Legal
Privacy Policy
Last updated September 21, 2026
This policy explains what Queep does with personal data. It covers the iPhone app, the Mac app, and this website. It is written for Brazil’s General Data Protection Law (LGPD) and for App Store and Mac App Store review.
1. Who controls the data
The controller is LGM Soluções Ltda, trade name Rudimentar, CNPJ 61.525.054/0001-65, with its principal place of business at SHCS CRS Quadra 516, Bloco B, Pavimento 1, nº 69, Asa Sul, Brasília, DF, CEP 70381-525, Brazil. Queep is a product of that company.
Privacy and support requests: contato@queep.app. There is no separate data-protection officer. That address is the channel for access, correction, and deletion requests.
2. What Queep is
Queep is a private reference library. You save notes, links, images and, on the Max plan, audio and video files. The library syncs between your Mac and iPhone. After an item is saved, a private worker reads it and builds a summary and a search index so you can find it later by meaning. The library is not a social network. Other Queep users cannot see it, and we do not publish it.
3. Account data
You can create an account in one of three ways. All of them use Firebase Authentication.
- Email and password. We receive the email address. The password is handled by Firebase Authentication. Our API never stores the password.
- Sign in with Apple. Apple sends an identity token. We receive the email Apple shares, which may be a private relay address, and the name only if Apple provides it on the first sign-in. We do not receive your Apple ID password.
- Sign in with Google. Google sends an identity token. We receive the name, email, and Google account identifier needed to open the session. We do not receive your Google password, and we do not read your Google Drive, Gmail, or other Google products.
Firebase assigns an internal user id. That id is how the library, usage counters, and subscription status are tied to you. Mac and iPhone use the same account.
Deleting the account, recovering it, or changing security-sensitive settings requires a fresh sign-in from the last few minutes: your password, Apple, or Google, depending on how you signed in.
4. The library
When you save something, we store:
- notes you write, including the title and text;
- links you save, and the optional context you add;
- images you import or capture, including a smaller thumbnail used inside the app;
- audio and video files you choose to upload, up to five minutes and 25 MB after the app prepares them, plus a video thumbnail;
- the analysis we produce from that material: a summary, topics, a speech transcript when there is speech, a description of sampled frames, and a numeric embedding used only to search your own library.
Files are not published at a public URL. The apps download an image or a media file only with your signed-in session, and a playback file stays in a temporary location on the device until you close the item.
On the Mac, a screenshot enters the library only when you take that screenshot inside Queep. We do not record the screen in the background. We do not record the microphone, and we do not import playlists. The share extension sends into Queep only what you choose to share.
5. Public pages you save
Saving a link does not connect Queep to your Instagram, X, YouTube, Vimeo, GitHub, or browser account. The worker requests the public page over HTTPS, without your cookies, tokens, or login session. It does not run the page’s scripts and it does not follow the page into private networks.
What we keep depends on what the public page actually returns:
- ordinary pages: the accessible text, up to a size limit;
- a public GitHub README: the rendered text, not the repository;
- YouTube and Vimeo: the public title and author;
- a public X post: the author’s name, the post text, public photos, GIFs, and video posters. From the first video we transcribe speech in the first 15 seconds. The video file is not kept for playback, and background music is not kept;
- Instagram: the public caption, when the page exposes one.
If a page is behind a login, blocked, or otherwise unreadable, we keep the link and whatever context you typed. We do not invent the missing content. Coverage is partial. We do not watch the page for later changes.
6. Plans, usage, and payments
Queep has a Free plan and paid Pro and Max subscriptions sold by Apple. To apply those limits we store counters on your account: items saved, storage used, AI operations, searches, and, on Max, seconds of audio and video uploaded. Monthly counters reset on the first day of each month (UTC). A separate daily counter exists only to slow abuse. Those records do not include the text or files you saved.
Apple processes the payment. We never receive your card number, bank account, or full receipt from Apple. RevenueCat, using your Firebase user id, tells our API whether a subscription is active, which plan it is, and whether it renewed, expired, or was refunded. We keep a short-lived copy of that status so the app can apply the plan, and a processing receipt of each billing notice for 30 days. The receipt does not contain your library.
Restoring purchases stays on the original Queep account. A subscription is not silently moved to a different Queep account. Family Sharing is off.
7. Why we use the data
- create the account and keep the session;
- store the library and sync it between your devices;
- read what you saved so search can find it inside your account;
- read a public page you asked us to save;
- apply Free, Pro, or Max limits and restore an Apple purchase;
- block abuse, keep the service reliable, and answer support;
- delete the account when you ask.
Under the LGPD, the account, the library, and the subscription are processed to perform the contract. Sign-in with Apple or Google, and the content you choose to save, are also covered by your request to use those features. Security logs and abuse limits rely on legitimate interest, limited to what is needed to protect the service and without using your library for advertising.
8. Artificial intelligence
Interpretation happens after the item is saved. A private worker, not the app, sends the material needed for that item to OpenRouter, on fixed Google routes. There is no automatic switch to another provider.
- notes, images, link text, speech, and sampled video frames: Gemini 2.5 Flash-Lite;
- the search embedding: Gemini Embedding 2, processed in the United States;
- the check that a search result actually matches your query: Gemini 3.1 Flash-Lite, on Google’s global route.
Images are reduced before interpretation. Long notes and transcripts are truncated. A video file is not sent whole: the worker samples a limited number of frames and transcribes speech separately from the picture, so a spoken description is not handed to the model as if it were what the frame shows. Search sends the query in the request body, not in the address bar, compares it with your own finished items, and can return nothing.
Each call asks the provider not to retain the content and not to use it for training (zero data retention, data collection denied). We do not use your library to train a Queep model, and we do not sell it. A failed analysis does not delete the original. This is not end-to-end encryption: for the analysis to exist, that provider receives the excerpt the feature needs.
Records of the call itself — that a call happened and what it cost — do not include the content and expire after 30 days.
9. Where data lives and who receives it
Account data, the library, analyses, and files are stored on Google Cloud and Firebase in São Paulo (southamerica-east1). The iPhone and Mac apps cannot read that database or those files directly. Every read and write goes through the Queep API, which checks the Firebase session and that the item belongs to you.
We share data only with the processors required to run Queep:
- Google Cloud and Firebase — authentication, database, and private file storage in São Paulo;
- OpenRouter and Google (Gemini on Vertex AI) — the analysis and the search check described above. Embedding and some model calls run outside Brazil;
- Apple — App Store and Mac App Store distribution, Sign in with Apple, and payment;
- Google Sign-In — only if you choose that sign-in method;
- RevenueCat — subscription status for your Firebase user id. RevenueCat does not receive the contents of the library.
We do not sell personal data. We do not use it for advertising, and the apps do not use Apple’s tracking permission. We share data when the law requires it, or when you ask us to.
10. How long we keep it, and how deletion works
The library stays while the account exists. You can delete the account in the app, under Account → Delete account, or by writing to contato@queep.app. See Support.
- By default, deletion is scheduled for 30 days later. During that time the library, new captures, search, and new analysis are blocked. Sign-in and the files remain, so you can recover them.
- Signing in again does not cancel the deletion. Recovery is a separate action, before the deadline, and requires you to confirm your identity. Notes, images, links, media, and analyses return to the same account.
- You can choose immediate deletion. Cleanup then starts in the background. The app cannot restore that account.
- When the 30 days end, the same cleanup runs automatically. A recovery and a late cleanup job cannot both win: a recovered account is not deleted by a job that was already queued.
Cleanup removes:
- the Firebase Authentication user;
- notes, links, images, audio, video, thumbnails, and previews;
- analyses, transcripts, and search embeddings;
- pending processing jobs and usage counters;
- the cached subscription status.
A small tombstone remains: a hash of the user id, the deletion operation id, a version, the state, and the date. It has none of your content. It exists so an old upload or an old job cannot recreate the library after you deleted it. A recovery record, if you recovered an account, keeps the same kind of operational id and date, not the library.
A few technical leftovers are separate from the 30-day recovery window:
- after a file is actually removed, the storage bucket’s soft-delete window can keep the object for up to 7 days. The app cannot open it during that window. It then expires;
- AI call records and billing notices, both without library content, expire after 30 days;
- in the current version, deleting the Queep account does not yet call RevenueCat to erase the subscriber record. We keep an internal note of that user id so that deletion can be completed with RevenueCat. That note is not your library. You can also ask RevenueCat, or us, to remove it.
Deleting Queep does not cancel an Apple subscription, and cancelling the subscription does not delete the Queep account. The app says so on both screens. Manage the renewal in the App Store or Mac App Store settings.
11. Your rights
You may ask us to confirm whether we process your data, to give you access, to correct it, to delete it, to restrict it, or to provide it in a portable form. You may withdraw consent and object to processing based on legitimate interest. You may also complain to the Brazilian National Data Protection Authority (ANPD).
Write to contato@queep.app. We will answer within 15 days. Deletion of the account itself can be done in the app, without waiting for an email.
12. Children
Queep is not directed at children under 13, and we do not knowingly create accounts for them. If we learn that we have data from a child under 13, we will delete the account. In Brazil, data of a child under 12 is processed only with the consent required by the LGPD; this service is not offered for that purpose.
13. Security and transfers outside Brazil
Sessions are authenticated, transport is encrypted, and files are private to the owner. Access to the database from the apps is denied by the Firebase rules. No service is incapable of being breached.
The library is stored in São Paulo. Sign in with Apple, Apple payments, RevenueCat, and part of the AI processing (embeddings in the United States, and a global Gemini route for the search check) involve companies and infrastructure outside Brazil. Those transfers are made to provide the service you asked for, under the contracts of those providers, including the instruction that model providers not retain the content for training.
14. This website
queep.app is a static marketing site. It does not create an account, does not set analytics cookies, and does not ask you to sign in. Download buttons open Apple’s stores. Writing to us uses your own email app. If we later add a cookie that is not essential, we will ask before setting it and update this section.
15. Changes
When this policy changes in a way that matters, we update the date at the top of this page. The version published here is the one that applies.