Dr. Ren Silva
Legal document

Privacy Policy

In effect since July 28, 2026. It covers this site, drrensilva.com, and the weekly letter What’s New in Mood Disorders. It’s short because there’s almost nothing to describe. The Estabiliza app is a separate product with its own terms and its own policy, and nothing here applies to it.

Who controls the data

The controller is PLANO DE VOO TAB LTDA, a company registered in Brazil under CNPJ 36.890.904/0001-87. The site is written and published by Dr. Ren Silva. The controller is Brazilian and most of the audience is American, so this document is written to satisfy both the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados, Law 13.709/2018, the LGPD) and the US state privacy laws that cover readers in California, Colorado, Connecticut, Virginia, Texas and the other states with comprehensive privacy statutes.

What this site collects

Nothing. There’s no form on it, no login, no shopping cart, no comment box.

It doesn’t run analytics and it doesn’t record sessions. There’s no Google Analytics, no Google Tag Manager, no Meta pixel, no Microsoft Clarity, no heatmap and no advertising tag. The site sets no cookie of its own and asks for no consent, because there’s nothing to consent to.

Every file the page loads comes from the same address you’re reading it on: the text, the stylesheet, the images and the typeface are all served from this domain. While you read, the page makes no request to any other company. If you’ve got a tracker blocker installed, you’ll see it register zero blocks here.

What the hosting provider sees

The site is delivered by Cloudflare. Like every web server, Cloudflare records the technical detail of each request so it can serve the page and absorb attacks: the IP address, the time, the file requested, the browser and the operating system. That record exists for delivery and security, it isn’t tied to your name, and it’s never used to build a profile of you or to target anything at you. I don’t receive it, I don’t store it and I can’t query it. Request logging isn’t switched on for this site, so the only copy lives at Cloudflare, under Cloudflare’s own retention schedule.

What happens when you subscribe to the letter

What’s New in Mood Disorders is published on Substack, at drrensilva.substack.com. The subscribe buttons on this site are links, not forms: they hand you over to Substack, and your email address is typed there, on Substack’s page. It doesn’t pass through this site at all.

From that point on, Substack Inc. holds the subscription and acts as the processor. What it holds is your email address, the date you subscribed, whether each letter was delivered, opened or clicked, and the technical detail of those events, including IP address and approximate location. Substack’s own privacy policy and terms govern that data, and since Substack is a US company, that data sits in the United States.

What I see, as the writer, is the aggregate: how many people opened an edition, how many clicked, how many unsubscribed. I also see the subscriber list itself, because that’s how the letter gets sent.

There’s one purpose, and it’s sending you the letter you asked for. The legal basis is your consent under LGPD article 7, item I. In US terms it’s the newsletter you signed up for, and nothing else.

What is never done with any of it

  • Your data is never sold. Not for money, not for anything else of value.
  • It’s never shared for cross-context behavioral advertising, which is the technical name for what most people mean when they say a site sold their data.
  • It’s never handed to a data broker, an advertising network or a list rental.
  • It’s never fed into automated decision-making or profiling with legal or similarly significant effects.
  • It’s never used to draw a clinical conclusion about you. Reading a page about bipolar disorder isn’t health data about you, and it isn’t treated as if it were.

Because nothing is sold and nothing is shared for advertising, the opt-out those laws give you has nothing to act on. A Global Privacy Control signal from your browser is honored by default, for the simple reason that there’s no sale or share to turn off.

Why the processing is lawful

  • Delivering the site and keeping it up: the controller’s legitimate interest, LGPD article 7, item IX.
  • Sending the weekly letter: your consent, LGPD article 7, item I, given when you subscribe and withdrawn the moment you unsubscribe.
  • Meeting a legal or regulatory obligation, including the rules of the Brazilian Federal Council of Medicine on how a physician may identify themselves in public: LGPD article 7, item II.

How long it’s kept

Two categories, two different answers.

  • Delivery and security logs. I don’t hold them, so I can’t set a period for them. The retention is Cloudflare’s, on Cloudflare’s own schedule, and there’s no copy on this side to keep or to delete.
  • Your subscription and its engagement history. Kept for as long as you stay subscribed. When you unsubscribe the sending stops at once, and the platform keeps the address marked unsubscribed, which is how it knows never to write to you again. That marked record goes when you delete it from your Substack account, or when the publication closes.

Data that leaves Brazil

Substack and Cloudflare are US companies and process data in the United States. Under LGPD article 33 that transfer rests on the contractual clauses and safeguards those providers offer, and on your consent for the newsletter itself. If you’re reading from the United States, your data is already being processed in your own country.

Your rights, and how to use them

LGPD article 18 gives you the right to confirm that processing exists, to access the data, to correct it when it’s incomplete, inaccurate or out of date, to have it anonymized, blocked or deleted when it’s unnecessary or handled improperly, to move it to another provider, to delete data processed on the basis of consent, to know who it was shared with, to be told what happens if you refuse consent, and to withdraw consent.

US state privacy laws give you a broadly matching set: the right to know and to access, to correct, to delete, to receive a portable copy, to opt out of sale, of sharing for targeted advertising and of profiling, and the right not to be treated worse for having asked. California adds the right to limit the use of sensitive personal information, and no sensitive personal information is collected here.

Most of that you exercise yourself, without going through anybody, because of how little exists:

  • The site holds nothing about you. There’s no account, no profile and no record to see, correct, export or delete. A request to access or delete would come back empty.
  • The letter is under your own control. Every edition carries a one-click unsubscribe link in its footer, and that link is the withdrawal of consent. In the Substack account settings at substack.com/settings you can change the email address, manage or drop the subscription, and delete the account outright. Access to the engagement history, and a portable copy of it, are the one thing those settings don’t cover: Substack routes those requests to privacy@substackinc.com, and that’s where to write.
  • The logs aren’t yours to be found in. Delivery records at the hosting provider are technical and aren’t tied to your identity, and there’s no copy on this side, so no lookup could isolate them as your data.

If you want to take a complaint further, the supervisory authority in Brazil is the Autoridade Nacional de Proteção de Dados (ANPD). In the United States it’s your state attorney general.

Links that leave this site

The page links out to Substack, Amazon, YouTube, Spotify, TikTok, Instagram, LinkedIn, the Estabiliza app and the Instituto de Transtornos de Humor. The moment you follow one of those links you’re on that company’s property and under its privacy policy, not this one. No identifier travels with the click, because there isn’t one to travel. The Amazon link is a plain product address with no affiliate tag and no tracking parameter on it.

Children

This site is written for adults. It isn’t directed at children under 13, and no data about a child is knowingly collected. Since nothing at all is collected here, there’s nothing about a child to delete either.

Changes

This document can be updated, and the date at the top is the version in force. If the site ever adds a form, an analytics tag or a cookie, this page changes before that goes live, not after.

Version in force: July 28, 2026.