Privacy policy
A clear explanation of what data we use, why, who we share it with and when we delete it. We comply with the EU General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
1. Data controller
[COMPLETAR: tu nombre y apellidos, o la razón social] (Tax ID [COMPLETAR: NIF/DNI]), [COMPLETAR: domicilio fiscal completo]. For any privacy question: [COMPLETAR: email de contacto].
2. What data we use and why
If you create or buy a card
- What you put in the card: your name, the recipient's name, the photos, the message, the voice message, the album, the music and the opening date.
- What you tell the AI to write the message (your relationship, a memory, what you wish them) and, if you use it, your idea for editing the photo.
- Your email (optional): to send you the link and, if the recipient replies, their reply.
- Payment data: handled by Stripe. We only receive the amount, the date and the payment email, never your card details.
Purpose: to prepare, show and deliver the card you bought. Legal basis: performance of the purchase contract (Art. 6(1)(b) GDPR) and, for what the law requires us to keep (invoicing), compliance with legal obligations (Art. 6(1)(c)).
If you receive a card
We only process your data if you choose to reply: your text and/or photo are emailed to the person who gave you the card. The photo is cleaned before sending (we remove the GPS location and other hidden data phones store). Legal basis: your consent, given when you press send (Art. 6(1)(a)). We never show you the sender's email or give them yours.
People in the photos
The person creating the card guarantees they have permission from the people appearing in their photos and, if they are minors, that they are their parent or guardian or have their authorization. Photos are used only for that card, never for advertising or to train our own AI models, and they are not public: only people with the link can see them.
Technical data
We use your IP address to prevent abuse (for example, limiting how many times the AI can be used per hour) and to show prices in your currency. These counters are deleted automatically within 24 hours at most. Legal basis: our legitimate interest in protecting the service (Art. 6(1)(f)). We measure visits in aggregate and without cookies, and we never measure card addresses (more in the cookie policy).
3. Artificial intelligence
- Message: if you ask for help writing it, the details you give us are sent to Kie.ai to draft it. You see it and can change it before paying.
- Photo magic touch: only if you choose it (and tick the permission box), the main photo is sent to Kie.ai to apply the style. If you write your own idea, Kie.ai’s AI reviews it first to prevent inappropriate use.
The AI makes no decisions about you: it only generates a text or an image that you review. Photos edited with AI are labeled as such in the card.
4. Who we share data with
We don't sell or transfer data to anyone. It is only processed, on our behalf and under a data processing agreement, by the providers we need for the website to work:
| Provider | Purpose | Where |
|---|---|---|
| Cloudflare (Workers) | Website hosting and cookie-free visitor analytics | Global network (EU / USA) |
| Neon | Database (orders and card texts) | USA |
| Cloudflare (R2) | Private storage of photos and audio | EU |
| Stripe | Card payments (we never see your card details) | EU / USA |
| Resend | Sending emails (card link and replies) | USA |
| Upstash | Anti-abuse counters by IP address (deleted within 24 h at most) | EU |
| Kie.ai | AI: writing the message, reviewing custom photo ideas and editing the main photo if you choose a “magic touch” (uses models from providers such as OpenAI) | Outside the EU |
| Spotify | Embedded Christmas song player | Sweden / USA |
When a provider is outside the European Economic Area, the transfer is covered by the EU-U.S. Data Privacy Framework or by the Standard Contractual Clauses approved by the European Commission. We only share data with authorities when legally required.
5. How long we keep it
- Unpaid cards: deleted with their photos after 48 hours.
- Paid cards: available for 90 days from their opening date (or from the purchase, if they open right away). After that, we automatically delete the photos, audio, message, names, your email and any replies received.
- Sales record (amount, date and payment reference): kept for as long as tax and commercial law requires.
- Replies by email: once sent, they stay in the recipient's inbox.
6. Your rights
You can ask us at any time to access, correct or delete your data (for example, to remove a card early), to object to or restrict its use, or to receive it in a portable format. Write to [COMPLETAR: email de contacto] including the card link if you have it. We reply within one month at most.
If you believe we haven't handled your data properly, you can file a complaint with the Spanish Data Protection Agency (aepd.es) or with the data protection authority of your country.
7. Minimum age
You must be 18 or older to make a purchase.
8. Security
Photos and audio are kept in private storage and only shown through temporary links. Each card has an address that's impossible to guess, and the website only works over an encrypted connection (HTTPS). If a security incident affecting you ever occurred, we would notify you and report it to the authorities as required by law.