Privacy

I wrote this page by reading the site's code, one data point at a time. Every claim here maps to something that actually exists.

Last updated: July 28, 2026.

This is a translation, here to make the page easier to read. If anything in it conflicts with the Brazilian Portuguese version, the Portuguese version is the one that governs.

Who's accountable for the data

Me, Thiago Xikota, based in Florianópolis, Brazil. This site is my personal portfolio. For anything to do with your data, the address is thiagoxikota@gmail.com. Whoever writes gets a reply from me, not a system.

Visit statistics

I use Umami, a cookie-free analytics tool, to count visits and see how people find their way to the mentorship and the resources. It records the page viewed, the referring site, the device type, and the country. According to Umami's own documentation, the tool collects no personally identifiable information and anonymizes everything it records; the IP is used on the server to derive the country, not kept tied to you. Important clicks become events carrying the campaign parameters from the URL, never a name, an email, or anything you typed. None of it identifies you as a person. Legal basis: legitimate interest in measuring the audience (Article 7(IX) of the LGPD, Brazil's data protection law). The statistics are aggregated and kept for up to 6 months, the retention period of the plan I use, published on Umami's pricing page.

The campaign parameters live in your browser's session storage (the xk-utm key) while the tab is open, so the attribution doesn't get lost as you move around. Close the tab and they're gone.

Contact form

The contact form sends your name, email, subject, and message to the Netlify Forms dashboard, since Netlify hosts the site. I use that only to reply to you. There's no automatic deletion window: I review and delete by hand. Legal basis: handling the contact you started yourself (Article 7(V) of the LGPD), with the consent box checked when you send.

The message field is free text. Don't put health data, ID documents, or anything sensitive in there. If something like that arrives when it didn't need to, I delete it from the dashboard and don't use it.

AI Product Club newsletter

If you arrive from Instagram, you see the invitation to subscribe to the newsletter. The form sends nothing but your email to Buttondown, which handles delivery. You only join the list after you confirm from the email you receive (double opt-in), and every send has an unsubscribe link. Your choice sits in your browser's local storage (the xk-nl-capture key): if you subscribed, the invite doesn't come back; if you only dismissed it, it may return after 30 days. Legal basis: consent (Article 7(I)).

Cookies

This site uses no tracking or advertising cookies, which is why there's no banner. There are two cookies, both functional.

portfolio_case_access: created when you unlock a password-protected case. It holds only the list of cases you've unlocked and their expiry, for 12 hours, and it's digitally signed so it can't be tampered with (the signature guarantees integrity, it doesn't hide the contents). It contains none of your personal data. Flagged as HttpOnly, Secure, and SameSite=Lax.

NEXT_LOCALE: stores the language you picked for 1 year, so the site opens in your language. It holds no personal data.

Preferences that stay on your device

Light or dark theme, larger text, high contrast, language, the last resource you opened, your progress through the tracks, and your reading position all sit in your browser's storage and are never sent to any server. All of it disappears when you clear your browser data.

WhatsApp

On the mentorship page, the scheduling button builds a WhatsApp message from the focus you picked and whatever you typed into the role, goal, and challenge fields. That message opens in your own WhatsApp, and sending it is up to you, after you've read it over. The site keeps none of it. When you tap the button, the pre-filled text passes through Meta's wa.me page, and from the moment you send, the conversation follows WhatsApp's own rules and encryption. Everywhere else on the site, the WhatsApp link is plain, with none of your data attached.

Those fields are free text: write only what you'd put in a first professional conversation.

Security logs

During security events (too many attempts, a blocked origin, a violation report sent by the browser), the server records your IP address and browser information in Netlify's logs. According to Netlify's documentation, those logs expire in about 24 hours (up to 7 days on paid plans). I use those records only to protect the site against abuse. Legal basis: legitimate interest (Article 7(IX)).

International transfer

Netlify, Buttondown, Umami, and Meta run servers outside Brazil, mostly in the United States. When you use the site, your data passes through that infrastructure, under the contractual safeguards those providers maintain (Article 33 of the LGPD).

Your rights

The LGPD (Article 18) gives you the right to: confirm whether I process any of your data, see what's there, correct anything wrong, ask for anonymization or deletion, request portability, find out who I shared it with, and withdraw any consent. Write to me at thiagoxikota@gmail.com. If you feel I didn't sort it out, you can petition the ANPD, Brazil's national data protection authority.

Changes to this page

If the site starts collecting something new, this page changes first, with the date at the top updated. Beyond what's described here, the site collects nothing from you.