1. Who we are and what this policy covers
This policy describes how the quebragalho.dev service ("service", "we") handles personal data. quebragalho.dev is an API gateway that lets you access language models from different providers through a single endpoint, with a web dashboard to manage API keys and follow usage.
The policy applies to the quebragalho.dev website, the
service's web dashboard, and the gateway API. For the purposes of Brazil's
General Data Protection Law (Law No. 13.709/2018), the service acts as
controller of the account and usage data described below,
and as processor with respect to the content you send to
models through the API.
Contact channel for any privacy matter: contato@quebragalho.dev.
2. Data we collect
2.1 Account data
When you create an account, we collect your name, your email address, and, when you set a password, only its cryptographic hash — never the password in clear text.
If you choose an interface language in the dashboard, that preference is associated with your account so it can be reapplied on a later visit. It does not change billing, balance, aggregation time zone, or the payment method.
2.2 Data received from Google when using "Sign in with Google"
If you choose to sign in with your Google Account, we receive from Google,
with your authorization, only the following data from the
openid, email, and profile scopes:
- your display name;
- your email address and whether it has been verified;
- the URL of your profile photo, when it exists;
- the unique identifier of your Google Account.
We do not receive your Google password and we do not request access to Gmail, Google Drive, Google Calendar, contacts, or any other service on your Google Account.
2.3 Service usage data
For each API request we record operational metadata: date and time, requested model, destination provider, input and output token counts, estimated cost, duration, status code, and the identifier of the API key used.
We do not record the content of your requests or the models' responses. Prompts and completions pass through the gateway in memory, are forwarded to the chosen provider, and are not written to logs, a database, or an audit trail.
2.4 Technical data
IP address, user agent, and HTTP request information, collected transiently for security, abuse prevention, rate limiting, and fault diagnosis.
2.5 Cookies
We use only strictly necessary cookies: a session cookie to keep you
authenticated in the dashboard; security cookies against request forgery;
and the qg_locale cookie, exclusive to the dashboard host, which
stores this browser's interface-language preference. That cookie is a
presentation hint: it does not authenticate, does not grant access, and does
not replace the preference stored on the account when you are signed in.
If you reach the dashboard through a referral link, we set the
qg_ref cookie, exclusive to the dashboard host, with the code of
the person who referred you, for up to 30 days. It serves only to associate
your account, if you create it within that period, with the person who
referred you; it is deleted as soon as you sign into an account and is not
used for tracking or shared with third parties.
We do not use advertising cookies, cross-site tracking, or behavioral profiling, and there is no third-party analytics on this site.
3. Why we use this data
- Create and authenticate your account
- Data received from Google, or the email and password you register, are used exclusively to identify you and allow access to the dashboard.
- Provide the contracted service
- Forward your requests to the corresponding model provider and issue and revoke API keys.
- Measure usage and bill
- Calculate tokens and cost per request, show history in the dashboard, and, when there is a charge, issue the amount due.
- Security and integrity
- Detect abuse, apply usage limits, investigate incidents, and keep an audit trail of administrative actions.
- Operational communications
- Send messages about your account, such as sign-up confirmation, password reset, and downtime notices. We do not send marketing.
The corresponding legal bases under the LGPD are performance of the contract (art. 7, V), compliance with a legal or regulatory obligation (art. 7, II), legitimate interest in security and fraud prevention (art. 7, IX), and, for Google authentication, your consent given on the authorization screen (art. 7, I).
4. Limited use of Google API data
Use and transfer, by quebragalho.dev, of information received from Google APIs comply with the Google API Services User Data Policy, including the Limited Use requirements.
In concrete terms, this means that data obtained from Google:
- are used only to authenticate you and maintain your account;
- are not sold, rented, or shared with data brokers;
- are not used for advertising, remarketing, profiling, or any purpose not described in this policy;
- are not used to train generalized or personalized artificial-intelligence models;
- are not read by people, except with your express authorization, to resolve a support issue you reported, as required by law, or in aggregated and anonymized form for security purposes.
5. Who we share with
We do not sell personal data. Sharing occurs only with service providers needed to operate the product, limited to the indispensable minimum:
- Language-model providers — receive the content of the requests you yourself send to the gateway, to produce the response. Treatment of that content is then also governed by the policy of the destination provider you chose on the request.
- Hosting and database infrastructure — servers where the service runs and account data is stored.
- Content delivery network and DNS — for availability and protection against attacks.
- Resend, transactional email delivery — receives your address and the body of the operational message described in section 3 (password recovery, email confirmation). We do not send marketing.
- Woovi / OpenPix and PushinPay, Pix payment processors — receive the amount and the charge identifier to issue the QR Code and notify us of settlement. Payer data (name, CPF, institution) stay with the processor and your bank: they are not stored here — when the payment confirmation lookup returns them, we discard them without saving. Of the payment we keep only amount, date, charge identifier, and which account it credited.
We may also disclose data when required by a court order or competent authority, limiting disclosure to what is strictly determined.
5.1 Who referred you
If your account was created from a referral link, the person who referred you
sees on the "Referrals" page of their dashboard: your partially masked email
(for example, ga•••@gm•••.com), the date you created the
account, whether you have made a paid top-up, and the amount of credit they
received for it — which, under the program rules, allows inferring the value
range of your first top-up up to the program cap. They do not see the exact
amount, the date of the top-up, or any other data of yours. The masked email
is a pseudonymization: anyone who already knows your email may recognize it.
6. International transfer
Part of the infrastructure is located outside Brazil, including servers in the European Union and the United States. In those cases the transfer occurs under article 33 of the LGPD, for performance of the contract and under contractual clauses that require an adequate level of protection from the providers.
7. How long we keep data
- Account data — while the account exists, and for up to 30 days after deletion, to allow reversal of accidental deletions.
- Usage metadata and billing records — for up to 5 years, a period compatible with tax obligations and with challenging amounts.
- Technical and security records — for up to 6 months, under article 15 of the Brazilian Civil Rights Framework for the Internet.
- Request and response content — is not stored, as in section 2.3.
8. Security
All traffic is encrypted with TLS. API keys are stored only as a hash and shown only once, at issuance. Provider credentials are encrypted at rest. Administrative access is restricted, authenticated, and audited. No security measure is infallible; in case of an incident with relevant risk to your rights, we will notify you and the National Data Protection Authority within the legal time limits.
9. Your rights
Under article 18 of the LGPD, you may request at any time: confirmation that processing exists; access to your data; correction of incomplete or outdated data; anonymization, blocking, or deletion of unnecessary data or data processed out of compliance; portability; information about who we share with; and withdrawal of consent.
To exercise any of these rights, write to contato@quebragalho.dev. We reply within 15 calendar days. We may request additional information to confirm your identity before fulfilling the request.
9.1 How to delete your account and revoke Google access
You may request deletion of the account and all associated data through the email above. Independently of that, you may revoke the authorization granted to quebragalho.dev at any time at myaccount.google.com/permissions. Revocation prevents new Google sign-ins, but does not by itself delete the account already created on the service — for that, make the deletion request.
10. Children and adolescents
The service is not intended for anyone under 18, and we do not intentionally collect data from children or adolescents. If we become aware of an account in those conditions, the account will be deleted.
11. Changes to this policy
We may update this policy to reflect changes in the service or in the law. The last-updated date at the top of the page always indicates the version in force. Material changes will be communicated by email or a dashboard notice before they take effect.