Privacy Policy

Last updated: September 5, 2026

This Policy describes how PingArmor processes personal data under Brazilian Law No. 13.709/2018 (LGPD). Please read it carefully and reach out to the DPO if you have any questions.

1. Who we are

The PingArmor service is a brand operated by Rafael Soarde Matias, a Brazilian individual residing in Araraquara/SP, Brazil. For LGPD purposes, Rafael Soarde Matias is the Controller of personal data collected in PingArmor operations. The official channel for the Data Protection Officer (DPO) is [email protected]. Full Controller details (CPF and home address) are available on formal request, to preserve the operator's personal security.

2. Data we collect

We collect only what is strictly necessary to provide the Service. The data falls into four categories:

3. What we use the data for (purpose and legal basis)

Each data category has a defined purpose and a specific LGPD legal basis:

4. How long we keep your data

Each type of data has a defined retention term:

5. Who we share with (Processors)

To deliver the Service we use a small set of Processors that handle personal data on our behalf. They operate in four areas: payment processing, transactional email delivery (account verification, receipts, password reset), DNS/CDN protection for the site and hosting of the server and database. We share only the minimum required for each purpose and only with Processors contractually bound to handle data in accordance with this Policy and LGPD. The nominal list of Processors can be requested from the DPO at [email protected].

6. International transfer

Some Processors operate outside Brazil (United States and Europe). Transfers rely on art. 33, item II, of LGPD — standard contractual clauses present in the agreements signed with each Processor. A copy of the contractual clauses (Data Processing Addendums) can be requested from the DPO at [email protected].

7. Local network monitoring by the app

The PingArmor desktop application reads, in real time, the list of active TCP connections on your computer (only IP addresses, ports and process names) using a native Windows API. This reading lets the app detect when your game connects to a server.

We do not read the contents of network packets. The app sends the PingArmor server only the public IP address and port of the game server you connected to, along with the game name — never your IP address, your username, your character or any other information about your computer. This is what lets other players find the protected route already in place the first time they open the same game, instead of having to discover it themselves.

That record is not linked to your account: we keep only the pair (game, server address), with nothing about who sent it. The request is authenticated to stop strangers from injecting fake addresses, but we do not record who it was. Nothing else from this data leaves your device, and none of it is shared with third parties.

Once a day, for each game you protect, the app tells the server that this game was used with protection on — just the game name, nothing else. That notice is not linked to your account either: the server adds 1 to a daily per-game counter, without keeping who sent it or when it was sent. With protection off nothing is sent. It only tells us which games to prioritise.

The connection list is kept only in memory while the app is running. If you enable Verbose log mode in Settings, selected events are written to a local debug.log file with automatic 7-day rotation — you can delete the file at any time from the app log folder.

The legal basis for this local reading is legitimate interest (LGPD art. 7, item IX) in protecting the operation of the service against connection failures. The Legitimate Interest Assessment (LIA) is available on request to the DPO at [email protected].

To warn you when both of your connections leave through the same internet — a situation in which failover offers no protection — the app sends one empty UDP packet per connection to a public STUN service (an internet standard, the same one used by video calls), which replies with the public IP address it saw. None of your data travels in that packet: the service only sees the source address, as any server would. This is the only external query this mechanism makes. The comparison happens on your device and the full address is not stored — with Verbose log mode on, debug.log records only the result and the masked IP (e.g. 203.0.113.0/24). The query runs when you connect and when your network changes, not continuously.

8. Your rights

LGPD grants you, as the data subject, the following rights (art. 18). You may exercise them by emailing the DPO at [email protected]:

9. DPO, ANPD and updates to this Policy

The Data Protection Officer (DPO) is the official channel for any matter related to this Policy. To reach the DPO, email [email protected].

If you are not satisfied with the DPO's reply, you may also file a complaint with the Brazilian Data Protection Authority (ANPD) at www.gov.br/anpd.

This Policy may be updated periodically. Significant changes will be communicated by email or a prominent notice on the website. Continued use of the Service after such notification constitutes acceptance of the updated version.

10. Partners (Referral Program)

If you are a partner in the Referral Program (you receive a formal invitation, accept a versioned contract and offer a discount to referred users), we process additional contract-related data. Details:

11. Diagnostic telemetry (opt-in)

The app has two diagnostic options in Settings, both off by default and independent of each other: "Send diagnostics on failure" and "Send diagnostics for every session". Enabling either one means we process additional data to diagnose connection problems. Details: