Skip to content
nanodorama
Sign in

Last updated: August 25, 2026

Privacy Policy

Last updated: 25 August 2026

This Policy explains how AIz Serviços de Inteligência Artificial Ltda. ("nanodorama", "we", "us") handles personal data in the context of the nanodorama platform (nanodorama.com and nanodorama.com.br and their subdomains — the "Service"). It was drafted in compliance with the Brazilian General Data Protection Law — LGPD (Law 13.709/2018).

Governing version. This Policy was drafted in Portuguese under Brazilian law. This English text is provided for convenience; in case of any discrepancy, the Portuguese version prevails.

1. Controller and Data Protection Officer

Data controller: AIz Serviços de Inteligência Artificial Ltda. CNPJ 66.955.511/0001-75 Av. Marechal Floriano, 399 – Rio de Janeiro/RJ, Brazil Email: leo@aizintel.com

Data Protection Officer (Encarregado): Reachable at leo@aizintel.com.

2. Data we collect

  • Anonymous session: when you open the Service, an anonymous identifier (Firebase UID) is created to hold your progress and lists before any sign-up. It is not tied to your name or email.
  • Account data: email and user identifier, including basic profile data when you use Google sign-in. The anonymous session is upgraded to this account, preserving your history.
  • Viewing data: episodes watched, playback position, favourited series, preferred subtitle language and interface language.
  • Purchase data: package bought, VIP plan, status, expiry date and coin statement. Full card details are handled directly by Stripe — we do not store them.
  • Content you submit: comments and profile picture.
  • Usage and security logs: IP address, browser/device identifier (user-agent), date and time, routes accessed and error codes.
  • Notifications: device token, when you allow push notifications.
  • Support communications: messages you send us.

We do not intentionally collect sensitive personal data, and the Service does not ask you to provide any.

3. Purposes and legal bases (LGPD art. 7)

Purpose Legal basis (LGPD)
Holding progress and preferences before sign-up Legitimate interest (art. 7, IX)
Account creation and authentication Performance of a contract (art. 7, V)
Catalogue playback and episode access control Performance of a contract (art. 7, V)
Billing, invoicing and fraud prevention Contract + legal obligation (art. 7, V and II)
Comment moderation and community safety Legitimate interest (art. 7, IX)
Information security and abuse prevention Legitimate interest (art. 7, IX)
Audience measurement and catalogue improvement Legitimate interest (art. 7, IX)
Compliance with legal and regulatory duties Legal obligation (art. 7, II)
New-episode notifications and marketing Consent (art. 7, I)
Non-essential cookies and identifiers Consent (art. 7, I)

4. Sharing with processors and third parties

We share data only with processors that provide services to us, under contract and only as far as necessary:

  • Google LLC / Google Cloud: authentication (Firebase Authentication), application hosting (Cloud Run), database (Firestore), video storage and delivery (Cloud Storage, Transcoder API, Media CDN), notifications (Firebase Cloud Messaging) and measurement (Google Analytics, BigQuery).
  • Stripe, Inc.: payment processing and fraud prevention.
  • Transactional email provider: receipts, welcome messages and operational notices.

We do not sell personal data. We may disclose data where required by law, court order or a competent authority, or to protect the rights, safety and integrity of the Service and of third parties.

5. International data transfers

The Service's infrastructure runs in the United States (Google Cloud region us-east1). This means the data described in section 2 is stored and processed outside Brazil, as is the processing carried out by Stripe.

These transfers comply with article 33 of the LGPD, using standard contractual clauses and other appropriate safeguards to ensure a level of protection consistent with Brazilian law. You may request information about those safeguards from the Data Protection Officer.

6. Retention periods

  • Anonymous session with no account: up to 12 months without access, after which the identifier and associated progress are deleted.
  • Account and viewing data: until the account is deleted.
  • Comments: until deleted by the author or with the account; comments removed by moderation are kept for up to 6 months to assess repeat behaviour.
  • Payment and tax records: for the period required by law (as a rule, up to 5 years).
  • Coin statement: for the life of the account, as it is the record that allows a disputed balance to be audited.
  • Usage and security logs: at least 6 months, under article 15 of the Brazilian Internet Civil Framework (Law 12.965/2014).
  • Support communications: up to 3 years.

Once the period or purpose ends, data is deleted or anonymised, except where the law requires retention.

7. Your rights (LGPD art. 18)

At any time you may request:

  • Confirmation that processing takes place;
  • Access to your data;
  • Correction of incomplete, inaccurate or out-of-date data;
  • Anonymisation, blocking or deletion of unnecessary or excessive data, or data processed unlawfully;
  • Portability to another provider, on request;
  • Deletion of data processed on the basis of consent;
  • Information about data sharing;
  • Information about the option to withhold consent and its consequences;
  • Withdrawal of consent;
  • Objection to processing carried out without consent, where the law has not been complied with;
  • Review of decisions taken solely by automated means.

To exercise your rights, write to leo@aizintel.com. We will respond within the periods set by the LGPD and may ask for information to confirm your identity.

8. Security

We apply technical and administrative measures to protect data, including: encryption in transit (TLS) and at rest, role-based access control, secret management (Google Secret Manager), short-lived signed video URLs, database rules that prevent the client from writing balances and unlocks, rate limiting, audit logging and monitoring.

If a security incident occurs that may cause significant risk or harm, we will notify the Brazilian data protection authority (ANPD) and the affected individuals, as required by law.

9. Automated decisions

9.1. Comment moderation. Comments are screened for toxicity in all four languages of the Service. The outcome may be removal or referral to human review.

9.2. Recommendation. The order in which series appear may take your viewing history into account. This produces no legal effects on you.

9.3. Under article 20 of the LGPD, you may request review of these decisions from the Data Protection Officer.

10. Children and adolescents

10.1. The Service is intended for users aged 16 or over and is not directed at children. We do not intentionally collect children's data; if we identify an account in that age group, it will be closed and the data deleted.

10.2. For users aged 16 and 17, processing follows the best interests of the data subject under article 14 of the LGPD, limited to what the Service needs to function.

11. Cookies and local storage

The Service uses local storage and essential cookies to keep your session, remember your chosen language (the nd_locale cookie) and hold your playback position. Measurement and marketing cookies depend on your consent and can be declined without losing access to the catalogue.

12. Supervisory authority

You have the right to lodge a complaint with the Brazilian National Data Protection Authority (ANPD)https://www.gov.br/anpd/ — if you believe your rights have not been respected.

13. Changes to this Policy

We may update this Policy from time to time. Material changes will be communicated through the Service, and the "Last updated" date always reflects the version in force.

14. Contact

For privacy questions, or to exercise your rights, contact the Data Protection Officer at leo@aizintel.com.

AIz Serviços de Inteligência Artificial Ltda. — Av. Marechal Floriano, 399 – Rio de Janeiro/RJ, Brazil — CNPJ 66.955.511/0001-75.