Maykon Christian Meneghel

Privacy Policy

Effective September 22, 2026.

This Policy explains what personal data my apps process, why, with whom it is shared and how you can exercise your rights. It is based on Brazil's General Data Protection Law (Law No. 13,709/2018, “LGPD”) and applies to every app listed in section 2. This English text is a translation; if there is any conflict, the Portuguese version prevails.

1. Who the controller is

The controller of the personal data processed by the apps is Maykon Christian Meneghel, an individual who develops and publishes the apps. In this Policy, “I”, “me” and “my” refer to him.

Contact for any privacy matter, including exercising your rights under the LGPD: maykonmeneghel@icloud.com. This address also serves as the contact channel of the person in charge of data processing.

2. Apps covered

I do not sell personal data, and none of the apps shows third-party advertising or tracks you across other apps or websites for advertising.

3. Data processed by all apps

3.1. Technical connection data

Whenever an app talks to a server, that server receives technical data inherent to the connection, such as IP address, date and time of the request and information about the device and operating system. Infrastructure providers may log this data for security and diagnostics.

3.2. Purchases and subscriptions

In-app purchases are processed by the Apple App Store or Google Play, which act as independent controllers of payment data. I do not receive your card number or billing details. The apps receive from the store only what is needed to unlock what you bought, such as the product purchased, the purchase status and transaction identifiers.

3.3. E-mail contact

If you write to me, I process your e-mail address and the content of your message to reply and, where applicable, to handle your request.

4. Data processed by each app

4.1. Pocket English

Anonymous account. The first time you open the app, an anonymous session is created in Firebase Authentication (Google). It generates a random user identifier that is not linked to your name, e-mail or phone number. The app does not ask you to sign up.

App backend. The Pocket English backend is hosted on Amazon Web Services (AWS), in the São Paulo region (sa-east-1). Linked to the anonymous identifier, it stores:

AI conversation practice. In the Practice feature, your answers (typed or transcribed from your speech) and the lesson context — the situation, your English level and the lesson vocabulary — are sent, through the backend, to Anthropic (Claude model), which generates the virtual partner's reply and a short evaluation. Do not type personal data in your answers; the field is free text and is sent as typed or transcribed.

Speech synthesis. Lesson phrases and the virtual partner's lines may be sent, through the backend, to ElevenLabs to generate audio. The generated audio is cached on your device. Some audio may also be produced by the operating system's built-in text-to-speech, with nothing sent to a server.

Speech recognition (microphone). If you choose to answer by voice, the app asks for microphone access and uses the operating system's speech recognizer (Apple on iOS, Google on Android). Depending on the device and its settings, the audio may be processed on Apple's or Google's servers under their policies. The app uses only the transcribed text; it does not record the audio or send it to the backend.

Suggestions. If you send a suggestion from Settings, the text, the anonymous identifier and the date and time are saved in Cloud Firestore (Google). The database access rules allow creating suggestions but do not allow the app to read, change or delete them.

Firebase services (Google). Besides Authentication and Firestore, the app uses Firebase Analytics, which automatically collects usage and device data (for example, app-open and session events, device model, operating system, language, approximate country and app instance identifiers) for aggregate statistics; Firebase App Check, which uses Apple App Attest or Google Play Integrity to verify that requests come from a genuine copy of the app; and Firebase Remote Config, which delivers settings to the app.

Lesson content. New lessons are downloaded from the same backend on AWS. That request uses the anonymous identifier to authenticate the call and sends nothing beyond the technical connection data described in section 3.1.

Data kept only on the device. Preferences (such as English level and theme), completed lessons, a copy of the lessons and cached audio stay in the device's local storage and are deleted when the app is uninstalled.

Purposes: to provide lessons and AI practice, manage plan, credits and usage limits, unlock purchases, protect the service against abuse, receive suggestions and understand in aggregate how the app is used.

4.2. Neoos

Account. You can sign in anonymously, with a link sent to your e-mail or with your Google account, through Firebase Authentication (Google). When you sign in with e-mail or Google, the app saves your e-mail address, display name (if any) and last sign-in date in Cloud Firestore. You can change your display name in Profile.

Portfolio. The assets you add to your list are saved in Cloud Firestore, linked to your account: asset code, name, exchange, type, country, currency and date added. The app does not ask for quantities, purchase prices or amounts invested.

News and market data. To fetch news and asset information, the app queries the providers EODHD, Finnhub, NewsAPI and Marketaux directly. These requests include the codes (tickers) of the assets in your portfolio and the terms you type in the asset search, plus technical connection data. Your e-mail and name are not sent to these providers.

Sentiment analysis. News sentiment is classified on the device by a machine-learning model bundled with the app. Texts are not sent to any server for this analysis.

Reading news. When you open a news item, the publisher's page loads inside the app, and preview images and logos may be loaded from third-party sites. If you use the translate option, the article address is opened in Google Translate. Those sites follow their own privacy policies.

Other Firebase services. The app uses Firebase Remote Config to receive settings and includes Firebase Cloud Messaging, which may generate a device identifier for sending notifications if you allow them.

Subscription. The subscription is purchased through the App Store or Google Play and checked on the device using the information provided by the store (section 3.2).

Purposes: to keep your account and sync your portfolio across devices, show news and data related to your assets and unlock subscription features.

4.3. Coach Management

Data stored on your computer. The data you enter — clients (name, phone, address, date of birth, profession, social media and notes), sessions, assessments and payments — is stored locally on your computer in a local database. It is not sent to servers of mine, and you can delete it within the app.

The coach's role. Regarding your clients' data, you, the professional using the app, decide what is entered and why. You are therefore the controller of that data under the LGPD and are responsible for having a legal basis to process it and for informing your clients.

Video sessions (LiveKit). Live sessions use LiveKit Cloud. During a call, participants' audio and video travel through LiveKit's infrastructure, and the participant's name (for example, the client's name) is included in the room access token. The client joins from a web browser, through the LiveKit Meet app, using the generated link. The app does not record sessions.

Google Calendar and Google Meet. If you connect your Google account, the app asks, via OAuth, for permission to access your Google Calendar and then creates events with a Google Meet link. The event title includes the client's name. Access lasts while the app is open and can be revoked at any time in your Google Account settings.

Actions you start. Features such as opening an address in Google Maps, sending the session link via WhatsApp or searching Google Scholar open those services with the data needed for the action, and their policies then apply.

Purposes: to let you organize your coaching work, hold video sessions and schedule sessions in your calendar.

I process personal data under the legal bases of article 7 of the LGPD, as shown below.

ProcessingLegal basis
Creating and keeping the account (anonymous or not), syncing the portfolio, providing lessons, AI practice, speech synthesis, news and video sessionsPerformance of a contract or preliminary procedures at the data subject's request (art. 7, V)
Managing plan, credits, purchases and usage limitsPerformance of a contract (art. 7, V)
Aggregate usage statistics, abuse and fraud prevention, app integrity checks and technical connection dataLegitimate interest (art. 7, IX), always respecting your rights and expectations
Microphone use, sending suggestions, connecting a Google Account and notificationsConsent (art. 7, I), which you give by enabling the feature and may withdraw at any time
Keeping records of purchases and of data subject requestsCompliance with a legal or regulatory obligation (art. 7, II) and regular exercise of rights (art. 7, VI)

6. Sharing and processors

The apps rely on service providers that process personal data on my behalf (processors) or act as independent controllers. I share only what is needed for each purpose described above.

ProviderAppPurpose
Google (Firebase: Authentication, Firestore, Analytics, App Check, Remote Config, Cloud Messaging)Pocket English, NeoosAccounts, database, statistics, abuse protection, settings and notifications
Amazon Web ServicesPocket EnglishHosting the backend and lesson content (São Paulo region)
AnthropicPocket EnglishGenerating conversation-practice replies
ElevenLabsPocket EnglishSpeech synthesis
Apple and Google (system speech recognition)Pocket EnglishTranscribing speech when you use the microphone
EODHD, Finnhub, NewsAPI, MarketauxNeoosNews and market data
LiveKitCoach ManagementAudio and video transmission for sessions
Google (Calendar and Meet)Coach ManagementCreating events and meeting links when you connect your account
Apple (App Store) and Google (Google Play)AllApp distribution and payment processing (independent controllers)

I may also share data when required by law, by order of a competent authority or to defend rights in judicial, administrative or arbitration proceedings.

7. International transfers

Several of these providers, including Google, Anthropic, ElevenLabs, LiveKit and the news providers, process data on servers outside Brazil, mainly in the United States. These transfers rely on the grounds in article 33 of the LGPD, such as the need to provide the service you requested and the contractual safeguards offered by the providers, which may include standard data protection clauses.

8. Retention and deletion

Once the purpose ends, data is deleted or anonymized, unless the law allows or requires it to be kept (article 16 of the LGPD).

9. Security

I apply reasonable technical and organizational measures to protect data, such as encrypted communication (HTTPS/TLS), authentication of backend requests, app integrity checks and restrictive database access rules. No system is completely secure; if you find a vulnerability, please write to the contact address. If a security incident may create relevant risk or harm, I will notify Brazil's National Data Protection Authority (ANPD) and the affected data subjects, as required by article 48 of the LGPD.

10. Your rights

Under article 18 of the LGPD, you may request at any time:

How to exercise them: send an e-mail to maykonmeneghel@icloud.com stating which app you use and what you would like. I may ask for information to confirm the request is yours. Because Pocket English uses only an anonymous identifier, you may need to provide purchase details (for example, the store receipt) so I can locate the records; without them, it may not be possible to link the data to you. For Neoos, provide the account e-mail. I reply within the time limits set by article 19 of the LGPD.

You can also revoke permissions (microphone, notifications, Google Account access) in your device or account settings, and you have the right to lodge a complaint with the ANPD.

Client data entered into Coach Management stays on the coach's computer and is not accessible to me; requests about that data should be sent directly to the coach who entered it.

11. Children and teenagers

The apps are not directed to children under 13. Pocket English has an all-ages content rating in the stores; that rating concerns the content and does not mean the app is aimed at children, and I recommend that children use it under the supervision of a parent or guardian. Neoos and Coach Management are intended for adults. I do not knowingly collect personal data from children. If you are a parent or guardian and believe a child provided personal data without the consent required by article 14 of the LGPD, write to the contact address so the data can be deleted.

12. Changes to this Policy

This Policy may be updated, for example when an app gains a new feature or changes service provider. The effective date at the top shows the current version. Material changes will be announced on this page and, where appropriate, in the app.

13. Contact

Maykon Christian Meneghel
maykonmeneghel@icloud.com