Home/Privacy Policy

Privacy Policy

PRIVACY POLICY — MAINSAFE AI SKILL MANAGER

Last updated: September 1, 2026

This Privacy Policy explains how RSA Consultoria e Treinamento Ltda., operating under the MainSafe / MainSafe Soluções brand, processes personal data in connection with MainSafe AI Skill Manager.

RSA Consultoria e Treinamento Ltda. is registered under Brazilian CNPJ No. 33.601.650/0001-41 and has its address at Avenida Amazonas, 115 – Sala 1102, Centro – Belo Horizonte – Minas Gerais – Brazil.

For the purposes of this Policy, the company may be referred to as “MainSafe”.

This Policy should be read together with the MainSafe AI Skill Manager Terms of Use.

1. SCOPE OF THIS POLICY

This Privacy Policy applies to personal data processed in connection with MainSafe AI Skill Manager, including account creation, authentication, subscription management, support, security, storage and use of the service.

It also explains how personal data that users choose to include in Prompts, Skills, Agents, files, notes and other stored content may be processed through the platform.

2. DATA CONTROLLER AND DATA PROTECTION OFFICER

For processing activities where MainSafe determines the purposes and essential means of processing, RSA Consultoria e Treinamento Ltda. acts as the data controller.

The Data Protection Officer / Encarregado for MainSafe AI Skill Manager is:

Rodrigo Alves
rodrigo@mainsafe.com.br

Privacy and data-protection requests may be submitted through this email address.

3. PERSONAL DATA WE MAY PROCESS

Depending on how the service is used, MainSafe may process the following categories of personal data:

a. Account and authentication data

This may include:

  • name;
  • email address;
  • authentication identifiers;
  • account identifiers;
  • information necessary for login, session management and account security.

Where Google authentication is used, certain account information may be provided through Google according to the permissions and authentication process used.

b. Subscription and billing information

This may include:

  • selected plan;
  • subscription status;
  • billing status;
  • payment-related dates;
  • payment or billing identifiers made available by Stripe;
  • information necessary for assisted plan management;
  • information necessary to distinguish applicable billing flows.

Payment-card details are entered directly in the environment provided by Stripe.

MainSafe does not receive or store the full credit card number or card security code (CVV).

c. Content stored by users

Users may voluntarily store information within Prompts, Skills, System Prompts, Agents, Plugins, Automations, Templates, notes, files, references, versions, usage-location information and other content supported by the service.

Such content may contain personal data if the user chooses to include it.

d. Sharing information

Where sharing features are used, MainSafe may process information necessary to identify the sender, recipient, shared asset, specific shared version, permission granted and related service events.

e. Support and communication data

When users contact MainSafe, the company may process the information provided in the communication, including name, email address, message content and information reasonably necessary to respond to the request.

f. Technical, security and operational information

MainSafe may process technical information reasonably necessary for authentication, session management, platform security, prevention of abuse, troubleshooting and operation of the service.

The exact technical information processed may depend on the infrastructure, security mechanisms and service providers in use.

4. DATA PROVIDED THROUGH GOOGLE AUTHENTICATION

MainSafe AI Skill Manager may allow users to authenticate through Google.

When this authentication method is used, MainSafe may receive information necessary to identify and authenticate the user, such as their name, email address and technical authentication identifiers, according to the authentication permissions in effect.

MainSafe does not use Google authentication as authorization to access unrelated content from the user’s Google account.

5. PAYMENT PROCESSING THROUGH STRIPE

Paid subscriptions are processed through Stripe.

Users provide their payment-method information directly to Stripe through the payment environment made available for the applicable transaction.

MainSafe does not receive or store the user’s full credit card number or CVV.

Stripe may provide MainSafe with information necessary to manage subscriptions and billing, such as payment status, transaction or billing identifiers, subscription information, plan information, dates and other payment-related data made available through the service.

Stripe may process personal data in accordance with its own legal obligations, terms and privacy practices.

6. USER CONTENT

MainSafe AI Skill Manager is designed to store content chosen by the user.

Users determine the content they choose to add to the service.

This content may include information that is not personal data as well as personal data relating to the user or third parties.

MainSafe does not require users to insert personal data of third parties into Prompts, Skills, Agents or other stored content unless such information is necessary for the user’s own intended purpose.

7. PERSONAL DATA OF THIRD PARTIES INSERTED BY USERS

Users may choose to include personal data relating to third parties in Prompts, Skills, Agents, files, notes or other content.

The user is responsible for determining whether such data should be inserted and for ensuring that an appropriate legal basis, authorization or other lawful ground exists for that processing.

Where MainSafe merely hosts, stores or otherwise processes such data according to the user’s instructions in order to provide the service, MainSafe may act as a processor or operator in relation to that processing, depending on the applicable law and the actual circumstances.

The characterization of MainSafe or the user as controller, processor, operator or equivalent data-processing agent depends on the decisions and activities effectively performed in each processing context.

8. PURPOSES OF PROCESSING

MainSafe may process personal data for purposes including:

  • creating and maintaining user accounts;
  • authenticating users;
  • providing access to the service;
  • storing and organizing user content;
  • operating versioning, sharing and other service features;
  • administering plans and subscriptions;
  • processing or confirming payment-related events;
  • providing customer support;
  • maintaining platform security;
  • preventing fraud, abuse and unauthorized access;
  • diagnosing technical issues;
  • protecting users, third parties and infrastructure;
  • maintaining service continuity and disaster-recovery capabilities;
  • complying with applicable legal and regulatory obligations;
  • establishing, exercising or defending legal rights.

9. LEGAL BASES

Depending on the specific processing activity and applicable law, MainSafe may rely on legal bases including:

a. Performance of a contract and procedures related to entering into a contract

This may apply to activities necessary to create accounts, authenticate users, provide the service, administer subscriptions and perform other operations necessary for the contractual relationship.

b. Compliance with legal or regulatory obligations

Personal data may be processed when necessary to comply with obligations imposed by applicable law or competent authorities.

c. Exercise of rights in judicial, administrative or arbitration proceedings

MainSafe may retain or process information where necessary to establish, exercise or defend legal rights.

d. Legitimate interests

Where legally permitted and appropriate, MainSafe may rely on legitimate interests for activities such as platform security, fraud prevention, prevention of abuse and operational protection, taking into account the rights and reasonable expectations of affected individuals.

e. Consent

Consent is not used as the primary legal basis for processing necessary to provide the core MainSafe AI Skill Manager service.

Where optional features in the future require consent, it will be requested when appropriate.

10. PRIVATE CONTENT AND AI TRAINING

MainSafe does not use private content stored by users to train its own artificial intelligence models or third-party artificial intelligence models.

MainSafe also does not use private user content for advertising purposes.

If this practice changes in the future, any such use will require an appropriate legal basis, adequate transparency and, where applicable, specific user choice before implementation.

11. COOKIES AND SIMILAR TECHNOLOGIES

MainSafe currently uses only cookies and similar technologies that are strictly necessary for operation, authentication, session management, security and effective delivery of the service.

At this time, MainSafe does not intentionally use Google Analytics, Meta Pixel, Hotjar, advertising pixels, remarketing tools or similar non-essential advertising or analytics technologies on the commercial website.

MainSafe does not display a consent banner merely for tools that are not actually in use.

If non-essential analytics, advertising or similar technologies are introduced in the future, the applicable notices and privacy information will be reviewed before such technologies are activated.

Technical technologies used by hosting or infrastructure providers may be described in this Policy when their use and relevance are confirmed.

12. SHARING AND DISCLOSURE OF PERSONAL DATA

MainSafe does not sell personal data to advertisers.

Personal data may be shared with service providers or other parties where reasonably necessary to operate, protect or provide the service, comply with legal obligations or respond to legitimate requests.

Such parties may include technology, authentication, payment, infrastructure, security and hosting providers.

MainSafe seeks to limit disclosure to information reasonably necessary for the applicable purpose.

13. THIRD-PARTY SERVICE PROVIDERS

MainSafe may use specialized service providers including:

Google — authentication;

Stripe — payment processing and subscription-related services;

Cloudflare and related services — infrastructure, security, storage and related technical services.

MainSafe may replace or add providers when necessary for operation, security, legal compliance or evolution of the service.

The role of each provider in relation to personal data may vary according to the relevant processing activity and the provider’s own legal responsibilities.

14. INTERNATIONAL DATA TRANSFERS

MainSafe may use service providers or infrastructure located in Brazil or other countries.

As a result, certain personal data may be processed or stored outside Brazil.

Where an international transfer of personal data occurs, MainSafe will seek to use the measures and mechanisms required by applicable data-protection law.

This Policy does not represent that all data is stored in any particular country or geographic region unless MainSafe has specifically confirmed that fact.

15. STORAGE AND RETENTION

MainSafe retains personal data for periods reasonably necessary for the purposes for which it is processed, the operation of the service, security, compliance with legal obligations and the exercise of legal rights.

Retention periods may vary according to the type of information, purpose of processing and legal or technical requirements.

Account, billing, security and legal records may be retained for different periods where justified by their respective purposes and applicable law.

16. TRASH AND OPERATIONAL DELETION

Content moved to Trash may remain restorable for up to 30 days according to the functionality available in the service.

After that period, content becomes eligible for deletion from the operational environment.

Deletion may be performed through technical or administrative processing and MainSafe does not guarantee physical deletion at the exact instant the 30-day period expires.

17. TECHNICAL BACKUPS

MainSafe may maintain separate technical backups for disaster recovery, security and service continuity.

After content has been deleted from the operational environment, residual copies may remain in restricted-access technical backups until they are removed according to MainSafe’s technical retention and deletion cycles or where retention is required by applicable law.

These backups are not used as an ordinary active library for users.

Access is restricted and recovery from such backups may require administrative or technical procedures intended for disaster recovery, security or continuity purposes.

MainSafe does not currently represent that residual backup copies are deleted within a fixed number of days following operational deletion.

18. ACCOUNT DELETION

The service currently does not provide an automated self-service function for permanent account deletion.

Users may request permanent account deletion through:

comercial@mainsafe.com.br

Requests will be handled administratively according to applicable technical, contractual, privacy and legal requirements.

Deletion of an account is separate from cancellation of a paid subscription.

Residual data may continue to exist where necessary for legal obligations, exercise of rights, security records or technical backups as described in this Policy.

19. SECURITY

MainSafe adopts technical and administrative measures designed to protect personal data and the platform against unauthorized access, loss, misuse, alteration and other security risks.

Such measures may include authentication controls, access restrictions, security mechanisms, user segregation, private storage, infrastructure protections and other controls appropriate to the service.

No Internet-connected service can guarantee absolute security or zero risk.

Users are also responsible for taking reasonable measures to protect access to their accounts.

20. SECURITY INCIDENTS

Where a personal-data security incident occurs, MainSafe will evaluate the circumstances and take measures required under applicable law.

Where legally required, MainSafe may notify affected individuals, competent authorities or both.

Incident handling may include containment, investigation, correction, recovery and other reasonable actions appropriate to the nature and severity of the event.

21. DATA SUBJECT RIGHTS

Subject to the conditions and limitations of applicable law, individuals may have rights regarding their personal data, including rights to:

  • confirm whether personal data is processed;
  • access personal data;
  • request correction of incomplete, inaccurate or outdated personal data;
  • request anonymization, blocking or deletion where legally applicable;
  • request portability where applicable;
  • obtain information about certain disclosures or sharing;
  • obtain information concerning the possibility and consequences of refusing consent where applicable;
  • withdraw consent where processing is based on consent;
  • object to processing in circumstances provided by applicable law;
  • request review or clarification of certain decisions where legally applicable.

The existence and scope of a right may depend on the applicable law and the specific circumstances of the processing.

22. HOW TO EXERCISE PRIVACY RIGHTS

Requests relating to privacy or personal-data protection may be submitted to the Data Protection Officer:

Rodrigo Alves
rodrigo@mainsafe.com.br

MainSafe may request information reasonably necessary to verify the identity of the requester and protect personal data against unauthorized disclosure.

Requests will be evaluated and answered according to applicable legal requirements.

23. DATA PROTECTION OFFICER

MainSafe’s Data Protection Officer / Encarregado is:

Rodrigo Alves
rodrigo@mainsafe.com.br

The Data Protection Officer acts as a contact point for users, data subjects and competent data-protection authorities regarding matters related to personal-data protection.

24. USER RESPONSIBILITY

Users are responsible for the personal data and other information they choose to place within their own stored content.

Users must not use MainSafe AI Skill Manager to process personal data unlawfully or in violation of third-party rights.

Where a user determines the purposes for which third-party personal data is inserted into the service, the user is responsible for complying with the legal obligations applicable to that processing.

Nothing in this section excludes MainSafe’s own obligations under applicable data-protection law.

25. CHILDREN AND MINORS

MainSafe AI Skill Manager is intended exclusively for individuals who are 18 years of age or older.

The service is not intended for children or minors and does not currently provide a parental-consent flow.

If MainSafe becomes aware that an account has been created or used in violation of this age requirement, appropriate measures may be taken according to applicable law and the Terms of Use.

26. NO SALE OF PERSONAL DATA

MainSafe does not sell users’ personal data to advertisers or data brokers.

MainSafe also does not use private stored content for advertising purposes.

27. LEGAL REQUESTS AND AUTHORITIES

MainSafe may preserve or disclose information when required by applicable law, valid legal process or a competent authority.

MainSafe may also preserve information where reasonably necessary to establish, exercise or defend legal rights, prevent fraud, protect security or investigate unlawful activity, subject to applicable law.

28. CHANGES TO THIS PRIVACY POLICY

MainSafe may update this Privacy Policy because of legal, regulatory, technical, commercial, security or functional changes.

Material changes will be communicated to users with reasonable advance notice where possible.

The current version of the Policy and its applicable date will be made available through MainSafe’s official channels.

29. GOVERNING PRIVACY LAW

MainSafe’s processing activities are primarily subject to applicable Brazilian data-protection legislation, including Law No. 13,709/2018 — the Brazilian General Data Protection Law (LGPD), where applicable.

Users in other jurisdictions may also have mandatory rights under data-protection or consumer laws that cannot legally be waived.

30. CONTACT

For privacy and personal-data protection matters:

Rodrigo Alves — Data Protection Officer
rodrigo@mainsafe.com.br

For general support, plan management, billing and service-related matters:

comercial@mainsafe.com.br

RSA Consultoria e Treinamento Ltda.
CNPJ: 33.601.650/0001-41
Avenida Amazonas, 115 – Sala 1102
Centro – Belo Horizonte – Minas Gerais – Brazil