LogNPortuguêsEnglishEspañol

LogN Privacy Policy

Version 4 · Effective from September 30, 2026

This policy explains what data LogN collects, what for, where it is kept, for how long, and how you exercise your rights. It describes what the app does today. If anything changes, we publish a new version (section 14).

1. Who is responsible for your data

The data controller, under Brazil's General Data Protection Law (Law No. 13,709/2018, "LGPD"), is:

  • Legal name: JOSE CLEITON BORGES CORREIA (Brazilian sole proprietorship, "Empresário Individual")
  • Trade name: CLEITON TECH
  • CNPJ (Brazilian company registration number): 40.463.475/0001-39
  • Address: Caminho das Árvores, 1057, Salvador Shopping Business, Torre América, salas 911 e 912, Salvador (BA), CEP 41.820-790, Brazil
  • Privacy contact and data protection officer (DPO): contact@logn.sh

In this policy, "we" means the controller above, and "you" means the person using the app.

2. Where LogN is available

LogN is offered in every country except those of the European Union, the United Kingdom and China. This policy was written for those countries of distribution.

3. What data we collect

3.1 When you create an account

  • Email address. It is your login and the address we send verification codes to.
  • Password, when the account is created with an email. We do not store your password. We store only a cryptographic digest of it (an Argon2id hash), which cannot be turned back into the original password.
  • Signing in with Google, Apple or GitHub. If you create the account or sign in with one of them, we receive from that service your email address, the fact that it was verified, and an identifier for your account on it, which we keep to recognize you on later sign-ins. We do not receive your name, your photo or your password on those services. With Apple, if you choose to hide your email, we receive a forwarding address created by Apple instead of yours. With GitHub, the email is the account's primary one, and the access GitHub gives LogN to read this information is deleted right after the sign-in. If the email we receive already has a LogN account, the sign-in is linked to that account.
  • Minimum age confirmation. At sign-up you tick a box confirming you meet the minimum age. We store the date and time of that confirmation and the country it applied to. We do not ask for or store your date of birth.
  • Acceptance of the documents. We store which versions of these terms and this policy you accepted, in which language and when, and a cryptographic digest (hash) of the accepted text. When you accept a new version in the app, we also store which version you came from, which changes the screen showed, the app version and the device's system (iOS or Android). The time is our server's.
  • Account creation date.

3.2 When you play with an account

  • Game events. Each answer to a challenge becomes a record containing: the challenge, the trail node, the challenge type, whether the answer was accepted, the time, and an integrity code (hash) that chains each record to the previous one. The text of your answer is not sent.
  • Progress. Your XP, counters of challenges solved, progress on each trail node, and the list of challenges that have already earned XP.

3.3 When you buy a paid trail

  • Purchase record. The store you bought from gives us the record of each transaction, with the product bought, the transaction identifiers and date, the store environment and your LogN account identifier, which the app puts in the purchase. On the App Store, it is a record signed by Apple; on Google Play, the server looks the purchase up on Google Play itself, with the purchase token the app sends. We keep this record as the store delivers it, and it may also include the price, the currency and the store's country. We do not receive your card number or any other payment data: the store does the charging.
  • Licence. Which trail the account bought, whether the licence is active or revoked and, if revoked, the reason (section 10 of the Terms of Use). Revoked transactions are kept on a list, so they do not come back through a purchase or a restore.
  • Device record. When a device asks for the licence of a purchased trail, we store a LogN identifier for that device, the trail, and the first and last time it asked. On iPhone, it is the identifier iOS gives LogN (identifierForVendor), the same for apps from the same developer on the device. On Android, it is a random identifier the app creates when it is installed: it is not shared with other apps, and it changes if you reinstall LogN. Neither is the advertising identifier. It is used to identify account sharing, and it does not limit how many devices you use.
  • Manual revocation and appeal. If we revoke the licence for a trail because of redistribution of the content or account sharing (section 10.5 of the Terms of Use), we keep a history of each step: the reason, our note of what was observed and where, the answer to your appeal, when each step happened and the internal LogN account that recorded it. It is the evidence the terms say we keep, and it is what we use to answer the appeal.

3.4 Codes sent by email

To confirm your email at sign-up and to reset your password, we send a six-digit code. The database stores only a cryptographic digest of the code (not the code itself), its purpose, its expiry (15 minutes), the number of wrong attempts and the time it was sent. The code is deleted as soon as it is used.

3.5 Session

When you sign in, we create a session. On the server we store only a cryptographic digest of the session token and its expiry. The session lasts 30 days and renews each time it is used.

3.6 Usage data (telemetry)

We collect data about how the app is used, to understand and improve the product. Section 6 details what is sent and how to turn it off.

3.7 Server technical logs

The server writes operational records (logs) containing your account identifier, without your email address, for example when a progress upload is accepted or rejected. The hosting platform (Google Cloud Run) also records each request made to the server, with the IP address and the identifier of the app or browser that made it. These records are kept for up to 30 days.

Every request to the server first goes through Cloudflare, which protects the API against abuse and, to do so, sees the IP address and the request (section 7).

To limit attempts at signing in, signing up and requesting codes, the server uses the IP address of the request. This happens in the server's memory, and the IP is not written to the database.

3.8 What we do not collect

We do not ask for your name, date of birth, phone number, location, contacts, photos or the device's advertising identifier. The device identifier of section 3.3 is only stored for a purchased trail. We do not use your data for advertising, we do not sell it, and we do not track you across third-party apps or websites.

3.9 Waiting list for the iPhone version

On the logn.sh website you can leave your email address to be told when LogN comes out for iPhone. You do not need an account. We keep:

  • the email address;
  • the language of the website you signed up on, which is the language of the email we send;
  • when you signed up, when we sent the confirmation email and when you confirmed.

Right after you sign up, we send an email with a confirmation link. Only those who open that link and confirm join the list. We send a single notice, when the iPhone version comes out. Every email from the list carries the link to leave it, and leaving deletes your email address from the list right away. The link does not carry your email address, and your email address does not go into the server's technical logs.

To keep robots from using the form, and to keep it from being used against other people's addresses, the server uses the IP address of whoever signs up to limit requests, in memory only and without writing it down, as in section 3.7.

4. What is stored on your device

To work without an internet connection, the app keeps some information on the device itself:

  • In the system's password vault (Keychain on iPhone, Android Keystore on Android): the token that keeps you signed in and the key that opens each purchased paid trail. They stay on this device only and are not included in backups.
  • In the app's local storage: your email address, the session expiry, answers not yet sent to the server (offline queue), a copy of the trail and your progress so the app can open offline, the list of problem origins you have already seen and, for each downloaded paid trail, the encrypted package with its content and the offline licence period. The package may go into the device's backup, because it does not open without the key.

When you sign out, the app deletes from the device the token, the email address, the session expiry, the offline queue and the trail copy. The key and the package of paid trails belong to the account that bought them: they stay on the device to open again when that account comes back, and are removed when the licence is revoked or when you delete the trail from the device.

Guest mode. You can play without an account. In that case your progress stays on the device only and is not sent to the server. If you delete the app, that progress is lost.

5. What we use your data for, and on what legal basis

PurposeDataLegal basis (LGPD, art. 7)
Creating and maintaining your account, authenticating you and sending verification codesEmail, password hash, Google, Apple or GitHub identifier, session, codesPerformance of a contract (item V)
Storing and syncing your progressGame events, progress, XPPerformance of a contract (item V)
Unlocking purchased paid trails, restoring purchases and handling refundsPurchase record, licencePerformance of a contract (item V)
Identifying account sharing and purchase fraudDevice record, purchase record, manual revocation historyLegitimate interest and regular exercise of rights (items IX and VI)
Proving the age confirmation and the acceptance of the documentsConfirmation date, country, accepted versions and language, hash of the accepted text, version you came from, changes shown, app version and systemCompliance with a legal obligation and regular exercise of rights (items II and VI)
Protecting the service against abuse (attempt limits, technical logs)IP address and account identifier in technical logsLegitimate interest (item IX)
Understanding how the app is usedUsage data (section 6)Legitimate interest (item IX), with an option to turn it off
Telling you, a single time, that the iPhone version is out (section 3.9)Email, language, dates of sign-up, sending and confirmationConsent (item I), which you withdraw by leaving the list
Finding and fixing app failuresErrors, crash reports, technical logs and performance measurements, not linked to the account when usage analytics is off (section 6)Legitimate interest (item IX)

6. Usage data (telemetry)

We use PostHog, a product analytics service with servers in the United States. It is analysis done only by us, about the use of LogN itself. It is not used to track you across other apps or websites, which is why the app does not show the system's tracking permission prompt (App Tracking Transparency).

What is sent:

  • when the app is opened, moves to the background or is closed;
  • when you get a challenge right or wrong, with the identifier of that answer;
  • app errors and performance measurements, so we can find failures;
  • crash reports, when the app closes on its own;
  • technical logs of calls to the LogN server that did not succeed: which route was called and the response code, without the content sent or received.

Crash reports: if the app closes on its own, the next time it opens it sends a report with the kind of failure, the sequence of app calls at the moment it happened, the app and system versions, and the device model. The report does not include what you typed or the content of your answers.

How you are identified: if you have an account, by the account's internal identifier. We never send your email address to PostHog. If you play as a guest, by a random identifier that PostHog itself creates and keeps on the device. It is neither the advertising identifier nor the identifier the device's system assigns to it.

IP address: the app is configured so that the IP is not associated with events, and PostHog discards the client IP.

How to turn it off: the app has a "Usage analytics" switch, which is on by default. When you turn it off, the app stops sending usage data. The choice is saved on the device and also applies to guests.

Errors keep going: even with the switch off, the app keeps sending errors, crash reports, technical logs and performance measurements, so we can find failures. When you turn it off, the app switches to a new anonymous identifier, and these reports are no longer linked to your account.

7. Who we share your data with

We use these providers (processors) to run the app. They process data on our behalf and only to provide the contracted service:

ProviderWhat forWhere
SupabaseDatabase holding your account and progressUSA (region us-east-1)
Google Cloud RunAPI server and technical logsUSA (region us-east1)
ResendSending the emails with codes and the waiting list emailsUSA (region us-east-1)
PostHogUsage data (telemetry)USA
CloudflareProxy and protection of the API and the website against abuse: receives the IP address and the requests in transitGlobal network

Google, Apple and GitHub: if you sign in with one of them, the sign-in happens on that service's screen, under each one's privacy policy, and it learns that you used LogN. They are not LogN's providers: we receive from them only what section 3.1 describes.

Google Play and App Store: buying a paid trail happens in your device's store, under its privacy policy: Google on Google Play, and Apple on the App Store, charge and process the payment. In that purchase, the store is not LogN's provider: we receive from it only the transaction record (section 3.3).

We do not sell your data and do not share it with advertisers. We may hand data over to authorities when the law or a court order requires it.

8. International transfer

None of your data is stored in Brazil: all the providers above process data outside Brazilian territory. This international transfer is based on article 33 of the LGPD, under the data processing agreements we have with each provider.

9. How long we keep data

  • Account and progress: for as long as the account exists. We do not delete accounts for inactivity.
  • Licences, device record and manual revocation history: for as long as the account exists.
  • Purchase records: kept for 5 years from the transaction, including after the account is deleted, so the purchase can be restored to a new account, so we can handle refunds and fraud, and so we can defend ourselves in a dispute (LGPD, art. 16, I and II, and art. 7, VI). After deletion, the record keeps the identifier of the deleted account, which the store's record carries inside it, and not your email address. After the 5 years, it is erased. The list of revoked transactions follows the same period.
  • Email codes: until used or replaced by a new code; each one is valid for 15 minutes.
  • Server technical logs: up to 30 days.
  • Waiting list for the iPhone version: a confirmed sign-up is kept until the iPhone version comes out and the notice is sent, or until you leave the list, whichever comes first. A sign-up that is not confirmed is deleted 7 days after it was made.
  • Email delivery metadata at Resend: up to 30 days.
  • Usage data, errors and measurements at PostHog: up to 30 days, including those of a deleted account. The app stops sending them with the account's identifier as soon as you request deletion.

No backups. Our database has no backup copies. So when an account is erased, the erasure is final.

10. How to delete your account

You can delete your account inside the app, under Manage account → Delete my account. The app asks you to type the word EXCLUIR and confirm it is you: with your password, or by signing in again with Google, Apple or GitHub. If the account also signs in with Apple, the confirmation must go through Apple.

  1. Immediately: the account is deactivated and all open sessions are ended, on every device. If you confirmed with Apple, Google or GitHub, the authorization you gave LogN on that service is revoked, and LogN leaves the list of apps with access to your account there.
  2. During the next 30 days: if you sign in or reset your password, the deletion is cancelled and everything goes back to how it was.
  3. After 30 days: an automatic process that runs once a day erases the account. In practice, erasure happens within 31 days of the request.

What is erased: your email address, password hash, Google, Apple and GitHub identifiers, sessions, game events, progress, XP, paid trail licences, the device record, the manual revocation history, the age confirmation and acceptance records, and pending codes. Deleting the account does not refund purchased trails, and the purchase records stay for the period in section 9, with the identifier of the deleted account and without your email address. The data at PostHog is not erased item by item: it disappears through the 30-day retention (section 9).

Answers not yet sent: if there are answers in the offline queue of the device where you request deletion, they are discarded. The app warns you before you confirm.

What stays outside the database: the server's and hosting platform's technical logs, with the account identifier and the IP address and without the email address, which disappear on their own within 30 days; and the email delivery metadata kept by Resend (section 9).

11. Your rights

Under the LGPD (art. 18), you may request:

  • confirmation that we process your data, and access to it;
  • correction of incomplete, inaccurate or outdated data;
  • anonymisation, blocking or erasure of unnecessary or excessive data, or data processed in breach of the law;
  • portability of your data;
  • erasure of data processed on the basis of your consent;
  • information about who we share your data with;
  • information about the possibility of not giving consent and the consequences of refusing;
  • withdrawal of consent;
  • objection to processing based on legitimate interest, such as telemetry (which you can also turn off in the app, section 6).

How to request: account deletion can be done in the app itself (section 10). For all other requests, including receiving a copy of your data, write to contact@logn.sh. We reply within 15 days. To protect your account, we only act on requests sent from the email address registered to it, or we ask you to confirm the request by replying from that address.

You may also complain to Brazil's National Data Protection Authority (ANPD) or to the data protection authority of your country.

12. Minimum age

To create an account, you must be 13 or the minimum age required by the law of your country, if higher. Confirmation is done through a box at sign-up. We do not ask for or store your date of birth.

If we learn that an account belongs to someone under the minimum age, it is deleted, without the 30-day grace period of section 10. Parents or guardians can tell us at contact@logn.sh.

13. Security

  • Passwords stored only as Argon2id hashes.
  • Session tokens and email codes stored only as cryptographic digests.
  • Session renewed on each use; changing your password ends all open sessions.
  • Communication between the app and the server over HTTPS.
  • Paid trail purchases confirmed by the server with the store itself, never by the device alone: against Apple's signature on the App Store, and by asking Google Play on Google Play.
  • Downloaded paid trails stored encrypted (AES-256-GCM), with the key in the device's password vault (section 4).
  • Each email code accepts at most 5 wrong attempts, and a new code can only be requested after 60 seconds.
  • Per-IP request limits on the sign-in, sign-up and code routes.

No system is completely secure. If a security incident occurs that may cause you significant risk or harm, we will notify you and the ANPD, as the LGPD requires (art. 48). The notice to you goes to your account's email address and appears in the app, within 3 business days of our learning of the incident, the deadline set by Resolution CD/ANPD No. 15/2024.

14. Changes to this policy

When we change this policy, we will publish a new version with a new effective date and let you know in the app. If the change is significant, we will ask you to accept the new version in the app before you continue using your account.

15. Language

This policy exists in Portuguese, English and Spanish. If the versions differ, the Portuguese version prevails.

16. Contact

Privacy questions, requests and complaints: contact@logn.sh.