Skip to content
Mercurios
Back to Wayfinder

Wayfinder

Privacy Policy

What Wayfinder keeps about you, why, where it lives, and how to have it removed.

Effective from September 03, 2026

Wayfinder is an app for setting the direction of your life — values, mission, vision, goals and habits — and revisiting it in cycles. It is published by Filipe Daniel Fonseca dos Santos, sole proprietor (MEI), CNPJ 21.477.667/0001-50, trading as Mercurios Comércio, Tecnologia e Análise de Dados ("Mercurios", "we"), of São Paulo, Brazil. We are the controller of the personal data described here.

This policy covers the Wayfinder Android app (package com.filipefonseca.lifeplanner) and the account and sync services behind it. It describes the app as it works today. Where something is planned and does not exist yet, we say so.

This English text is a translation provided for convenience. If the two versions differ, the Portuguese version governs.

Contact for anything about privacy: [email protected].

What Wayfinder keeps about you

Account data. To create an account you give an email address and a password, or sign in with your Google account. Authentication is handled by Firebase Authentication, a Google service: it is Firebase that holds your credential. We never see your password and never store it in any form. If you sign in with Google, Google sends Firebase your email, name and profile photo; the app uses only the email and the name. On our side we keep your email, an opaque account identifier and the date the account was created.

The content you write. Wayfinder exists to hold this, and none of it is asked for by us — you decide what to write:

  • your life areas and the scores you give them in the self-assessment;
  • your values and your mission;
  • your visions, milestones, goals and habits, and the links between them;
  • your habit completion history, your commitments and each day's schedule;
  • your notes and lists;
  • your planning sessions (annual, quarterly, weekly and daily).

This content can be as personal as you choose. What you write about health, relationships, beliefs, money or work may fall into categories the law treats as sensitive. We do not analyse it to infer anything about you, we do not use it for advertising or to train models, and we do not read it, except when you ask us for help and authorise it. Write only what you are comfortable storing.

Sync data. Each installation of the app gets a random identifier. When you create, change or delete something, the app sends that change to our server together with that identifier and the time. The server keeps a change log — which kind of item changed, when, and from which installation — so that your other devices receive the update. When you delete an item, its content is removed from the server at once; the record that something was deleted remains for as long as the account exists.

Technical data. To keep the service running and secure, the server logs the IP address, date, time and path of each request, and the app keeps your session tokens on your device.

Crash reports. When the app hits an error it sends a report to Firebase Crashlytics (Google): the error type, stack trace, device model, operating system and app version, and the opaque identifier of your account. A report never includes what you wrote. This is on by default and can be turned off under Settings › Privacy.

Usage and performance data. Only if you accept, the first time you open the app, it sends Firebase Analytics and Firebase Performance (Google) events about what you do, never about what you write: screens opened; sign-in and sign-up (and whether by password or Google); the start and end of each planning session; items created and deleted (only the kind — vision, goal, habit — never the text); habits completed; assessments completed; values committed; the outcome and duration of sync; and how long operations and screens take. Counts and durations are sent as ranges, not exact values. These events carry the opaque identifier of your account. You can change your choice at any time under Settings › Privacy.

When it receives crash reports and usage events, Google also records the device model, operating system version, language, and an approximate location (country and city) derived from the IP address. It does not receive your name or email through this route.

When you write to us. We keep your email address and the content of the message for as long as it takes to resolve the matter.

What Wayfinder does not do

  • It does not ask for your location, contacts, photos, microphone, camera or files. The only permissions it uses are internet, notifications, and re-scheduling reminders after the device restarts.
  • It does not use advertising identifiers, ad networks or third-party trackers.
  • It does not sell your data and does not share it with data brokers.
  • It charges nothing today; there is no payment data.
  • Reminders are local notifications scheduled on your device, with fixed text. They pass through no delivery service.
  • The AI assistant visible in the app's design is switched off. Nothing you write is sent to any AI provider. If it is switched on, this policy will be updated first, saying what is sent, to whom and under what terms.

Where your data lives

Wayfinder works on your device first: everything you create is written to a local database, and the app reads from that copy. When you are online, changes are synced in the background to our server, so your data survives the loss of a device and can be used on more than one.

If you sign out, or sign in with a different account on the same device, the app erases the previous account's local copy.

The server and database are hosted by DigitalOcean in the New York region, United States, in the same cluster. There is currently no backup of the database. If it is lost, whatever exists only there is lost; the local copy on your device is your safeguard. When that changes, this policy will say so.

Why we process this data

PurposeData usedLegal basis
Creating and maintaining your account, authenticating youAccount dataPerformance of the contract
Storing and syncing your content between devicesContent, sync dataPerformance of the contract
Keeping the service secure, preventing abuse and fixing defectsTechnical data, crash reportsLegitimate interest
Understanding how the app is used and how it behavesUsage and performance dataConsent, which you can withdraw in Settings
Answering your messagesEmail and messageLegitimate interest
Meeting a legal obligation or defending rightsWhatever the law requiresLegal obligation

Who we share it with

We use a small number of providers, each processing only what its function requires, under a contract that limits it to acting on our instructions:

ProviderWhat forWhere
Google (Firebase Authentication)Holding your credential, authenticating you, sending the password-reset emailUnited States
Google (Firebase Crashlytics, Analytics and Performance)Crash reports; usage and performance data, if you acceptUnited States
DigitalOceanHosting the server and the databaseUnited States (New York)
Google PlayDistributing the app, under the store's own termsGlobal

We may also disclose data where the law requires it or where necessary to exercise or defend rights.

International transfer. Your data is stored outside Brazil. The transfer relies on the safeguards Brazilian law recognises — such as standard contractual clauses with these providers. If you are in the European Economic Area or the United Kingdom, the transfer relies on the equivalent safeguards under the GDPR. Write to us if you want details.

How long we keep it

  • Account and content: for as long as the account exists.
  • After you delete the account: removed at once. The Account and Data Deletion page says exactly what is erased.
  • Backups: there are none; nothing persists after deletion.
  • Server logs (IP and requests): 30 days.
  • Crash reports: up to 90 days.
  • Usage and performance data: up to 14 months.
  • Support messages: up to 1 year.
  • What the law obliges us to keep: only for the legal period.

Your rights

Under the LGPD, Brazil's data protection law, you can ask us to: confirm that we process your data; give you access to it; correct it; anonymise, block or delete what is unnecessary or excessive; port it to another provider; tell you who we share it with; and withdraw consent where processing relies on it. You can also object to processing based on legitimate interest, and lodge a complaint with the Brazilian data protection authority (ANPD).

If you are in the European Economic Area or the United Kingdom, you have equivalent rights under the GDPR and can complain to your country's data protection authority.

Write to [email protected]. We reply within 15 days. We may ask you to confirm your identity before acting, so that nobody but you exercises these rights over your account.

Security

  • All communication between the app and the server uses TLS.
  • Your credential is held by Firebase Authentication; we store it in no form.
  • Session tokens are kept in the device's secure storage (Keystore).
  • Access to production systems is restricted to the operator and protected by secrets management.
  • The database is not encrypted at rest. It is reachable only from inside the cluster's network, never from the internet.

No system is perfectly secure. If an incident affects your personal data and creates a risk to you, we will notify you and the ANPD within the periods the law requires.

About your device: because Wayfinder keeps a full copy of your data on it, anyone with access to the unlocked device can read what you wrote. Use a passcode or biometrics on the device.

Minimum age

Wayfinder is for adults. You must be 18 or older to create an account. We do not knowingly collect data from anyone younger; if we learn that an account belongs to someone under that age, we will delete the account and its data.

Software under test

Wayfinder is still in development and may contain defects capable of causing data loss. Do not use Wayfinder as the only record of anything you cannot afford to lose.

Changes to this policy

When this policy changes, we update the version and effective date at the top. If a change materially affects what we collect, who we share it with or what for, we will tell you in the app or by email before it takes effect.

Contact

Filipe Daniel Fonseca dos Santos — sole proprietor (MEI), CNPJ 21.477.667/0001-50 Mercurios Comércio, Tecnologia e Análise de Dados São Paulo, Brazil [email protected]