Provisional version: this text will be reviewed by a lawyer and completed before launch.
Last updated: 6 October 2026
Versão em português1. Who is responsible for your data
The data controller is Fire Horse - Wealth Management, Lda (Mais Português), tax number (NIF) 514994584, with registered office at Av. da República, n.º 45, 7.º Dto., 1050-187 Lisboa.
For any question about your data, write to geral@firehorse.pt.
2. What data we process
- Account: name and email address. Your password is stored encrypted by our authentication provider; we never see it.
- Profile: the level and goals you choose at the start and your preferences (reminders, sounds, subtitles, appearing on the leaderboard).
- Progress: lessons completed and correct answers in each one, game results, daily challenges, XP and the date of each activity.
- Weekly leaderboard: your first name with the initial of your surname and your XP for the week, visible to other learners. You can stop appearing on it in Settings.
- Purchases: the course bought, the date, the payment email address and the payment identifiers at Stripe. Card details stay with Stripe only; we never receive them.
- Security: IP address and technical browser data, used for the anti-bot check on the account forms and in our providers’ access logs.
3. What we use the data for, and on what legal basis
- Providing the course (account, lessons, progress, achievements): performance of the contract.
- Payments and invoicing: performance of the contract and compliance with legal obligations, such as tax obligations.
- Service emails (confirming your account, resetting your password): performance of the contract.
- Security and abuse prevention: legitimate interest in protecting accounts and the service.
- Weekly leaderboard: legitimate interest in making learning more motivating; you can object at any time by turning off “Show me on the leaderboard”.
4. What we do not do
We do not show advertising, we do not sell or pass on data to third parties for commercial purposes, and we do not use third-party analytics or tracking tools on the site.
5. Who processes data on our behalf
We use these providers, which only process the data in order to provide the service:
- Supabase — database and authentication, on servers in the European Union (Ireland).
- Cloudflare — site hosting, domain and anti-bot check (Turnstile).
- Resend — sending service emails.
- Stripe — payment processing.
- YouTube and Vimeo — only in lessons with a video hosted there: when you play it, your browser connects to them and they receive your IP address. We use YouTube’s privacy-enhanced mode (youtube-nocookie.com).
Some of these providers may process data outside the European Economic Area. In those cases, the transfer is protected by the European Commission’s standard contractual clauses or by the EU-U.S. Data Privacy Framework.
6. How long we keep the data
We keep the data for as long as your account exists. If you delete your account, your profile, progress, history and access to the courses are deleted immediately.
The purchase records needed for invoicing (plan, amount, date and payment reference) and the record of the consent you gave before paying are kept for the period required by Portuguese law, even after the account has been deleted, but without your name, email or account.
7. Your rights
You have the right to access, correct, delete and take your data with you, and to object to or ask for the restriction of processing. You can exercise many of these rights yourself, in the app’s Settings:
- Download my data — a file with everything we keep about you.
- Delete account — deletes your account and all your progress.
- Show me on the leaderboard — turns your presence on the leaderboard on or off.
For anything else, write to geral@firehorse.pt. We reply within one month. If you think your data is not being handled properly, you can lodge a complaint with the Portuguese data protection authority, Comissão Nacional de Proteção de Dados (cnpd.pt).
8. Children
Children may use the course, but an account for a child under 13 must be created and managed by their parents or by a person with parental responsibility, who give the necessary consent. Purchases are always made by an adult.
9. Security
Data is always encrypted in transit (HTTPS). The access rules are built into the database itself: each learner can only see and change their own data, and only the authorised team can access the management tools.
10. Changes to this policy
If we make significant changes to this policy, we will tell you by email or in the app before the change takes effect. See also the Terms and conditions and the information about cookies.
