Privacy Policy

Last updated: 14 de setembro de 2026

Este documento está disponível apenas em inglês. É a versão de referência: um texto jurídico traduzido sem revisão pode alterar obrigações. (English)

This policy explains what personal data The Alchemist Letter platform processes, why, who it is shared with, and what you can demand about it.

The controller is BABINI E FASSINA TREINAMENTOS EM INFORMATICA LTDA., registered under CNPJ 12.651.460/0001-69. Privacy contact: privacy@thealchemistletter.com.

The platform hosts blogs and newsletters for independent authors. That splits the roles, and the split matters to you: when you subscribe to an author's newsletter, the person deciding what happens to your address is that author — we only run the infrastructure on their behalf. The policy for the blog you subscribed to lives at that blog's own address. This document covers what is ours: platform accounts, the thealchemistletter.com site, and the operation behind all of it.

1. Who is who

  • Controller, for platform accounts and the thealchemistletter.com site: BABINI E FASSINA TREINAMENTOS EM INFORMATICA LTDA..
  • Controller, for the subscribers of an author's newsletter: that author, who owns the blog.
  • Processor, for those same subscribers: us — we store and send on the author’s instruction, and never use their list for any purpose of our own.

2. Data we process

It depends on how you arrive.

If you hold a platform account (an author or an invited collaborator): name, email address, preferred language, role, and when you last signed in. If you sign in with Google or Microsoft we keep the identifier that provider gives us and the email it reports — never your password, which is not disclosed to us and which this platform stores for nobody.

If you subscribe to an author's newsletter: email address, language, the topics and newsletters you chose, and your consents — editorial, marketing and personalisation are recorded separately, because they are separate choices.

If you only read an article: we count the visit, and section 5 explains why that count does not identify you.

3. Security data that signing in produces

Signing in without a password does not mean signing in without a record. To contain automated attempts we keep login attempts — the email address typed, IP address, browser identification, whether it succeeded and, if not, why. The six-digit code emailed to you is stored only as a hash, lasts ten minutes, works once, and dies after five wrong attempts.

Administrative actions go into an audit log: who did what, when, from which IP. Without it there is no answering the question that matters after an incident — who touched this.

4. Email measurement

Newsletters sent through this platform measure delivery, opens and clicks. Concretely that means two things: the message carries a one-pixel image that loads when you open it, and links pass through a redirect before reaching their destination.

We say so plainly because it is invisible while reading. The measurement tells the author what was read; we do not sell this data and do not use it for advertising. If your mail client blocks images — Apple Mail does by default — the open is simply never recorded.

We also record bounces and spam complaints. A permanent bounce removes the address from every list on the platform, because the mailbox exists for nobody. A spam complaint removes you from the list of the author who sent that message, and only that one: you objected to a newsletter, not to every newsletter you may follow.

5. Article reads

We count views per article per day. No IP address, raw or derived, reaches our database.

To avoid counting the same person twice we derive a pseudonym from the request using a secret that rotates daily. That value lives only in temporary storage, for at most 48 hours, after which it is no longer linkable to any address — by us included. A fixed secret would turn the same calculation into a permanent visitor identifier, which would be personal data; the daily rotation is precisely what prevents that.

6. Legal bases

  • Consent (LGPD art. 7, I; GDPR art. 6(1)(a)): newsletter delivery, which you confirm by email before the first send and withdraw at any time.
  • Performance of a contract (art. 7, V; GDPR art. 6(1)(b)): your account, your site, your plan.
  • Legitimate interests (art. 7, IX; GDPR art. 6(1)(f)): service security — login attempt records, auditing and abuse prevention — and aggregate audience measurement.
  • Legal obligation (art. 7, II; GDPR art. 6(1)(c)): whatever the law requires us to retain, including tax records.

7. Who we share with

We do not sell personal data and do not hand it to third-party advertising. To function, the platform relies on the following providers, each receiving the minimum it needs:

ProviderPurposeWhat it receives
SendGrid (Twilio)Email delivery, open and click measurementRecipient's address and message content
ResendEmail delivery (alternative)Recipient's address and message content
GoogleSocial sign-in, when you choose itIdentity confirmation; we receive email and name
MicrosoftSocial sign-in, when you choose itIdentity confirmation; we receive email and name
OpenAIEditorial content generation and translationArticle text and public sources; no subscriber data
Google (Gemini)Content and image generationArticle text and public sources; no subscriber data
DigitalOceanHosting, database and file storageThe whole database, at rest
SentryError monitoringTechnical diagnostics, possibly including a user identifier
LinkedInArticle publishing, when the author enables itArticle content, by the author's action

Some of these providers operate outside Brazil, notably in the United States. International transfers rest on the contractual clauses and safeguards each of them offers.

The language models receive editorial material — public news, article drafts, the author’s own style samples. We do not send subscriber data to them.

8. How long we keep it

  • Active subscription: for as long as it lasts.
  • Cancelled subscription: the record of the cancellation stays, so you are not mailed again by mistake. A full deletion request erases that record too.
  • Login codes and signups in progress: they expire in minutes and are deleted within 24 hours.
  • Visitor pseudonym: at most 48 hours.
  • Audit and login attempt records: kept as long as incident investigation requires.
  • Closed account: deleted on request, save for what the law requires us to retain.

9. Your rights

The LGPD entitles you to confirm that processing exists, access the data, correct it, request anonymisation or deletion, request portability, withdraw consent and object to processing. Readers in the European Union hold equivalent rights under the GDPR.

Write to privacy@thealchemistletter.com. If the request concerns a particular author's newsletter we forward it to them, because the decision is theirs — and we tell you that we forwarded it.

Leaving a newsletter requires writing to nobody: every email carries an unsubscribe link that works without signing in, for 90 days from the send.

10. Cookies

The public site uses no advertising cookies and no third-party analytics. The admin area uses strictly necessary cookies to keep you signed in and to carry a signup from one step to the next.

11. Security

Traffic over HTTPS, no passwords at all by design, second-factor secrets stored encrypted, isolation between each site’s data enforced at database access rather than by the goodwill of whoever writes the query, and rate-limited sign-in. No system is impregnable; in an incident carrying relevant risk we will notify you and the national authority as the law requires.

12. Children

The service is not directed at people under 18, and we do not knowingly collect data from children. If you learn that this has happened, write to us and we will delete it.

13. Changes

If this policy changes materially we will email account holders and stamp the new date at the top of this page. This English version is the reference one where translations diverge.