1. Who is responsible
RW Studio, in Petrópolis / RJ, Brazil, is the controller of your personal data. For anything in this policy, including any request about your data, write to [email protected].
2. What we collect and why
Account details: your name, username, email address and a hashed version of your password. We need these to give you an account and to sign you in. Passwords are stored hashed with bcrypt and cannot be read back, by us or by anyone else.
Subscription and payment records: which plan you are on, its status, the paid-through date and a reference to the transaction at Stripe or PayPal. We keep amounts and dates. We never receive or store your card number.
Use of the site: the date of your last sign-in, and the lessons you mark as favourites. View counts are aggregated per lesson and per month, and are not tied to individual members.
Messages you send: if you write through the contact form, we keep your name, email, the message and the IP address it came from, so we can reply and so the form can be protected from abuse.
Older accounts imported from the previous version of the site also carry the country and the IP address recorded at the original sign-up. Nothing on the current site writes those fields.
3. What we do not do
We do not run analytics, advertising pixels or third-party trackers of any kind. There is no Google Analytics, no Meta pixel, no heatmap tool.
We do not sell or rent your data, and we do not share it for anyone else's marketing.
We do not build profiles about you or make automated decisions that affect you.
4. Cookies and local storage
A session cookie, set when you sign in, keeps you signed in. Without it the site cannot tell that a member is a member. It is strictly necessary and cannot be turned off while you are logged in.
A language cookie named bc-lang remembers whether you chose English, Portuguese or Spanish, and lasts a year.
Your light or dark theme choice is kept in your browser's local storage under bc-theme. It never reaches our servers.
The contact page loads Cloudflare Turnstile, an anti-spam check, which may set its own cookie. It is used to tell a person from a bot, not to track you across sites.
5. Who else touches your data
Stripe processes payments and holds your card details under its own privacy policy. PayPal does the same for a small number of older subscriptions.
Amazon Web Services stores the lesson videos and files and delivers them through CloudFront. Access to member files is granted by short-lived signed links.
Hostinger provides the mailbox that sends our transactional email, such as the welcome message and password resets.
Cloudflare provides the anti-spam check on the contact form.
Google is involved only if you choose to sign in with it, in which case it tells us your name and email address.
Each of these is a processor acting for us, or an independent controller for their own part, and none of them receives your data for their own marketing.
6. Where your data goes
We are based in Brazil, and the providers above operate in the United States and Europe. Using the site therefore involves transferring your data across borders, under the safeguards those providers offer, including standard contractual clauses where they apply.
7. How long we keep it
Your account data is kept while your account exists. If you ask us to delete it, we do so.
Payment and invoicing records are kept for as long as tax and accounting law requires, even after an account is closed. This is a legal obligation we cannot waive.
Password reset tokens are deleted seven days after they expire, and the counters used to rate-limit forms are deleted after twenty-four hours.
8. Your rights
Under the Brazilian LGPD, and under the GDPR if you are in Europe, you can ask us to confirm what data we hold, give you a copy, correct it, delete it, restrict how it is used, or object to a particular use. You can also ask us to send it to another provider.
Write to [email protected] from the address on the account and we will answer within fifteen days. There is no charge, and you do not need to explain why.
If you are not satisfied with our answer, you can complain to the ANPD in Brazil or to your local supervisory authority in Europe.
9. Security
The site is served over HTTPS. Passwords are hashed, never stored in readable form. Lesson videos and files are not publicly reachable: they are served through signed links that expire.
Password reset links are stored only as a hash, expire after an hour and work once, so a copy of our database cannot be used to take over an account.
No system is perfect. If a breach ever affects your data, we will tell you and the relevant authority as the law requires.
10. Children
BassCamera is not aimed at children under 16. If you believe a child has given us personal data, write to us and we will delete it.
11. Changes to this policy
If we change how we handle your data in a way that matters, we will tell you by email before it takes effect. The date at the top always shows the current version.