Três Limões · PLAYER 3
Privacy Policy — PLAYER 3
Version 1.2 · in force from 20 September 2026
Language: this is a translation of the Portuguese original, published at
player3.treslimoes.com.br/privacidade. The Portuguese version is the legally binding one;
if the two ever diverge, the Portuguese text prevails.
This document describes what PLAYER 3 collects, what it uses it for, and what rights the user has over that data. This policy is versioned: any material change produces a new version, with its own effective date, and the previous version remains available for consultation.
1Who processes your data
PLAYER 3 is operated by BARBOSA E FOLLE DESENVOLVIMENTO DE SOFTWARE LTDA ("Três Limões", "we"), CNPJ 68.586.378/0001-52, registered at Av. Paulista, 91, Brazil.
For anything to do with your privacy — questions, requests for access, correction or deletion of data — write to us at privacidade@treslimoes.com.br.
Data Protection Officer: in accordance with Art. 41 of the LGPD (Brazil's General Data Protection Law, Law No. 13,709/2018), Três Limões appoints Logan Cunha Folle as the officer responsible for personal data processing. The channel is free and direct:
- E-mail: dpo@treslimoes.com.br
- Hours: Monday to Friday, 9am to 6pm (BRT), except public holidays
Section 9 describes the rights you can exercise through that channel and the response deadline.
2Minimum age
PLAYER 3 requires a minimum age of 13 to create an account. The date of birth given at sign-up is checked at the moment of registration, and an account is only created if the age calculated from it is 13 full years or more. PLAYER 3 therefore declares itself an app not directed at children under 13.
3Data we collect
We collect only what the app needs to work:
- E-mail address, used to identify the account, for authentication, and to send the password recovery code when you ask for it. That is the only message PLAYER 3 sends: there is no newsletter, no product announcement and no marketing communication.
- Password, always stored as a hash — never in readable text, not even by us.
- Date of birth, used exclusively to verify the minimum age described in section 2. It is not shown to other users.
- Reviews: the scores, tags and other information a person records when rating a game (overall score, per-attribute scores, context tags, verdict tags, whether they would recommend the game, play-time range and, where applicable, the platform played on).
PLAYER 3 has no free-text field visible to other users on any screen of the app. Any suggestion to add a game sent by a user is visible only to the PLAYER 3 team, never to other users of the app.
4Reports with aggregate data — and your consent
Beyond direct use inside the app (calculating and displaying the game ranking), PLAYER 3 may produce reports with aggregate, non-identifiable data — for example, average scores by attribute, by platform and by region — including in order to share or commercialise that kind of report with third parties, such as game studios and publishers interested in understanding how their titles were received.
This depends on your consent, and on nothing else. The legal basis is consent (Art. 7, I of the LGPD), not legitimate interest: we treat these reports as personal data, not as anonymised data outside the reach of the law.
How you control it. Consent is requested at sign-up, with this explanation in view, and remains available to switch on or off at any time in the Profile tab. Three things follow from that:
- Declining does not prevent you from using the app. You create the account and use everything normally without consenting — consent is freely given, and making access conditional on it would make it invalid.
- Withdrawing is as easy as granting, and it applies from the moment you switch it off.
- We record when, and under which version of this policy, you consented, so that it is possible to know which text you said yes to.
Calculating and displaying the ranking inside the app does not depend on this consent: it is the purpose for which you created the account, and the app would have no function without it. What consent covers are the reports described above.
These reports never identify an individual: the data is aggregated before it leaves the database, in such a way that a specific person's review cannot be reconstructed from the report.
5Account deletion
PLAYER 3 offers account deletion directly from the app, with no need to contact support externally — this is a requirement from Apple itself for apps with sign-up, and an obligation under this policy. The control is in the Profile tab, available to anyone with an active session, and it asks for explicit confirmation before deleting anything.
When exercised, account deletion permanently removes the e-mail address, the password (the stored hash) and the date of birth associated with the account, as well as any data dependent on it. After deletion, the account cannot be recovered.
About the record of access requests handled. If you request a copy of your data through the channel in section 9 and we fulfil it, we keep a record of that: the e-mail address the copy was delivered to and the date of delivery — nothing of the exported content. That record survives account deletion, and it is the only exception to the paragraph above. The reason is the same as for reports already produced: it does not exist to give us access to you, it exists to prove what was done. A record of a request handled that disappears along with the data accounts for nothing — not to you, if you one day need to show that you exercised the right, and not to the authority, if it asks. The legal basis is compliance with a legal and regulatory obligation by the controller (Art. 7, II of the LGPD), together with the principle of accountability (Art. 6, X).
About reports already produced. An aggregate report that has already been generated and delivered to a third party is not undone by the deletion of your account, because it contains no data that allows you to be identified — there is nothing in it of yours to delete. What deletion guarantees is that your data does not enter any future report. The same applies to withdrawal of consent (section 4), which takes effect from the moment you switch the control off.
6Ads and tracking
PLAYER 3 plans to display third-party ads (via AdMob) and to offer affiliate links as part of how it sustains itself financially. This section is written into this first version of the policy even though the ad SDK will only be integrated at a later stage of development — so that introducing ads does not require a change of policy, nor fresh consent, at the moment the feature launches.
- App Tracking Transparency (ATT): before any tracking across third-party apps or sites for personalised advertising purposes, PLAYER 3 asks for the user's consent through Apple's ATT mechanism. Without that consent, the app carries on working normally and shows only non-personalised ads — the app's behaviour does not change between the two choices, only the type of ad shown.
- Ad consent (UMP): for users in Brazil (LGPD) and in the European Union (GDPR), PLAYER 3 presents an ad consent form before loading any personalised ad, following the User Messaging Platform message standard.
- Privacy manifest: the app declares, in its privacy manifest (
PrivacyInfo.xcprivacy), the tracking domains used by the integrated ad SDK.
Ads never appear inside the game ranking list, nor on a game's detail screen, nor while a review is being filled in.
7Data security
Passwords are stored only as hashes. Authenticated access to the app uses session tokens with limited validity. Communication between the app and the server runs over an encrypted connection (HTTPS).
8Service providers
To work, PLAYER 3 depends on three companies, which process data on our behalf:
- Fly.io — hosts the application and the database, in the São Paulo region.
- Cloudflare — publishes the site and the admin panel, and handles DNS.
- Resend — delivers the e-mail with the password recovery code. It receives your e-mail address, and only when you request recovery.
9Your rights and how to exercise them
Questions about this policy, about the data on a specific account, or the exercise of any right under the LGPD go to dpo@treslimoes.com.br, the officer's channel named in section
- Once the app is published, the support channels on the App Store listing apply as well, without replacing that address.
Through the same channel you may request:
- Confirmation and access — to know whether we process your data and to receive a copy of it.
- Correction — to update incomplete, inaccurate or outdated data.
- Deletion or anonymisation — to erase or block data that is unnecessary or processed in breach of the law. Deleting the whole account is also done inside the app itself, without needing this channel (section 5).
- Withdrawal of consent — to take back an authorisation given earlier.
- Portability — to receive your data in order to take it to another service provider.
Requests are answered within 15 (fifteen) days of the date of the request. Before fulfilling one, we may ask you to confirm your identity — without that, anyone who knew your e-mail address could ask for a copy of your data.
10Version history
- Version 1.2 — 20 September 2026: section 5 now declares the record of access requests handled — the e-mail address the copy was delivered to and the date of delivery, nothing of the exported content — and that this record survives account deletion. It is the only exception to deletion, and it has existed since the request handling stopped being manual; version 1.1 already practised it without declaring it, and that is what this version corrects. No new data began to be collected: what changed is the text saying what the system does.
- Version 1.1 — 11 September 2026: password recovery by e-mail entered the product, and two things changed because of it. Section 3 now says that the e-mail address is also used to send the recovery code, and not only to identify the account. And section 8, "Service providers", was born, naming the three companies that process data on our behalf — Fly.io (hosting and database), Cloudflare (site, panel and DNS) and Resend (delivery of the e-mail with the code) — which until then were not declared anywhere.
- Version 1.0 — 25 August 2026: first published version, covering identification of the controller and the officer, the data subject's rights, minimum age, data collected, account deletion, use of aggregate data, and the ads and tracking section (written before the corresponding SDK was integrated).

