NoHarm is run by Leonardo da Silva Gotardo, an individual in Londrina, Paraná, Brazil, who is the controller of your personal data. Contact: contact@noharm.site.
Data protection officer (encarregado, under Brazil's LGPD): Leonardo da Silva Gotardo, at contact@noharm.site. Write there for anything in this policy.
This policy is effective from 28 September 2026.
We do not use analytics, advertising or tracking tools, and we do not collect your location, contacts, or anything from your device beyond what is listed here.
We never sell your data, and never use it for advertising or to build a profile of you.
Messages, your email address, username, date of birth, profile picture address and several other fields are encrypted in our database. Connections between the app and our server are encrypted in transit.
This is not end-to-end encryption. The server holds the key, so it can read messages — that is what lets it deliver them and attach them to a report. No one reads your conversations as a matter of routine. A moderator sees the last 20 messages of a conversation only when one of its two participants reports the other.
If you allow notifications on your phone, a new-message notification includes the first 200 characters of the message, so that you can read it from the lock screen. To reach your device, that notification passes through Google's Firebase Cloud Messaging and, on iPhone, Apple's push service. Friend-request notifications carry no personal content.
In a browser, notifications are created by the page itself on your computer and do not go through a third party.
You can turn notifications off in Settings, entirely or by type. On a phone that choice is sent to our server, so it applies even while the app is closed. You can also turn them off in your device's settings.
Other NoHarm users can see your username and profile picture. Only your friends see whether you are online, your current streak and how many badges you have earned. Messages are seen only by the person you send them to.
We use these service providers, who process data on our behalf and only for these purposes:
We share data with authorities only when the law requires it.
Our server and database are in the United States (AWS, us-east-1), and Google's services may process data in other countries. This means your data is transferred outside Brazil. We rely on our providers' data processing terms and the safeguards the LGPD allows for international transfers (LGPD art. 33).
When your account is erased, your sign-in record in our Firebase project (your email and Google account identifier) is erased with it. Your Google account itself is yours and is not affected.
You have the right to know what we hold about you, get a copy, correct it, have it deleted, withdraw consent, object to how we use it, and know who we share it with (LGPD art. 18). Most of this you can do yourself:
For anything else, write to contact@noharm.site. We answer within 15 days. You can also complain to Brazil's data protection authority, the ANPD (gov.br/anpd).
The app keeps your sign-in session, a cache of recently loaded screens, your theme and your notification preferences in your browser's or phone's local storage. Firebase keeps your Google sign-in state there too. Signing out clears the session. We do not use advertising or tracking cookies.
NoHarm is for adults. We do not knowingly hold data about anyone under 18; if we learn an account belongs to a minor, we close it and erase its data.
If a security incident puts your data at risk, we will tell you and Brazil's data protection authority within the time the law requires, and say what happened, what data was affected and what we are doing about it.
When this policy changes, the app asks you to accept the new version before you continue, and shows it to you first. The version you accepted and when are stored with your account and included in your data download.