1. Who we are
Relesk is operated by Danillo Estrela, an individual natural person, acting as the data controller under the LGPD and, where applicable, as the controller under the GDPR, for the Relesk task management service.
For privacy and data protection matters, please contact us at [email protected].
Relesk has not appointed a separate Data Protection Officer or person in charge. As a small processing agent under ANPD Resolution CD/ANPD No. 2/2022, Relesk provides this direct contact channel to handle data protection requests, questions and complaints.
If Relesk no longer qualifies as a small processing agent or becomes subject to additional requirements regarding representation or appointment of a data protection officer, this Policy will be updated accordingly.
2. What data we collect
We collect only the data necessary to operate, protect and improve Relesk, depending on the features you use.
- Account data: name, email address, password stored as a salted hash, never in plain text, optional avatar and basic account preferences.
- Task and project content: tasks, projects, comments, habits and other content you create, organize or import while using Relesk.
- OAuth-linked accounts: if you connect Google Sign-In, we receive basic Google profile data, such as your name and email address. If you connect Google Drive, we request only the
drive.filescope, which allows Relesk to access only files you explicitly upload through Relesk or select using the Google file picker. Relesk does not access your full Google Drive. If you connect GitHub, we store the minimum OAuth credentials necessary to display activity from linked repositories. - File metadata: for files or folders you explicitly connect, we may store file names, identifiers, file types, dates and other metadata necessary to support search, organization and linking inside Relesk. File contents are not indexed unless a specific feature requires it and that feature is clearly presented in the product.
- Technical data and logs: IP address, access date and time, basic device, browser and operating system information, authentication events, error records and security logs.
- Necessary cookies: Relesk may use cookies or similar technologies that are strictly necessary for authentication, session management, security and application functionality.
- Analytics and advertising: Relesk does not currently use analytics, behavioral tracking or third-party advertising technologies. If this changes, this Policy will be updated before implementation and, where required, consent will be requested.
3. Why we process your data
We process personal data under the following legal bases, as applicable:
- Performance of a contract: to create your account, authenticate your access, save tasks, projects, habits, comments and linked files, and provide the features you request or subscribe to.
- Consent: for optional processing, such as OAuth integrations, future analytics, marketing or other features that require specific authorization.
- Legitimate interest: for security, fraud prevention, abuse prevention, service stability, error analysis and infrastructure protection.
- Compliance with legal or regulatory obligations: when we need to retain or share data to comply with laws, court orders, valid authority requests or regulatory obligations.
- Exercise of legal rights: when necessary to protect the rights of Relesk, users or third parties in administrative, judicial or arbitration proceedings.
You may withdraw optional consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
4. How long we keep your data
We retain personal data only for as long as necessary to fulfill the purposes described in this Policy, subject to legal, contractual, regulatory and security requirements.
- Account data and user content: kept for as long as your account remains active.
- Account deletion: if you delete your account, we will erase or anonymize your personal data from our primary systems within 120 days, unless retention is necessary for legal compliance, security, fraud prevention or the exercise of legal rights.
- Backups: backup copies may retain data for an additional period until the backup cycle automatically expires, currently up to 30 days.
- Security and authentication logs: kept for up to 30 days, unless a longer period is necessary to investigate abuse, a security incident, legal obligation or service protection.
- External integration data: kept while the integration remains active or while necessary to provide the requested feature. When you revoke an integration, Relesk will stop accessing new data from that account and will delete or anonymize associated data according to the timelines above.
5. Who we share data with
Relesk does not sell your personal data and does not use third-party advertising.
We share data only with service providers necessary to operate, protect and make Relesk available. Each provider acts under contract and only for the purposes described in this Policy.
- VPS hosting provider: infrastructure used to host the application, database and related services. The provider name is available upon request at [email protected].
- Transactional email service: SMTP provider used to send essential emails, such as account confirmation, password recovery and security alerts. The provider name is available upon request.
- Google LLC: only when you use Google Sign-In or connect Google Drive.
- GitHub, Inc.: only when you connect your GitHub account.
- External AI providers: only when external AI features are enabled and configured in your workspace. Locally hosted models, such as Ollama, process data within infrastructure controlled by Relesk.
We may also share data with public authorities, courts, consultants, auditors or legal advisors when necessary to comply with a legal obligation, respond to valid requests, investigate incidents or protect the rights of Relesk, users or third parties.
6. International transfers
Relesk is operated from Brazil and its main infrastructure is hosted in Brazil.
However, depending on the features you use, some data may be processed or accessed outside Brazil, especially when you use Google Sign-In, connect Google Drive, connect GitHub, receive transactional emails sent by an international provider or use AI features provided by external providers.
When international transfers of personal data occur, we adopt appropriate safeguards under the LGPD, the GDPR where applicable and other applicable data protection laws, including standard contractual clauses, contractual, technical and organizational measures, or other legally valid mechanisms.
If you access Relesk from outside Brazil, your personal data may be transferred to Brazil so the service can be provided.
7. Your rights
Depending on where you live, you may have rights regarding your personal data, including the right to:
- confirm whether we process your data;
- access your data;
- correct incomplete, inaccurate or outdated data;
- request export or portability of your data, where applicable;
- request anonymization, blocking or deletion of unnecessary, excessive or unlawfully processed data;
- delete your account and associated personal data;
- withdraw optional consent;
- object to certain processing activities;
- request information about data sharing;
- lodge a complaint with the competent data protection authority.
In Relesk, you can edit your profile directly in the app, request an export of your data in a portable format, such as JSON, revoke external integrations and request account deletion.
To exercise any of your rights, contact us at [email protected].
If you are not satisfied with our response, you may lodge a complaint with your local data protection authority, such as the ANPD in Brazil or the relevant data protection authority in the European Union or the United Kingdom.
8. Security
We use technical and organizational measures to protect your personal data against unauthorized access, loss, alteration, destruction, improper disclosure or inappropriate processing.
These measures include:
- password storage using hash and salt;
- encryption at rest for sensitive credentials, such as connected account tokens;
- encryption in transit through TLS;
- restricted access to production systems;
- access control limited to authorized personnel;
- security and authentication logs;
- secure development practices.
No system is completely risk free. If a security incident creates a relevant risk or harm to data subjects, we will take the communication and mitigation measures required by applicable law.
9. Children
Relesk is not directed at children and is not intended for use by anyone below the minimum age required by applicable law in their region.
As a reference, the service should not be used by children under 13 in the United States under COPPA, or by children under 16 in the European Union, unless local law allows a lower age or valid parental consent is provided.
We do not knowingly collect personal data from children below these limits. If we become aware of improper collection, we will take steps to delete the data.
10. Changes to this Policy
We may update this Policy to reflect changes to Relesk, our data practices, integrations, providers or applicable law.
If we make material changes, we will update the “last updated” date and, where appropriate, notify you by email, in-app notice or another suitable method before the change takes effect.
11. Contact and complaints
Questions, requests or complaints about this Policy or how we process your personal data may be sent to:
See also our Terms of Use.
Relesk currently uses only cookies that are strictly necessary for authentication, security and application functionality. For this reason, we do not display a consent banner for optional cookies. If analytics, marketing, advertising or optional functionality cookies are adopted in the future, an appropriate information and consent mechanism will be made available where required by applicable law.