UXTap
  • UXTap

    • Protótipos Figma
    • Sites reais
    • Entrevistas com IA
    • Pesquisa contínua
    • Arquitetura da informação
    • Teste de preferência
    • Teste de conteúdo
    • Resultados e repositório
    Todos os recursos
  • Grupo TAP

    • Painel TAP
    • OpinaTAP
    • VisionCX
    • ZapTap
    • QualiTAP
    • AnáliseTAP
    • UXTap
  • Como funciona
  • Recrutamento
  • Preços
  • Blog
PT·ES·ENEntrarCriar conta grátis
Draft — pending legal review

Privacy Policy

How we process data of those who contract UXTap and those who participate in research.

Version 2.0 · in effect since September 4, 2026

Courtesy translation. In case of divergence, the Portuguese version prevails. View Portuguese version

In plain language

  • There are two different relationships here. Regarding the account of the contracting party, we decide and respond as controllers.
  • Regarding the data of those who respond to a study, the client who created the study decides. We only execute their instructions, as operators.
  • Screen and voice recording only occur with specific, separate consent, which can be refused without preventing participation, unless the study requires recording and notifies beforehand.
  • We use artificial intelligence providers contracted under a modality that does not allow training models with the submitted content.
  • Recordings are automatically deleted according to the client's plan duration.
  • Anyone can request access to or deletion of their data on a dedicated page, and we respond within 15 days.

This summary helps to understand, but does not replace the text of the clauses below.

1. Who we are2. Two different roles, and why it matters3. Data of those who contract, and for what purpose4. Data of those who participate in a study5. Participant consent6. Children and adolescents7. With whom we share8. Artificial intelligence9. International transfer10. How long we store data11. Security12. Security incidents13. Cookies and browser storage14. Your rights15. Changes to this policy

1. Who we are

UXTap is a user research platform operated by Painel TAP, CNPJ 59.701.681/0001-68. This policy explains what data we process, for what purpose, on what legal basis, for how long, and with whom we share it.

  1. 1.1Data subject channel: privacidade@uxtap.app, or the public form available at uxtap.app/privacidade/meus-dados.
  2. 1.2Response time: up to 15 days, as per article 18 of the General Data Protection Law.

2. Two different roles, and why it matters

The distinction below is the backbone of this policy. It defines who decides what happens with each piece of data and to whom the data subject should appeal.

  1. 2.1We are controllers of the data of those who contract: user registration, workspace, billing data, usage and support logs. Here, we define the purposes.
  2. 2.2We are operators of the data of those who participate in studies. The client who created the study is the controller: they decide the questions, who is invited, whether there will be recording, and for how long the data will be used. We process this data according to their instructions and the Data Processing Agreement.
  3. 2.3If you participated in a study and want to exercise your rights, you can contact us: we forward it to the client controller and, when the request can be directly fulfilled by us, we perform the deletion.

3. Data of those who contract, and for what purpose

  1. 3.1Registration: name, email, password stored only as a cryptographic hash (bcrypt), preferred language, and role in the workspace. Purpose: create and operate the account. Legal basis: contract performance.
  2. 3.2Uso da plataforma: estudos criados, ações no painel, registros técnicos de acesso e erros. Finalidade: operar, dar suporte e melhorar o serviço, além de segurança. Bases legais: execução de contrato e legítimo interesse. Guardamos também eventos de uso do próprio UXTap (qual tela foi aberta, qual ação foi feita) por até dezoito meses, sempre com identificadores e metadados curtos, nunca com conteúdo de estudo ou resposta de participante.
  3. 3.3Billing: name, email, document, and payment data processed directly by Stripe. We do not store card numbers. Purpose: invoicing. Legal bases: contract performance and compliance with legal and tax obligations.
  4. 3.4Communication: transactional emails for invitation, quota, password reset, and summaries. Purpose: operate the service. Legal bases: contract performance and legitimate interest. Summaries can be turned off in the settings.
  5. 3.5Figma integration, when you connect your account: we store an access token encrypted with AES-256-GCM, used only to import the screens you indicate.

4. Data of those who participate in a study

What is collected depends on how the client set up the study. The list below is the maximum the platform is capable of collecting.

  1. 4.1Responses to study questions, including open questions written by the participant.
  2. 4.2Behavior during the task: clicks with coordinates, screens visited, scrolling, time per screen, path taken, and abandonment.
  3. 4.3Technical data: device type, browser, system, language, and screen dimensions. We do not use tracking cookies on the response screen.
  4. 4.4When the study comes from a recruitment panel: an opaque identifier sent in the URL and the variables configured by the client, such as age range or state. This identifier is provided by the panel and does not, by itself, contain name or contact information.
  5. 4.5Screen recording of the study tab, when the participant specifically consents.
  6. 4.6Microphone audio, when the study asks the person to think aloud or when there is a voice interview, always with specific consent.
  7. 4.7In real website studies: pages visited, clicks, scrolling, and screenshots of the indicated website. We never capture typed keys or content from text fields.

Voice and screen images deserve reinforced care because they can reveal more than the question asked. Therefore, they require separate consent, are stored in private storage with short-duration signed link access, and are deleted at the end of the plan's retention period.

5. Participant consent

  1. 5.1Before starting, the participant sees a clear notice about what will be collected, by whom, and for what purpose, with a link to this policy and to the list of subprocessors.
  2. 5.2Screen and microphone recording require a second, explicit, and separate consent, with the option to refuse and continue without recording, unless the study requires recording, a hypothesis informed before the start.
  3. 5.3The participant can interrupt at any time, including stopping sharing through the browser's own interface, without prejudice to the answers already given.
  4. 5.4Consent is recorded with date and time and with the version of the text presented.

6. Children and adolescents

  1. 6.1The platform is not intended for minors as contractors.
  2. 6.2Studies with underage participants can only be conducted with the specific and prominent consent of at least one parent or legal guardian, as per article 14 of the General Data Protection Law. Obtaining and proving this consent is the responsibility of the client who created the study.
  3. 6.3If we become aware of data collection from a minor without such consent, we may suspend the study and delete the data.

7. With whom we share

  1. 7.1With service providers necessary for the operation, listed completely and updated on the subprocessors page, with purpose, data processed, and country.
  2. 7.2With the study's client controller, regarding the data of their participants.
  3. 7.3With authorities, when there is a legal request or court order, to the strict extent of the request.
  4. 7.4In case of corporate reorganization, with the successor, maintaining the conditions of this policy.
  5. 7.5We do not sell personal data and do not use it for third-party advertising.

8. Artificial intelligence

  1. 8.1We use third-party models to transcribe audio, identify themes, generate reports, and conduct the automated interviewer. The providers are on the subprocessors page.
  2. 8.2We send only the content necessary for the task: excerpts of responses, transcriptions, images of study screens, and, in real-time voice mode, the audio of the conversation.
  3. 8.3We contract these providers under a paid modality, whose terms do not authorize the use of submitted content to train or adjust models without client instruction.
  4. 8.4The results are probabilistic and may contain errors. We do not make automated decisions with legal effect on participants.
  5. 8.5The participant is informed when conversing with an automated interviewer.

The guarantee of non-use for training depends on the plan contracted with the provider. See "Pending Definitions" at the end of this page.

9. International transfer

  1. 9.1Some providers are outside Brazil, mainly in the United States and the European Union, as indicated on the sub-processors page.
  2. 9.2These transfers rely on the mechanisms of the General Data Protection Law, especially the standard contractual clauses approved by ANPD Board Resolution No. 19/2024, whose adoption became mandatory starting August 2025.
  3. 9.3We maintain contractual data protection instruments with these suppliers and review this list periodically.

10. How long we store data

  1. 10.1Screen and audio recordings: according to the client's plan. On the free plan, 30 days; on Starter, 90 days; on Pro, 180 days; on Business, extended term defined in contract. Once the term expires, the file is deleted from storage and the recording is marked as expired.
  2. 10.2Responses, navigation events, and aggregated results: as long as the study exists in the client's account, unless deletion is requested.
  3. 10.3Interview transcripts and audio follow the same term as the recording they refer to.
  4. 10.4Registration and billing data: during the contractual relationship and, after it, for the legal terms of fiscal retention and statute of limitations.
  5. 10.5Application access logs: 6 months, as per Article 15 of the Brazilian Civil Rights Framework for the Internet.
  6. 10.6Backup copies may retain data for a limited additional period, being deleted in the normal rotation cycle.

11. Security

The measures below are implemented today. The Information Security Policy, on its own page, provides the details and what is still evolving.

  1. 11.1Encrypted traffic in transit via HTTPS, with HSTS so that the browser never attempts an unencrypted connection.
  2. 11.2Passwords stored only as cryptographic hash with bcrypt; never in plain text.
  3. 11.3Recordings and audio in private storage, without a public URL, accessible only via a signed link valid for 1 hour.
  4. 11.4Third-party integration tokens encrypted with AES-256-GCM before being stored.
  5. 11.5Role-based access control within the workspace, verified on the server with each request.
  6. 11.6Limitation of requests per address and per session on public routes, and daily resource usage caps per account.
  7. 11.7Error monitoring with removal of request body and response content before sending to the provider.

12. Security incidents

  1. 12.1We maintain an internal incident response plan, with responsible parties, deadlines, and record-keeping.
  2. 12.2When we act as operators, we communicate with the client controller without undue delay as soon as we become aware of an incident that may affect the data under their responsibility.
  3. 12.3When we act as controllers, we communicate with the ANPD and data subjects within the terms of ANPD Board Resolution No. 15/2024, which sets 3 business days, doubled to 6 business days in the case of a small-sized processing agent.

13. Cookies and browser storage

  1. 13.1On the panel, we only use a session cookie, strictly necessary to keep you authenticated. Without it, login does not work.
  2. 13.2On the response screen, we use local browser storage only to allow resuming the survey from where it stopped and to store events while the connection is unstable.
  3. 13.3We do not use advertising cookies or cross-site tracking. On public pages, with your permission, UXTap measures visits, clicks and scrolling using random browser identifiers, without typed text or URL parameters.
  4. 13.4You can decline or revoke analytics under Privacy preferences in the footer. Sessions are retained for up to 30 days and aggregates for up to 90 days; DNT and GPC are respected.

14. Your rights

The General Data Protection Law ensures data subjects the rights below, exercised free of charge.

  1. 14.1Confirmation of data processing existence and access to data.
  2. 14.2Correction of incomplete, inaccurate, or outdated data.
  3. 14.3Anonymization, blocking, or elimination of unnecessary, excessive, or unlawfully processed data.
  4. 14.4Data portability and information about sharing.
  5. 14.5Revocation of consent and information about the possibility of not consenting and the consequences.
  6. 14.6Opposition to processing based on legitimate interest.
  7. 14.7To exercise these rights, use uxtap.app/privacidade/meus-dados or write to privacidade@uxtap.app. We respond within 15 days. When the request refers to data from a client's study, we forward it to the controller and technically support the fulfillment.

15. Changes to this policy

  1. 15.1We may update this policy. Relevant changes are communicated by email or on the panel 30 days in advance.
  2. 15.2The current version is always on this page, with version number, date, and history.

Pending definitions

Points in this document that still depend on commercial or legal decision before the final version.

  • Name and contact of the data processing officer: today the channel is privacidade@uxtap.app, with no natural person publicly named. The ANPD requires the designation of the officer.
  • Confirm with the lawyer if it is appropriate to register Painel TAP as a small-sized processing agent with the ANPD, which changes incident communication deadlines.
  • Confirm if the Gemini plan in use is the paid one: in the free plan, Google may use the submitted content to improve models, which would make the guarantee in clause 8 false.

Legal basis cited

  • General Data Protection Law (Law 13.709/2018), especially articles 6, 7, 11, 14, 18, 33 to 36, 37, 38, 41 and 48.
  • CD/ANPD Resolution No. 15/2024, which approves the Security Incident Communication Regulation.
  • CD/ANPD Resolution No. 19/2024, which approves the International Data Transfer Regulation and the standard contractual clauses.
  • Brazilian Civil Rights Framework for the Internet (Law 12.965/2014), article 15, regarding the retention of application access logs.

Version history

  • 1.0 · September 2, 2026 · First version, summarized, published in beta.
  • 2.0 · September 4, 2026 · Rewritten: roles of controller and operator, legal bases by purpose, retention by plan, AI, international transfer, and data subject rights.
Privacy PolicyTerms of useSub-processorsData processing agreement
UXTap

Usability testing and user research for product and design teams.

UXTap is a Painel TAP.

CNPJ 59.701.681/0001-68

Product

  • All features
  • Figma prototype
  • Live site
  • In-product survey
  • Results and repository
  • Blog
  • How it works
  • Recruitment panels
  • Price
  • Frequently asked questions

Group products

  • Painel TAP
  • OpinaTAP
  • VisionCX
  • ZapTap
  • QualiTAP
  • AnáliseTAP
  • UXTap

Account

  • Help Center
  • Log in
  • Create free account
  • Privacy Policy
  • Terms of use
  • Sub-processors
  • Security
  • My data

Contact

  • contato@uxtap.app
  • paineltap.com.br

We reply by email on business days.

© 2026 Painel TAP. All rights reserved.