Privacy Notice
Last updated: March 2026
About the Company and This Document
TWOBETTER LTDA, registered under CNPJ 65.021.247/0001-30 and located in São Paulo, Brazil, is directly responsible for developing the website https://www.twobetter.com ("Site"). We are a technology company specialized in managed products. With ethics, respect, and transparency, we present this Privacy Notice.
This document demonstrates our commitment to safeguarding your privacy and protecting your Personal Data, establishing the rules for Processing and explaining your rights and how to exercise them.
Please read this Notice carefully. If you have any questions, feel free to contact us through the channels provided below.
Glossary: Essential Definitions
For the purposes of this Notice, the following apply:
| Term | Definition |
|---|---|
| LGPD | Brazil's General Data Protection Law (Law No. 13,709/2018), which regulates Personal Data Processing activities, including in digital environments, with the aim of protecting fundamental freedoms and privacy and the free development of the natural person's personality. |
| Personal data | Information relating to an identified or identifiable natural person. |
| Sensitive personal data | Personal data concerning racial or ethnic origin, religious beliefs, political opinions, trade union membership, religious, philosophical or political organization affiliation, data concerning health or sex life, genetic or biometric data when linked to a natural person. |
| Data subject | The natural person to whom the personal data being processed refers. |
| Processing | Any operation performed on personal data, such as collection, production, receipt, classification, use, access, reproduction, transmission, distribution, processing, storage, archiving, deletion, evaluation or control of information, modification, communication, transfer, dissemination or extraction. |
| Consent | Free, informed and unambiguous manifestation by the data subject agreeing to the Processing of their personal data for a specific purpose. |
| DPO | Person designated to act as a communication channel between us, data subjects, and Brazil's National Data Protection Authority (ANPD). |
| Our platforms | www.twobetter.com and our application. |
| Cookies | Small files sent to your browser or devices that store your preferences and other information about how and when our platforms are visited, as well as the number of people who access them. |
| IP | Internet Protocol abbreviation. An alphanumeric set that identifies users' devices on the Internet. |
1. Data We Collect
1.1. Data Displayed on the User Profile (registration or identification)
Personal identification and eligibility verification for account creation will be confirmed through:
- Full name, date of birth, gender, CPF (Brazilian tax ID);
- Email and mobile phone;
- City, state, and country of residence;
- Photographs for profile display;
- Full address for geolocation and proximity-based Matches.
Faith and religious data enabling Matches based on spiritual compatibility. Users must provide:
- Christian denomination (evangelical, Catholic, Protestant, etc.);
- Church attended, time since conversion;
- Involvement in ministries or prayer groups;
- Frequency of worship service attendance;
- Spiritual and devotional practices.
1.2. Facial Biometric Data for Registration and Identity Verification
For account security, fraud prevention, identity verification, and access authentication, the platform may collect and process facial biometric data, considered sensitive personal data under applicable law.
Facial biometric processing will occur through the user's specific consent, formalized, among other means, by express acceptance of these Terms of Use together with this Privacy Notice, which details purpose, processing methods, retention period, and data subject rights.
Facial biometrics will be used exclusively to:
- Confirm the data subject's identity during registration, login, or additional security validations;
- Prevent unauthorized access, fake profiles, and misuse of the platform;
- Strengthen security and integrity mechanisms of the digital environment.
Processing will observe the principles of purpose, necessity, proportionality, security, and transparency. Specifically:
- Only information strictly necessary for authentication will be collected;
- Biometric data will be stored securely using encryption or equivalent technical measures;
- Biometrics will not be used for purposes other than those stated here, such as marketing, behavioral profiling, or sharing with third parties, except by legal obligation or court order.
1.3. Internal Company Usage Data
1.3.1 User Preferences
- Desired characteristics in a partner;
- Age range, geographic location, and preferred denomination;
- Relationship goals and expectations.
1.3.2 Usage and Navigation
To enable Matches based on preference and affinity, the Company will monitor:
- IP address, device type, operating system;
- Access logs, interactions, matches, and messages;
- Time spent and features used;
- Cookies and similar technologies;
- Improve the app through anonymous analytics; comply with legal obligations and prevent fraud.
2. Data Sharing
2.1. We share your data, upon acceptance of the Terms of Use and Privacy Notice, with:
| Economic Group | Companies in the same economic group (including outside Brazil) |
| Other Users | Enabling matches |
| Service Providers | Infrastructure providers |
| Strategic Partners | Partner churches and communities, advertising |
| Public Authorities | For protection of rights |
3. Data Processing
3.1. Processing of Users' personal data, preceded by express consent, may serve interests beyond consent under LGPD Arts. 5, 7, and 11:
- Consent (sensitive data such as religion);
- Contract performance (app operation);
- Legitimate interest (security, fraud prevention, improvements);
- Legal obligation compliance (data retention for tax and legal purposes).
4. Processing Purposes
4.1. Your data is used to:
- Create and manage your Account;
- Provide matching and communication features;
- Personalize the experience with compatible recommendations;
- Security, fraud prevention, and content moderation;
- Compliance with legal and regulatory obligations;
- Communications about updates, events, and features;
- Service improvement through anonymized data analysis;
- Regular exercise of rights in judicial, administrative, or arbitration proceedings.
5. Data Monitoring
5.1. Monitoring user data is an ongoing obligation to ensure system security and compliance. Regulations such as EU Regulation 1689/2024 and the LGPD suggest the following actions:
- Risk Management System including identification, estimation, and evaluation of known and foreseeable risks and measures to eliminate/reduce them;
- Data Governance: systems using model training techniques must be developed with training, validation, and test datasets meeting quality criteria and bias mitigation that could harm health, safety, or fundamental rights;
- Technical Documentation: when prepared and kept updated before market release, demonstrates regulatory compliance and effective provision of information to competent authorities;
- Logging: throughout the app's lifecycle, logs must ensure adequate traceability to identify risks, facilitate post-market monitoring, and control system operation;
- Information Transparency: through clear usage instructions including provider identity, system characteristics, capabilities, performance limitations, intended purpose, and human oversight measures;
- Human Oversight: ensures human operators understand system capabilities, correctly interpret results, detect anomalies, and intervene or stop the system when necessary;
- Accuracy, Robustness, and Cybersecurity: Systems must maintain consistent performance throughout their lifecycle and resist failures, inconsistencies, and unauthorized third-party attempts to alter usage or performance.
5.2. Regulation 670/2016 (GDPR) extends the need for platform data monitoring to user behavior, requiring specific safeguards:
- Profiling: behavioral monitoring includes searching user data online to create profiles, analyze, or predict preferences and behaviors (such as cookies);
- Requirement of a Data Protection Officer (DPO) and Data Protection Impact Assessment (DPIA) for operations requiring regular, systematic monitoring of data subjects on a large scale or systematic monitoring of publicly accessible areas.
6. Data Storage
6.1. We store Personal Data only as long as necessary to fulfill the purposes for which it was collected, comply with legal or regulatory obligations, or preserve rights.
6.2. Data will be stored as necessary on AWS Cloud for purposes established in the Terms of Use, Privacy Notice, and Policies as required by the LGPD, Marco Civil da Internet, and other applicable laws:
| Data Type | Retention Period |
|---|---|
| Registration data | Account activity period plus 5 years after termination (statute of limitations for legal actions) |
| Message data | 6 (six) months after Account deletion |
| Access logs | 6 (six) months, complying with Marco Civil da Internet requirements |
| Sensitive data | Only while valid consent exists |
7. Your Rights and How to Exercise Them
7.1. The General Data Protection Law (Art. 18) guarantees Users the following rights:
| # | Right | Description |
|---|---|---|
| (i) | Confirmation and access | You may request confirmation of Processing and access to your Personal Data, including copies of records we hold about you. |
| (ii) | Correction | You may request correction of incomplete, inaccurate, or outdated Personal Data. |
| (iii) | Anonymization, blocking, or deletion | You may request anonymization of your Personal Data, blocking temporarily suspending Processing for certain purposes, or deletion of your Personal Data. |
| (iv) | Portability | You may request your Personal Data in a structured, interoperable format for transfer to a third party, respecting our intellectual property or trade secrets. |
| (v) | Information about sharing | You may request information about third parties with whom we share your Personal Data, limited to information that does not violate our intellectual property or trade secrets. |
| (vi) | Consent withdrawal | You may withdraw consent for any purpose you previously agreed to. Withdrawal does not affect the legality of prior Processing. If you withdraw consent for purposes essential to our platforms and services, they may become unavailable. |
| (vii) | Objection | You may object to Processing of your Personal Data if you disagree with any purpose. |
7.2. Requests. For your security, when you submit a request to exercise your rights, we may request additional information to verify your identity and prevent fraud.
7.3. Non-fulfillment of requests. We may decline requests if fulfillment would violate our intellectual property or trade secrets, or when legal or regulatory obligations require retention. We may also decline if we must retain Data for our or third parties' defense in disputes.
7.4. Responses to requests. We commit to responding to all requests within a reasonable time and in compliance with applicable law.
Requests must be made only by the data subject via email at privacy@twobetter.com.
7.5. Data accuracy and updates. You are solely responsible for the accuracy and updates of Data you provide. We are not obligated to process your Data if we have reason to believe such Processing may violate applicable law, or if you use our platforms for illegal or immoral purposes.
8. How We Protect Your Data
8.1. Security and Governance Practices. To safeguard your privacy and protect Personal Data, we maintain a governance program with best practices, policies, and internal procedures covering organization, training, educational actions, and risk supervision and mitigation related to Personal Data Processing.
8.2. Access to Personal Data, proportionality, and relevance. Internally, Personal Data is accessed only by authorized professionals, respecting proportionality, necessity, and relevance (need to know) for business purposes, plus confidentiality and privacy commitments under this Notice.
8.3. Good practices. You are also responsible for keeping your Personal Data confidential. Sharing passwords and access data violates this document and may compromise security. If you identify a security breach, contact us through the channels provided below.
8.4. External links. When using our platforms, you may be directed via links to other portals that collect your Data and have their own Privacy Policies. You are responsible for reading and accepting or rejecting them. We are not responsible for third-party privacy policies or content on websites not operated by us.
8.5. Processing by third parties under our direction. We carefully evaluate service providers and establish contractual information security and Personal Data protection obligations to protect you.
9. Information Security
9.1. We implement appropriate technical and organizational measures to protect your data:
- Encryption of data in transit (TLS/SSL) and at rest;
- Role- and privilege-based access controls;
- Continuous monitoring of threats and vulnerabilities;
- Regular backups and disaster recovery plans;
- Periodic employee training on data protection;
- Regular security assessments.
9.2. Storage location. Personal Data and activity records are stored in a secure, controlled environment, which may include servers in Brazil or cloud computing resources requiring transfer and/or processing outside Brazil. Transfers involve only companies demonstrating compliance with applicable laws at a level similar to or stricter than Brazilian legislation.
10. Use of Cookies
10.1. The company uses cookies and other profiling technologies for personalization and security. You can manage them in app or browser settings.
11. International Data Transfers
11.1. If your data is transferred outside Brazil, the following will be ensured:
- Compliance with LGPD rules (Art. 33);
- Adequacy of destination country or standard contractual clauses when applicable (LGPD Art. 33);
- Security measures equivalent to those required in Brazil (ANPD Resolution No. 19/2024).
12. Use of Artificial Intelligence
12.1. The platform may use Artificial Intelligence (AI) solutions, automated or semi-automated, to support certain features, always in compliance with applicable law, governance best practices, and personal data protection principles.
AI technologies may be used, as applicable, to:
- Verify and validate user identity;
- Authenticate access and strengthen account security;
- Prevent fraud, fake profiles, and misuse of the platform;
- Moderate and classify content (messages and photos);
- Support profile compatibility and interaction suggestions;
- Improve user experience and platform operation.
12.2. Personal data used by AI. AI use may involve processing the following categories of personal data, depending on the feature:
- Registration data provided by the user (including sensitive data);
- Profile photographs and images;
- Facial biometric data, when applicable and with specific consent;
- Platform usage and interaction information;
- Content voluntarily submitted by the user.
When sensitive personal data is processed, it will occur restrictively, proportionally, and under applicable law.
12.3. Automated decisions. Certain platform features may involve automated decisions such as identity validation, preventive security blocks, feature limitations, or content moderation. When applicable, users may request additional information or human review under LGPD Art. 20.
12.4. Data sharing and transfer. AI use may involve sharing personal data with technology vendors acting as data processors, subject to contractual confidentiality, security, and legal compliance obligations. International transfers will comply with applicable law and adequate safeguards.
12.5. Security and governance. The platform adopts appropriate technical and organizational measures to protect personal data used in AI systems, including access controls, encryption or equivalent measures, monitoring, and periodic review of models, algorithmic biases, and processes employed.
13. Final Provisions
13.1. Minors.
- Our app is exclusively for people 18 and older;
- We do not intentionally collect data from minors;
- Posting images of unaccompanied minors or nudity, or any content involving harm to minors or human trafficking, is prohibited even if the photos are the user's own.
In compliance with the Child and Adolescent Statute (ECA - Law No. 8.069/1990) and principles of full protection for children and adolescents in digital environments, the Platform never processes personal data of anyone under 18. Registration and access are strictly prohibited for this age group. To enforce this restriction, the Platform adopts the following age verification validations:
- a) Express user declaration: at registration, the user declares under their responsibility to be 18 or older, aware that false information leads to immediate account cancellation and applicable legal consequences;
- b) CPF verification: the date of birth is validated against CPF registration databases, enabling automated identification of users who do not meet the age requirement;
- c) Identity document upload: the user must submit an official photo ID (national ID, driver's license, or equivalent) for age verification;
- d) Facial biometrics with age verification: the platform may use facial biometric analysis as an additional age verification layer, in accordance with Section 1.2 of this Notice.
Consequence of minor access detection: if at any time the account holder is identified as under 18, the Platform will immediately block access and permanently delete all collected personal data under LGPD Art. 14 and applicable ECA guidelines for digital environments.
13.2. Changes. You acknowledge our right to change this document at any time for purpose or necessity, including legal compliance. You should review it whenever you access our platforms. If updates require new consent, you will be notified through the contact channels you provide.
13.3. Severability. If any provision is deemed inapplicable by ANPD or a court, the remaining conditions remain in full force.
13.4. Communication. The Data Subject acknowledges that all communication by email to addresses in their registration is effective and sufficient for disclosure of any app-related matter, except as expressly provided in this Notice.
13.5. Contact Channels. For any questions about this document, including exercising your rights, you may contact us at privacy@twobetter.com.
13.6. Governing law and jurisdiction. This Notice is governed by Brazilian law. The courts of your domicile are elected to resolve any dispute involving this document, except as otherwise required by applicable law. Translations into other languages are for informational purposes only; the Portuguese version prevails in case of conflict.