1. Who we are
This Privacy Policy explains how the Solar Future mobile app (iOS and Android) and its backend service handle personal data. The data controller is Rafael Macedo Leoncio, operator of the Solar Future app.
Controller registration number: 63.520.366/0001-01.
Access is limited to Solar Future customers. There is no open self-service registration; accounts are created by our team. You sign in with a Brazilian tax ID (CPF or CNPJ) and a password.
2. Data we collect
We collect only what we need to sign you in, show energy use and solar credits, issue plan invoices, and accept PIX payments.
Account and identification
- CPF or CNPJ (login identifier)
- Name
- Password (stored only as a cryptographic hash; we never store your password in plain text)
- Account role (customer or manager) and linked consumer units
Energy and consumer units
- Consumer unit name and code
- Monthly kWh usage, billed energy, compensated energy, and accumulated credit
- Meter reading, billing cycle, and credit expiry date
- Plan details: monthly kWh allowance, base price, and overage rate
Energy data comes from utility invoices and records processed by the Solar Future team (including operational ingestion of utility documents). The app does not access your Gmail, camera, contacts, or device location.
Invoices and PIX
- Invoice amount, due date, and status (paid, pending, awaiting payment, cancelled, or expired)
- PIX copy-and-paste code and QR code generated for payment
- Charge identifiers held by our payment processor
Session, device, and security
- Access and refresh session tokens (the refresh token is stored on our servers as a hash)
- IP address and device User-Agent, when available, for the active session
- On your device: session tokens, the CPF/CNPJ from your last sign-in, your last selected unit, and a local copy of data you have already viewed (for offline access)
What we do not collect
- Precise location, contacts, photos, microphone input, or advertising identifiers
- Credit or debit card numbers (the app supports PIX only)
- Advertising, cross-app tracking, or third-party analytics/crash-reporting SDKs
3. How we use your data
- Authenticate your access and keep you signed in
- Display energy consumption, solar credits, and consumer units
- Generate and display plan invoices and accept PIX payment
- Let authorized managers administer units, users, plans, and billing
- Prevent abuse (for example, login rate limits) and meet legal obligations
- Show previously downloaded data on your device when you are offline
Under Brazil’s General Data Protection Law (LGPD, Law No. 13,709/2018), we rely on: performance of a contract (providing usage tracking and plan billing), compliance with a legal or regulatory obligation (financial records), and legitimate interests (account security and fraud prevention), always in a proportionate manner.
4. Who we share data with
We do not sell personal data and we do not use it for advertising.
- Asaas Gestão Financeira Instituição de Pagamento S.A. — to register you as a payer and generate PIX charges (we send your name and CPF/CNPJ). Asaas processes that data under its privacy policy (Portuguese).
- Hosting and infrastructure providers that operate the service on our behalf.
- Public authorities when required by law.
5. Storage on your device
The app stores session tokens and a local copy of consumption, credits, and invoices you have already opened, so you can view them without an internet connection. New payments and invoices require connectivity. When you sign out, session tokens and that local cache are removed from the device. On Android, tokens are kept in the app’s encrypted storage.
6. How long we keep data
- Account and service data: while your account is active and for as long as needed to provide the service, comply with law, and resolve disputes
- Server-side sessions: until the token expires, is rotated, or you sign out
- On-device data: until you sign out or uninstall the app
7. Your rights under the LGPD
You may request confirmation of processing, access, correction, anonymization, blocking or deletion, data portability, information about sharing, and review of automated decisions, as provided by Brazilian law.
The app does not offer in-app account deletion. To correct, delete, or close an account, contact the Solar Future team. Managers may update certain registration details in the app when that feature is available.
To exercise your rights or ask questions, email solarfuturedev@gmail.com or contact the Rafael Macedo Leoncio team that created your account.
You may also file a complaint with Brazil’s National Data Protection Authority (ANPD).
8. Security and children
In production we use HTTPS, hashed passwords, short-lived access tokens, and account-scoped access (customers see only their own units; managers have administrative access). No system is completely risk-free—please protect your password and device.
The app is not directed at children. Accounts belong to energy customers (individuals or businesses) created by our team.
9. International transfers and policy changes
Data is processed primarily in Brazil. Asaas is a Brazilian payment institution. If infrastructure providers process data in another country, we do so with safeguards compatible with the LGPD.
If we make material changes to this policy, we will update this page and the date at the top. Continued use of the app after publication means you have been informed of the current version, to the extent permitted by law.