Privacy and data

Privacy Policy

This Policy explains how Tecopas LLC, organized in the State of Delaware, United States, processes personal data when operating QuienFue. It applies to senders, recipients, public-profile owners, visitors, and people whose contact details are provided to deliver a letter.

Effective
August 27, 2026
Version
2.1
Controller
Tecopas LLC · Delaware, United States
Privacy
apps@tecopas.com

Contents

  1. 1. Controller and scope
  2. 2. Information we collect
  3. 3. Data provided about other people
  4. 4. Purposes and legal bases
  5. 5. Visibility, letter privacy, and anonymity
  6. 6. Moderation and artificial intelligence
  7. 7. Sensitive rewards and consent
  8. 8. Providers and data recipients
  9. 9. International transfers
  10. 10. Cookies, analytics, and advertising
  11. 11. Email, notifications, and opt-out
  12. 12. Retention and deletion
  13. 13. Security and confidentiality
  14. 14. Your rights and choices
  15. 15. Children and teenagers
  16. 16. Legal compliance and protection of people
  17. 17. Automated decisions and review
  18. 18. Changes to this Policy
  19. 19. Privacy contact

Letters are protected, but not end-to-end encrypted

We restrict access and use private links, authentication, and technical controls. However, Tecopas LLC and authorized providers may process content to deliver and moderate it, protect users, and meet legal duties.

1. Controller and scope

Tecopas LLC, organized under the laws of the State of Delaware, United States, is the controller of QuienFue data unless a provider acts as an independent controller for its own services, as may be the case with Stripe, Google, or Meta. Contact us at apps@tecopas.com.

This Policy covers the website, dashboard, public profiles and inboxes, letter pages, emails, notifications, assisted social delivery, payments, support, moderation, and administrative tools. It does not govern third-party sites reached through external links.

2. Information we collect

Depending on how you use QuienFue, we may process:

  • Account and profile data: email, name, alias, photo, username, language, authentication provider, account IDs, and preferences.
  • Legal-acceptance evidence: user, accepted Terms and Privacy versions, date and time, language, and signup source. We do not add your IP address to this specific record.
  • Recipient and contact data: name or alias, email, phone number, social platform, handle, contact consent, saved contacts, and physical delivery information if a future feature requires it.
  • Content and game data: letters, clues, context, replies, reactions, guesses, revealed letters, progress, reward images and messages, reports, and participation choices.
  • Sensitive-content controls: moderation classification, warnings, adult-age declaration, consent to open a reward, and later revocation.
  • Payments and credits: Stripe customer and session, product, amount, currency, status, refunds, disputes, and balance entries. We do not store full card numbers.
  • Technical and safety data: IP address, browser, device, operating system, timestamps, essential cookies, session IDs, logs, risk signals, limits, email bounces, and delivery events.
  • Analytics and marketing data where applicable: public pages viewed, campaign, referrer, product events, and advertising identifiers.

3. Data provided about other people

A sender may provide recipient details to deliver a letter, and a recipient may reply to or report a sender. In those cases, we obtain information indirectly from the person using the Service. We also receive delivery, validation, payment, authentication, analytics, and safety status from providers.

If you provide another person's information, you represent that you have a lawful basis to do so, use an appropriate channel, and do not violate their reasonable privacy expectations. Do not upload unnecessary sensitive or contact data. A recipient may refuse, report, or opt out of future letters.

4. Purposes and legal bases

We use information to:

  • Create and protect accounts, authenticate users, and maintain sessions.
  • Record and demonstrate acceptance of the electronic agreement and its current versions.
  • Create, deliver, and display letters and operate clues, replies, rewards, inboxes, and notifications.
  • Process purchases, credit balances, reconcile payments, handle refunds, and prevent fraud.
  • Validate delivery channels and manage bounces, opt-outs, and email reputation.
  • Moderate content, investigate reports, prevent abuse, apply limits, and protect people and systems.
  • Provide support, measure performance, debug errors, and improve experience and accessibility.
  • Meet tax, accounting, regulatory, judicial, and safety obligations.
  • Measure campaigns and conversions when you provide required consent.

Depending on jurisdiction, these activities rely on performance of a contract, consent, legitimate interests in safety and improvement, and legal obligations. You may withdraw consent prospectively without affecting prior processing or activities supported by another valid basis.

5. Visibility, letter privacy, and anonymity

An enabled public profile or inbox may display a username, name, image, bio, preferences, and approved counters. Individual letters, replies, and private rewards do not become public merely because they are associated with that inbox.

The sender's identity is hidden from the recipient until the game rules reveal it. This does not make the sender anonymous to Tecopas LLC: we process data needed for accounts, safety, payments, delivery, and legal compliance. A letter link may contain an access token and should not be published; rewards may require authentication and binding to the correct recipient.

6. Moderation and artificial intelligence

We may send letter text and, through temporary private links, images to OpenAI or other configured systems for classification or user-requested writing suggestions. Moderation seeks categories such as sexual content, exploitation, threats, hate, violence, self-harm, or illegality.

Results may allow delivery, hold it for human review, require additional consent, or block it. Authorized reviewers may access only the content needed through administrative tools. We do not use AI to verify a person's age through identity documents. We aim not to impose permanent enforcement solely from an ambiguous automated signal and provide a contact channel to request review.

7. Sensitive rewards and consent

An allowed erotic or sexual reward remains private and locked until the authorized recipient solves the letter, signs in, declares they are at least 18, sees a warning, and expressly agrees to open it. We record that declaration, per-letter consent, and revocation to apply the choice and demonstrate how the control operated.

Prohibited content—including sexual material involving minors or uncertain age, non-consensual intimate imagery, threats, or exploitation—may be blocked, preserved as safety evidence, and reported when legally required.

8. Providers and data recipients

We do not sell personal data for money. We share the minimum necessary with providers that help us operate:

  • Supabase: database, authentication, and private storage.
  • Vercel: hosting, functions, network, and performance analytics.
  • Stripe: payments, fraud, refunds, and disputes.
  • Resend and Emailable: email sending, events, and deliverability validation.
  • OpenAI: text and image moderation and requested writing assistance.
  • Inngest: durable tasks, retries, and scheduled processes.
  • Upstash: limits, risk signals, and temporary technical storage.
  • OneSignal: web push notifications and subscription status.
  • Sentry: error, performance, and diagnostic data with sensitive-data filtering.
  • PostHog and Vercel Analytics: product analytics configured to minimize data.
  • Microsoft Clarity and Meta: measurement and marketing only after applicable consent.
  • Google: authentication when you choose Google sign-in.
  • Tecopas HQ and authorized personnel: operations, safety, and support.

We may also share information with advisers, a buyer in a corporate transaction subject to confidentiality, or authorities when there is a valid legal duty or basis.

9. International transfers

Tecopas LLC and multiple providers operate infrastructure in the United States and other regions. Information may therefore be processed outside your country. We use contracts, privacy settings, access controls, and other reasonable mechanisms to protect it under applicable law.

10. Cookies, analytics, and advertising

We use strictly necessary cookies and storage for authentication, security, language, preferences, and operation. Non-essential analytics and marketing are enabled only when you select “Accept analytics and marketing,” unless applicable law permits another basis.

With consent, we may use PostHog, Vercel Analytics, Microsoft Clarity, and Meta Pixel/Conversions API. PostHog is configured without indiscriminate autocapture or general session recording; Sentry removes or masks sensitive data; and Meta events may include hashed identifiers for deduplication and attribution. In some jurisdictions, disclosures to advertising platforms may be considered targeted advertising or “sharing.” Choose “Necessary only” or use available controls to change your decision. Rejecting marketing removes the Pixel and accessible Meta cookies.

11. Email, notifications, and opt-out

We send transactional communications to verify accounts, deliver letters, report replies, manage payments, maintain security, and provide support. We may use web push if both you and the browser grant permission. We do not send marketing email without the required legal basis.

A recipient may block future letters to their email through opt-out. We retain the minimum identifier needed to honor that choice. Providers may report delivery, opens, clicks, bounces, complaints, or suppression. Push notifications can be disabled through the browser or device.

12. Retention and deletion

We retain data while an account, letter, or process remains active and afterward for as long as needed to fulfill the purpose, resolve disputes, prevent abuse, and meet obligations. Current operational rules include:

  • Evidence of accepted legal versions: while the account is active; deleted with the account unless a separate, documented, and minimized legal hold applies.
  • Temporary checkout attribution and processed outbox data: up to 30 days after completion.
  • Resolved risk assessments: up to 90 days.
  • Closed incidents and terminal deletion requests: up to 180 days, with data minimized or redacted.
  • Expired deletion codes: canceled or redacted after 24 hours.
  • Payment, tax, dispute, and safety records: for applicable legal or defense periods.
  • Opt-outs, blocks, and abuse evidence: while needed to honor the choice or protect the Service.

Letter content is deleted, expires, or is unlinked based on letter and account status. Backups may persist for limited overwrite cycles. Open processes are not deleted until resolved. We may anonymize information for statistics that no longer reasonably identify a person.

13. Security and confidentiality

We use HTTPS, private reward storage, time-limited signed links, authentication, role controls, rate limits, audit records, minimization, monitoring, and environment-separated secrets. Administrative access is restricted to authorized functions.

QuienFue is not end-to-end encrypted: content must be processed to deliver and moderate it and protect users. No system is completely secure. If we identify a breach, we will investigate and provide notices required by law. Protect your links, email, OTP codes, and device.

14. Your rights and choices

Depending on location, you may request access, information, correction, updating, portability, objection, restriction, or deletion; withdraw consent; opt out of targeted advertising; and complain to a competent authority. You may also edit your profile, pause your inbox, manage email opt-out, revoke access to a sensitive reward, and delete your account in the application.

Argentina's Law 25,326 provides access, rectification, updating, and deletion rights subject to legal exceptions. To exercise rights, email apps@tecopas.com from the associated address and describe your request. We may reasonably verify identity before responding. If unsatisfied, you may contact Argentina's Agency for Access to Public Information.

15. Children and teenagers

QuienFue is not directed to children under 13, and we do not knowingly collect their data. If we learn that a person under 13 uses the Service, we may suspend the account and delete information except where retention is needed to protect them or comply with law.

People aged 13 to 17 cannot open adult-sensitive rewards. We absolutely prohibit sexual content involving, depicting, or appearing to involve minors, including digitally generated or manipulated material. Report any concern that a child may be at risk immediately.

16. Legal compliance and protection of people

We may preserve and disclose information in response to a valid legal demand, emergency, need to investigate fraud or abuse, defense of rights, protection of a person, or reporting obligation. This may include reports of apparent child sexual exploitation to authorities or legally designated organizations.

We evaluate government demands for validity and scope unless prohibited by law or faced with an emergency. We do not reveal a sender's identity to a recipient outside the game rules, but that protection does not prevent legal compliance.

17. Automated decisions and review

We use rules and models to validate email, calculate risk, apply limits, detect fraud, and classify content. These tools may influence whether a letter is delivered, held, or blocked. Serious or ambiguous decisions may receive human review when reasonable and safe.

You may request review at apps@tecopas.com. We will not disclose technical details that enable safety evasion, but will seek to explain the general decision category when doing so does not harm another person or an investigation.

18. Changes to this Policy

We may update this Policy when the product, providers, practices, or laws change. We will publish the new version and effective date. If a change materially affects your rights or changes a purpose that requires consent, we will seek to notify you and obtain a new choice where appropriate.

19. Privacy contact

The controller is Tecopas LLC, organized in the State of Delaware, United States, and operator of QuienFue. For questions, rights requests, privacy reports, or complaints, email apps@tecopas.com. Do not email passwords, OTP codes, full card details, or sensitive images. We may request limited additional information to authenticate your request.

Related document

Terms and Conditions

Review the rules governing accounts, content, delivery, credits, and permitted use.

Terms and Conditions
apps@tecopas.com