quipo

Privacy Policy

Updated August 14, 2026

Quipo is a reading product. It needs to know what you read in order to recommend well and to pay the people who write — and it needs nothing beyond that. No advertising, no data sales, no third-party trackers.

This is a translation provided for convenience. The Portuguese version prevails if the two disagree.

Who is responsible

Quipo is operated by [RAZÃO SOCIAL A DEFINIR], registered under [CNPJ A DEFINIR], based in Brasil. Under Brazil's General Data Protection Law (LGPD, Law 13.709/2018) and the GDPR, we are the controller of the data described here.

Questions, requests and complaints about privacy: privacidade@quipoo.com. We answer within 15 days, the deadline the LGPD sets.

The honest summary

Before the detail, the essentials. Quipo sets two cookies, both first-party and both necessary: one keeps you signed in, the other remembers your interface language. There is no advertising cookie, no social pixel, and no third-party analytics on the site.

The application does not record your IP address or your browser string in its database. Our infrastructure providers keep technical logs of their own, and that is spelled out below rather than left implied.

What we collect

Account data
Email, name, username, and whatever you choose to add: a profile photo, one line about you, a bio, and the languages you read in. Email is required because it is what identifies the account.
Signing in with Google
If you choose that route, Google tells us your email and name. We never receive your password and have no access to your account there.
Reading data
For each idea, book or Quipu you open we record progress, scroll depth, active reading time in seconds, how many times you opened it, and whether you finished. We also record which ideas you have already been shown, so they are not shown again.
What you create
Ideas, Quipus, highlights, comments, likes, saved items and uploaded images. Some of this is public by nature — a published idea is public. Highlights and saved items are private unless you make them public.
Product events
A technical record of what happened: an event name, a session identifier, and which content it refers to. It exists to tell whether the product works, not to build an advertising profile.

What we do not collect

This section is a claim about the code, not a statement of intent. Quipo does none of the following:

  • We do not store your IP address or browser fingerprint in our database.
  • We use no Google Analytics, no Meta pixel, and no third-party tracker of any kind.
  • We do not follow you across other sites, and we do not buy data about you.
  • We do not collect sensitive data (racial origin, religious belief, political opinion, health, sex life, biometrics). If you write about those subjects, that is content you published, not data we asked for.
  • We do not sell, rent or trade personal data. There is no advertising.

Why we process it

The LGPD and the GDPR require a legal basis for each purpose. Ours:

Performance of the contract
Keeping your account, remembering where you stopped reading, showing your library and publishing what you write. Without this there is no service.
Legitimate interest
Recommending what to read, measuring whether an idea was genuinely read, calculating what writers are owed, and protecting the platform from fraud and abuse. You may object at any time through the contact address.
Consent
Optional email. You can withdraw it whenever you like, without affecting what was done beforehand.
Legal obligation
Keeping records the law requires and responding to lawful orders.

Who we share with

We do not sell data. We share only with the providers who run the infrastructure on our behalf, under contract, and only as far as necessary:

Supabase
Database, authentication and image storage. The data sits on servers in the São Paulo region.
Vercel
Hosting and delivery. Vercel keeps its own request logs, which may include IP addresses, for a limited period, for security and operations.
Google
Only if you choose to sign in with a Google account, and only to authenticate you.

International transfers

The database is in Brazil. Hosting is operated by a company based in the United States and processing may occur outside the country. Those transfers rely on standard contractual clauses and the safeguards set out in article 33 of the LGPD and chapter V of the GDPR.

How long we keep it

  • Account data: as long as the account exists. On deletion, erased within 30 days.
  • Reading progress and highlights: as long as the account exists.
  • Product events: 24 months.
  • Backups: up to 30 days after deletion, when the data leaves the backup copies too.
  • Published content: for as long as it is published. You can unpublish or delete at any time.
  • Records required by law: for the statutory period, even after the account is deleted.

Your rights

The LGPD (article 18) and the GDPR give you the right to:

  • Confirm whether we process your data and obtain a copy of it.
  • Correct data that is incomplete, inaccurate or out of date.
  • Request deletion of data processed on the basis of your consent.
  • Receive your data in a machine-readable format and take it elsewhere.
  • Object to processing founded on legitimate interest.
  • Withdraw consent at any time.
  • Know who we share your data with — the list above is complete.

How to exercise them

Write to privacidade@quipoo.com from your registered address. We answer within 15 days. Much of this you can also do yourself: profile data lives in Settings, and account deletion can be requested at the same address.

If you are not satisfied, you may complain to Brazil’s data protection authority (ANPD) or, in Europe, to your national supervisory authority.

Cookies

Two, both first-party and strictly necessary. Because they are required for the service you asked for, there is no consent banner — there would be nothing to consent to.

quipu_session
Keeps you signed in. Cryptographically signed, unreadable by JavaScript, expires after 60 days.
quipu_lang
Remembers the interface language you chose.

Minimum age

Quipo is for people aged 13 and over. We do not knowingly collect data from children. Where local law sets a higher age or requires guardian consent, that requirement governs. If we learn an account belongs to a child without the required consent, it is removed.

Security

Passwords stay with the authentication provider and never reach us in readable form. Traffic is encrypted in transit. Database access is constrained by row-level security policies, which means each reader can only reach their own rows. No system is perfect: if an incident occurs with material risk, we will notify you and the ANPD as article 48 of the LGPD requires.

Changes to this policy

If something material changes, we update the date at the top and tell you in the product or by email before it takes effect. The version history lives in the project repository.

Privacy Policy · Quipo · Quipo