Privacy Policy
SAM is a professional electoral intelligence platform for Brazilian campaign teams. This policy describes which personal data we collect, how we use it, and with whom we share it.
In short:
- We collect account data (name, email), the content of the questions you ask the assistant, and minimal technical data required for operation and security.
- We do not collect precise location, contacts, photos, camera, microphone, or advertising identifiers.
- We share your questions with Anthropic (Claude) and Google (Gemini) exclusively to generate analytical responses — under enterprise contracts that prohibit use for model training.
- We do not sell your data, do not share it for advertising, and do not use it for cross-service tracking.
This policy is governed by the Brazilian General Data Protection Law (LGPD — Law No. 13,709/2018) and is written to be readable by non-lawyers as well.
1. Controller and Data Protection Officer
Controller: SAM INTELIGÊNCIA ARTIFICIAL LTDA
Address: Rua João Lourenço, nº 713, apartamento 132, E3BX, Vila Nova Conceição, São Paulo/SP, ZIP 04508-031, Brazil.
Data Protection Officer (DPO / Encarregado): Rafael Correia — rafael.correia@oisam.ai
Privacy channel (LGPD): privacy@oisam.ai
2. Data we collect
2.1 Account data
- Name
- Password (stored only as a bcrypt hash — we have no access to your plaintext password)
- Link to your campaign account (which team, which role)
2.2 Assistant usage data
- Content of the questions you ask SAM
- Content of the responses generated by the assistant
- Conversation history
- Access and interaction timestamps
2.3 Technical data
- IP address (for security and fraud prevention)
- Browser user-agent or app version
- Error logs (only stack traces with internal identifiers, no question content, no personal data)
2.4 Federated authentication data
When you sign in with Google, we receive from Google: name, email, and profile picture (only these three fields).
3. Data we do NOT collect
- Precise device location
- Phone contacts
- Photos, camera, microphone
- Advertising identifiers (IDFA, Advertising ID)
- Biometric data
- Health data
- Financial data (card, bank account)
4. Purposes and legal bases (LGPD Art. 7)
| Purpose | Legal basis (LGPD) |
|---|---|
| Service operation (login, processing questions, returning responses) | Art. 7, V — performance of a contract |
| Platform security (logs, IPs, fraud prevention) | Art. 7, IX — legitimate interest |
| Transactional communication (email verification, password reset, account notifications) | Art. 7, V — performance of a contract |
| Analysis of public third-party data to generate campaign intelligence (see Section 6) | Art. 7, IX — legitimate interest, combined with Art. 11, II, "d" where applicable |
| Compliance with legal obligations (including Marco Civil da Internet) | Art. 7, II |
5. AI providers: what we send, what we do not send
To generate analytical responses, your questions are processed by third-party AI models:
| Provider | Function | What we send |
|---|---|---|
| Anthropic (Claude) | Interpretation of the question and composition of the analytical response | Your question text + aggregated results produced internally by SAM |
| Google (Gemini) | Qualitative synthesis of large volumes of public social media content | Aggregated public social media content, when you request qualitative analysis |
What we do NOT send to these providers:
- Your password or credentials
- Your email
- Data from other campaign accounts
- Personally identifiable data about third parties unrelated to the requested analysis
Contractual guarantee: the enterprise agreements signed with Anthropic and Google prohibit the use of submitted data for model training. Data is processed solely to generate the response to your question and is discarded from the model's context after the interaction.
6. Analysis of public third-party data
To generate campaign analyses, SAM processes two categories of public data about third parties who are not SAM users:
6.1 Public social media content
We collect exclusively public posts from accounts with identity verified by the platforms themselves (Instagram, TikTok, YouTube, X/Twitter, Facebook). The data processed is limited to:
- Public username
- Text of the post
- Public metrics (likes, comments, reach)
- Date of the post
We do not access private messages, follower-only content, contact information, or any non-public information.
Scope of processing: public figures in an electoral context — candidates, elected officials, party leaders, institutional profiles — about whom there is legitimate public interest in analysis. Incidental mentions of ordinary citizens are used solely in aggregate counts, without persistent individual identification.
Material commitments (LGPD Art. 10):
- We do not profile, politically classify, or perform demographic, behavioral, or identity categorization of any data subject.
- We do not make automated decisions that affect any data subject whose data is analyzed.
- We do not share this data for marketing, targeted advertising, or commercial database enrichment.
- We recognize the right to object (LGPD Art. 18, §2). Any data subject may request that we stop processing their data via privacy@oisam.ai; we respond within 15 business days.
Legal bases: Art. 7, IX (legitimate interest), considering the public interest in critical analysis of electoral discourse, weighed against the reduced privacy expectation of public figures regarding political statements they themselves made public. For sensitive data incidentally revealed in public statements by electoral figures, we additionally invoke Art. 11, II, "d" — regular exercise of rights, including freedoms of information and political expression in a democratic regime and social oversight of public representatives.
6.2 Electoral data from TSE
Sourced from the official public databases of the Brazilian Superior Electoral Court (TSE):
- Vote results per electoral section
- Aggregate voter profile
- Campaign finance (declared revenue and expenses)
Voter data is aggregated by electoral section, municipality, or microregion, never allowing individual identification of any voter (LGPD Art. 12). No individual voter data is processed by SAM.
7. Categories of operators
We work with service providers (operators, in LGPD terminology) who process data on our behalf and under our contractual instructions, organized into the following categories:
| Category | Function | Location |
|---|---|---|
| AI providers (Anthropic Claude, Google Gemini) | Question processing and qualitative synthesis | United States |
| Cloud hosting | Server and storage infrastructure | United States |
| Licensed providers of public data | Access to public social media and governmental data | US / UK / EU |
| Transactional email | Account notifications (verification, password reset) | United States |
| Error monitoring | Stack trace capture for technical diagnostics | United States |
| Federated authentication | Login via external identity provider | United States |
The AI providers are named because this involves processing of user-generated content and receives specific regulatory attention (including Apple App Store Guideline 5.1.2(i)).
The complete nominal list of operators, with legal name and specific location, may be made available to customers and data subjects upon a justified request to privacy@oisam.ai — consistent with the standard practice in the B2B SaaS market.
8. International data transfers
Most of our sub-processors operate in the United States. Per ANPD Resolution No. 19/2024, we ground these transfers on:
- Specific contractual clauses signed in each sub-processor's enterprise contract, providing safeguards equivalent to LGPD requirements.
- Minimization commitment: we send only the data strictly necessary for each sub-processor's specific function.
The European Union has been recognized by ANPD (Resolution No. 32/2026) as an adequate jurisdiction — no additional restriction applies to transfers to European sub-processors.
9. Isolation between campaign accounts
SAM is built with strict per-account isolation (multi-tenancy). Each campaign account sees only its own data. There is no cross-access between competing campaigns — adversaries and their teams cannot view what you query, and we do not permit such access via any path.
10. Your rights as a data subject (LGPD Art. 18)
You may, at any time:
- Confirm the existence of processing of your data
- Access the data we hold about you
- Correct incomplete, inaccurate, or outdated data
- Anonymize, block, or erase unnecessary or non-compliant data
- Port your data to another provider
- Erase data processed on the basis of consent
- Be informed about the entities with whom we share your data
- Be informed about the consequences of denying consent
- Revoke consent previously granted
- Object to processing carried out under one of the bases of Art. 7
How to exercise: send a request to privacy@oisam.ai from your registered email. We respond within 15 business days.
11. Data retention and erasure
| Category | Retention period |
|---|---|
| Content of conversations with the assistant | While the account is active, plus 6 months after cancellation (churn) |
| Technical logs (IP, user-agent, errors) | 6 months |
| User account after cancellation request | 90 days (reactivation window); after that, permanent erasure |
| Minimal account data (name, email) for accounting / tax audit purposes | As required by law (5 years for tax records) |
After these periods, data is permanently erased or irreversibly anonymized.
12. Technical and organizational security
- HTTPS required for all traffic (TLS 1.2+)
- Passwords stored with bcrypt (12 rounds) — no reversal possible
- Data encrypted at rest (managed encryption by the cloud infrastructure)
- Session tokens with automatic rotation and short expiration
- Multi-tenant isolation by design — each account operates in a separate context
- Access monitoring with auditable logs
- Administrative access restricted to authorized staff with federated authentication
In the event of a security incident that may result in risk or relevant harm to data subjects, we will notify ANPD and affected subjects within a reasonable timeframe, as required by LGPD Art. 48.
13. Cookies and local storage
SAM does not use tracking, advertising, or third-party analytics cookies. We use exclusively:
localStoragein the browser — to store the session refresh token (keeps you logged in across visits)- Strictly necessary session cookies — for authentication during the active session
You can clear these at any time via your browser settings, with the effect of immediate logout.
14. Children and adolescents
SAM is a B2B product intended for professional electoral campaign teams, exclusively for users aged 18 or older. We do not create accounts for minors and do not intentionally process data of children or adolescents. If we identify a minor's account, it will be removed. If you are responsible for a minor and suspect they created an account, contact privacy@oisam.ai.
15. Brazilian electoral regulation (TSE)
SAM is an internal strategic analysis tool for campaign teams. It:
- Does not generate electoral propaganda
- Does not communicate with voters
- Does not recommend voting or rank candidates for public consumption
- Does not produce content intended to directly influence voters
For these reasons, SAM falls outside the scope of the TSE Resolutions that regulate the use of artificial intelligence in electoral propaganda.
16. Changes to this policy
This policy may be updated to reflect changes to the service or to applicable legislation. When a relevant change occurs, we will notify users at their registered email and update the revision date at the top of the document. The version history is available upon request to privacy@oisam.ai.
17. Contact
| Channel | Address |
|---|---|
| Data Protection Officer (DPO) | Rafael Correia — rafael.correia@oisam.ai |
| LGPD requests (data subjects) | privacy@oisam.ai |
| Controller's address | Rua João Lourenço, nº 713, apartamento 132, E3BX, Vila Nova Conceição, São Paulo/SP, ZIP 04508-031, Brazil |
For data protection questions that have not been satisfactorily addressed, you may also contact the Brazilian Data Protection Authority (ANPD) at www.gov.br/anpd.