Last updated: October 2, 2026
Previaly Privacy Policy
Translation. This English version is provided for convenience. The Portuguese version is the binding one: if the two differ, the Portuguese text prevails.
This Policy explains how Previaly handles personal data, in accordance with the Brazilian General Data Protection Law (LGPD — Law 13,709/2018) and the Brazilian Internet Civil Framework (Law 12,965/2014).
Controller: the Previaly platform, available at previaly.com. Data protection officer: contatoprevialy@gmail.com. WhatsApp +55 21 95948-3883.
1. Controller
We decide why and how dashboard and storefront data is processed. That makes us the controller: the party accountable to you and to the ANPD (Brazil's data protection authority).
Companies that process data on our behalf (hosting, database, photo processing) are processors. The list by category is in section 6.
When an optical store's customer talks to the store on WhatsApp, that conversation belongs to the store, not to us. We only build the link.
2. Who this applies to
There are two audiences, with different rules.
Store owner (you). Creates an account, registers the optical store, uploads product photos, pays for the plan. You are the one we have a contract with.
End customer (whoever opens the storefront on their phone). Doesn't create an account or give an email address. May allow the camera to try on frames — section 3. At some points the store may ask for a name and WhatsApp number (and, if you measure, your measurements) to help you — section 3.1.
If you're a store owner and also test the try-on, your account falls under section 4 and the camera under section 3.
3. End customer: the camera runs on your device
This is the most important rule in this Policy.
No image of your face is sent to Previaly, to the store or to any artificial intelligence server. The camera video is processed in your browser, on your own device. Measurements (monocular PD and fitting height) are also calculated on the device. They only leave the device if you identify yourself and authorize sending them to the store — section 3.1.
You tap "Allow camera". You can decline: the catalog stays visible. The browser turns on the camera (no audio). A face-tracking software component runs on the device, just as any website downloads scripts; it doesn't send the video to the cloud. The frame photo is drawn over the video. When you leave, the camera turns off.
What leaves the device: the request for the page and the frame photos, and the download of that component. Whoever serves the file sees that a device at your internet address downloaded it. They don't receive your face.
What doesn't leave: camera images, photos of you, facial landmarks, biometrics or any recording by us.
The try-on screen says that the camera is processed only on this device and that no image is sent or stored.
Legal basis (LGPD): consent (art. 7, I). Without your tap, the camera doesn't even turn on. Declining doesn't stop you from viewing the catalog or messaging the store on WhatsApp. We don't use the camera to identify you, for advertising or to create a profile.
3.1. Name, WhatsApp and measurements when you identify yourself
The store may ask for your name and WhatsApp number when you save a style, send it to the store, try it on or measure. Each store chooses at which of these moments it asks, and whether answering is required.
Without your acceptance of the authorization text, Previaly doesn't keep your name or WhatsApp number. Declining or tapping "Not now" (when the store lets you skip) doesn't stop you from viewing the catalog. If the step is required, that specific action won't continue without the contact.
What the store then sees in its Interests dashboard: your name, WhatsApp number, the style, the type of action (saved, sent, tried on, measured) and, if you measured after identifying yourself, your measurements. The store uses this to help you, usually on WhatsApp. Previaly doesn't create an account for you and doesn't return this history on another device.
A local copy stays on your device (name, WhatsApp and favorites for that store), only in this browser. Clearing the site data deletes that copy. Deleting the entry in the store's dashboard, or asking by email to the data protection officer, deletes what's on the server.
Anonymous storefront counts (how many people tried frames on today, how many WhatsApp taps) use a random device identifier, with no name.
Legal basis: consent (art. 7, I), for the contact details and for the measurements sent to the store.
4. Store owner data
What data
- Email and password — Where it comes from: sign-up and login. What for: to authenticate the account. The password is stored in protected form, not as readable text
- Store name and storefront address — Where it comes from: store setup. What for: to create the store and its public link
- WhatsApp, address, hours, social profiles and website — Where it comes from: Information screen. What for: to show on the storefront, plus the chat button
- Logo, cover image and icon — Where it comes from: dashboard. What for: visual identity
- Frame photos, name, brand, model number, price, measurements, categories — Where it comes from: frame setup. What for: catalog, try-on and the preview when the link is shared
- Theme and texts — Where it comes from: Customize screen. What for: the storefront's look
- AI credit usage — Where it comes from: system. What for: to deduct from the allowance
- Bot check — Where it comes from: sign-up. What for: to prevent automated sign-ups
We don't ask for a Brazilian taxpayer number (CPF) at sign-up. If the payment partner ever needs an ID document to issue an invoice, that will happen in the partner's environment.
Legal bases
- Performance of a contract (art. 7, V): account, storefront, credits, support.
- Legitimate interest (art. 7, IX): security, service improvement, defense in any dispute. You may object.
- Consent (art. 7, I): promotional messages that aren't needed for the contract; measurement cookies (Google Analytics, Microsoft Clarity and the Meta Pixel) and the notice to Meta about sign-up and first paid subscription — see section 5.
- Legal obligation (art. 7, II): keeping invoices and data required by tax law, once billing is active.
Product photos and AI
The photos you send to the studio are of the glasses, not of customers. They're processed by AI image generation and processing providers, some outside Brazil, with the safeguards of art. 33 of the LGPD. Details in section 6.
5. Cookies and on-device storage
Usage and advertising measurement is optional and only runs with your acceptance.
- Dashboard session — Duration: while you're logged in; deleted when you log out. Essential?: Yes
- Bot protection at sign-up (only from the 3rd attempt within the same hour) — Duration: short, set by the verification provider. Essential?: Yes, at sign-up
- Local dashboard and try-on preferences (only on your device) — Duration: until you clear the site data. Essential?: No
- Storefront identification (name, WhatsApp and favorites for that store, only on this device) — Duration: until you clear the site data. Essential?: No
- Visit measurement — Google Analytics (optional, only with your consent; on the site and the dashboard) — Duration: up to 2 years, Google's default. Essential?: No
- Click maps and session recording — Microsoft Clarity (optional, only with your consent; on the site and the dashboard) — Duration: up to 1 year, Microsoft's default. Essential?: No
- Ad measurement — Meta Pixel (optional, only with your consent; on the site and on the sign-up, login and payment screens) — Duration: up to 90 days, Meta's default. Essential?: No
- Progress in the quiz (previaly.com/diagnostico): your answers, how far you got and the ad link that brought you, stored on the device and on our server — Duration: on the device, until you clear the site data; on the server, while it's useful for measuring the quiz, or until you ask for deletion (section 8). Essential?: No
The cookie notice appears on the site (homepage, blog, terms and privacy, in all languages) and in the store owner dashboard (sign-up, login, payment and internal screens). Without acceptance, nothing fires. Declining or ignoring the notice has the same effect.
In the quiz (previaly.com/diagnostico) there's no notice on top: the text right below the first button says that, by starting, you agree to the Terms of Use, to this Policy and to the measurement described here. Tapping the button is the acceptance. If you had already declined the cookie notice on another page, the decline stays. The quiz answers help us understand where it's confusing and what stores need. The name you type in the first question isn't stored on the server unless you create the account at the end.
For bot protection, we count sign-up attempts from each connection for one hour, with the IP address scrambled by a secret key (it can't be turned back into the IP). After the hour, the count is deleted.
Microsoft Clarity records clicks, scrolling and the layout of screens so we understand where the site and the dashboard are confusing. It doesn't record what's typed into fields, and on dashboard screens with the store's customer data (Home, Interests) and team data (Team, Account) the text is blurred. Dashboard screen addresses are sent without their search parameters.
The Meta Pixel records the visit, the click to chat on WhatsApp, viewing the plans and starting a payment. With the same acceptance, our server tells Meta when an account is created and when the first subscription is paid (with the amount), so we know which ads bring in customers. Sent along are the email and phone number in scrambled form (hashed, unreadable), the browser, the IP address and the Pixel identifiers. Declined the notice? None of this is sent.
The optical stores' storefronts and try-on, the try-on embedded in a store's website and the admin area don't load any of these measurements. A store's end customer is never sent to Meta.
You can clear cookies and site data in your browser settings. If you clear the dashboard session, you'll need to log in again.
6. Processors and international transfer
The site is served from the delivery network closest to you. Part of the infrastructure may be outside Brazil. When that happens, we use contracts with standard clauses and the basis of art. 33 of the LGPD.
- Hosting and content delivery network providers — What it receives: the page request, the storefront's media files and, at sign-up, the bot check
- Authentication and database service — What it receives: email, protected password, store data, frames, credits and, when the end customer identifies themselves, name, WhatsApp, acceptance and measurements
- AI image generation and processing providers — What it receives: the frame photo the store owner uploaded in the dashboard
- Face-tracking library that runs in your browser — What it receives: only the download of the software component; it doesn't receive your face
- Payment partner — What it receives: the store owner's billing data, once the subscription is active. Doesn't receive any face photo
- Usage measurement tools (Google Analytics and Microsoft Clarity), only with acceptance — What it receives: pages visited, clicks, device type and browser, approximate city — on the site and the dashboard, never on the storefront
- Meta (Pixel and Conversions API), only with acceptance — What it receives: visits and clicks on the site and in the sign-up funnel; sign-up and first paid subscription, with hashed email and phone number, browser, IP and the amount
The storefront's end customer: the AI providers in the table receive nothing from them. Only the product photo, uploaded by the store owner in the dashboard.
If the visitor clicks on WhatsApp, they leave Previaly and start talking to the store in the app. That step isn't our operation.
7. Retention and deletion
- Active account: we keep the data while the store exists and the contract requires it.
- Closure: the storefront goes offline. We delete or anonymize account data, media and backups within 90 days, unless there's a legal obligation to keep them (invoices, for the tax period).
- Deletion request: see section 8. We may keep the minimum needed for defense in legal proceedings (art. 16 of the LGPD).
- Technical access logs: page path, status and duration, without the content of the password or cookie. Kept for a short period, usually under 30 days.
- End customer without identification: there's no record to delete. The camera wasn't stored. Preferences that stayed only on their device they can delete themselves by clearing the site data.
- Identified end customer: name, WhatsApp, acceptance and measurements are kept while the store keeps the contact in its Interests dashboard, or until a deletion request (section 8). The store can delete the contact from its own screen.
There's no "download my data" or "delete account" button in the dashboard. The way to ask is the data protection officer's email.
8. Data subject rights
If you're a store owner (or, where applicable, a homepage visitor), the LGPD guarantees, among others:
- confirmation that we process your data;
- access;
- correction of incomplete or outdated data;
- anonymization, blocking or deletion of unnecessary data;
- portability, where applicable;
- information about whom we share data with;
- withdrawal of consent (measurement cookies, marketing);
- objection to processing based on legitimate interest.
How to ask: write to contatoprevialy@gmail.com, preferably from your account email, with the subject "LGPD" and what you'd like. We reply within 15 days, extendable by another 15 if the complexity requires it — in which case we'll tell you why.
Complaints to the ANPD: https://www.gov.br/anpd/
End customers who only opened the storefront and didn't identify themselves: we have no record of you. If you left your name and WhatsApp number, ask for deletion at the same email or ask the store, which sees the contact in its dashboard.
9. Security
The site uses an encrypted connection. The dashboard session cookie can't be read by page scripts. The AI providers' keys never reach the browser. Each store only sees its own data. File uploads are validated. Sign-up uses a bot check. There's protection against repeated password attempts.
No system is invulnerable. If we learn of an incident affecting your data, we'll notify you as required by the LGPD (art. 48).
10. Children
Previaly isn't aimed at people under 18. The dashboard sign-up is for whoever represents an optical store.
We don't ask the age of people trying frames on the storefront, and we don't turn on the camera without the "Allow" tap. We don't profile minors.
If we learn that a store owner account was created by a child, we close it.
11. Changes
This Policy may change. The date at the top is when it takes effect. Significant changes will be announced by account email or a notice in the dashboard, and on this page: https://previaly.com/privacidade (Portuguese) and https://previaly.com/en/privacy (this translation).
12. Contact and ANPD
Data protection officer: contatoprevialy@gmail.com
General: contatoprevialy@gmail.com
WhatsApp: +55 21 95948-3883
ANPD: https://www.gov.br/anpd/