Privacy Policy
This Policy explains how Tecopas LLC, organized in the State of Delaware, United States, processes personal data when operating QuienFue. It applies to senders, recipients, public-profile owners, visitors, and people whose contact details are provided to deliver a letter.
- Effective
- August 27, 2026
- Version
- 2.1
- Controller
- Tecopas LLC · Delaware, United States
- Privacy
- apps@tecopas.com
Letters are protected, but not end-to-end encrypted
We restrict access and use private links, authentication, and technical controls. However, Tecopas LLC and authorized providers may process content to deliver and moderate it, protect users, and meet legal duties.
1. Controller and scope
Tecopas LLC, organized under the laws of the State of Delaware, United States, is the controller of QuienFue data unless a provider acts as an independent controller for its own services, as may be the case with Stripe, Google, or Meta. Contact us at apps@tecopas.com.
This Policy covers the website, dashboard, public profiles and inboxes, letter pages, emails, notifications, assisted social delivery, payments, support, moderation, and administrative tools. It does not govern third-party sites reached through external links.
2. Information we collect
Depending on how you use QuienFue, we may process:
- Account and profile data: email, name, alias, photo, username, language, authentication provider, account IDs, and preferences.
- Legal-acceptance evidence: user, accepted Terms and Privacy versions, date and time, language, and signup source. We do not add your IP address to this specific record.
- Recipient and contact data: name or alias, email, phone number, social platform, handle, contact consent, saved contacts, and physical delivery information if a future feature requires it.
- Content and game data: letters, clues, context, replies, reactions, guesses, revealed letters, progress, reward images and messages, reports, and participation choices.
- Sensitive-content controls: moderation classification, warnings, adult-age declaration, consent to open a reward, and later revocation.
- Payments and credits: Stripe customer and session, product, amount, currency, status, refunds, disputes, and balance entries. We do not store full card numbers.
- Technical and safety data: IP address, browser, device, operating system, timestamps, essential cookies, session IDs, logs, risk signals, limits, email bounces, and delivery events.
- Analytics and marketing data where applicable: public pages viewed, campaign, referrer, product events, and advertising identifiers.
3. Data provided about other people
A sender may provide recipient details to deliver a letter, and a recipient may reply to or report a sender. In those cases, we obtain information indirectly from the person using the Service. We also receive delivery, validation, payment, authentication, analytics, and safety status from providers.
If you provide another person's information, you represent that you have a lawful basis to do so, use an appropriate channel, and do not violate their reasonable privacy expectations. Do not upload unnecessary sensitive or contact data. A recipient may refuse, report, or opt out of future letters.
4. Purposes and legal bases
We use information to:
- Create and protect accounts, authenticate users, and maintain sessions.
- Record and demonstrate acceptance of the electronic agreement and its current versions.
- Create, deliver, and display letters and operate clues, replies, rewards, inboxes, and notifications.
- Process purchases, credit balances, reconcile payments, handle refunds, and prevent fraud.
- Validate delivery channels and manage bounces, opt-outs, and email reputation.
- Moderate content, investigate reports, prevent abuse, apply limits, and protect people and systems.
- Provide support, measure performance, debug errors, and improve experience and accessibility.
- Meet tax, accounting, regulatory, judicial, and safety obligations.
- Measure campaigns and conversions when you provide required consent.
Depending on jurisdiction, these activities rely on performance of a contract, consent, legitimate interests in safety and improvement, and legal obligations. You may withdraw consent prospectively without affecting prior processing or activities supported by another valid basis.
5. Visibility, letter privacy, and anonymity
An enabled public profile or inbox may display a username, name, image, bio, preferences, and approved counters. Individual letters, replies, and private rewards do not become public merely because they are associated with that inbox.
The sender's identity is hidden from the recipient until the game rules reveal it. This does not make the sender anonymous to Tecopas LLC: we process data needed for accounts, safety, payments, delivery, and legal compliance. A letter link may contain an access token and should not be published; rewards may require authentication and binding to the correct recipient.
6. Moderation and artificial intelligence
We may send letter text and, through temporary private links, images to OpenAI or other configured systems for classification or user-requested writing suggestions. Moderation seeks categories such as sexual content, exploitation, threats, hate, violence, self-harm, or illegality.
Results may allow delivery, hold it for human review, require additional consent, or block it. Authorized reviewers may access only the content needed through administrative tools. We do not use AI to verify a person's age through identity documents. We aim not to impose permanent enforcement solely from an ambiguous automated signal and provide a contact channel to request review.
7. Sensitive rewards and consent
An allowed erotic or sexual reward remains private and locked until the authorized recipient solves the letter, signs in, declares they are at least 18, sees a warning, and expressly agrees to open it. We record that declaration, per-letter consent, and revocation to apply the choice and demonstrate how the control operated.
Prohibited content—including sexual material involving minors or uncertain age, non-consensual intimate imagery, threats, or exploitation—may be blocked, preserved as safety evidence, and reported when legally required.
8. Providers and data recipients
We do not sell personal data for money. We share the minimum necessary with providers that help us operate:
- Supabase: database, authentication, and private storage.
- Vercel: hosting, functions, network, and performance analytics.
- Stripe: payments, fraud, refunds, and disputes.
- Resend and Emailable: email sending, events, and deliverability validation.
- OpenAI: text and image moderation and requested writing assistance.
- Inngest: durable tasks, retries, and scheduled processes.
- Upstash: limits, risk signals, and temporary technical storage.
- OneSignal: web push notifications and subscription status.
- Sentry: error, performance, and diagnostic data with sensitive-data filtering.
- PostHog and Vercel Analytics: product analytics configured to minimize data.
- Microsoft Clarity and Meta: measurement and marketing only after applicable consent.
- Google: authentication when you choose Google sign-in.
- Tecopas HQ and authorized personnel: operations, safety, and support.
We may also share information with advisers, a buyer in a corporate transaction subject to confidentiality, or authorities when there is a valid legal duty or basis.
9. International transfers
Tecopas LLC and multiple providers operate infrastructure in the United States and other regions. Information may therefore be processed outside your country. We use contracts, privacy settings, access controls, and other reasonable mechanisms to protect it under applicable law.
11. Email, notifications, and opt-out
We send transactional communications to verify accounts, deliver letters, report replies, manage payments, maintain security, and provide support. We may use web push if both you and the browser grant permission. We do not send marketing email without the required legal basis.
A recipient may block future letters to their email through opt-out. We retain the minimum identifier needed to honor that choice. Providers may report delivery, opens, clicks, bounces, complaints, or suppression. Push notifications can be disabled through the browser or device.
12. Retention and deletion
We retain data while an account, letter, or process remains active and afterward for as long as needed to fulfill the purpose, resolve disputes, prevent abuse, and meet obligations. Current operational rules include:
- Evidence of accepted legal versions: while the account is active; deleted with the account unless a separate, documented, and minimized legal hold applies.
- Temporary checkout attribution and processed outbox data: up to 30 days after completion.
- Resolved risk assessments: up to 90 days.
- Closed incidents and terminal deletion requests: up to 180 days, with data minimized or redacted.
- Expired deletion codes: canceled or redacted after 24 hours.
- Payment, tax, dispute, and safety records: for applicable legal or defense periods.
- Opt-outs, blocks, and abuse evidence: while needed to honor the choice or protect the Service.
Letter content is deleted, expires, or is unlinked based on letter and account status. Backups may persist for limited overwrite cycles. Open processes are not deleted until resolved. We may anonymize information for statistics that no longer reasonably identify a person.
13. Security and confidentiality
We use HTTPS, private reward storage, time-limited signed links, authentication, role controls, rate limits, audit records, minimization, monitoring, and environment-separated secrets. Administrative access is restricted to authorized functions.
QuienFue is not end-to-end encrypted: content must be processed to deliver and moderate it and protect users. No system is completely secure. If we identify a breach, we will investigate and provide notices required by law. Protect your links, email, OTP codes, and device.
14. Your rights and choices
Depending on location, you may request access, information, correction, updating, portability, objection, restriction, or deletion; withdraw consent; opt out of targeted advertising; and complain to a competent authority. You may also edit your profile, pause your inbox, manage email opt-out, revoke access to a sensitive reward, and delete your account in the application.
Argentina's Law 25,326 provides access, rectification, updating, and deletion rights subject to legal exceptions. To exercise rights, email apps@tecopas.com from the associated address and describe your request. We may reasonably verify identity before responding. If unsatisfied, you may contact Argentina's Agency for Access to Public Information.
15. Children and teenagers
QuienFue is not directed to children under 13, and we do not knowingly collect their data. If we learn that a person under 13 uses the Service, we may suspend the account and delete information except where retention is needed to protect them or comply with law.
People aged 13 to 17 cannot open adult-sensitive rewards. We absolutely prohibit sexual content involving, depicting, or appearing to involve minors, including digitally generated or manipulated material. Report any concern that a child may be at risk immediately.
16. Legal compliance and protection of people
We may preserve and disclose information in response to a valid legal demand, emergency, need to investigate fraud or abuse, defense of rights, protection of a person, or reporting obligation. This may include reports of apparent child sexual exploitation to authorities or legally designated organizations.
We evaluate government demands for validity and scope unless prohibited by law or faced with an emergency. We do not reveal a sender's identity to a recipient outside the game rules, but that protection does not prevent legal compliance.
17. Automated decisions and review
We use rules and models to validate email, calculate risk, apply limits, detect fraud, and classify content. These tools may influence whether a letter is delivered, held, or blocked. Serious or ambiguous decisions may receive human review when reasonable and safe.
You may request review at apps@tecopas.com. We will not disclose technical details that enable safety evasion, but will seek to explain the general decision category when doing so does not harm another person or an investigation.
18. Changes to this Policy
We may update this Policy when the product, providers, practices, or laws change. We will publish the new version and effective date. If a change materially affects your rights or changes a purpose that requires consent, we will seek to notify you and obtain a new choice where appropriate.
19. Privacy contact
The controller is Tecopas LLC, organized in the State of Delaware, United States, and operator of QuienFue. For questions, rights requests, privacy reports, or complaints, email apps@tecopas.com. Do not email passwords, OTP codes, full card details, or sensitive images. We may request limited additional information to authenticate your request.
Related document
Terms and Conditions
Review the rules governing accounts, content, delivery, credits, and permitted use.



