Privacy Policy

Effective Date: 7 October 2026

Version privacy@2026-10-07 · Last updated: 7 October 2026. Earlier versions are kept, and we will send you any of them on request.

In short

  • Who: Quelper LLC, run from Madrid, Spain. We apply the EU General Data Protection Regulation (GDPR) to everyone who uses Quelper, and the Spanish data protection authority (AEPD) supervises us.
  • Why: to run your account, your profile, the communities you join or run, your purchases and payouts (our contract with you); to keep Quelper secure, count visits, rank search results, keep track of creators we talk to about joining and keep a record of what creators confirm when they publish (our legitimate interests); Google Analytics, maps and your place on a community’s member map only with your consent.
  • Who else: Stripe for payments, our hosting and database providers, OpenAI for search and translation, and the creators whose communities you join or from whom you buy. Some of them are in the United States (section 5).
  • Your right to object: you can object at any time to any use based on our legitimate interests (Article 21 GDPR) by writing to s.alekhin@quelper.com.
  • Your other rights: to see, correct, erase or export your data, to restrict its use and to withdraw consent — write to the same address. You can also complain to the AEPD.
  • Your public profile and everything you publish are public, and search engines and AI crawlers may read them. We do not sell personal data and we do not run advertising.

1. Who is responsible for your data

The controller is Quelper LLC, a limited liability company registered in Delaware, USA (file number 10022353). The company is run entirely from Madrid, Spain, and every decision about Quelper is taken there. Under Article 3(1) GDPR, what counts is where a business actually operates, not where it is registered or where its servers are. That is why the GDPR applies to all users of Quelper, not only to people in Europe, and why our supervisory authority is the Agencia Española de Protección de Datos (AEPD).

If you are in the United Kingdom, the UK GDPR also protects you: write to us directly at the address below, and you can complain to the UK Information Commissioner’s Office (ICO).

Postal address: Quelper LLC, c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA (our registered agent in Delaware). More company details are on the Legal Notice page.

Contact for anything in this policy, including requests about your data: s.alekhin@quelper.com. This is also our designated address for requests under Nevada law (NRS 603A). We have not appointed a data protection officer. Neither Article 37 GDPR nor article 34 of Spain’s Organic Law 3/2018 requires one of us: we do not monitor people regularly and systematically on a large scale, process special categories of data on a large scale, or build user profiles on a large scale. The address above reaches the person who decides on your request.

2. What we collect, why, and on what legal basis

The GDPR requires a legal basis for each use of personal data. We use four: contract (Art 6(1)(b): needed to provide what you signed up for), legal obligation (Art 6(1)(c): for example tax and accounting records), legitimate interest (Art 6(1)(f): a reason of ours that we have weighed against your interests, and that you can object to), and consent (Art 6(1)(a): you can withdraw it at any time). Each section below says which one applies.

2.1 Your account

What: your email address and password (our database provider, Supabase, stores only a one-way hash of the password), the name you enter at sign-up, and, if you signed up through someone’s invitation, who invited you. The sign-in system also records when you confirmed your email address and when you last signed in. You sign in with email and password only; we do not offer sign-in through Google, Facebook or similar services.

Why: to create your account, keep it secure, let you sign in and reset your password, and to write to you. The only automatic emails are the address-confirmation and password-reset messages, sent by Supabase’s sign-in service. Apart from those, we write to your email address ourselves, one message at a time: about your account, your orders and payouts, changes to our terms and policies, and decisions about your account or your listings, and to answer you. We send no newsletters or advertising.

Basis: contract. Your email address, a password and a name are required: without them we cannot create an account for you.

2.2 Your public profile

What: display name, username (you can change it once), profile photo, cover image, bio, links you add to your website and social accounts (X/Twitter, Instagram, YouTube, LinkedIn, TikTok, GitHub, Telegram), and your language and currency settings.

Who can see it: once your profile is published, it is public at quelper.com/pro/your-username, without signing in. A new account’s profile starts unpublished; you publish it, or unpublish it again, in the creator studio. Every account is given a username automatically (such as user12345) until its owner chooses one. Your photo and cover image are stored as public files that anyone with their web address can open.

Search engines and AI crawlers. Our sitemap, the list of pages we offer to search engines, includes only the published profiles of creators (accounts that have become creators on Quelper, run a community, or have published a service, course, product or blog post) and their public pages. Other profiles are not listed in it, even when published. We allow search engines and AI crawlers to read every public page on Quelper, apart from the profiles of people who objected (below), including crawlers that collect web content for training AI models, such as Common Crawl (CCBot) and Google-Extended, so a published profile that is not in the sitemap can still be read by a crawler that reaches it, for example through a link. We add your social links to the page’s machine-readable data so that search engines can connect your profile to them.

Why and basis. Showing your profile to people who visit Quelper: a profile exists so that others can find and recognise you, and for creators being found is the reason to be on Quelper. Basis: contract. Listing creators’ profiles in our sitemap and letting search engines and AI crawlers read public pages, including for AI training, is a separate purpose: we want Quelper and its creators to be found and cited by search engines and AI assistants. Basis: legitimate interest. You can object to it by writing to us. If you do, we take your profile and the pages under its address (quelper.com/pro/your-username and everything after it) out of our sitemap and ask search engines and AI crawlers, in our robots.txt, not to read them; your profile stays visible on Quelper. Crawlers that ignore robots.txt, and copies made before, are outside our control. You can also unpublish your profile yourself in the creator studio, which takes it out of public view altogether.

When you replace your photo, the old file is not deleted automatically. Deactivating your account in Settings hides your profile page, but it does not by itself unpublish your listings, communities or posts.

2.3 What creators publish

What: services, courses, digital products and communities, with their titles, descriptions, prices, categories, languages and images.

In-person services: when you type a meeting address, Google’s address search suggests places, so Google receives what you type. We store the city and the country (if Google returns no city, the address you typed is stored in its place), the exact coordinates and Google’s identifier for the place. Every visitor to the service page sees the exact meeting point and any meeting instructions you write, so do not put door codes or anything else you would not put on a public sign into those instructions.

Basis: contract.

2.4 Posts, files, events and messages

What: posts, comments, likes, poll votes, questions and answers in communities; blog posts and portfolio items; community events and your replies to them; your progress through courses; and direct messages to other members (text only).

How files are stored:

  • Images in posts, blog posts and portfolios, and course videos, lesson images, downloadable resources and classroom attachments, are stored at long, hard-to-guess web addresses. They are not listed anywhere, but anyone who has the address can open the file without signing in. This includes images and course material inside paid communities and courses.
  • Files attached to community posts, items in a community’s content library and the files of digital products are stored privately. Each time someone opens one, we check that they are allowed to and give them a link that expires shortly afterwards.

Deleting: deleting a community post, a community comment or an item in a community’s content library hides it from everyone. The record stays in our database, and its files stay in storage, until your account is erased; ask us if you need something removed sooner. Blog posts, blog comments, portfolio projects and images, and service listings are removed from our database as soon as you delete them, but the files uploaded with them stay in storage until we remove them at your request or your account is erased. You cannot currently delete direct messages yourself. They are visible to you and the other person and are kept until either account is erased. We do not read direct messages in the ordinary course of running Quelper, but our administrators can sign in to any account, which shows them its messages (section 11).

Basis: contract.

2.5 Communities: who sees what

When you join a community we record your membership: the plan, how you joined (paid, free invitation, guest or lifetime), the relevant dates, and when you were last active in it.

  • Other members see your name, username, photo and bio, when you joined, whether you are the community’s owner and when you were last active, and can search the member list by name, username and bio. If you bought a lifetime package, they see its name as a badge next to your name. While you are visible on the member map, members who are visible on that community’s map themselves also see the city, country and flag saved through it and your place on the map (see below), and can search the member list by city and country among the members who are visible on the map. Members who are not on the map themselves see only how many members are in each city, without names or photos, and no other member’s city in the member list.
  • Leaderboard. Once a community’s leaderboard is open, members see the people at the top of it, with their names, photos, rank and the points they earned in the last 30 days.
  • The creator who owns the community also sees your plan, its price, your membership status, how you joined, when your subscription renews and its Stripe reference numbers. Other members do not see these. The creator also sees the member map and members’ cities in full, whether or not they are on the map themselves. Quelper has no moderator role yet.
  • Quelper Bot. If the creator switches it on (it is off by default), a weekly post introduces up to six new members to the community with their name, photo and bio, and their city while they are visible on the member map — to everyone in the community, including members who are not on the map themselves — and monthly posts show community numbers and run a feedback poll. Basis: legitimate interest in helping communities welcome new members. To object, tell the creator or write to us.
  • Invitation links. For free seats and invitation links we record who created the link and who used it. We do not collect the invited person’s email address.

Member map (optional). If you press “Set my location” (or “Update location”) on a community’s map, or switch on “Visible on map” before you have a location, your browser asks for your location. Your browser sends that exact position to Mapbox, which tells it the town you are in, its country and the towns within 50 km of you. The exact position is not sent to us and is not saved. We save the town, the country and its flag, and a point rounded to about 10 km and shifted by a small random amount, and show you on the map. You can then pick one of those nearby towns instead, and we save that town, its country and flag, and a point rounded and shifted in the same way around it. Members who are on that community’s map themselves, and the creator, see your name, photo and pin at roughly 10 km precision; members who are not see only how many members are in your city. Basis: consent, which you give by pressing the button and letting your browser share your location. If you refuse your browser’s request, nothing is looked up or saved. If you had no location yet, you are not shown on the map; a location saved earlier stays until you press “Remove location”.

Until 5 October 2026, refusing the browser’s request made the page estimate your location from your IP address through the service ipapi.co (run by Kloudend, Inc. in the United States) and save it. It no longer does this. If you think a location was saved for you that way, press “Remove location” on that community’s map: that deletes it.

Hiding and deleting your location. Switching the map to “Hidden” takes you off that community’s map at once: Quelper no longer shows your city, country, flag or pin to anyone else there, the creator included — not on the map or in its city counts, not in the member list, on your card or in its search, and not in Quelper Bot posts, including posts that introduced you earlier. While you are hidden, you too see only how many members are in each city, and no other member’s city in the member list. We keep what we saved, so that switching back to “Visible on map” shows the same town again with one click, without setting your location anew. “Remove location” withdraws your consent: it deletes the city, country, flag and point we saved for you in that community and takes you off the map; to appear on the map again, set your location anew. When this version of the policy took effect, we deleted the locations still stored for members who were hidden at that time. A short note next to the map’s buttons says what is sent to Mapbox, what we save, who sees it and how to hide or delete it.

Creators and Quelper. Inside a community, the creator and Quelper decide together how some of your data is used: the creator decides who may join and switches features such as Quelper Bot and the leaderboard on or off, and Quelper decides how those features work. For this we are joint controllers (Article 26 GDPR). Under our arrangement with creators (Terms of Use, section C7), Quelper gives you the information in this policy, answers your requests about your rights and handles security incidents on the platform; you can also send a request to the creator, who will pass it to us. What a creator does outside Quelper with what they see — for example copying member details or contacting members elsewhere — is the creator’s own responsibility as an independent controller, and our Terms of Use allow it only for running their community and in line with data protection law.

Basis: contract, except where stated above.

2.6 Buying on Quelper

Paying. Checkout happens on Stripe’s own payment page. You enter your card details there; we never see or store them. Stripe creates a customer record for you. When you look at a subscription on Quelper, we fetch the card brand and its last four digits from Stripe to show you, without storing them.

What we send to Stripe: your account’s email address; the item, with its title, description, image and price; reference numbers for your account, the creator, the item and any referrer or scout involved; for services, the booking date and package and, if you ask for the service to start within your 14-day withdrawal period, the time of that request; and, for a tip, the message you write, which also becomes the item description on Stripe’s page.

What we keep: an order record: what you bought, from whom and when, the amount, fees and commissions, the currency, the status (paid, refunded or disputed) and Stripe’s reference numbers. It also holds, for a tip, the message you wrote; for a service, the date and package you chose, the reason for any discount and, if you asked for it to start within your withdrawal period, when you asked; for a physical product, the delivery name and address you gave on Stripe’s page; and, if you bought for someone else, that person’s account.

Who receives the payment depends on where the creator’s Stripe account is:

  • United States, Canada, the United Kingdom, the European Economic Area or Switzerland: Quelper receives the payment through Stripe and passes the creator’s share on to them straight away. Quelper’s Stripe account settles the card payment.
  • Any other country (since 23 September 2026): the creator’s own Stripe account settles the card payment. Stripe processes it in the creator’s country, the creator’s name appears on Stripe’s page and on your card statement, and the creator receives the payment. Depending on the settings of our Stripe account, Stripe can also show the creator, in their Stripe dashboard, the details of the payment, such as your email address, the name on the card and the card’s brand and last four digits. We also use this route for any creator, wherever they are, if Stripe cannot tell us the creator’s country at the moment you check out.

If the creator has no Stripe account yet that can accept payments, Quelper receives the whole payment and pays the creator later (section 2.7). In every case the creator sees on Quelper your name or username, what you bought, the amount and the fees and, for a physical product, the delivery name and address. Who settles the card payment does not change who you contract with: memberships, courses, digital products and other digital access are sold by Quelper LLC, and services and physical products come from the creator (Terms of Use, section A2).

Physical products. For a physical product, Stripe’s payment page asks for the name and address to deliver it to, and Stripe gives them to us with the payment. We keep them with the order record; the creator sees them on Quelper with your order and uses them only to send you the item and handle a return. We do not ask for a phone number.

Basis: contract for the purchase; legal obligation for keeping order records for tax and accounting; legitimate interest for fraud checks and our internal revenue reports. Stripe also uses payment data for its own purposes, such as fraud prevention and its legal duties, under the Stripe Privacy Policy.

If you deactivate your Quelper account or ask us to erase it, we cancel your running memberships (Terms of Use, section B3); your Stripe customer record stays with Stripe.

2.7 For creators: getting paid

Through Stripe. When you set up payouts, we open a Stripe Connect Express account for you and give Stripe your email address, your country and your display name (your full name, or your username if no name is set). Stripe collects your identity documents, date of birth, address, bank account and tax details directly from you, under the Stripe Connected Account Agreement and Stripe’s privacy policy; we never receive them. We keep only your Stripe account ID and whether Stripe has enabled payments and payouts for it. If your Stripe account has no business name when a buyer first pays you, we fill in your Quelper display name, because Stripe shows that name to buyers. Closing your Quelper account does not close your Stripe account; you close it with Stripe. If you do not give Stripe what it asks for, it does not enable payouts, and you cannot be paid through Stripe.

Payouts we make ourselves. Some money reaches you from us rather than through Stripe: sales whose payment went to Quelper instead of directly to you (for example because your Stripe account was not set up yet), and referral and scout commissions, which we release by hand when you ask. If your Stripe account is in the United States, Canada, the United Kingdom, the European Economic Area or Switzerland, we can pay these as a transfer to it through Stripe, which needs nothing more from you. Otherwise we pay them by bank transfer from Quelper’s account at Mercury, a US financial technology company whose banking services are provided by its partner banks, Choice Financial Group and Column N.A. For a bank transfer we ask you for your full name, IBAN or account number, SWIFT/BIC code and postal address. We currently collect these in a Telegram chat with you and save them as a payee at Mercury. Quelper’s own systems do not store bank details: on our side we record only that a payout was made, with its transfer reference, date and amounts. Without these details we cannot send the transfer, so we cannot pay you this way.

  • Basis: contract (paying you what we owe) and legal obligation (accounting records). We do not need your consent for this.
  • Who receives it: for a transfer through Stripe, Stripe; for a bank transfer, Mercury and its partner banks, any intermediary banks on the route of the transfer, and your bank. Telegram carries the chat.
  • How long: the payee record stays at Mercury until we delete it. We delete it when your Quelper account is erased or when you ask us to, once no payout to you is pending. Mercury and the banks keep their own records of each transfer for as long as banking law requires them to. The Telegram messages stay in the chat until one of us deletes them; you can delete them for both of us at any time. Our payout records are kept like order records (section 6).

2.8 Referrals, promoters and scouts

  • If you sign up through someone’s invitation, we save who invited you on your account.
  • If you arrive through a referral link, your browser remembers the referrer’s code for 30 days, so that the discount and the referrer’s commission still apply if you buy later. If you click an item that a promoter recommends on their profile, your browser remembers that until you close the tab.
  • When you buy, the referrer’s or scout’s reference number travels with the payment to Stripe and is saved on the order and in our commission records.
  • To prevent people from referring themselves, a referrer’s commissions become payable only after at least three different people have bought through them. We check this automatically from the orders.
  • Referrers and promoters see totals (sales and earnings), not who bought; we do not count clicks. Scouts see how many creators they brought in and their balances. The order record available to a creator includes the reference number of any referrer involved.

Basis: contract (the programme terms and the discount you were offered); legitimate interest in preventing abuse of the programme.

2.9 Search, discovery and translation

  • Search. What anyone types into Quelper’s search, signed in or not, is sent to OpenAI to be turned into a numerical form (an “embedding”) that lets us find listings with a similar meaning. Please do not type personal details into the search box.
  • Search history. If you are signed in, we also record your searches, the results we showed and their positions, which ones you clicked, and your language, linked to your account, so that we can improve the ranking. Basis: legitimate interest; you can object by writing to us. Kept for 12 months, then deleted automatically, or sooner if your account is erased.
  • Listings. The titles, descriptions and categories of services, courses, products and communities, and for services the city and country, are sent to OpenAI to build the same kind of embedding. A community’s name and description are sent each time its settings are saved, even if the community is not listed publicly; a community without a name is titled after its creator’s name.
  • Translation. Community names and short descriptions, and the titles and descriptions of creators’ blog pages, are machine-translated by OpenAI so they can be shown in 35 languages.

We do not send direct messages, community posts or payment details to OpenAI. Basis: legitimate interest in a marketplace whose search and translations work; for creators, also contract.

2.10 Notifications, points and support

  • Notifications appear inside Quelper only: new followers, members joining, comments (with their first 120 characters) and sales (with the amount). We do not send automatic notification emails or marketing emails.
  • Points and levels. We record a daily sign-in event, the points you earn and purchase-related bonuses. In our admin area these also produce an activity score from 0 to 10 for each account, based on how many of the last 90 days it was active. Only our administrators see the score, in the list of accounts in our admin area, which they can sort by it; we use it to see which accounts actually use Quelper. It is not used for anything else and does not change what you can do on Quelper.
  • Admin records. Our administrators can keep internal notes on an account and set its status (active or banned). These are kept until the account is erased.
  • Support chat. Messages you send through the support window, including requests to delete a community, arrive in our ordinary message inbox and are read and answered by a person. They are kept like other direct messages.

Basis: contract; legitimate interest for the activity score (our interest: knowing how Quelper is used) and for admin records (our interest: giving support and acting on abuse).

2.11 Security and abuse prevention

We record successful and failed sign-ins: the time, your IP address, your browser’s identification string (“user agent”), the country your IP address belongs to (supplied by our hosting provider), and for failed attempts the reason and a salted one-way hash of the email address that was tried, never the address itself. These records are deleted automatically after 90 days.

When we ban an account for abuse, we take the most recent IP address on record for it, from its sign-in records or its consent records (section 2.12), whichever is newer, and add it to a block list. Almost every request to Quelper is checked against this list, and requests from a listed address are refused, whoever sends them. Not checked are notifications from our payment provider, the page that email-confirmation and password-reset links lead to, and static files such as images and the files meant for search engines. Entries are deleted automatically 12 months after they are added; we can remove one sooner by hand, for example when a ban is lifted. Lifting a ban does not remove the address by itself, because another banned account may use the same address.

Basis: legitimate interest in keeping accounts and the platform safe, as recognised by the EU Court of Justice in Breyer (C-582/14). The cookie banner does not affect this. You can object under Article 21 GDPR, and we will stop unless we have compelling grounds to continue.

2.12 Records of your consent and acceptance

When you answer the cookie banner, create an account or accept the creator terms, we keep a record of what you chose, which version of which document it referred to, the time, and your account if you are signed in. Except when you only refuse optional cookies, the record also holds your IP address and your browser’s user agent, and your browser keeps a random ID (see the Cookie Policy) that is sent with the record, so that a choice made before you signed up can be linked to the account you then create. A record of a refusal holds no IP address, user agent or browser ID. The sign-up record is the only place where the IP address you signed up from is kept. Acceptance of the creator terms is also logged in an older, second table, with your browser’s user agent.

Why: to be able to show what you agreed to and when. As section 2.11 explains, the IP address in these records is also used when we ban an account.

Basis, by type of record:

  • Cookie-banner choices that allow something: our legal obligation to be able to show that you consented (Art 7(1) with Art 6(1)(c) GDPR).
  • Cookie-banner refusals: legitimate interest in being able to show that we respected your refusal.
  • Sign-up and acceptance of the creator terms: these record that you entered into a contract, not a consent. Basis: legitimate interest in being able to prove what was agreed and to defend legal claims.

How long: cookie-banner records are deleted automatically three years after they are made. Sign-up and creator-terms records are kept while your account exists; once it has been erased, they are deleted automatically when three years have passed since the record was made. Until then, after erasure, the records in our main consent table no longer point to your account but keep the IP address, user agent and random ID; your rows in the older table of creator-terms acceptances we delete when we erase the account.

2.13 Measuring visits

Our own counter. For every page view by every visitor we record the page path (without anything after a “?”), the interface language, the country supplied by our hosting provider, the domain of the site you came from, whether the visit looks like a bot or a browser, the browser, operating system and device type, and a visitor code. The visitor code is a hash of a fixed secret, the date, your IP address and your user agent, so the same browser gets a different code each day. Your IP address and full user agent are not stored with it, and nothing is written to your device. But we keep the secret and it does not change, so for any day on which we know your IP address and user agent we can recompute your code. We hold IP addresses and user agents linked to accounts in our sign-in and consent records (sections 2.11 and 2.12), so we could link visits on different days to each other and to an account. This data is therefore pseudonymous, not anonymous.

We use it for traffic statistics in our admin area, including daily counts of unique visitors to each creator’s profile pages (quelper.com/pro/username and every page under it, their community included), which we use to follow how a community launch is going. Basis: legitimate interest in knowing how Quelper is used. The counter runs whatever you choose in the cookie banner and whether or not your browser sends Global Privacy Control. You can object, or ask for a copy or erasure of your rows, by writing to us: if you tell us the IP address and the browser’s user-agent string you used and the dates, we can recompute your codes and find or delete those rows. How long: rows are deleted automatically 13 months after they are recorded. The counter has been running since 27 August 2026. The rows it recorded before this version of the policy took effect are kept and used in the same way and on the same basis as the rows it records now.

Google Analytics. It loads only after you allow analytics in the cookie banner, wherever you are. Until you choose, it is off. Google receives your IP address, information about your device and the pages you view, and sets its own cookies. Basis: consent.

Choices saved before 7 October 2026. A saved choice that switched Analytics or Maps on before this date is no longer used: some of those saved before 5 October 2026 were saved without a click on that switch, and they cannot be told apart from the others, so the cookie banner asks everyone who saved such a choice again, with everything off until they answer. Refusals saved before then still apply (Cookie Policy, section 3).

2.14 Maps, video and other content from other sites

  • Maps (a cookie-banner category): Google Maps on service pages and Mapbox on community member maps. Until you allow maps, a placeholder is shown instead; on service pages it comes with a link that opens the exact meeting point in your own maps app. Once a map loads, Google or Mapbox sees your IP address and may store data in your browser.
  • Lookups you start yourself run when you use the feature, whatever your maps setting: the Mapbox lookup of your town and the towns near you when you set your location on a member map, and Google’s address search when a creator types an address.
  • Embedded video (not a cookie-banner category): videos from YouTube and Vimeo that creators add to lessons, posts, community pages, the content library, events, blog posts and course descriptions, and that community members add to their posts in a community feed. We always embed YouTube in its privacy-enhanced mode (the youtube-nocookie.com address) and Vimeo with its Do Not Track setting. When a player loads, YouTube or Vimeo receives your IP address and information about your browser and device. The YouTube player may store data in your browser, and once you press play YouTube may set cookies; Vimeo’s Do Not Track setting tells its player not to track the session, including with cookies. Preview images for videos are loaded from YouTube’s and Vimeo’s servers, which see your IP address too. In community feeds and for a community’s intro video, the player loads only when you press play; on other pages, including the editors where videos are added, it loads with the page.
  • Other images: placeholder avatars come from DiceBear (the username is sent to generate them), some stock images come from Unsplash, and creators can use images hosted on other websites. Your browser fetches these directly, so those services see your IP address.

These providers may collect information about your activity across different websites under their own privacy policies.

Basis. Maps: consent. Video: storing and reading data in your browser so that a video can play needs no consent, because the video is part of the content you asked to see (article 22.2 of Spain’s Law 34/2002, the LSSI); sending your IP address and browser data to YouTube or Vimeo when a player loads is based on our legitimate interest in showing the videos creators and community members publish on Quelper (Art 6(1)(f) GDPR), with the privacy-enhanced players described above to limit what YouTube and Vimeo collect. There is no cookie-banner setting for video. Lookups you start: contract. Images from other sites: legitimate interest in showing a picture for every account and the images creators choose, without copying them to our own servers.

2.15 Error reports and hosting logs

Sentry. When a page or one of our servers fails, an error report goes to Sentry: technical details of the error, your browser and operating system, and the page address with sign-in codes removed. For one page load in ten, timing data is sent as well. Reports contain no cookies, request headers or session recordings, and our setup tells Sentry not to record your IP address. Only reports about problems with payments, subscriptions and creators’ Stripe accounts include account IDs, together with Stripe reference numbers and amounts. Reports go to Sentry’s EU data region in Germany, and Sentry deletes them after at most 90 days.

Vercel hosts Quelper; our server code runs in Vercel’s region in Washington, D.C., in the United States. Vercel receives every request, with your IP address, user agent and the address requested. On our current plan, its request and server logs stay available to us for one day. A few of our own server log lines contain IP addresses (when we block a flood of failed sign-ins and when we ban an address) or account and order reference numbers.

Basis: legitimate interest in running a working, secure service.

2.16 People we contact about joining Quelper

We contact creators who we think might want to run a community on Quelper, through channels where they present themselves publicly, such as Instagram, Facebook, LinkedIn, Telegram, WhatsApp or email. For this we keep a record of the person’s name, links to their public profiles and website, their handles, the email address or phone number they published, their city, country, language and field, their follower count, our estimate of what they charge, where we found them, and notes on our conversations. We also record where we stand with them (the stage of the conversation, its outcome, and why they declined or paused, if they did), the date they announce their community, and our forecast of its income. If they later open a Quelper account, the record is linked to it, and our internal launch reports then compare that forecast with their community’s actual members, sales and visits.

Source: their public profiles and websites, and what they tell us. Basis: legitimate interest in offering our service to creators. Your right to object: you can object to this at any time: reply to our message or write to s.alekhin@quelper.com, and we will stop contacting you. We then delete our record about you, except your name, the link to the public profile where we found you and a note not to contact you again, which we keep so that we do not contact you again by mistake. How long: we review these records by hand every three months and delete the record of anyone who has not joined Quelper two years after our last contact with them.

2.17 Launch waitlists

Quelper no longer runs launch waitlists, and no page asks for your email address to put you on one. If you left your address on a creator’s launch waitlist earlier, we keep it, with which launch it was for and any referral code, only until it is deleted: we do not use it to contact you or for anything else, and Quelper does not show it to the creator. Basis: steps you asked us to take (Art 6(1)(b)). How long: your address is deleted automatically 12 months after you joined the list; ask us and we will remove it at once.

2.18 What creators confirm when they publish

What: each time a creator publishes their creator page (and with it their community), a course, a product or a service, switches on a community plan, publishes one of these again after taking it down, or changes the listed price of one of these while it is on sale, we ask them to tick a confirmation that they hold the rights to the material (or the right holder’s permission), that they are responsible for its content and for the accuracy of what they state, and that only they, or someone they have given access to their account, publish it (Terms of Use, section C6). We keep a record of each confirmation: the account, the item (its kind, its title and the price shown, and its ID if it already exists), whether it was a first publication, a publication after taking the item down or a price change, the exact wording shown and its version, the language of the page, the time, the IP address the request came from and the browser’s user agent. When the publication or the new price is then saved, we add a second record, linked to the first, with the item’s ID and the title and price actually saved. Each confirmation covers one publication or one price change.

Why: to be able to show, if a rights holder, a buyer or an authority complains about something a creator published, that the creator confirmed it, when and from where, and to establish, exercise or defend legal claims. We use these records for nothing else: not for the block list in section 2.11 and not to contact anyone. Basis: legitimate interest in being able to prove what was confirmed and to defend legal claims (Art 6(1)(f) GDPR). You can object under Article 21 GDPR; we keep a record that we need to establish, exercise or defend legal claims, which that article allows. How long: ten years from the confirmation, because claims about published material, such as copyright claims, can be brought years later. The records cannot be changed, only our administrators can read them, and they are kept, with the account ID, after an account is erased: the GDPR allows this for the establishment, exercise or defence of legal claims (Article 17(3)(e)).

3. Your IP address, specifically

It comes up in several places, on different bases:

  • Received with every request. No website can deliver a page without it, so there is nothing to consent to here. Our hosting provider also derives your country from it, which we record with sign-ins (2.11) and use to count visits by country (2.13).
  • Used and discarded to compute the daily visitor code (section 2.13) and to check the block list (section 2.11).
  • Stored in sign-in records for 90 days (2.11), in the block list if your account is banned (2.11), in consent records (2.12), and, for creators, in the record of each confirmation given when publishing, for ten years (2.18).
  • Seen by other services whose content your browser loads (2.14).

We do not use any service of our own to locate you from your IP address, and we do not try to locate you more precisely than your country. If you allow analytics, Google Analytics estimates your city from your IP address for its reports.

4. Who receives your data

We do not sell personal data, including sensitive personal data, and we never have. We do not share it for advertising either. (Some US state laws, including those of Texas and Nebraska, ask us to say this explicitly.) We share personal data only as follows.

RecipientWhat and whyWhere
SupabaseEverything in our database and file storage; sign-in; the confirmation and password-reset emails.Switzerland (AWS Zurich region). Supabase Inc. is a US company.
VercelEvery request to the site, with IP address and user agent; our server logs. Hosting.United States (server code runs in Washington, D.C.); pages and files are delivered from Vercel’s global network. Vercel Inc. is a US company.
StripePayment data (2.6) and creators’ payout set-up (2.7).United States
OpenAISearch queries, published listing text, and community and blog page names and descriptions, for search and translation (2.9).Ireland (OpenAI Ireland Limited) and the United States
GoogleAnalytics (2.13); Maps on service pages and address search for creators (2.3, 2.14); YouTube players and preview images (2.14); our email (Google Workspace), where the messages you send to us arrive.United States and Ireland
MapboxCommunity maps, and your exact location, used to look up your town and the towns near you (2.5).United States
VimeoVideo players and preview images (2.14).United States
SentryError reports (2.15).EU (Germany) region; US company
DiceBear, Unsplash, other image hostsYour IP address; the username, for placeholder avatars (2.14).Varies
Mercury and the banks involvedPayee details and amounts, for payouts we make ourselves (2.7).United States, and the countries of the banks on the route
TelegramThe chat in which creators send us payout details (2.7).Telegram’s servers
CreatorsWhat sections 2.4 to 2.8 say they see, and payments that the creator’s Stripe account settles (2.6).Worldwide
Other members and the publicWhat you publish, and the community details in 2.5.Worldwide
Authorities and advisersWhere the law requires it; our accountants and lawyers where needed.As required

Supabase, Vercel, OpenAI, Sentry, and Google for our email, handle data only on our instructions, as our processors. Stripe, Google for its other services, Mapbox, Vimeo, the image services, Mercury and Telegram use what they receive at least partly for their own purposes, under their own privacy policies. Creators decide some uses inside their community together with us, and are responsible on their own for what they do with your data outside Quelper (section 2.5).

5. Transfers outside Europe

Our database and files are stored in Switzerland, which the European Commission recognises as protecting personal data adequately. Several of the providers above are based in the United States. For those that handle data on our instructions:

  • Supabase and Vercel: their data processing terms, which include the EU standard contractual clauses and, for data about people in the United Kingdom, the UK’s equivalent, are part of our contract with each of them.
  • Sentry and Google: both are certified under the EU–US Data Privacy Framework and its UK Extension.
  • OpenAI: its Data Processing Addendum is part of our contract with it. Under that addendum, personal data from the European Economic Area and Switzerland is processed on our instructions by OpenAI Ireland Limited, which passes it to OpenAI companies in the United States only under agreements containing the EU standard contractual clauses; for data about people in the United Kingdom, the standard contractual clauses with the UK Addendum apply. OpenAI is not certified under the Data Privacy Framework. What we send to OpenAI is limited to what section 2.9 describes.

Some recipients outside Europe decide for themselves what to do with what they receive. Stripe, Mapbox and Vimeo are certified under the EU–US Data Privacy Framework and its UK Extension. Creators who live outside the European Economic Area, the United Kingdom, Switzerland and the other countries the European Commission recognises as protecting personal data adequately, and who see details of their members and buyers (sections 2.5 and 2.6), are bound by the EU standard contractual clauses for transfers between controllers (Commission Decision (EU) 2021/914, Module 1), with the UK Addendum for data about people in the United Kingdom, which our Terms of Use include (section C7). For payouts through Mercury and the banks on the route, and for the Telegram chat, we rely on Article 49(1)(b) GDPR: each transfer is needed to pay you under our contract with you. Services whose content your browser loads directly (section 2.14) receive what your browser sends them under their own policies. Every payout we make ourselves goes through Mercury in the United States, wherever the creator’s bank is, and from there to the country of the creator’s bank. When the creator’s Stripe account settles a payment (section 2.6), Stripe processes it in the creator’s country.

You can ask us for a copy of the safeguards we rely on, such as the standard contractual clauses, by writing to s.alekhin@quelper.com.

6. How long we keep things

DataHow long
Account and profileUntil your account is erased. Deactivating it only hides the profile.
Posts, comments, files and messagesUntil your account is erased, including community posts, comments and library items you deleted. Blog posts, blog comments, portfolio items and listings you delete are removed straight away. Uploaded files: until we remove them at your request or your account is erased.
Admin notes and account statusUntil your account is erased.
Order and payout recordsSeven years after the end of the year of the order or payout, for tax and accounting; there is no automatic deletion yet. After erasure, they are kept without the link to your profile, which Article 17(3)(b) GDPR allows.
Sign-in records90 days, deleted automatically.
IP block list12 months, deleted automatically; sooner if we remove the entry by hand (section 2.11).
Consent and acceptance recordsCookie-banner choices: three years, deleted automatically. Sign-up and creator-terms records: while your account exists; after erasure, deleted automatically three years after the record was made (section 2.12).
Creators’ publish confirmationsTen years from the confirmation, also after the account is erased; the records cannot be changed (section 2.18).
Visit counter13 months, deleted automatically.
Search history (signed in)12 months, deleted automatically; sooner if your account is erased.
Referral code in your browser30 days; an expired code is ignored and removed the next time the site reads it.
Bank details for payoutsAt Mercury: until we delete the payee, at the latest when your account is erased. In Telegram: until one of us deletes the messages (section 2.7).
People we contact about joiningTwo years after our last contact, if you have not joined; we review the records by hand every three months. If you object, only a do-not-contact note stays (section 2.16).
Launch waitlists (no longer run)12 months after you joined the list, deleted automatically; at once if you ask.
Error reports and hosting logsSentry: at most 90 days. Vercel request and server logs: one day.
Data held by other providersUnder their own retention rules.

7. Your rights and how to use them

You can ask us for a copy of your data, to correct it, to erase it, to restrict how we use it, and to give it to you in a portable format, and you can object to any use based on legitimate interest. Where we rely on consent you can withdraw it at any time. That does not make what we did before unlawful, but we then stop and delete what has no other basis.

Write to s.alekhin@quelper.com. If you have an account, write from its email address so that we know the request is yours; if you have none, or no longer use that address, write from any address and we will ask only for what we need to confirm who you are. We answer within one month; if a request is complex we may extend this by up to two more months, and we tell you why within the first month. It costs nothing.

Erasure in practice. In Settings you can deactivate your account. This hides your profile and signs you out, but erases nothing. Full erasure is done by us on request. It covers your account and profile and what is attached to them, including community memberships, posts and comments, direct messages you sent or received (for both people in the conversation), notifications, points, search history and referral records, and the files you uploaded, which we remove by hand as part of the erasure. We keep order and payout records without the link to you (section 6), and the records of the confirmations you gave when publishing, with your account ID, for ten years (section 2.18). If you run a community with paying members or sell courses that people still have access to, we will first agree with you how to wind them down. We cancel the memberships you still have as part of the erasure; your Stripe customer record or Stripe account stays with Stripe.

Export. There is no download button yet. Ask us and we will prepare a copy of your data by hand.

Complaints. You can complain to the AEPD at any time, without contacting us first, or to the data protection authority where you live or work; in the United Kingdom, that is the ICO.

United States. You can review and change most of your information in Settings, or ask us to. We will not treat you differently for using any of these rights. Nevada residents can send requests not to sell their information to the address above; we do not sell it, and we will confirm that within 60 days.

8. Cookies, Global Privacy Control and Do Not Track

Our Cookie Policy lists every cookie and browser-storage item we use and explains how to change your choice. Analytics and maps are off for everyone until they are switched on, so if your browser sends Global Privacy Control, they stay off until you switch them on yourself on Quelper. GPC does not switch off our own visit counter, our security records or embedded videos (section 2.14). We do not respond to the older Do Not Track signal, which has no agreed meaning. You can change your cookie choice at any time here: .

9. Automated decisions

We do not make decisions about you that are based only on automated processing and that have legal or similarly significant effects. Search results are ranked automatically, and the rule that referral commissions become payable after three different buyers is checked automatically.

10. Children

Quelper is for adults: our Terms of Use, which you accept when you create an account, require you to be at least 18. We do not check documents. If we learn that someone under 18 has an account, we will close it and erase their data. If you think a child is using Quelper, write to us.

11. Security

All traffic to Quelper is encrypted (HTTPS). Passwords are stored only as hashes by our sign-in provider. Access rules in the database limit each account to the data it is allowed to see, and only Quelper’s administrators can read security and consent records. Error reports are stripped of cookies and sign-in codes. If a breach puts your data at risk, we will tell the AEPD and, where the law requires, you.

Administrator access to accounts. To give support or investigate abuse, our administrators can sign in to any account. While signed in, they see everything that account can see, including its direct messages, orders and settings. Each such sign-in leaves a line with the account ID in our hosting logs; there is no separate record yet of who signed in or why. Basis: legitimate interest in giving support and keeping Quelper safe.

12. Changes to this policy

When this policy changes in a way that matters, we give it a new version, keep the previous text, and tell everyone who has an account, by email or with a notice on Quelper or a message to their Quelper inbox. We do not apply a new use to data we collected under an earlier version without asking you first. Earlier versions: privacy@2026-10-06, privacy@2026-10-05, privacy@2026-10-03, privacy@2026-09-08 and privacy@2025-12-17; ask us for any of them.

Wir schätzen deine Privatsphäre

Quelper verwendet notwendige Cookies, Google Analytics und Karten (Google, Mapbox) nur mit deiner Zustimmung. Mehr erfahren ·