Privacy Policy
Last updated: September 2026
Khartos takes the protection of your personal data seriously. This Privacy Policy explains what data we collect, why we collect it, how we use it, who we share it with, and what your rights are as a data subject, in compliance with the Brazilian General Data Protection Law (Lei nº 13.709/2018 — LGPD).
1. Data We Collect
We collect the following personal data, organized by category: (a) Registration data: name, email address, password (stored as a bcrypt hash, never in plain text). If you choose social login (Google), we receive your name and email from the identity provider — we never receive your password from these services. (b) Profile data (optional): date of birth, phone number, country, city, dietary restrictions, accessibility needs, biography. (c) Travel data: destination, origin, dates, number of travelers and children's age range (never exact dates of birth of third parties), travel preferences, budget, accessibility preferences. (d) Payment data: transactions are processed entirely by Mercado Pago. Khartos never stores card numbers, CVV, or direct payment data. We store only the transaction identifier and payment status. (e) Usage data: interactions with the service, AI content generation logs (with anonymized identifier), communication preferences, and consent records. (f) Technical data: IP address (truncated in audit logs), browser type, and essential session cookies. Khartos does not collect CPF (Brazilian tax ID) or biometric data.
2. How We Use Your Data
We use your personal data for the following purposes: (a) Service delivery: creating and maintaining your account, generating destination guides, travel itineraries, pre-trip checklists, and logistics insights personalized to your trip. (b) Personalization: tailoring AI recommendations to your travel profile, preferences, budget, and accessibility needs. (c) Communications: sending emails related to account security (password reset, session alerts) and, with your consent, communications about your trip or service news. (d) Payments: processing credit purchases and subscriptions through Mercado Pago, recording transaction history, and granting corresponding credits. (e) Security and fraud prevention: applying rate limiting, detecting anomalous patterns, and protecting the integrity of the service. (f) Service improvement: analyzing aggregated and anonymized usage data to understand usage patterns and improve features.
3. Legal Basis for Processing (LGPD Art. 7)
Each processing purpose is supported by a specific legal basis: (a) Performance of contract (Art. 7, V): providing the travel planning service, account management, and payment processing. (b) Consent (Art. 7, I): use of artificial intelligence to process your travel data; sending engagement and marketing communications; processing optional profile data. To revoke AI consent, contact support at support@khartos.com. Other consents (communications and profile data) may be revoked at any time in My Account. Revocation does not affect processing carried out prior to revocation. (c) Legitimate interest of the controller (Art. 7, IX): service security, fraud prevention, rate limiting, and aggregated usage analysis. (d) Legal obligation (Art. 7, II): retention of transaction records as required by tax legislation and Brazil's Civil Internet Framework (Marco Civil da Internet); maintenance of consent records (Art. 8, par. 2, LGPD).
4. Artificial Intelligence Processing
Khartos uses artificial intelligence models to generate destination guides, itineraries, checklists, and logistics insights, subject to your explicit consent. Data sent is sanitized and any identifiable information is masked before sending; your name, email, and documents are never sent to AI providers. The full details — data processed, providers, international transfer, and how to revoke consent — are set out in the AI Use Consent Term document.
5. Data Sharing and Sub-processors
Khartos does not sell, rent, or trade your personal data. We share data strictly with the sub-processors necessary to operate the service, listed below with their purpose and location: (a) Natural language processing providers powered by Artificial Intelligence (located mostly in the United States) — generation of personalized content across the expedition phases (guides, itineraries, checklists, and logistics insights). Receive only sanitized travel data, without PII. (b) Google / OAuth (USA) — social login authentication (when the user chooses this method). (c) Mercado Pago (Brazil) — payment processing. Receives data necessary for the transaction; Khartos never stores card data. (d) Resend (USA) — transactional and communication email delivery. Receives email address and email content. (e) Managed database provider (cloud infrastructure, USA) — storage of your data. Production and staging environments are completely separate projects. (f) Caching provider (cloud infrastructure) — temporary caching for rate limiting and AI results. Ephemeral data, maximum TTL of 24 hours, isolated by environment via key prefix. (g) Hosting provider (USA) — web application hosting, performance analytics, and speed metrics. Analytics collect aggregated browsing data without direct personal identification. (h) Error-monitoring provider (USA) — application error monitoring. PII is actively scrubbed before sending: email, IP address, username, cookies, and authorization tokens are removed from all events. (i) Maps and geocoding provider (USA) — geocoding services and map rendering. Receives geographic coordinates and locality names. (j) Open geographic data provider (distributed infrastructure) — fallback geocoding. Receives locality names for coordinate resolution. (k) Destination image provider (USA) — images used in guides. No personal data is shared. (l) Encyclopedic data provider (distributed infrastructure) — factual data about destinations. No personal data is shared.
6. Data Storage and Security
Your data is stored in a managed PostgreSQL database (Neon), with infrastructure in the us-east-2 region (USA). We adopt the following security measures: (a) Encryption at rest: sensitive travel document data (passport number, national ID number) is encrypted using AES-256-GCM before storage. (b) Encryption in transit: all communications use HTTPS/TLS. (c) Passwords: stored exclusively as bcrypt hashes; never in plain text. (d) Sessions: managed via JWT tokens with defined expiration. (e) Access control: each user accesses only their own data (ownership verification on all operations). (f) Audit logs: record actions on sensitive data with an anonymized user identifier (truncated SHA-256 hash). IP addresses are truncated; no personally identifiable data appears in logs. (g) Error monitoring: Sentry receives error events with PII actively scrubbed (email, IP, cookies, tokens).
7. Data Retention
We retain your personal data only for the period necessary for the purposes described in this policy: (a) Account and profile data: retained while your account is active. (b) Travel data (itineraries, guides, checklists): retained while your account is active and the content has not been deleted by you. (c) Consent records: retained for the applicable legal period, as evidence of consent provided (Art. 8, par. 2, LGPD). (d) Transaction records: retained for the period required by tax legislation and Brazil's Civil Internet Framework. (e) Audit logs and AI interaction logs: anonymized (user identifier replaced with an irreversible hash, metadata removed) when the account is deleted; retained in anonymized form for security and service improvement purposes. (f) Redis cache: ephemeral data with a maximum time-to-live (TTL) of 24 hours, automatically purged. After account deletion, your data follows the process described in section 8 (Your Rights).
8. Your Rights as a Data Subject (LGPD Art. 18)
You have the following rights regarding your personal data, which may be exercised in My Account or by contacting our team: (a) Confirmation and access (Art. 18, I and II): confirm the existence of processing and access your personal data. (b) Correction (Art. 18, III): correct incomplete, inaccurate, or outdated data directly in My Account. (c) Anonymization, blocking, or deletion (Art. 18, IV): request the anonymization, blocking, or deletion of unnecessary or excessive data. This request is made manually by contacting support at support@khartos.com. (d) Portability (Art. 18, V): request portability of your data to another service provider. This request is made manually by contacting support at support@khartos.com. (e) Deletion of data processed based on consent (Art. 18, VI): request deletion of personal data processed on the basis of your consent. (f) Information about sharing (Art. 18, VII): obtain information about the entities with which your data is shared (see section 5). (g) Revocation of consent (Art. 18, IX): revoke AI consent at any time by contacting support at support@khartos.com; revoke other consents (communications and profile data) at any time in My Account. Account deletion process: when you request account deletion, Khartos immediately deactivates your account (soft-delete), making your account and data inaccessible. After 30 (thirty) calendar days, an automated process performs the definitive deletion (hard-delete) of your personal data, including: account and profile data, trips and generated content, travel document data, gamification data, sessions and access tokens, subscription and purchase data. Audit logs and AI interaction logs are anonymized (user identifier replaced with an irreversible hash, metadata removed), not deleted, for security and compliance purposes. Important: certain operational records (such as email delivery logs and address suppression records) may not be immediately eliminated by the current automated process. We are continuously working to expand the coverage of automated deletion. If you wish to confirm the complete elimination of your data, please contact us through the channel indicated in section 13.
9. Cookies and Similar Technologies
Khartos uses only strictly necessary cookies for the operation of the service: (a) Authentication session cookie: managed by the authentication framework (Auth.js/NextAuth), required to keep your session active. Expires at the end of the session or according to the token duration setting. (b) Language preference cookie: stores your language choice (Portuguese or English) so the service is displayed in the correct language. We do not use tracking cookies, third-party advertising cookies, or fingerprinting technologies. Vercel Analytics collects aggregated performance metrics without personal tracking cookies.
10. Protection of Minors
Khartos is intended exclusively for users aged 18 (eighteen) or older. We do not knowingly collect data from individuals under 18. By creating an account, you declare that you are at least 18 years old. If we become aware that we have collected data from a minor under 18, we will promptly delete such data. In the travel planning feature, it is possible to indicate that children will be part of the traveling group. In this case, we collect only the age range (an integer representing age), never the child's name, date of birth, or any other identifiable data. This information is used exclusively to adapt itinerary recommendations (for example, suggesting age-appropriate activities).
11. International Data Transfers
Your personal data may be transferred to countries that do not offer the same level of data protection as Brazil, specifically to the United States, where our AI processing sub-processors, hosting and database, error monitoring, maps and images, and our email provider (Resend) are located. These transfers are carried out pursuant to LGPD Art. 33 and are supported by: (a) specific and prominent consent of the data subject, obtained through acceptance of this Privacy Policy and AI usage consent; and (b) contractual clauses with sub-processors that ensure an adequate level of protection. Data sent to AI providers passes through the protection pipeline described in section 4, which removes any directly identifiable information before transfer.
12. Changes to This Policy
We reserve the right to update this Privacy Policy periodically. When substantial changes are made, we will notify you through the service (in-app notification or email, depending on the nature of the change). Continued use of the service after notification constitutes acceptance of the updated version. The date of the last update is always indicated at the top of this page. We recommend that you review this policy periodically.
13. Contact and Data Protection Officer (DPO)
To exercise your rights as a data subject, clarify questions about this policy, or report privacy-related incidents, please contact us: Khartos Email: support@khartos.com The Data Protection Officer (DPO) can be reached through the same channel. We are committed to responding to data subject requests within 15 (fifteen) business days, as provided by LGPD Art. 18, par. 5.