1. Scope
This policy applies to applications published by Isaac Caires Santana under the ZRFISAAC identity. Features vary between applications. The sections concerning Google sign-in and Firebase apply only to applications that offer those features.
The examined project documents Firebase Authentication, Google account sign-in, and Cloud Firestore. No configuration confirming Firebase Analytics, Crashlytics, or Firebase Storage was found, so this policy does not describe those services as being used.
2. Google account and authentication
When an application offers “Sign in with Google,” authentication is handled by Firebase Authentication together with Google sign-in. After authorization, the application may receive basic account details such as name, email address, profile photo, and the unique account identifier known as the uid.
The application and Isaac Caires Santana never receive or store the Google account password. Application information is not saved to the user's personal Google Drive. It is associated with the Google sign-in and stored in the Firebase infrastructure used by the application.
3. Data that may be stored and why
In addition to account identification data, an application may store information entered by the user, depending on its features: sales, products or services, quantities, prices, discounts, payment methods, histories, customers, names, phone numbers, notes, debts, and payments.
This information is used to provide requested features, organize records, calculate totals, show history, track outstanding amounts, identify the correct account, synchronize information, and restore data on another device. We do not intentionally collect more information than is needed for the application's stated functions.
4. Customer and third-party data
Some applications allow users to enter information about customers or other people. This data may also be sent to Cloud Firestore even if that person does not use the application or have an account. The user entering the data is responsible for having a lawful purpose, providing any required notice, keeping it accurate, and avoiding unnecessary or excessive information.
Users must not enter sensitive, unlawful, offensive, or unauthorized third-party information.
5. Firestore, synchronization, and offline use
In applications with synchronization, data is stored in Cloud Firestore, part of the Firebase platform provided by Google. Each account is identified by the uid issued by Firebase Authentication. Signing in on another device with the same Google account may restore the data associated with that identifier.
Cloud Firestore may temporarily cache data on the device so the application can work without an internet connection. Pending changes may be synchronized when connectivity returns.
6. Security and service providers
Access is organized by uid. Firestore security rules must restrict each user to their own records and prevent access to another account's data. Firebase uses protected connections and encryption for data in transit and, for applicable services, at rest. No system can guarantee absolute security.
Personal data is not shared for third parties' own purposes. Google may process it as the authentication and database infrastructure provider as needed to deliver and protect the service and meet legal obligations. Read the Google Privacy Policy and Firebase privacy and security information.
7. Retention and deletion
Data is retained while the account is active or as long as needed to provide the application, resolve problems, prevent fraud, or comply with applicable law. Users may use an in-app “Delete account” option when available or request deletion through the contact email below.
Identity verification may be required. Once confirmed, the account and related data should be removed from active systems, except where temporary retention is legally required, needed for security, or limited to recovery copies.
8. Ads, analytics, diagnostics, and sale of data
The examined project did not show collection through Firebase Analytics, Crashlytics, Firebase Storage, or advertising tools. This policy does not state that those services are active. If an application adopts advertising, analytics, or diagnostics, the application and this policy must disclose it before or when that processing begins.
Isaac Caires Santana and ZRFISAAC applications do not sell personal data or use the information described here to create advertising profiles.
9. Your rights
Subject to applicable law, users may request confirmation of processing, access, correction, information about sharing, portability where applicable, anonymization, restriction or deletion of unnecessary or unlawful data, and withdrawal of consent when consent is the legal basis. Requests may require identity verification and remain subject to legal and technical limits.
10. Contact
The controller responsible for the applications and this processing is Isaac Caires Santana. For questions or access, correction, and deletion requests, email zrfisaac@gmail.com. We may ask for the email address used to sign in, but never for your Google password.