📈 Invista — Terms of Use and Privacy Policy
Version of September 9, 2026 · invista.powerguido.pro · previous versions
Terms of Use
1. What the platform is
Invista is a tool for tracking of investments: it consolidates public market data (B3, CVM, Banco Central and quote providers), tracks the portfolios you register, calculates returns and provides an estimate of taxes on exchange-traded transactions.
2. What the platform is NOT
Nothing here is investment advice. Scores, rankings, reference prices (Bazin, Graham), rebalancing suggestions and AI assessments are methodological references calculated from public data, with assumptions displayed on screen. The decision to buy, hold or sell is entirely yours. Tax calculations are supporting estimates: check the amounts with your accountant before paying DARF or filing income tax returns.
3. Data accuracy
Data comes from external and free sources, which may contain errors, delays or gaps. The platform runs verification routines, but does not guarantee the accuracy of quotes, distributions or metrics. In case of a discrepancy, the official source prevails (B3, CVM, your broker).
4. Your account
- The service is intended for adults aged 18 or over. By creating an account, you declare that you are 18 or over; we do not knowingly process minors' data.
- You are responsible for safeguarding your password; we recommend enabling two-factor authentication (2FA) or a passkey in your profile.
- An account created and not verified by email within 7 days is included in the weekly automatic purge, together with all its data — protecting anyone whose email was registered by someone else. Deletion may occur up to 7 days after that deadline.
- The service is provided "as is", without any guarantee of continuous availability.
- Accounts used for abuse (unauthorized access attempts, deliberate overload, fraud) may be suspended or closed.
- You can delete your account at any time on your profile page — deletion is immediate and permanent (section 9 explains what remains and for how long).
Privacy Policy (LGPD)
5. Who processes the data and how to contact us
The controller is Rafael Gili, responsible for the Invista platform (invista.powerguido.pro). Contact for personal data matters: privacidade@powerguido.pro (you can also reply to any email sent by the platform). Requests concerning your data are answered within 15 days; when a complete response requires more extensive research, within 30 days (the deadline for small processing agents under CD/ANPD Resolution No. 2/2022), always acknowledging receipt beforehand. The platform operates as a small processing agent and maintains this channel instead of an appointed data protection officer, as permitted by that resolution.
6. What data is collected and why
- E-mail (required, with verification): sign-in, account recovery and essential account notices.
- Name (optional): identify you in the interface and in the reports you generate.
- Phone (optional): an alternative contact channel for account security when email is not sufficient.
- Date of birth (optional): tailor goals and investment horizons in planning features.
- Profile photo and investor profile (optional): displayed in your header; the profile calibrates rebalancing suggestions.
- Preferences (theme, language, screen filters, email opt-ins): remember your choices between sessions.
- Portfolio: the trades, distributions and holdings you record or import from your statements — the purpose of the service.
- Distribution reconciliation: after imports and when you request reconciliation, we store the result and a snapshot of trades and receipts for assets with pending issues, linked to the account and portfolio, to investigate inconsistencies and track their resolution.
- Notification devices (if you enable push): subscription endpoint and browser identification, so you can recognize and revoke each device.
- Interface performance: counts and average and maximum request and interaction times, aggregated by screen and hour to identify slowness. Batches do not include names, accounts, portfolios, URLs, typed text or financial values. They are sent to Invista itself after acceptance of this version, without additional trackers or cookies.
- Technical data: session cookie (httpOnly, essential for sign-in — no tracking or advertising cookies), last access date, and IP address in server access logs and attempt limits.
7. Who handles the data
We do not sell data or share it with third parties for their own purposes. To operate, the service uses:
- Hosting: a server in Brazil (São Paulo), contracted from Hostinger International Ltd. The database, backups and reports reside there.
- E-mail: messages are sent from the platform's own server and delivered to the provider of your address (Microsoft, Google, etc.) — if your provider stores your mailbox outside Brazil, the content we send you (including the monthly PDF report, if enabled) is transferred there.
- Push notifications (optional): delivered by your browser's service (Google, Apple or Mozilla, usually in the US). The content is encrypted end-to-end; these services only see delivery metadata (device and time).
- Property map: map tiles come from OpenStreetMap (United Kingdom) — opening the map makes your browser contact that service, which receives your IP and map image requests. Portfolio data, trades and receipts are not sent in this access. An external fallback copy of the chart library may be used if the local file fails; in that case, it also receives the connection's IP address.
8. Isolation and security
Passwords are stored using strong hashing (argon2). Portfolio data is isolated by user at database level (row-level security), so each account holder accesses their own portfolios. Administrative support has read-only access to distribution reconciliation diagnostics, including the trades and receipts involved, to investigate inconsistencies. This permission does not allow general browsing of other users' portfolios. Administrative account actions are logged; administrative password resets trigger an email notice to the account holder. All traffic uses HTTPS.
9. Retention and deletion
Your data is stored while the account exists. Additional retention periods have automatic rules by category:
- Backups: encrypted, with an automatic cycle of up to 8 weeks; one-off maintenance copies (before migrations) are kept for as long as necessary for operational safety.
- Server access logs (IP, date and time): 6 months, as legally required (Article 15 of Brazil's Internet Civil Framework).
- Session history: revoked sessions become eligible for purging 30 days after issuance; expired sessions, 30 days after expiry.
- Performance statistics: up to 7 days after receipt, with automatic expiry of hourly aggregates. No individual browsing history is stored.
- Sent notification log: 12 months.
- Administrative audit: a record of administrator actions (without portfolio content, identifying accounts by internal number), eligible for purging after 5 years.
- Reconciliation diagnostics: while the account and portfolio exist; included in your data download and removed when the account or portfolio is deleted.
Unverified accounts, sessions, notifications and audit records are purged weekly: automatic deletion may occur up to 7 days after the stated retention threshold. Backups, access logs and statistics follow their specific cycles above.
When you delete your account (profile → Delete account), your account and portfolio data is removed from the database immediately. A minimal service record remains (internal identifier and date), subject to audit retention. An internal identifier does not guarantee anonymization while association remains possible; remaining backups and access logs follow their respective retention periods.
10. Your rights
Access and portability: the "Download my data" button in your profile — a file containing everything the system stores about you and your portfolios, available to every account regardless of plan or module. Correction: through the platform itself (profile and portfolio). Erasure: through self-service account deletion. Other LGPD rights (information about processing, review, objection): through the channel in section 5, within the deadlines stated there.
11. Changes
Significant changes to this text create a new dated version on this page, and the platform requests your acceptance again on your first access after publication — use is not treated as implied agreement. Your acceptance history is recorded with the date and version.
Version history
- 09/09/2026 — controller identification, reconciliation diagnostics and support access, technical data in external resources, purge frequency and minimal deletion record.
- 08/09/2026 — interface performance statistics, aggregated by screen and hour, without identification, retained for up to 7 days.
- 21/08/2026 — LGPD framework: purpose of each data item, declared processors and destinations, retention periods by category, minimum age, profile data export, renewed acceptance per version, contact channel and response deadlines.
- 08/08/2026 — first version.