Skip to content
FIGURÔ
Back to Figurô
PTENESIDTR
Get the app

Privacy Policy

Updated July 30, 2026

This Policy explains how Volke Ideias Digitais Ltda. handles data in the Figurô app, on the figuro.com.br website, in support, and in the services that keep the product running.

1. Controller

Volke Ideias Digitais Ltda.

CNPJ 66.727.282/0001-31

Brazil

Contacts:

  • privacidade@figuro.com.br — privacy and data rights;
  • dpo@figuro.com.br — data protection officer;
  • oi@figuro.com.br — general support.

2. Summary

  • There is no Figurô account.
  • Making stickers is free; ready-made packs are bought through the app store, which processes the payment — Figurô never receives your card number and never creates an account.
  • Photos, sticker texts, pasted content and personal packs stay on your device.
  • When you import a pack you received, the check that protects paid catalog content runs on the device itself; nothing is sent to a server because of it.
  • The photo cutout happens on your device whenever the feature is available.
  • When the device cannot do the cutout, a reduced copy of the photo may be processed in our server's memory and discarded as soon as the cutout is done.
  • The app uses Firebase for usage measurement, notifications and configuration.
  • The app uses Sentry for crash reports.
  • Support may receive your message, an optional email address and the diagnostic information shown to you before sending.
  • The website uses Google Analytics (GA4); where the law requires it, we ask for consent before measuring.
  • There is no third-party advertising, no selling of data and no use of personal content for advertising.

3. Data we process

3.1 App usage and installation

To understand how the app is used, Firebase (Analytics and Installations) may process:

  • a technical identifier created for this installation of the app — it contains no name, phone number or email;
  • usage events from a fixed list, such as sticker created or pack added;
  • app version, platform, system version and device category;
  • app language, content country and whether that choice was automatic or manual;
  • sessions, first and last activity, and where the install came from;
  • pack, campaign and experiment identifiers, with no personal content;
  • IP address and other technical data the provider processes to deliver and protect the service, including a rough estimate of your region.

This data is not linked to any profile of you — there is no account — and we never send your name, email or personal content into usage measurement.

3.2 Notifications

When you turn notifications on, we process:

  • the installation's technical identifier;
  • this device's notification delivery address (push token);
  • platform;
  • the state of the notification permission;
  • the notification categories you chose;
  • language, content country and time zone;
  • which campaigns were sent, opened and converted.

The push token is used only to deliver messages to this installation. You can turn categories off inside the app and withdraw the permission in your device settings.

3.3 Configuration and catalog

The app may send to our servers:

  • the installation's technical identifier;
  • app, version and platform;
  • language;
  • content country and how it was determined;
  • the device's app store, when the platform provides it;
  • time zone;
  • app preferences;
  • the state of consent, where applicable;
  • the version of the configuration the app is using.

The catalog downloads pack metadata, covers and previews. The full file of a paid pack is delivered through a protected link after the purchase is validated. The CDN and the cloud provider process technical connection data, such as IP addresses, needed for delivery and security.

3.4 Support

When you use "Talk to us", we process:

  • category and message;
  • your email, only if you choose to receive a reply;
  • the installation's technical identifier;
  • app version, platform, language and content country;
  • a transaction identifier, only when the matter concerns a purchase.

Before sending, the app shows you the diagnostic information that will be attached. Photos, pasted content, sticker text and pack content are never attached automatically.

3.5 Diagnostics

When the app crashes, Sentry may receive:

  • the crash record and the point in the code where it happened;
  • app version, platform and technical device data;
  • performance measurements and technical context from a fixed list.

Automatic collection of personal data and attachments are turned off. Reports go through automatic scrubbing, but are still treated as potentially personal data and kept only for a short time.

On Android, the cutout uses Google's ML Kit, which may process technical data and diagnostic identifiers as described in the Google Play Services documentation included in the app.

Firebase may also process technical quality metadata, such as app and system version, device model and event delivery statistics. To prevent fraud, the app proves it is a legitimate copy running on a real device (App Check, with App Attest on iOS and Play Integrity on Android); this verification uses technical data about the app and device and is not used to track anyone across apps or websites.

3.6 Source photo cache

Source photo cache: when you pick a photo, Figurô may keep a normalized local copy (without EXIF metadata) in a private cache for up to 7 days, only so you can re-adjust the cutout. It never leaves your device, is excluded from backups, and disappears when you delete the sticker or draft — or earlier, if the system reclaims space.

3.7 Online cutout

When the device cannot cut out the photo locally, or during an authorized internal test:

  • the app shrinks and recompresses the image before sending it;
  • the request is only accepted if it comes from a legitimate app (App Attest or Play Integrity);
  • the server processes the image in memory only;
  • the response contains only the cutout outline;
  • the image is discarded when processing ends, including on errors;
  • nothing is written to disk: there is no temporary file, backup, image cache, model training or human review;
  • the server's technical logs never store the image.

Infrastructure providers may process IP addresses and technical metadata needed for the connection and for security.

3.8 Buying and restoring packs

Ready-made packs are sold through your device's app store. The store processes the payment; Figurô never receives or stores card numbers and never creates its own account.

To validate a purchase or restore packs, the app may process:

  • the installation's technical identifier;
  • the transaction identifier and receipt provided by the store;
  • app, version, platform and store of origin;
  • the record that this installation is entitled to the purchased pack.

Validation happens on our server, together with the store. Restoring uses the store account used for the purchase, with no Figurô account. We never receive card data or your store purchase history.

3.9 Importing received packs

When you import a .figuro or .wastickers pack, the app may compare its content with technical identifiers of catalog packs, on the device itself, to protect our paid content. This comparison is local: the received file and its images are never sent to a server because of it. If it matches a paid pack, the app offers the purchase instead of materializing the copy.

3.10 iMessage extension (iOS)

iMessage extension (iOS): Figurô includes a Messages app extension that only reads, on your device, a local copy of your sticker library (images, pack names, and order) shared through an iOS App Group. None of it leaves your device: the extension has no internet access, collects no data, and never sees your conversations.

3.11 Website

The website uses Google Analytics (GA4) to measure pages and clicks through to the stores. Depending on your region and your choice, the following may be processed:

  • measurement identifiers and cookies;
  • pages viewed and buttons used;
  • language, platform and originating campaign;
  • IP address and approximate region, processed by Google;
  • the privacy choice you made in the site's notice.

No support text or email ever enters measurement. The site's fonts and images are hosted by Volke itself.

4. Data we do not use

We do not use the following for measurement, campaigns, advertising or training:

  • photos, thumbnails, cutouts or pixels;
  • clipboard content;
  • sticker text;
  • the name and content of personal packs;
  • contacts, calendar, microphone or GPS location;
  • the device's advertising identifiers (IDFA/GAID);
  • name, national ID, phone number, gender or date of birth.

The optional support email is used only to reply and handle your case.

5. Purposes

  • run the cutout, catalog, export and the other features;
  • process and validate pack purchases and restores;
  • improve the product and its content;
  • measure acquisition, activation, retention and quality;
  • deliver the notifications you chose;
  • pick notifications by language, country, stage of use and content obtained;
  • offer and measure our own or clearly labeled sponsored marketing;
  • answer support;
  • prevent abuse, fraud and failures;
  • meet legal and store obligations.

Personal content is never used for targeting.

6. Legal bases and choices

In Brazil:

  • performance of the service supports the features you request, including the server cutout, pack purchase and restore, and support;
  • legitimate interest may support usage measurement, security, stability and improvement, always after assessing purpose, necessity, expectations and safeguards;
  • you can turn usage measurement off in the privacy choices;
  • marketing notifications depend on you turning them on yourself.

In regions that require prior consent for measurement or on-device storage, the corresponding collection only starts after your choice. Declining is as easy as accepting, and the decision can be changed later.

Services strictly necessary for security or for a requested feature may rely on another permitted legal basis. Regional rules are reviewed before they take effect.

7. Sharing and processors

We use providers that process data on our behalf:

  • Google Cloud, Firebase and Google Analytics;
  • Sentry;
  • Apple and Google, for distribution, integrity verification and platform services;
  • email providers, to answer support.

They receive only what is needed for the contracted purpose. We do not sell data or share it with ad networks. Legal disclosure may happen when required by law or a competent authority.

When you tap an external link, the destination's policy applies.

8. International transfers

Providers may process data outside Brazil. We use contracts, data processing terms, security measures and applicable transfer mechanisms. Where a jurisdiction requires a specific safeguard, it is put in place before processing.

9. Retention

Operational periods, confirmed in the production configuration:

DataRetention
Photo sent to the server cutoutonly while it is being processed
Pasted content (clipboard)on the device only, while useful for the creation
Usage measurement (Firebase/BigQuery)up to 14 months
Active installation and preferenceswhile active; expires after 13 months without use
Invalid push tokenremoved when detected as invalid
Transaction, receipt and the right to the packwhile the purchase and restore remain valid, plus legal and tax periods
Support caseup to 24 months after resolution
Email given to supporttogether with the case
Crash reports (Sentry)up to 90 days
Technical server logsup to 30 days, except for incidents or obligations
Record of your privacy choiceas long as needed to prove the choice and comply with the law

Aggregated and effectively anonymized data may be kept longer. Legal obligations, fraud, disputes or incidents may justify additional restricted retention.

10. Security

  • encrypted connections (HTTPS);
  • verification that the app is legitimate and the device is trustworthy;
  • validation and limits on every server call;
  • internal access restricted to the minimum necessary;
  • keys and secrets kept in a vault, outside the code;
  • paid content in private storage;
  • integrity checks on delivered files;
  • technical logs free of sensitive data;
  • backups and a restore plan;
  • monitoring and incident response.

No measure removes all risk, but the architecture reduces collection and exposure.

11. Rights and controls

Under applicable law, you may request confirmation, access, correction, objection, deletion, information, portability and review of consent.

Direct controls:

  • language and country in Settings;
  • notification preferences in the app;
  • notification, photo and camera permissions in the system;
  • privacy choices in the app and on the website;
  • the action that deletes this installation's data;
  • local deletion of packs when you delete them in the app or uninstall.

Since there is no account, we cannot find a person by name. The app shows a technical identifier you can use to follow up on requests and offers secure deletion of this installation's own data. Requests can also be sent to privacidade@figuro.com.br.

12. Children and teenagers

Figurô is not directed at children and creates no accounts. Use by minors should happen under a guardian's supervision. If we become aware of improper processing of a child's data, we will investigate and delete whatever is necessary.

13. Marketing and advertising

  • there is no third-party advertising in the app;
  • nobody has to watch an ad to make a sticker, and the close button is never hidden;
  • our own ads and sponsored content are clearly labeled and can always be closed;
  • the pack catalog is app content, not an interrupting ad;
  • usage measurement does not use the device's advertising identifiers;
  • we do not track anyone across apps or websites for advertising;
  • preferences and opt-outs are applied before anything is sent.

14. Changes

This Policy changes when the product, providers or the law change. The current version and its effective date are shown on this page. Significant changes are announced in the app or through another suitable channel.

15. Contact and authority

Requests: privacidade@figuro.com.br or dpo@figuro.com.br.

In Brazil, you may also petition the National Data Protection Authority (ANPD) and consumer protection bodies.


Volke Ideias Digitais Ltda. — CNPJ 66.727.282/0001-31.

FIGURÔ

Made by Volke in Brazil — where stickers are serious business.

oi@figuro.com.br
Terms of Use Privacy Policy Support Privacy & choices
PTENESIDTR

This site measures pages and store clicks with minimal data. Analytics never receives ads data, free text or personal content.

© 2026 Volke Ideias Digitais Ltda. · figuro.com.br · pt-BR · en · es · id · tr

May we measure how this site is used?

We use ad-free analytics to understand pages and store clicks. Rejecting is as easy as accepting.