Privacy Policy
What data we process, what for, with whom, for how long — and how you exercise your rights.
Version 2026-09-29 · In force since September 29, 2026
1. Who the controller is and how to reach the Data Protection Officer
The controller of your personal data is AMONG SOLUÇÕES EM SOFTWARES E TECNOLOGIA LTDA, Brazilian company registration (CNPJ) no. 58.088.554/0001-72, headquartered at Avenida Augusto Franco, 2960, Ponto Novo, Aracaju/SE, CEP 49097-670, responsible for Time Capsule (in Portuguese, Cápsula do Tempo) (“we” or “us”).
The channel of the Data Protection Officer (DPO) is [email protected]. For questions about the service, payments and refunds, use [email protected].
This policy applies to the Time Capsule website and app and follows the Brazilian General Data Protection Law (Law No. 13,709/2018, “LGPD”).
2. What data we process and what for
Account and access
Email, display name (optional), preferred language, account creation date, sign-in codes (stored only as a cryptographic hash and valid for 10 (ten) minutes) and sessions. We use them to create and protect your account and to identify you to the other participants in the capsule. Legal basis: performance of a contract.
Capsule content
Goals, letters, photos and videos that you and the participants send, plus the capsule’s data (name, occasion, dates, plan, participants and the backup contact’s email, if you name one). The capsule’s content, name and occasion are stored encrypted. We use them only to keep the capsule and show it to the participants at the right moment — never for advertising, profiling or training systems. Legal basis: performance of a contract.
Invitations
The invited person’s email and the status of the invitation. We use them to send the invitation and to link the person to the capsule when they accept. Legal basis: performance of a contract and the legitimate interest of the person inviting.
Payments
Payment is made with Stripe, which receives the card or Pix details directly. We keep only what is needed to confirm and reconcile the payment: amount, currency, payment method (card or Pix), status, date and the transaction identifiers at Stripe. We never receive or store the card number. Legal basis: performance of a contract and compliance with a legal (tax) obligation.
Waitlist
If you join the waitlist, we keep your email and language to let you know when a spot opens up. Legal basis: consent, which you can withdraw at any time.
Acceptances and recorded choices
Date, time and version of the terms you accepted, and the key-keeping choice for each capsule. Legal basis: compliance with a legal obligation and the regular exercise of rights (proof of what was agreed).
Transactional emails
Your email and the content of the service’s messages (sign-in codes, invitations, confirmations, reminders and the opening notice), plus the delivery status of each message. Legal basis: performance of a contract.
Technical and security logs
Application access logs (IP address, date and time of sign-in code requests), required by the Brazilian Internet Civil Framework (Marco Civil da Internet), and technical logs of operation and performance (such as route, result and response time), used to keep the service stable, investigate errors and prevent abuse. These technical logs do not include emails, codes or the content of capsules. We do not use audience analytics or advertising tools. Legal basis: compliance with a legal obligation and legitimate interest (security and continuity of the service).
We do not make automated decisions that affect your interests and we do not sell personal data.
3. Who we share with
The service runs on our own server, in Brazil. To operate it, we rely on the following processors, which handle data only according to our instructions:
- Stripe — processing card and Pix payments;
- Resend — sending transactional emails, including the email with the capsule’s key;
- Backblaze B2 — storing media, already encrypted, and backups;
- Cloudflare — network, DNS, secure connection (HTTPS) and protection against attacks on the path between you and our server.
The other participants in a capsule see your display name (or your email, if you do not set a name) and what you wrote in it, under the conditions described in the Terms of Use. We may also share data when the law or a court order requires it.
4. International transfer
Stripe, Resend, Backblaze and Cloudflare may process data outside Brazil, mainly in the United States. These transfers are made to perform the contract with you and based on the safeguards set out in article 33 of the LGPD, such as data protection contractual clauses adopted by these providers. The content of capsules, including media, already leaves our server encrypted.
5. How long we keep data
- Account data: for as long as the account exists. When it is closed, the email and name are erased, as are codes, sessions and email delivery records.
- Capsules: for 24 (twenty-four) months from the opening date, whether opened or not; after that, they are deleted.
- Deleted capsule: texts and keys are erased immediately; encrypted media files are erased on the scheduled opening date.
- Closing an account with a sealed or opened capsule: carried out 30 (thirty) days after the request.
- Sign-in codes: valid for 10 (ten) minutes. Sessions: expire within 90 (ninety) days or when you sign out.
- Application access logs: for at least 6 (six) months, as required by the Marco Civil da Internet.
- Payments: for the period required by tax and accounting legislation.
- Acceptances of the terms and key-keeping choices: kept even after the account is closed, as proof of what was agreed, for the applicable limitation period.
We keep database backups for a limited time, overwritten in the normal rotation cycle. Data erased from the service may remain in them until that rotation, protected and not used for any other purpose.
6. Sealed capsules and the key
The content of each capsule is encrypted from the moment it is sent. While the capsule is open for writing, the key that protects it is in our keeping, so that participants can write and read. On sealing, the content comes to depend on the capsule’s key: if you choose for us to keep a copy of it, we can recover access for you; if you choose to be the only one who keeps it, we have no way to read the content without the key. We keep only a verifier that confirms whether a typed key is correct, without allowing the content to be read. The details, including the exceptions, are on the “Keeping the key” page.
That is why some rights have a technical limit while the capsule is sealed: without the key, we cannot show or correct the encrypted content. A deletion request, however, is always possible and follows the rules described above.
7. Your rights
Under article 18 of the LGPD, you can ask, at any time, for:
- confirmation that we process your data and access to it;
- correction of incomplete, inaccurate or out-of-date data;
- anonymization, blocking or deletion of data that is unnecessary, excessive or processed in breach of the law;
- portability of your data;
- deletion of data processed on the basis of your consent;
- information about whom we share your data with;
- information about the possibility of not giving consent and its consequences;
- withdrawal of consent;
- review of decisions made solely on the basis of automated processing.
To exercise these rights, write to [email protected] from your account’s email (or tell us what it is). We may ask you to confirm your identity to protect you. We reply within 15 (fifteen) days. You can also change your display name and language yourself, in your account settings.
If you are not satisfied with our reply, you can file a complaint with the National Data Protection Authority (ANPD).
8. Security
We take technical and administrative measures to protect data: encrypted connection (HTTPS), encrypted capsule content, passwordless sign-in with a one-time code, technical logs without sensitive personal data, backups, restricted access to systems and monitoring. No system is completely immune to failures, but we work to reduce risks continuously.
9. Security incidents
If a security incident occurs that may pose a significant risk or harm to you, we will notify you and the ANPD, in the form and within the time set by regulation, explaining what happened, which data was affected, the risks and the measures taken.
11. Children and teenagers
There is no minimum age to use Time Capsule. Teenagers use the service with the authorization and supervision of their father, mother or legal guardian. Data of children (under 12 (twelve) years old) is only processed with the specific and prominent consent of one of the parents or the legal guardian, in the best interest of the child (article 14 of the LGPD). Payments can only be made by people over 18 (eighteen) years old or by the guardian.
If you are a guardian and believe we have processed a child’s data without your consent, write to [email protected] and we will take action, including deletion.
12. Changes to this policy
We may update this policy to reflect changes in the service or in the law. Each version is dated and kept in the history below. When a change is significant, we will let you know by email or in the product before it takes effect.
13. Change history
- September 29, 2026First published version: identification of the controller and the Data Protection Officer, data by purpose and legal bases, processors and international transfer, retention periods, cookies, children and teenagers.