At Grind1600 (“Company,” “we,” “us,” or “our”), we are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, share, and protect information about users (“you” or “User”) of the Grind1600 platform, including our website, mobile applications, and all related services (collectively, the “Services”). This policy is designed in compliance with the Lei Geral de Proteção de Dados (LGPD — Law No. 13,709/2018), the Marco Civil da Internet (Law No. 12,965/2014), and other applicable data protection regulations.
1Information We Collect
We collect the following categories of personal data when you use our Services:
Information you provide directly:
- Account information: your name, email address, and password when you create an account.
- Academic data: your current SAT scores, target scores, test date, study preferences, weekly schedule, and domain performance levels.
- Study activity: your question attempts, answers, time spent on questions, practice test results, daily progress statistics, and streak data.
- Profile information: any additional information you choose to add to your profile.
- Communications: messages, feedback, or support requests you send to us.
Information collected automatically:
- Device and browser information: device type, operating system, browser type, screen resolution, and language preferences.
- Usage data: pages visited, features used, session duration, click patterns, and navigation paths within the platform.
- Network information: IP address, approximate geographic location (country and region level), and internet service provider.
- Cookies and similar technologies: session identifiers, authentication tokens, and user preference settings stored locally on your device.
2How We Use Your Information
We process your personal data for the following purposes, in accordance with the legal bases established by the LGPD:
- Service delivery: to create and manage your account, provide personalized study plans, deliver adaptive practice questions, track your progress, and calculate score analytics.
- Personalization: to customize the learning experience based on your performance levels, study schedule, and domain strengths and weaknesses.
- Platform improvement: to analyze usage patterns, diagnose technical issues, improve existing features, and develop new functionality.
- Communication: to send you account-related notifications, study reminders, and respond to your support inquiries.
- Security: to protect against unauthorized access, fraud, and other security threats to the platform and its users.
- Legal compliance: to comply with applicable laws, regulations, and legal processes.
3Data Storage & Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption: passwords are hashed using industry-standard cryptographic algorithms (bcrypt) and are never stored in plain text.
- Secure authentication: we use token-based authentication (JWT) with secure session management to protect your account access.
- Access controls: only authorized personnel have access to personal data, and access is limited to what is necessary for their role.
- Regular security reviews: we periodically review and update our security practices to address emerging threats.
While we take reasonable steps to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your information.
4Data Sharing & Third-Party Services
We do not sell, rent, or trade your personal data to third parties. We may share your information in the following limited circumstances:
- Service providers: we may share data with trusted third-party providers who assist in operating our platform (such as hosting, analytics, and payment processing), under strict confidentiality agreements and data processing contracts as required by the LGPD.
- Legal requirements: we may disclose your data when required by law, court order, or governmental authority, or when necessary to protect our legal rights or the safety of our users.
- Business transfers: in the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction, with prior notice and in compliance with the LGPD.
- Aggregated and anonymized data: we may share aggregated, de-identified statistics about platform usage that cannot be used to identify any individual user.
5Cookies & Tracking Technologies
We use cookies and similar technologies for the following purposes:
- Essential cookies: required for the platform to function properly, including authentication session tokens and security measures. These cookies cannot be disabled.
- Functional cookies: used to remember your preferences, such as display settings and study schedule configurations.
- Analytics cookies: used to understand how users interact with the platform, which pages are most visited, and where users encounter issues. This data helps us improve the Services.
You can manage your cookie preferences through your browser settings. Please note that disabling essential cookies may impair the functionality of the platform.
6Your Rights Under the LGPD
In accordance with the Lei Geral de Proteção de Dados (LGPD), you have the following rights regarding your personal data:
- Right to confirmation and access: you may request confirmation of whether we process your personal data and access the data we hold about you.
- Right to correction: you may request the correction of incomplete, inaccurate, or outdated personal data.
- Right to anonymization, blocking, or deletion: you may request the anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in violation of the LGPD.
- Right to data portability: you may request the transfer of your personal data to another service provider, in accordance with regulations established by the Autoridade Nacional de Proteção de Dados (ANPD).
- Right to deletion: you may request the deletion of personal data processed with your consent, except where retention is legally required.
- Right to information about sharing: you may request information about the public and private entities with which we have shared your data.
- Right to revoke consent: you may revoke your consent at any time, without affecting the lawfulness of processing carried out prior to the revocation.
To exercise any of these rights, please contact us at support@grind1600.com. We will respond to your request within the timeframe established by applicable law.
7Children's Privacy
Our Services are available to users aged 13 and older. For users under the age of 18, we require parental or legal guardian consent before the collection and processing of personal data, in compliance with the LGPD and the Estatuto da Criança e do Adolescente (ECA).
We take special care to collect only the minimum amount of personal data necessary to provide the Services to minor users. We do not knowingly collect personal data from children under the age of 13. If we become aware that a child under 13 has provided us with personal data without appropriate parental consent, we will take steps to delete that information promptly. If you believe we have inadvertently collected data from a child under 13, please contact us at support@grind1600.com.
8Data Retention
We retain your personal data for as long as your account is active or as needed to provide you with the Services. After account deletion, we may retain certain data for the following purposes:
- Legal obligations: to comply with legal, regulatory, or tax requirements that mandate data retention for specified periods.
- Dispute resolution: to resolve disputes, enforce our agreements, and protect our legal rights.
- Aggregated analytics: anonymized and aggregated data may be retained indefinitely for statistical analysis and platform improvement purposes.
9International Data Transfers
Your data may be processed on servers located outside of Brazil. In such cases, we ensure that appropriate safeguards are in place to protect your data in accordance with the LGPD, including standard contractual clauses or other approved transfer mechanisms recognized by the Autoridade Nacional de Proteção de Dados (ANPD). We will only transfer your data to countries or organizations that provide an adequate level of data protection or under legally approved conditions.
10Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. We will notify you of any material changes by posting the updated policy on our platform and updating the “Last Updated” date at the top of this page. For significant changes that affect how we process your personal data, we may also notify you through email or an in-platform notification. We encourage you to review this policy periodically to stay informed about how we protect your data.
11Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please contact us:
- Email: support@grind1600.com
- Data Protection Officer: dpo@grind1600.com
You also have the right to file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) if you believe your data protection rights have been violated.