Transparency
Cookies and data
This page describes everything the platform keeps about you, for how long and why. It is short because the list is short.
What we do not do
- We use no analytics — not Google Analytics, not anything equivalent.
- There is no advertising and no tracking pixel.
- We do not sell, rent or share your data with third parties.
- We build no behavioural profile and do not follow you across sites.
The cookies
There are two, both ours, both required for the site to work. Neither can be read by JavaScript.
| Cookie | What it is for | Duration |
|---|---|---|
__Host-fasorx_sessao |
Keeps you signed in. Without it, every page would ask you to sign in again. | 5 hours of inactivity 12 hours in total at most |
fasorx_oauth |
Protects the return from the Google or Microsoft sign-in against request forgery. | 10 minutes |
The session is renewed while you use the platform, so working never signs anyone out; the 5-hour clock only runs while you are away. The 12-hour ceiling is renewed by nothing — once past it, you have to sign in again.
Being strictly necessary, these cookies do not require consent — that is what the Brazilian LGPD (art. 7) and the ANPD cookie guidance say, and the GDPR reaches the same conclusion for essential cookies. That is why the notice in the footer informs rather than asks: a “reject” button here would either do nothing or sign you out. You can delete them at any time in your browser settings; the effect is being signed out.
The footer notice records in your browser’s localStorage that it has been dismissed. That stays on your device and is never sent to us.
What your account keeps
- Name and email, coming from Google or Microsoft when you sign in.
- Institution, type and intended use, if you fill them in — they are optional and let us know who uses the platform.
- The dates the account was created and of your last sign-in.
Your email is stored encrypted (AES-256-GCM), and lookups go through an index that cannot be reversed back to the address. A copy of the database leaked without the key gives up no email at all.
We hold no password. Google or Microsoft is who authenticates you; all we get back is the confirmation, your name and your email.
The access log
Every time you sign in, and every time you open one of the applications, we keep a row with date and time, which provider, which application, the IP address and whether the access came from a phone or a computer.
It serves security — spotting access that should not be there — and lets us know how much the platform is used. It is not used for advertising or profiling, and it does not leave here. Whoever administers the platform sees this log with the emails masked (abc***@example.com).
Who else sees anything
- Google and Microsoft — only when you choose to sign in through them, and they already know you did. They receive nothing from us.
- Cloudflare — delivers the site and filters attacks. It sees the traffic, as any network provider does, and runs Turnstile on the contact form to tell a person from a robot.
Your rights
You can ask to see, correct or delete your data. Deleting the account also removes the access log tied to it. Write to the platform contact and we will answer.
Last reviewed: 2026-10-11.