Where things stand today
Effective date: 2026-08-10
Last updated: 2026-08-10
SmartHealthCompass is operated by Vinicius Barros de Souza, an individual based in Brazil (“we,” “us”). This policy explains what we collect, why, and what you can do about it.
Short version: we don’t sell your data, we don’t ask you to create an account, we run no third-party analytics or advertising trackers, and the one thing we do record about your behaviour — that a commercial link was clicked — is stored without your IP address, without your browser details, and without the page URL.
Who is responsible
Vinicius Barros de Souza, an individual (pessoa física) established in Brazil, is the party responsible for the personal data described in this policy — the “controller,” in the language of data-protection law.
Contact: contact@smarthealthcompass.com
We don’t publish a postal address. This site is operated by one person, not a company, and the only address that exists is a home address; putting it permanently on the public internet would create a real personal-safety and privacy problem in exchange for very little. Email is the channel for every request described in this policy, including data-rights requests, and it is monitored. If a law that applies to us ever requires a postal address — the U.S. CAN-SPAM Act does, for commercial email, which would matter the moment a newsletter launches — we will obtain a suitable business address rather than publish a home one.
Which laws apply here, in plain terms
We’d rather explain this than list statutes.
Brazilian law (LGPD) applies to us. The operator is based in Brazil, so Brazil’s Lei Geral de Proteção de Dados governs our processing regardless of where you’re reading from. The rights described below are ones you actually have under it, not courtesies.
California’s CCPA/CPRA almost certainly does not apply to us. It binds businesses above specific thresholds — annual revenue over US$25 million, personal information of 100,000+ consumers, or half of revenue from selling personal information. This site meets none of them and is not close. We nonetheless honor the rights it grants, voluntarily. We’re telling you it’s voluntary rather than implying a compliance obligation we don’t have — but a promise made here is one you can hold us to either way.
If you’re in the EU or UK: this site is aimed at readers in the United States and we don’t target the EU market. If you’re reading from there anyway, exercise any of the rights below by email and we’ll handle your request the same way. We’re not claiming full GDPR compliance; we’re telling you what we’ll actually do.
What we collect
Information you give us. If you contact us, we receive whatever you send — typically your name, email address, and message. We use it to reply and to keep a record of the exchange. We don’t add you to a mailing list from a support message.
Server logs. Like every website, the servers that deliver these pages keep access logs — IP address, browser and device string, referring page, page requested, timestamp. These are generated and retained by our hosting provider as part of running and securing the site. We do not build profiles from them.
Affiliate click events. When you click a commercial link, we record that the click happened. What that record contains is deliberately narrow: which piece of content it came from, which product and offer it pointed to, which affiliate network, a placement label, and the time. What it does not contain: your IP address, your user agent, the full page URL, any search term, and any health information. The database table has no columns for those things, so there is nowhere for them to go even by accident.
Note: as of this writing the site carries no affiliate links at all, so no such records are being created. See our Affiliate Disclosure. This section describes what will happen when commercial links exist.
No third-party analytics or advertising trackers. The site loads no Google Analytics, no Google Tag Manager, no advertising pixels, and no session-recording or heatmap tools. This was verified by inspecting the rendered pages, not assumed.
What we don’t collect: we don’t ask for or store health information about you. Please don’t send us that in a contact message either — we’d rather not hold it.
Why we collect it, and on what basis
To operate and secure the site; to understand which content is useful; to maintain the accuracy of our commercial links; to reply to you; and, once affiliate links exist, to meet our obligations to affiliate partners for commission attribution.
Under the LGPD, our basis for this processing is our legitimate interest in operating and improving the site (art. 7, IX) — except for messages you send us, which we process because you chose to send them, and anything we must keep to comply with a legal obligation.
Cookies
We set no advertising cookies and no analytics cookies, because we run neither. Reading this site does not require accepting anything, which is why you see no cookie banner: there is no non-essential cookie for a banner to ask you about.
WordPress may set a small number of strictly functional cookies — for example if you are a logged-in administrator of this site, which readers are not.
Affiliate networks are different. When you follow a commercial link you leave our site, and the network on the other side typically sets its own cookie so that a purchase can be credited to us. That cookie is set by them, on their domain, under their policy — after you have left. We cannot see it, control it, or delete it for you.
How long we keep it
Affiliate click event records are retained for 90 days, then deleted. The retention window is a configured setting and a scheduled job deletes anything past it.
Contact messages are kept as long as needed to handle the matter and for a reasonable period afterward. Server access logs are retained according to our hosting provider’s own schedule.
Who we share it with
We don’t sell personal information, and we don’t share it for cross-context behavioral advertising. The list of parties who receive data is short: our hosting provider, which operates the servers and their access logs; and — once commercial links exist — affiliate networks, which receive click and conversion data through their own link and cookie once you leave our site.
That is all. No advertising platform and no data broker receives anything.
International transfers. The operator is in Brazil and the hosting infrastructure and readers are largely elsewhere, so data necessarily crosses borders in the ordinary course of serving a website.
Third parties we send you to. When you follow an affiliate link you leave our site. What the destination does with your data is governed by their privacy policy, not this one.
Your rights
You can ask us to confirm whether we hold personal data about you; to give you a copy; to correct it; to delete it; to tell you who we’ve shared it with; and to explain the basis on which we processed it. You can object to processing, and you won’t be treated differently for exercising any of this. Under the LGPD these are your rights under art. 18; if you’re in California, they mirror what the CCPA/CPRA grants, which we honor voluntarily as explained above.
To make a request, email contact@smarthealthcompass.com. We may need to verify your identity before acting, and we’ll respond within the timeframe the applicable law requires.
In practice there is usually very little for us to hand over: we hold no account for you, and the affiliate-click records contain nothing that identifies you.
If you’re in Brazil and unhappy with how we’ve handled a request, you can complain to the Autoridade Nacional de Proteção de Dados (ANPD).
Do Not Track and Global Privacy Control. We do not currently detect or respond to either signal. We would rather say that plainly than claim a compliance we haven’t built.
Children
This site is intended for adults. We don’t knowingly collect personal information from children under 13, and we don’t direct content to them. If you believe a child has given us personal information, contact us and we’ll delete it.
Supplements carry particular risks for children. Nothing on this site should be used to make decisions about a child’s health without a pediatrician.
Security
We use reasonable safeguards, including encrypted connections. No method of transmission or storage is completely secure, and we can’t guarantee absolute security.
Changes
We’ll update this policy when our practices change, revise the “last updated” date, and — for material changes — note the change visibly rather than swapping the text quietly.
Contact
Questions or requests: contact@smarthealthcompass.com, or via the Contact page.
