Privacy Policy — Juan Passport
Effective July 29, 2026.
Juan Passport is an app by HackLatino LLC. This policy explains what data we collect when you use the Juan Passport app or this site, what we use it for, and who we share it with. It is written based on what the system actually does.
If you have a question or want to exercise any of the rights listed below, write to us at info@hacklatino.com.
1. Data we collect
Your account. You sign in with Google or Apple. There is no password: we never receive or store one. From that sign-in we receive a user identifier, your email address, your name, and your profile photo. If you use "Sign in with Apple" and choose to hide your email, we receive the forwarding address Apple generates, not your real email. In your profile we also store your username, your display name, your photo, your bio, your country, and your favorite team, when you fill them in.
Your date of birth. We ask for it once, after you sign in. We use it for one thing only: the community videos section is limited to people 17 or older. It is self-declared; we do not verify it against any document.
What you create. Photos, videos, titles, free text and, if the experience's template includes it, the names of the people who are with you or whom you tag.
Location. We do not request or read your phone's location. The app does not request the operating system's location permission. The pins you see on the map are the location of places and experiences, data uploaded by the company that organizes each experience — not your position.
Camera, photos, and microphone. We request camera and microphone permission to record videos, and photo library permission so you can choose images from your gallery. We only access them when you start the action.
Notifications. If you accept them, we store an identifier for your device (the notification token) and the platform, iOS or Android, so we can notify you when someone tags you or starts following you.
App usage. We log usage events: which screens you open, QR code scans, creating and sharing keepsakes, following and unfollowing, and app errors, including the technical error message. Each event travels with your user identifier if you are signed in, or with an anonymous identifier generated on your device if you are not; and with the platform, the app version, the installed update version, and the active experience.
The assistant. If you use the app's assistant, we store the conversation. We also automatically derive some data about your preferences, to give better answers. It is kept until you delete your account.
This site's form. If you are a business and you write to us from juanpassport.com, we store your name, your company, your email, your phone number if you leave it, your business type, your message, the page's language, and two technical details of the request: the browser (user-agent) and the page you came from (referer).
2. Data we do not collect
- We do not store your IP address alongside your account or your content: that field does not exist in our database. Our infrastructure providers may log it transiently in their own technical logs.
- We do not read the EXIF metadata in your photos — for example, where the photo was taken. When you upload them we convert them to WebP on our server, and that process discards the original file's metadata. We also do not keep the original file that came from your phone.
- We do not store passwords, because there is no password sign-in.
- We do not use advertising or third-party tracking SDKs inside the app.
- We do not sell your data, nor do we hand it over to data brokers.
- We do not read your contacts.
3. Artificial intelligence
This section stands on its own because it involves sending your content to outside providers.
Stories. If you generate a Story from one of your photos,we send that photo to an outside AI model provider — today, Google models, through OpenRouter — along with a text instruction. That instruction explicitly asks it to preserve recognizable faces, so the postcard still shows the people in the photo. We keep the resulting image and the reference to the original photo.
The assistant. The messages you write and the recent history of the conversation are sent to outside model providers — today, Anthropic and Google, through OpenRouter — to generate the response. For these requests we ask the provider for zero retention: that it not keep the content after responding.
What we cannot promise today. Stories image generation does not yet ask for zero retention. That means your photo may temporarily remain in the provider's systems, subject to that provider's policies. We are working to bring the two paths in line; until we do, we would rather say so here than make a guarantee the system does not keep.
We do not train models with your content. We do not use your photos, your videos, or your messages to train our own models.
4. Who we share with
| Provider | What for | What it receives |
|---|---|---|
| Google Firebase | Sign-in and authentication | Your sign-in and your user identifier; your account's name, email, and photo |
| Amazon Web Services | Servers, file storage, and content delivery | Your photos and videos, and the traffic between the app and our servers |
| OpenRouter, with Anthropic and Google | AI features | Your photo when generating a Story; your messages when using the assistant |
| Mixpanel | Product analytics | Your usage events, identified with your user identifier |
| Expo | Sending notifications | Your device's notification token |
We do not share your data with anyone else, except when a law or a court order requires us to.
5. What is public and what is not
- Your profile — username, display name, photo, and bio — is visible to other people who use the app.
- Keepsakes you mark as public appear on the community wall.
- When you share a keepsake, the link stores your username, so we can attribute visits to you. Whoever receives the link can view it.
- If a company's admin adds you as a member of their team, that company's admins see your email, your name, and your photo, taken from your Google or Apple account.
- Your conversations with the assistant, your date of birth, and your email are not public.
6. How long we keep your data
We keep your data for as long as your account exists. We do not automatically delete anything based on age. When you delete your account, we delete what is detailed in the next section.
7. Deleting your account
You can delete it yourself, from the app: Settings → Delete account. There is no need to write to us or wait for approval.
Doing so deletes your profile, your keepsakes — with their photos, their text, and any names you wrote — your videos and their associated video files, the photos from your keepsakes and your profile photo from our storage, your likes and favorites, who you follow and who follows you, your blocks and your reports, your conversations with the assistant and the data derived from them, your generated Stories, your shared links, and your device's record for notifications. We then delete your user from the authentication system.
Two things survive that deletion, and we would rather say so:
- The image files from your experience keepsakes may remain in our storage even after the keepsake disappears from the database. They are stored under random names with no reference back to your account, and because of that we cannot bulk-delete them today without risking someone else's files. If you want us to remove them, write to us and we will do it by hand.
- If you are a member or admin of a company, the record of that role is kept, so the company does not lose all its admins overnight. It is no longer linked to an active account. If you want us to remove it, write to us.
8. Your rights
You can ask us for access to your data, its correction, its deletion, or a copy. Write to us at info@hacklatino.com. If you contacted us through this site's form and want us to delete that inquiry, tell us at that same email: today we do that deletion by hand.
9. Minors
Juan Passport is not directed at children under 13, and we do not knowingly collect data from them. The community videos section is limited to people 17 or older. If you are a parent or guardian and believe we have data from a child under 13, write to us and we will delete it.
10. Security
All traffic between the app and our servers is encrypted with HTTPS. Administrative access to the data is restricted. Your session is stored in the app's local storage, on your device.
11. Where your data is processed
Our servers and our providers' servers are in the United States. If you use the app from another country, your data is processed there.
12. Changes to this policy
If we change it, we update the date in the header and publish the new version at this same address.
Contact
HackLatino LLC — info@hacklatino.com