Privacy policy

A clear explanation of what data we use, why, who we share it with and when we delete it. We comply with the EU General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

1. Data controller

[COMPLETAR: tu nombre y apellidos, o la razón social] (Tax ID [COMPLETAR: NIF/DNI]), [COMPLETAR: domicilio fiscal completo]. For any privacy question: [COMPLETAR: email de contacto].

2. What data we use and why

If you create or buy a card

Purpose: to prepare, show and deliver the card you bought. Legal basis: performance of the purchase contract (Art. 6(1)(b) GDPR) and, for what the law requires us to keep (invoicing), compliance with legal obligations (Art. 6(1)(c)).

If you receive a card

We only process your data if you choose to reply: your text and/or photo are emailed to the person who gave you the card. The photo is cleaned before sending (we remove the GPS location and other hidden data phones store). Legal basis: your consent, given when you press send (Art. 6(1)(a)). We never show you the sender's email or give them yours.

At the end of every card there is a note saying it is private and the date on which it will be deleted automatically.

People in the photos

Before continuing, the person creating the card ticks a box guaranteeing they have the right to use the photos and names included and, if any minor appears, that they are their parent or guardian or have their authorization. Photos are used only for that card, never for advertising or to train our own AI models, and they are not public: only people with the link can see them.

Technical data

We use your IP address to prevent abuse (for example, limiting how many times the AI can be used per hour) and to show prices in your currency. These counters are deleted automatically within 24 hours at most. Legal basis: our legitimate interest in protecting the service (Art. 6(1)(f)). We measure visits in aggregate and without cookies, and we never measure card addresses (more in the cookie policy).

3. Artificial intelligence

The AI makes no decisions about you: it only generates a text or an image that you review. Photos edited with AI and messages written with AI are labeled as such in the card, so the recipient knows.

4. Who we share data with

We don't sell or transfer data to anyone. It is only processed, on our behalf and under a data processing agreement, by the providers we need for the website to work:

ProviderPurposeWhere and safeguard
Cloudflare (Workers)Website hosting and cookie-free visitor analyticsGlobal network (EU / USA) · EU-U.S. Data Privacy Framework and Standard Contractual Clauses
NeonDatabase (orders and card texts)EU (Frankfurt)
Cloudflare (R2)Private storage of photos and audioEU
StripeCard payments (we never see your card details)EU / USA · EU-U.S. Data Privacy Framework and Standard Contractual Clauses
ResendSending emails (purchase confirmation with the link, and replies)USA · EU-U.S. Data Privacy Framework and Standard Contractual Clauses
UpstashAnti-abuse counters by IP address (deleted within 24 h at most)EU (Frankfurt)
Kie.aiAI: writing the message, reviewing custom photo ideas and editing the main photo if you choose a “magic touch” (uses models from providers such as OpenAI)USA · Standard Contractual Clauses (in progress)
SpotifyChristmas song player, only if you tap “Listen on Spotify”Sweden (EU)

When a provider processes data outside the European Economic Area, the transfer is covered by the safeguard shown in the table: the EU-U.S. Data Privacy Framework (European Commission adequacy decision of 10 July 2023) for certified companies and/or the Standard Contractual Clauses approved by the Commission (Decision 2021/914). You can ask us for a copy of these safeguards at [COMPLETAR: email de contacto]. We only share data with authorities when legally required.

5. How long we keep it

6. Your rights

You can ask us at any time to access, correct or delete your data (for example, to remove a card early), to object to or restrict its use, or to receive it in a portable format. Write to [COMPLETAR: email de contacto] including the card link if you have it. We reply within one month at most.

If you believe we haven't handled your data properly, you can file a complaint with the Spanish Data Protection Agency (aepd.es) or with the data protection authority of your country.

7. Minimum age

You must be 18 or older to make a purchase.

8. Security

Photos and audio are kept in private storage and only shown through temporary links. Each card has an address that's impossible to guess, and the website only works over an encrypted connection (HTTPS). If a security incident affecting you ever occurred, we would notify you and report it to the authorities as required by law.

Privacy · Wrelia