Legal
Privacy Policy
Effective April 16, 2026
This Privacy Policy explains how Popcasso (“Popcasso”, “we”, “our”) collects, uses, stores, and shares information when you use popcasso.com and the related editorial intelligence services (the “Service”).
If you have any question about this policy or your data, contact us at lucas@neoquest.tech.
1. Who is responsible for your data
Popcasso is operated by NeoQuest (CNPJ 08.455.882/0001-91), a company organized under the laws of the Federative Republic of Brazil (“NeoQuest”), which acts as the data controller for the personal data processed through the Service. For privacy matters, data subject requests, security reports, and any communication related to this policy, please write to lucas@neoquest.tech.
2. Information we collect
Account information
When you create a Popcasso account we collect your email address and a password (stored only as a one-way bcrypt hash). You may optionally provide a display name. We also generate and store authentication tokens used to keep you signed in.
Manuscript content you provide
When you paste, type, or import a manuscript, we store the manuscript text, its structure (chapters, scenes, paragraphs), revision history, annotations, and any feedback our AI agents generate for it. Manuscripts belong to you; we process them only to provide the Service.
Operational data
Our servers automatically log standard request data — IP address, user-agent, request path, response status, and timestamps — for security, abuse prevention, and debugging. These logs are retained for a short period and rotated.
Cookies
Popcasso uses only essential first-party cookies required to keep you signed in and to remember your session preferences. We do not use advertising cookies, third-party analytics trackers, or cross-site tracking pixels.
3. How we use your information
- Provide the core Service: store your manuscripts, generate editorial feedback, and let you export your work.
- Authenticate you, secure your account, and prevent abuse.
- Communicate with you about account, security, and material changes to the Service. We do not send marketing emails today.
- Comply with legal obligations and enforce our Terms of Service.
5. Storage, transfers, and security
Popcasso’s primary infrastructure is hosted in Amazon Web Services data centers in the United States (us-east-1). If you are accessing the Service from outside the United States, your data will be transferred to and processed in the United States. We rely on Standard Contractual Clauses and equivalent safeguards offered by our sub-processors for international transfers.
We protect your data with industry-standard security controls: TLS encryption in transit, encryption at rest for our database and object storage, scoped IAM permissions, and audit logging. No system is 100% secure, so we cannot guarantee absolute security, but we treat your data with the seriousness it deserves.
6. Data retention and deletion
We keep your data for as long as your account is active.
- Delete a manuscript from the dashboard to remove its content, structure, and feedback from the Service.
- Delete your account by emailing lucas@neoquest.tech. We will permanently delete your account and the personal data associated with it within 30 days, except where we are required by law to retain specific records.
7. Your rights
Depending on where you live, you may have the following rights over your personal data. To exercise any of them, email lucas@neoquest.tech from the address associated with your account. We will respond within the timeframe required by applicable law.
Brazil — LGPD (Lei nº 13.709/2018)
- Confirmation that we process your data and access to that data
- Correction of incomplete, inaccurate, or outdated data
- Anonymization, blocking, or deletion of unnecessary or excessive data
- Portability of your data to another service provider
- Deletion of personal data processed with your consent
- Information about the public and private entities with which we share your data
- Information about the possibility of refusing consent and the consequences of doing so
- Revocation of consent at any time
European Economic Area, UK, Switzerland — GDPR
Rights of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, objection to processing, and the right to lodge a complaint with your local supervisory authority. Our legal bases for processing are: performance of a contract (providing the Service) and legitimate interests (security, fraud prevention, service improvement).
California — CCPA / CPRA
Rights to know what personal information we collect, to delete it, to correct it, and to opt out of the “sale” or “sharing” of personal information. Popcasso does not sell or share personal information as those terms are defined by the CCPA.
8. Children
Popcasso is not directed to people under the age of 18 and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
9. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top of this page and, when appropriate, notify you by email or through the Service before the changes take effect.
10. Contact
Questions, requests, or concerns about this Privacy Policy or your data: lucas@neoquest.tech.