Skip to content
◎ fc.ia.br
How it worksPricingSign inPortuguês

Privacy policy

Last updated: October 11, 2026

This policy explains which data fc.ia.br processes, why, for how long, and how you use your rights under the Brazilian General Data Protection Law (LGPD, Law 13,709/2018).

On this page

  1. Who is responsible
  2. Data that we process
  3. What we do not do
  4. Photo location
  5. Who sees what
  6. Why we use the data
  7. How long we keep data
  8. Companies that process data for us
  9. Your rights
  10. Children and teenagers
  11. How to ask for the removal of a photo that shows you
  12. Cookies
  13. Security
  14. Changes to this policy

Who is responsible

The data controller is Diego TI LTDA, which operates fc.ia.br. For any privacy question, write to contato@21h.dev.

The organizer creates the event, decides who gets the link, and moderates the album. We store and show the photos and protect the service.

Data that we process

From the organizer:

  • the email address, for sign-in links and for notices about the event;
  • the event data: name, type, dates, time zone, language, theme, and cover photo;
  • the purchase data: plan, amount, discount code, and the Stripe payment identifier. We do not receive or keep card details.

From guests:

  • the display name, if the guest gives one;
  • the avatar (a selfie or an image), if the guest adds one;
  • the uploaded photos, with optional captions and the date and time they were taken;
  • likes and the status of the photo quest (assigned, skipped, or completed);
  • a random credential kept in the browser, which identifies the guest only in that event, and an optional recovery code. We keep both only as hashes.

Technical data:

  • a hash of the IP address, to limit attempts and protect the service from abuse;
  • technical request logs, which the hosting provider keeps for a limited time to operate and protect the service.

What we do not do

  • We do not use facial recognition or automatic identification of people.
  • We do not make biometric face models (face embeddings).
  • We do not send photos to artificial intelligence for analysis.
  • We do not sell personal data.
  • We do not use advertising trackers or advertising cookies.
  • We do not use the selfie avatar as a password or as proof of identity.

Photo location

Many phone photos keep the GPS location in their metadata. We remove location data from shared photos. We keep the date and time when the photo was taken, to build the timeline.

Who sees what

  • Published photos, captions, display names, avatars, and likes: the people who have the event link, while guest access is open.
  • In approval mode, a photo appears to guests only after the organizer approves it.
  • The organizer sees all the content of the event and can download the original photos.

The event link is private and hard to guess, and the album does not appear in search engines. But anyone who has the link can forward it. Share the link only with people that you would invite.

Why we use the data

  • To provide the service that the organizer buys: create the event, store and show the photos, send notices, and process the payment (performance of a contract, LGPD art. 7, V).
  • To protect the service from abuse and fraud, with attempt limits and security records (legitimate interest, LGPD art. 7, IX).
  • To meet legal obligations, for example to keep purchase records (legal obligation, LGPD art. 7, II).

The name, avatar, and photos of each guest are optional. Each guest decides what to share and can remove their own photos.

How long we keep data

  • Photos, avatars, and guest data: until the event plan ends, counted from the event end date. After expiry, the organizer can export for 14 more days. Then we delete this data.
  • Photos that the organizer or the guest removes: they leave the album immediately, and we delete the primary files.
  • Backup copies of photos: we delete them 30 days after the primary deletion.
  • Daily database backups: kept for 35 days.
  • After deletion, we keep a minimal record of the event (name and dates) and the purchase records, for as long as the law requires and for support.
  • Organizer account: until the organizer asks support to delete it.
  • Guest credential in the browser: up to 400 days, or until the guest clears the browser data.

Companies that process data for us

  • Cloudflare: hosting, database, photo storage, email delivery, and the text AI that helps to write quests. The AI gets only event information, such as the type, the language, and the atmosphere. It gets no photos and no guest data.
  • Stripe: payment processing. Stripe receives the payment details directly at checkout.

These providers can process data outside Brazil. They give contractual safeguards for the protection of data in these transfers, as the LGPD requires.

Your rights

Under the LGPD, you can ask for:

  • confirmation that we process your data, and access to it;
  • correction of incomplete or incorrect data;
  • anonymization, blocking, or deletion of unnecessary or excessive data;
  • portability of your data;
  • deletion of your data;
  • information about who we share the data with.

The organizer can export all the photos and data of the event until the export window ends. Guests can remove their own photos in the album. For other requests, write to contato@21h.dev. We can ask for information to confirm that the request is yours.

You can also complain to the Brazilian National Data Protection Authority (ANPD).

Children and teenagers

The service is for adult organizers. At events with children, we recommend approval mode: the organizer sees each photo before it appears in the album. Ask parents or guardians for permission before you share photos of children. Photo quests avoid unsafe tasks and photos without permission.

How to ask for the removal of a photo that shows you

  • Ask the event organizer. The organizer can remove any photo immediately.
  • Or write to contato@21h.dev with the event link and a description of the photo: the approximate time, the caption, or who uploaded it.

We do not use facial recognition. Because of this, we need your description to find the photo.

Cookies

We use only functional cookies:

  • fc_host: keeps the organizer signed in for up to 30 days.
  • fc_g_…: the guest credential for one event. The browser sends this cookie only to the address of that event.
  • fc_lang: keeps the language that you chose.

We do not use advertising cookies or third-party analytics tools.

Security

Photos stay in private storage, and every access goes through a permission check. We keep credentials only as hashes. No system is completely secure. If an incident can cause relevant risk or harm, we tell the affected people and the ANPD, as the law requires.

Changes to this policy

We can update this policy. The date at the top shows the last update. If a change is important, we tell organizers with active events by email.

PricingPrivacyTermsSupportPortuguês

fc.ia.br is a service of Diego TI LTDA.

Support: contato@21h.dev