Privacy Policy - Sharp Arena
Last updated: July 14, 2026 · Version: 1.0
This Privacy Policy explains how the Sharp Arena app (published in Portuguese as Arena Sagaz) - the "App" - collects, uses, shares, and protects your personal data.
1. Who controls your data
- Controller: Santiago Data, a brand operated by Fernando Santiago da Silva (an individual) - identification required by Brazil's data protection law.
- Data Protection Officer (DPO): contato@santiagodata.com.
- App support and questions: sharparena@santiagodata.com.
For the purposes of the Brazilian General Data Protection Law (LGPD, Law No. 13.709/2018), we are the controller of the data processed in the App.
2. Data we collect
a) That you provide:
- Email (when you create an email account or the provider shares it);
- Display name (the nickname you choose);
- Minimum-age declaration (your confirmation that you are 13 or older). We store only that confirmation, not your date of birth;
- Login method and your account identifier at the provider (Google, Apple).
b) Collected automatically:
- Device identifier and notification token (push);
- Platform (Android/iOS) and App version;
- Match logs - see section 4, which covers them separately;
- Usage and progress data (XP, streak, achievements);
- Aggregated analytics (Google Analytics for Firebase);
- Ad delivery data processed by Google AdMob (see section 7).
c) Guest: if you play as a guest, no account is required and nothing is sent to our servers - your progress and match logs stay on your device. They are sent to the server only if you later create an account; at that moment your local history is linked to it.
We do not collect sensitive data (racial origin, health, biometrics, precise location) or card data - there are no purchases in the App.
3. Why we use the data (purposes)
- To create and maintain your account and authenticate your login;
- To save and sync your progress, XP, streak, and achievements;
- To build the leaderboard (you can hide yourself from it at any time);
- To send notifications you have authorized or that you have not blocked;
- To verify age and enforce the access rules;
- To train and evaluate artificial intelligence models - see section 4;
- To show non-personalized ads (section 7);
- To improve the App (diagnostics, aggregated metrics, abuse and fraud prevention);
- To comply with legal obligations.
4. Match logs and AI training
What we record. For each move in a match we store: the state of the board before and after, the move chosen, who played it (you or the AI), the difficulty level, and the AI model's output (the probability it assigned to each possible move). We do not record audio, images, free text, or anything you type.
What it is for. Two uses:
- Running the game - leaderboard, XP, statistics, resuming a match;
- Training, evaluating, and improving the neural networks that play against you.
Legal basis. Processing match logs for use (2) is part of the performance of the contract to use the service (LGPD, art. 7, V) and a condition for using the App with an account. The App is free and was created to train this AI: by creating an account, you agree to make your match logs available for that purpose. You are not required to use the App - if you do not agree, do not create an account and, if you have already created one, delete it (section 9) and stop using the App.
Being honest about "anonymous". The move tables do not store your user identifier, but you can be reached by joining tables. That is pseudonymization, and under the LGPD (art. 12) pseudonymized data is still personal data - which is why we do not call it anonymous.
What we do about it. When we export data to train a model, the export is dissociated: without the keys that link a move to a match and to an account. The training set itself is anonymous.
5. Legal bases (LGPD, art. 7)
- Performance of a contract - providing the App and account service and making match logs available to train and evaluate the AI models (section 4), as a condition of the free service;
- Consent - notifications;
- Legitimate interest - security, fraud prevention, and product improvement;
- Compliance with a legal obligation.
6. Who we share with
We do not sell your data. We share it with processors that help us run the App, only as needed:
- Google / Firebase (Authentication, Cloud Messaging, Analytics, App Check) - login, notifications, metrics, and abuse protection;
- Login providers (Google, Apple) - solely to authenticate you;
- Google AdMob - ad delivery (section 7);
- Server infrastructure - hosting for the API and the database.
These partners may process data outside Brazil; when that happens, we apply safeguards compatible with the LGPD.
7. Ads
The App shows Google AdMob ads. In this version they are non-personalized: they are chosen by context, not by your history or your advertising identifier.
Even so, Google processes limited technical data (such as device type and an identifier used to cap frequency and prevent click fraud). If we ever move to personalized ads, we will ask for your consent first.
8. Notifications
Push notifications depend on your permission on the device. You can turn them off at any time in the system or App settings.
9. Retention and deletion
We keep your data for as long as your account exists. You may delete your account at any time, from within the App (see Account Deletion).
On deletion we anonymize your account (removing email, name, and the age declaration) and erase the data linked to you. Match logs that have already been dissociated may remain, anonymously, in training sets and game statistics - they can no longer be tied back to you.
10. Your rights (LGPD, art. 18)
You may request: confirmation of processing and access to your data, correction, anonymization/deletion, portability, information about sharing, withdrawal of consent, and objection to processing based on legitimate interest.
To exercise them, write to sharparena@santiagodata.com (or, if you prefer to reach the officer directly, contato@santiagodata.com). We answer within the legal deadlines.
11. Children and teenagers
The App requires you to be 13 or older to create an account, and refuses registration for anyone who does not confirm that age. We do not show personalized ads. If we learn that we have improperly collected a child's data, we will delete it.
12. Security
We apply technical and organizational measures - encryption in transit, access control, environment separation, app integrity verification - to protect your data. No system is 100% secure, but we work to reduce risk.
13. Changes to this Policy
We may update this Policy at any time. Significant changes will be announced inside the App, and we will ask you to accept them again. Each version is archived at its own immutable address (e.g. `/legal/1.0/en/privacidade`).
14. Contact
Questions and requests: sharparena@santiagodata.com. Data Protection Officer: contato@santiagodata.com.