractual basis. Promotional messages, newsletters and campaigns can be controlled by you in the app or through the unsubscribe link in e-mails.
Push notifications can be disabled in your device settings, but this may affect critical health reminders. Alexa alerts follow the Skill's settings.
14. Children, adolescents and dependants
Creating an account requires a minimum age of 13; children under 13 do not have their own accounts — their data exists only as dependant profiles, registered and managed by the legal guardian. Processing of children's and adolescents' data is carried out in the minor's best interest, with specific, prominent consent from at least one parent or legal guardian. Regional age rules (such as Québec's under-14 parental consent requirement) are described in the regional section.
Parents or guardians are the primary controllers of dependants' data within the app's family context. We may request proof of guardianship before acting on requests related to dependants.
15. Corporate portal and employee data
In the corporate portal context, the contracting company acts as joint controller for employment-link data, and BeMiVe as controller of employees' health data.
The company never has access to employees' individual health data. The portal only provides aggregated, anonymized statistics, applying k-anonymity (minimum of 5 participants per group), pseudonymization and other recognized techniques to prevent individual re-identification within the state of the art; these processes may undergo independent audit. Health campaigns and questionnaires are optional for the employee.
16. Changes to this Policy
We may update this Policy to reflect legal, product, vendor or AI-feature changes. We will notify you by e-mail, push notification or in-app message. Substantial changes take effect 30 days after notice. Continued use after the new version takes effect indicates awareness of the changes.
17. Contact and Data Protection Officer
For questions, requests or to exercise data rights:
- Data Protection Officer (DPO) / Privacy Officer: Weverly Matos
- E-mail: support@bemive.com
- In-app channel: "Support" > "Privacy"
- Response time: 15 days (Brazil) / 30 days (other regions).
18. Incidents and reports
If you identify a vulnerability, misuse of your account or suspect a security incident, contact us immediately through the channels above. We will follow our incident response plan, investigate the event and notify the competent authority and affected data subjects when required by the applicable law (see the regional section for the authority in your region).
19. Device permissions
The app requests operating-system permissions only when needed for a specific feature, always with explanatory text at the moment of the request:
- Notifications: medication, appointment and vaccine reminders, health alerts.
- Camera and photo library: attaching exams, reports and prescriptions, and setting a profile photo.
- Microphone and speech recognition: voice commands and voice entries (assistant and Alexa).
- Face ID / biometrics: optional app lock.
- Calendar and reminders: syncing appointments and reminders, when you enable it.
- Apple HealthKit and Android Health Connect: importing smartwatch and wearable data (steps, heart rate, sleep, physical activity and other indicators you authorize).
- Ad tracking (ATT, iOS): use of the advertising identifier for personalized ads, only with your authorization (see section 12).
You can grant or revoke any permission at any time in iOS or Android settings. Denying a permission disables only the feature that depends on it.
20. Additional information by region
This section provides information required by the laws of the regions where BeMiVe is offered. Where it conflicts with the general text of this Policy, this section prevails for residents of the respective region.
20.1. United States
- Health app breach notification: as a vendor of personal health records, we comply with the FTC Health Breach Notification Rule: if there is a breach of unsecured identifiable health information, we will notify you, the Federal Trade Commission and, where required, the media, within the timeframes of the Rule.
- Consumer health data (Washington My Health My Data Act and similar state laws): we collect and share consumer health data only with your consent or as strictly necessary to provide a service you requested; you have the right to withdraw consent and to have your consumer health data deleted; we do not sell consumer health data, and we do not use geofencing around health care facilities.
- State privacy rights: we honor requests for access, correction, deletion and portability for all U.S. users regardless of state, using the contact channels in section 17, with a response within 30 days (extendable where the law allows). We do not "sell" or "share" personal information as those terms are defined by the California Consumer Privacy Act (CCPA/CPRA), and we do not discriminate against you for exercising your rights. You may appeal a refusal by replying to our decision; we will respond to the appeal within the legally required period.
- Not a HIPAA-covered entity: BeMiVe is a personal health-management tool used directly by you; it is not a health-care provider or health plan, and the data you record in it is generally not covered by HIPAA — it is protected by this Policy and the laws above.
- Retention: the 20-year Brazilian medical-record retention does not apply to you. Upon account deletion, your health data follows the deletion flow of section 9 (7-day grace period; permanent erasure after the 180-day window), unless a U.S. law applicable to you requires otherwise.
20.2. Canada (including Québec)
- PIPEDA: we process personal information under the federal Personal Information Protection and Electronic Documents Act: meaningful consent, purpose limitation, and your rights to access and correct your information. We respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (OPC).
- Québec (Law 25): the person in charge of the protection of personal information is Weverly Matos (support@bemive.com). We collect sensitive health information only with your express consent; you have the right to access and rectify your information, to data portability in a structured, commonly used technological format, and to withdraw consent. Parental consent is required for minors under 14. When a decision is based exclusively on automated processing, we inform you and you may submit observations to a member of our staff. In the event of a confidentiality incident presenting a risk of serious injury, we will notify the Commission d'accès à l'information (CAI) and the affected persons. Your information may be processed outside Québec (including in Brazil and the United States); we carry out privacy impact assessments for such transfers. You may file a complaint with the CAI.
- Retention: the 20-year Brazilian medical-record retention does not apply to you; deletion follows section 9 unless a Canadian law applicable to you requires otherwise.
20.3. Australia
- Privacy Act 1988 and the Australian Privacy Principles (APPs): health information is sensitive information and we collect it only with your consent (APP 3). This Policy is our APP 1 privacy policy. You may request access to and correction of your personal information (APPs 12 and 13); we respond within 30 days.
- Overseas disclosure (APP 8): your information is processed on servers outside Australia — mainly in Brazil and the United States (and China, for the optional DeepSeek AI features) — by the providers listed in section 5. We take reasonable steps to ensure overseas recipients handle your information consistently with the APPs.
- Data breaches: under the Notifiable Data Breaches scheme, if a data breach is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner (OAIC).
- Complaints: contact us first through section 17; we will investigate and respond within 30 days. If you are not satisfied, you may complain to the OAIC (oaic.gov.au).
- Retention: the 20-year Brazilian medical-record retention does not apply to you; deletion follows section 9, and we destroy or de-identify information that is no longer needed (APP 11.2), unless an Australian law applicable to you requires otherwise.