How Belo AI collects, uses, and protects personal information, including cookies, retention, safeguards, and privacy rights.
Effective date: 2026-07-26
This Privacy & Data Notice (“Notice”) explains how Belo Inteligência Artificial Ltda (“Belo,” “we,” “us”) processes personal data related to websites, applications, APIs, accounts, communications, billing, and associated services (the “Services”).
This Notice applies to personal-data processing activities in which Belo acts as a controller, including in relation to visitors, account users, administrators, representatives, and business customers’ commercial and support contacts.
Where Belo processes Customer Personal Data solely on behalf of, and in accordance with the documented instructions of, a business customer, Belo acts as a processor, and that processing is also governed by the applicable DPA. In the event of conflict, the DPA prevails solely with respect to processing performed by Belo in its capacity as processor. For all other activities in which Belo acts as controller, this Notice remains fully applicable.
Related documents:
Contact for privacy requests: belo@belo.ai.
The activities under Art. 41 §2 include receiving data-subject complaints and communications, providing clarifications, taking measures, receiving ANPD communications, and guiding personnel.
The Belo AI service is provided by Belo Inteligência Artificial Ltda, a company incorporated and headquartered in Brazil, at Rua da Consolação, 2302, São Paulo/SP – CEP 01302-001.
Depending on the context:
We do not purchase personal data from data brokers. We may receive:
Belo does not intentionally request sensitive or special-category personal data as a general condition of use. However, upload features, prompts, and integrations may technically receive such data if the user enters it. You should avoid submitting it unless strictly necessary, lawful, authorized by the contract, and accompanied by applicable safeguards. Belo may restrict or remove content that creates regulatory, security, or third-party risk.
Where a request relates to Customer Personal Data processed by Belo as processor, the data subject should preferably direct the request to the responsible business customer. Belo will provide the assistance to the customer specified in the DPA. Where a request relates to processing carried out by Belo itself as controller, it may be sent directly to Belo through the channels indicated in this Notice.
When you or another user publishes Public Content, or shares Content with co-authoring or byline permissions, the platform records who views that content and surfaces that record to the author(s) and to users with equivalent share permissions: viewer user ID, display name, handle, avatar, view count, and first/last viewed timestamps. Lists of people who liked, bookmarked, or subscribed to Content shown to the author or to users with equivalent share permissions also include whether the viewer's email address is verified. Belo does not currently provide a viewer-side opt-out from appearing in these author-facing records; anonymous or logged-out views are not attributed to an identified viewer.
A limited number of Belo personnel hold application-administrator access, used on a need-to-know basis for support, security, billing, and platform-operation purposes. That access can include a user's email address, last-login IP address and derived approximate location (city, region, time zone), and usage/event history, and — where necessary for the purpose above — can bypass ordinary workspace-resource ownership boundaries. Access by Belo personnel through this path is logged in Belo's audit trail.
We use information to:
We do not sell personal information and do not share personal information for cross-context behavioral advertising.
Depending on the context, Belo processes data to perform a contract and pre-contractual procedures; comply with legal and regulatory obligations; exercise rights in proceedings; protect life or physical integrity where exceptionally applicable; serve Belo’s or third parties’ legitimate interests, after assessing necessity and the data subject’s rights; and with consent where required, especially for non-essential cookies and optional communications.
They may include security, fraud and abuse prevention, support, proportionate product improvement, account administration, internal metrics, defense of rights, and relevant B2B communications. The data subject may object in cases provided by law, and Belo will assess the request considering overriding legitimate grounds.
Content that you submit (including prompts, files, and team content) is processed to provide features such as retrieval, analysis, chart generation, and AI-assisted responses. For enterprise processing under a DPA, Customer Personal Data is processed only on documented instructions.
Belo does not use Customer Content to train or fine-tune foundation models. Model providers are used in enterprise/API configurations that, under the terms applicable to Belo, restrict the use of inputs and outputs for general training. Belo does not control unilateral changes or legally required processing by third parties and will update its disclosures if a known material change occurs.
Prompts and relevant context may be sent to model providers solely to generate outputs for your request. Providers process data under their terms and the Subprocessor List.
The Services produce analyses that may support human decisions, but Belo does not intend to make, on its own behalf, decisions based solely on automated processing that produce legal effects or significant impacts on data subjects. Customers that use Outputs in decision-making processes are responsible for the legal basis, transparency, human review, explanation, and exercise of rights. Belo will provide reasonable assistance when acting as processor and where the DPA applies.
Unless a written enterprise agreement provides otherwise, Belo AI may use de-identified, aggregated, or transformed service signals to operate, protect, and improve the Services — for example:
This exception does not authorize model training using your prompts, files, or workspace content.
BYOC deployments: for customers running Belo AI in their own cloud infrastructure (BYOC), licensing metadata and basic telemetry (heartbeat — a license-validation signal) are processed by Belo AI as an independent controller for license management, security, billing disputes, and legal compliance (LGPD Art. 7, items II, V, and IX, as applicable). Fields that identify a natural person are personal data; aggregate counts that do not identify a person are not. Customer Content does not leave the customer environment through those heartbeats. Any international transfers of this metadata follow the applicable LGPD legal bases, as detailed in the Corporate/BYOC Addendum.
We share data only to the extent necessary with subprocessors, service providers, and partners that perform infrastructure, AI-model, search, translation, authentication, payment, email, analytics, security, and support functions. Some third parties, such as payment processors, marketplaces, or services that you voluntarily connect, may act as independent controllers for their own purposes and are subject to their respective privacy notices.
The detailed, up-to-date list of specific subprocessors that process personal data on our behalf — including vendors, purposes, locations, and transfer mechanisms — is available in the Subprocessor List. For corporate customers, prior-notice and objection rights for subprocessor changes are provided in the DPA.
We may also share information:
We use essential cookies and similar technologies for authentication, session management, security, and core functionality. They are required for the Services to function and cannot be disabled through an in-app control.
We may store some preferences (for example, display theme) in browser storage such as localStorage or sessionStorage. Some preferences are instead stored in a first-party cookie — see the global-chat-preferences row in the table below, which is cookie-based, not localStorage-based, and can include your selected data sources for a chat.
We use essential cookies and, with consent where required, Google Analytics 4 (GA4) and equivalent technologies for usage and performance metrics. Actual loading and parameters depend on the banner/CMP configuration and the jurisdiction. Belo does not use prompt or chat content for behavioral advertising. Consent preferences may be changed in the banner or available settings.
Messages sent to AI assistants run in a dedicated product context to provide the feature. We do not use advertising networks to monetize chat content.
belo_aid is gated by a single consent choke point: it is set, read, and refreshed only when you have granted analytics consent and no Global Privacy Control signal is present (see §7.7). Without analytics consent, no belo_aid value is issued — not a shorter identifier, not a hashed one, none. If analytics consent is withdrawn or a GPC signal is received after an id was previously set, the existing cookie is actively expired rather than continuing to be read.
You may adjust browser settings to remove or block cookies; doing so may break authentication or other core functionality. Non-essential cookies (currently belo_aid) can also be controlled directly through the consent banner or the available privacy/consent settings, and through a Global Privacy Control signal where your browser or extension sends one (see §7.7). Essential cookies listed in the table above are required for the Services to function and cannot be disabled through an in-app control.
Belo treats Global Privacy Control (GPC) as a floor, not a toggle: when your browser or extension sends the GPC signal, Belo denies the analytics and marketing consent categories for that visit, does not display a banner request for those categories, and derives that denial from the signal on every subsequent read — so a previously stored "accept all" consent choice cannot override an active GPC signal. Essential/necessary processing (for example, authentication and session cookies) is unaffected by GPC. The technical unavailability of a GPC signal does not prevent exercising rights through the channels in this Notice.
Analytics preferences may also be managed directly through the consent banner on the website (see §7.6 for the general cookie-management channels).
Periods vary by category and purpose, including account and contract duration; tax and accounting periods; six months for application-access records when required by the Marco Civil; the period necessary for security, audit, and fraud prevention; limitation periods; and technical backup cycles. Belo will maintain an internal retention schedule and may disclose more specific periods in the Trust Center.
We retain personal information only for as long as necessary for the purposes in this Notice, unless a longer period is required or permitted by law (including for tax, accounting, security, and dispute purposes).
Typical categories (illustrative; an enterprise DPA may establish different standards):
Belo provides an authenticated flow for individual data export and account-deletion requests. Deletion may require re-authentication and additional confirmation; it will not be completed while there is an active subscription or where the user is the sole owner of a shared workspace, and it can remain resumable while a payment-provider detachment is pending. Requests that cannot be completed through the flow may be submitted through the privacy channel after proportionate identity verification. Data in backups will be isolated and deleted according to the applicable cycle, except where restored for contingency purposes. Legal-retention, security, fraud-prevention, defense-of-rights, billing-record, mandatory-record, and backup-cycle exceptions continue to apply, subject to the six-month application-access-log retention required by the Marco Civil (§8.1) and the individual export/deletion scope described in §11.1.
Belo AI adopts administrative, technical, and organizational safeguards proportionate to its size and risk, including:
No system is 100% secure. Belo AI is not currently certified under SOC 2 or ISO 27001; this Notice does not claim formal certifications. Up-to-date security and compliance information is available on the Trust page1 (belo.ai/trust).
Data may be processed in Brazil, the United States, the European Union, and other locations identified in the Subprocessor List. Belo will use a valid mechanism according to origin and destination, including an adequacy decision, ANPD standard contractual clauses, EU SCCs, the UK Addendum/IDTA, or another permitted safeguard. Where necessary, supplementary measures, minimization, and risks in the importer country will be assessed.
Personal data may be processed in Brazil, the United States, and other locations where Belo AI and its subprocessors operate (see the Subprocessor List). Transfers rely on appropriate mechanisms under applicable law, which may include:
Hosting-region defaults (for example, the default region of the cloud provider in use) may change; enterprise residency commitments exist only if expressly contracted.
Subject to legal limits, you may request confirmation of processing, access, correction, anonymization, blocking, deletion, portability, information about sharing, withdrawal of consent (where processing is based on consent), and review of automated decisions (Art. 20).
Organization-level export and an authenticated flow for individual data export and account-deletion requests are available. The individual export is provided as a JSON file and does not include credentials. It includes your profile, your own chats/messages/content, your credits ledger, your billing customer/subscription data, your consent data, your linked OAuth account records, your session records, your user-event and usage-event records, and any database-connection metadata you configured (with connection secrets removed). The individual export does not include: credentials, tokens, or database-connection secrets; other people's data or co-owned workspace content you did not author; records retained under the exceptions in §8 (for example, credit-ledger and billing rows retained after unlinking, usage-event rows retained after unlinking, and session rows retained after IP-and-user-agent scrubbing); the organization-level export and rights flow; a viewership opt-out (see §2.5, which applies with no opt-out); or detachment from the Brazilian payment provider, which the deletion flow does not currently perform. When deletion is completed, Belo deletes data and storage objects demonstrably linked to the user, to the extent described above, while anonymizing financial and credit records that must be retained; the limitations stated in §8 apply. Requests may also be sent to belo@belo.ai (see §11.4).
Where the GDPR / UK GDPR applies, you may have rights of access, rectification, erasure, restriction, portability, objection, and complaint to a supervisory authority.
Where the GDPR applies and Art. 27 requires it, Belo AI's representative in the European Union is Números Salutares, Unipessoal, Lda (NIPC 516986180), Rua Mouzinho da Silveira, 32, 1250-167 Lisboa, Portugal. Contact: belo@belo.ai.
For residents of U.S. states with applicable comprehensive privacy laws (e.g., California), and subject to the legal applicability thresholds of each law, you may have rights to know/access, correct, delete, obtain a copy, and opt out of certain processing. International checkout is available; state rights apply as legal thresholds are met. We handle requests from residents of, among others:
We do not sell personal information. We do not share personal information for cross-context behavioral advertising as those terms are defined under the CPRA.
Email belo@belo.ai with enough detail to verify your identity and locate the data. We may need additional verification. Authorized agents may submit requests where law permits, subject to proof of authorization.
Enterprise end users should typically contact their organization first; Belo AI will assist the customer under the DPA.
The Services are not intended for persons under 18. We do not knowingly collect personal information from minors. If you believe a minor has provided data, contact us for deletion.
BYOC (customer-cloud) deployment can be made available upon request for Corporate customers. Deployment terms, cloud environment, and provisioning conditions will be defined in a mutually executed Corporate/BYOC Addendum (see also the Subprocessor List).
If your organization runs Belo AI in its own cloud under a Corporate/BYOC Addendum:
We may update this Notice periodically. The updated version will be published with a revised effective date. Material changes will be notified reasonably (website, in-product, and/or email). Where re-acceptance of the Terms is required, the legal-acceptance version gate applies.
Belo Inteligência Artificial Ltda
Rua da Consolação, 2302, São Paulo/SP – CEP 01302-001 – Brazil
Email: belo@belo.ai
For enterprise DPA / transfer questions: belo@belo.ai (subject: “Privacy / DPA”).
Belo AI



Jun 16
The inversion has unwound, but history suggests this isn't a recovery—it's a warning.
Apr 9

