FeedMedic
Privacy Policy
Last updated: May 25, 2026
1. Who we are
FeedMedic is a SaaS platform operated by FeedMedic Tecnologia Ltda., registered under CNPJ No. 20.331.387/0001-76, headquartered in Brazil. This Privacy Policy describes how we handle the personal data of the physicians who use the platform, in compliance with the Brazilian General Data Protection Law (Law No. 13.709/2018, the LGPD).
2. Data we collect
We collect only what is needed to operate the service:
- Account: name, email, profile picture (Google OAuth, where applicable), medical specialty, CRM number (self-declared).
- Clinical profile: target audience, communication tone, color palette, chosen visual template.
- Connected Instagram account: ID, username, account type, profile picture, bio, public counters (followers, posts) and the access token required to publish on your behalf. The token is stored on infrastructure with encryption at rest and restricted access, and used only for the operations you authorize.
- Generated content: text, titles, and images of the posts created on the platform, along with their publishing schedules.
- Operational telemetry: usage logs, errors, performance metrics, to diagnose issues and improve the service.
3. Legal bases and purposes
Data is processed under the following grounds of Article 7 of the LGPD:
- Performance of a contract (Art. 7, V): to provide the contracted service (content generation, scheduling, publishing to Instagram).
- Compliance with a legal obligation (Art. 7, II): responding to requests from authorities, keeping tax records.
- Legitimate interest (Art. 7, IX): fraud prevention, information security, aggregated usage metrics.
4. Sharing with third parties
FeedMedic runs on infrastructure from providers that process data on our behalf, under contracts compliant with the LGPD:
- Supabase (Supabase, Inc.): database and file storage. Data is hosted in the sa-east-1 region (São Paulo).
- Vercel (Vercel Inc.): hosting for the web application and serverless functions.
- Meta Platforms (Instagram Graph API): receives the text and images you publish from the platform.
- Anthropic (Claude API): processes the physician's brief and generates the suggested content. Inputs and outputs are not used to train models.
- Resend: sending transactional emails (signup confirmation, password recovery).
We do not sell personal data and do not share it for third-party marketing purposes.
5. Retention
We keep your data for as long as your account is active. When you request deletion through the Instagram panel (“Apps and Websites” → FeedMedic → Remove), removal is processed immediately and you can track the status via the link provided by Meta. On manual account cancellation, identifiable personal data is deleted within 30 days. Anonymized data may be retained indefinitely for aggregated statistics, and the record of the deletion request is kept for 90 days for auditing purposes.
Tax records and security audit logs are kept for the periods required by law (5 years for tax records, 6 months for access logs, under the Brazilian Internet Civil Framework).
6. Your rights (LGPD, Art. 18)
At any time, you may:
- Confirm that processing exists and access your data.
- Correct incomplete, inaccurate, or outdated data.
- Request the anonymization, blocking, or deletion of unnecessary data.
- Request the portability of your data to another provider.
- Withdraw consent and request full deletion of your account.
To exercise any of these rights, send an email to privacidade@feedmedic.com from your registered email address. We respond within 15 days.
If you have requested deletion through the Instagram panel (under “Apps and Websites” → FeedMedic → Remove), our platform automatically receives the notification and processes the deletion. Track it via the link provided by Meta.
7. Security
We use encryption in transit (TLS 1.2+) and at rest, role-based access control (RLS) in the database, per-user isolation, and periodic review of permissions. No method is 100% secure. In the event of an incident, we will notify the ANPD and the data subjects in accordance with Article 48 of the LGPD.
8. Minors
The service is intended for physicians with active CRM registration, therefore for those over 18 years of age. We do not knowingly collect data from minors.
9. Cookies
We use only strictly necessary cookies for authentication (Supabase session) and to preserve interface preferences. There are no advertising or third-party tracking cookies.
10. Changes to this policy
We may update this Policy periodically. We will notify you by email and through the application panel whenever there are material changes. The version in effect is always the one published at this URL with the date above.
11. Data Protection Officer (DPO)
Email: dpo@feedmedic.com