Privacy Policy

1. Summary

2. What we collect

DataWhere it comes fromWhere it is stored
Account identity — provider user id, display name, email (if the provider releases it), avatar URL, provider name Your chosen sign-in provider (X or Google) Our server (session store) and your browser
Session token Created at sign-in gq_session cookie + server session store
Plan and usage counters — plan tier, current-month Fast and Thinking ask counts, period end Generated as you use the Service Our server (billing record)
Payment metadata — Stripe customer id, subscription id, price id, status, current period end Stripe, via checkout and webhooks Our server (billing record) and Stripe
Coupon redemption — code nonce, plan, days, redeeming account id and email, timestamp You, when you redeem a code Our server
Feedback reports — your note plus the question and answer text you were looking at, and your account id/email You, when you press “Report” Our server
Share pages — question, answer, citations, your account id You, when you press “Share” Our server, published at an unguessable public URL
Saved clips — quote, note, tags You, when you save a citation Our server
Technical logs — IP address, timestamp, request path, status, user agent Automatic on every request Web server / reverse proxy logs on our host
Anti-abuse counters — request counts keyed to IP address or account Automatic Server memory only; discarded on restart
Chat history, drafts, mode preference Your use of the app Your browser only (local storage)

We do not collect precise geolocation, contacts, biometrics, or any special-category data, and we do not ask for your date of birth.

3. Your questions and answers

To answer a question, the text of that question and the relevant transcript passages are sent to our model provider for synthesis. That transmission is necessary to provide the Service. Our provider processes the request under its API terms; API traffic of this kind is not used to train their public models by default.

On our own server, question text is not written to a database in ordinary use. It exists in memory for the duration of the request and appears in logs only as a request path, not as content. It becomes stored data only in two cases you control: submitting a feedback report, or creating a share link.

Your conversation history is kept in your browser’s local storage so it survives reloads. Clearing site data in your browser erases it permanently — we cannot recover it, and it does not sync between devices.

4. Why we use it

We do not use your data for advertising, profiling, automated decision-making with legal effect, or resale.

5. Legal bases (UK/EU GDPR)

If you delete your account we keep a one-way hashed identifier plus the current period’s ask count, so that deletion cannot be used to reset a free allowance. That minimal record is kept under legitimate interests (fraud prevention) and cannot be used to re-identify you or contact you.

6. Processors and third parties

ProviderPurposeData involved
Model provider (OpenAI)Generating answers from retrieved transcript passagesQuestion text, retrieved passages, conversation context
StripePayments, subscriptions, billing portal, invoicesName, email, card details (held by Stripe), billing address/tax where required
Sign-in providers (X, Google)AuthenticationBasic profile released by the provider you choose
CloudflareDNS and, when proxying is enabled, TLS and DDoS protectionConnection metadata, IP address
Hosting provider (VPS)Running the serverAll server-side data listed above, at rest on the host
Email providerReplying to support, privacy and legal requestsYour email address and message

Each is used only for the purpose above. We have no advertising or data-broker relationships. We may disclose data if legally compelled, to protect rights and safety, or as part of a transfer of the Service — in which case this policy travels with it and we will give notice.

7. Cookies

We set one cookie: gq_session, an HttpOnly, SameSite=Lax, Secure-in-production session token used to keep you signed in. It is strictly necessary, so no consent banner is required for it. Stripe and Cloudflare may set their own cookies on their own domains during checkout or proxying. Details, including how to remove them, are in the Cookie Policy.

8. How long we keep things

ItemRetention
SessionUp to 30 days, or until you sign out
Account identity & usage countersWhile the account exists; deleted on request
Public share pages90 days, then automatically purged (earlier on request)
Feedback reportsUntil the issue is resolved, then periodically purged
Saved clipsUntil you delete them
Server / proxy logsShort rolling window (typically 14–30 days)
Anti-abuse countersMinutes to hours, in memory only
Payment and tax records (held by us and Stripe)As long as required by law, typically 7 years
Post-deletion anti-abuse hashUntil the end of the following calendar month

9. Your rights and controls

Depending on where you live you may have the right to access, correct, delete, restrict, object to, or port your data, and to withdraw consent. You can exercise most of these yourself:

Deleting your account does not cancel a Stripe subscription — cancel that in the billing portal first, or ask us and we will do both. If you are in the EU/UK and unhappy with our response, you may complain to your local data protection authority.

10. US state privacy rights

If you are a resident of California, Colorado, Connecticut, Virginia, Texas, Utah or another state with a comprehensive privacy law, you may request access to, correction of, deletion of, or a portable copy of your personal information, and you may appeal a refusal.

We do not sell personal information and do not share it for cross-context behavioural advertising or targeted advertising, so there is nothing to opt out of. We do not use sensitive personal information for inference. We do not knowingly process the data of anyone under 16 for such purposes. Requests: [email protected]. We verify requests using the account you are signed into. An authorized agent may act for you with written permission.

11. International transfers

The Service is operated from, and its providers are largely located in, the United States. If you use it from outside the US, your data is transferred to and processed in the US. Where required, transfers rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum) or another lawful mechanism provided by the relevant processor. You can ask us for details.

12. Security

No system is perfectly secure. If you find a vulnerability, please report it privately to [email protected] before disclosing it; we will not pursue good-faith security research. If a breach affects your personal data and creates a real risk to you, we will notify you and any required authority without undue delay.

13. Children

The Service is not directed to children under 13 and we do not knowingly collect their personal information. Paid plans require you to be 18 or older. If you believe a child under 13 has given us data, email [email protected] and we will delete it.

14. Changes to this policy

We will post revisions here with a new “Last updated” date, and announce material changes in-app. Your continued use after the effective date means you accept the updated policy.

15. Contact

the Operator of Groyper Quant · @groyper_quant on X
Privacy requests: [email protected]
General: [email protected]