Quad Home 的隐私政策
Quad Home 作者: Quad Labs Technologies
Quad Home Firefox extension
Your new-tab display preferences are stored locally. Optional frequent-site shortcuts are read from Firefox and are not uploaded to Quad. Web searches send your search terms to the selected search engine; website addresses open the requested site. Ask Quad opens quad.chat with your question. If you sign in, Quad processes account and authentication data and retrieves your recent chats and Briefing. Session credentials are stored locally in extension storage. You control which widgets appear.
Full service policy: https://www.quad.chat/privacy
Privacy Policy
Effective date: August 4, 2026 · Contact: privacy@quad.chat
This policy is designed to reflect how the product currently works in production: authenticated accounts, AI provider routing, subscriptions, integrations, diagnostics, and consent-based analytics and advertising measurement.
- Scope
Quad is an AI workspace that lets you create accounts, submit prompts, upload files, connect integrations, buy subscriptions, and use AI models and tools. This Privacy Policy explains how Quad Labs Technologies LLC collects, uses, discloses, and protects personal information when you use quad.chat, our web and mobile apps, and related services.
If you use the service through a team, the team's owner and billing managers control seats, roles, usage caps, and billing for that team. Your conversations and files remain in your own account and are not exposed to team administrators through team administration features.
- Information We Collect
Account and profile data: name, email address, profile image, login/session details, and account identifiers from our authentication provider.
Workspace content: prompts, conversation history, uploaded files, generated outputs, saved preferences, custom instructions, tasks, memories, API keys you choose to store, and integration settings.
Published content: when you choose to publish a generated site or interactive experience, the artifact content, title, and public address become available to anyone with that address until you unpublish or delete it. The conversation used to create it is not published.
Billing and subscription data: plan, subscription status, billing customer identifiers, invoices, and transaction metadata from our payment provider. We do not store full payment card numbers.
Team and organization data: when you create or join a team, we process the team name, member names and email addresses, roles, seat and invitation status, per-member usage totals (such as credits and searches consumed), billing settings, and an audit log of team administration actions.
Device and usage data: IP-derived location at a coarse level, browser/device information, app diagnostics, crash data, request metadata, product analytics when you consent to analytics, and ad conversion measurement data when you consent in the mobile app or enable marketing cookies on the web.
Integration data: information necessary to connect third-party services such as GitHub, Google Drive, OneDrive, MCP servers, and other tools you choose to enable.
Support and communications data: messages you send us, feedback, and account-deletion or data-rights requests.
Information from other sources: authentication and integration providers, payment and app-store providers, team owners who invite you, connected services you authorize, and security or fraud-prevention providers.
Your prompts and files may contain sensitive information that you choose to provide. Please do not submit health, biometric, government-identifier, financial-account, precise-location, children's, or other sensitive data unless it is necessary and you are authorized to do so.
- How We Use Information
To provide, operate, secure, and maintain the service, including authenticating users, storing conversations and files, routing requests to AI or search providers you select, and processing billing.
To improve reliability, performance, product quality, abuse prevention, moderation, fraud detection, debugging, and customer support.
To communicate with you about transactional matters such as account notices, receipts, verification, service updates, legal requests, and support.
To comply with law, enforce our Terms, protect users and the public, and investigate misuse.
We do not sell personal information, and we do not use your customer content to train our own general-purpose AI models.
- Legal Bases For Processing
Contract: we process account data, workspace content, selected model or tool requests, integration data, and subscription information to create your account and provide the features you request.
Legitimate interests: we process limited device, request, security, fraud-prevention, service-health, and support data to protect the service, diagnose failures, prevent abuse, and improve reliability. Our interests are operating a secure and dependable service; we assess necessity and privacy impact before relying on this basis.
Consent: we use optional product analytics, session replay, advertising measurement, and non-essential device storage only after your affirmative choice. In the mobile app, we separately ask before enabling anonymous usage analytics and ad conversion measurement, and before sending your prompts or selected content through Vercel AI Gateway to a third-party AI model provider. You can withdraw either mobile permission in Settings and change web analytics or marketing choices through Cookie settings, without affecting processing that occurred before withdrawal.
Legal obligations and legal claims: we process billing, tax, compliance, safety, and request records where law requires it or where necessary to establish, exercise, or defend legal claims.
- How We Share Information
Service providers and subprocessors that help us run the service, such as authentication, infrastructure, payment, monitoring, analytics, email, and support vendors.
Mobile AI processing: before the app sends personal data to an outside AI service, it presents an in-app disclosure and asks for explicit permission. If you allow it and request an AI feature, we collect the prompt you type and relevant chat history directly from your use of the app. We also collect files, images, audio, project instructions, or saved preferences only when you choose to attach, record, enable, or include them in that request.
For managed AI requests, we send that selected content through Vercel AI Gateway to the provider for the AI model or media feature you choose. They use it to generate the feature or response you request under the privacy terms shown for that feature. We do not send your name, email address, authentication credentials, payment data, contacts, or unselected photo-library content to AI model providers for inference.
We require subprocessors that receive personal information to apply the same or an equivalent level of privacy and security protection described in this policy. Private Lane chat requests enforce Vercel AI Gateway Zero Data Retention and route only to providers covered by a Zero Data Retention agreement. Some chat models are available only through Standard Lane. Before selecting one, we identify it and ask you to confirm that prompts, selected attachments, and responses may be retained under that provider's standard data policies. Image and video generation are not Private Lane features: before your first generation in Studio we ask you to confirm that prompts, reference images, and results are handled under the selected provider's standard retention terms. Current recipients, purposes, data categories, and regions are listed on our Subprocessors page.
You may decline AI processing and continue to use non-AI account and settings features. You can withdraw permission at any time in mobile Settings. After withdrawal, the app blocks new AI requests unless you make a new affirmative choice; withdrawal does not affect processing already completed at your request.
Your team administrators when you join a team workspace: the team owner and billing managers can see your name, email address, role, seat status, usage totals, and team audit records for seat management and billing. Team administration features do not give administrators access to the content of your conversations or files.
Advertising and measurement partners: with your consent to marketing cookies, we share limited conversion data (such as that a signup or purchase occurred) with Google to measure the effectiveness of our ads. We do not sell your workspace content or share it with advertisers.
Corporate transactions, legal disclosures, and safety-related disclosures when required to complete a merger, financing, reorganization, respond to lawful requests, enforce our rights, or protect people and systems.
Public sites and experiences: we display only the artifact you explicitly publish. Its source conversation, account identity, private memory, and unpublished drafts are not included in the public page.
Our current subprocessor list, including what each provider receives and why, is available on our /subprocessors page.
- Cookies And Similar Technologies
We use cookies, SDKs, local storage, and similar technologies for authentication, security, remembering preferences, measuring usage, improving performance, and measuring advertising.
Essential technologies are used to keep the service working. Analytics technologies are used only when you consent. We present a cookie banner, record your choices, and let you reject non-essential cookies as easily as accepting them.
Simple Analytics measures pageviews without analytics cookies. We still enable it only after you opt in to analytics. We redact private page identifiers and disable referrer, URL parameter, page-load identifier, scroll and time-on-page collection. We do not send chat titles, prompts or files through this integration. Withdrawing analytics consent stops new pageviews. Browser Do Not Track and Global Privacy Control signals also disable this integration.
Advertising measurement: we use Google Consent Mode and the Google tag for Google Ads conversion measurement. Google tags load with advertising storage, user data, personalization, and analytics storage denied by default and may send limited cookieless measurement pings. Google advertising cookies and enhanced-conversion user data remain disabled unless you consent to marketing cookies. You can change this choice at any time via the Cookie settings button on this page.
Where required by applicable law, we honor browser-based Global Privacy Control signals as a request to reject non-essential tracking related to sale or sharing.
- Retention
Account, workspace, conversation, project, integration, and stored-content data are kept while your account or the relevant feature remains active, and are deleted when you delete the item or account, subject to the limited exceptions below.
Unpublishing a site or experience disables its public address. Deleting its source conversation or your account removes the hosted artifact from active service, subject to the backup timing described below.
If a plan downgrade or ended subscription leaves an account above its new private-storage allowance, new uploads are paused and the account receives a 30-day grace period. Unless the user deletes files or restores sufficient storage before the deadline, the oldest stored files are deleted until usage fits the active allowance.
Operational usage events are normally kept for up to 395 days; billing webhook payloads, app command logs, and generated weekly suggestions for up to 90 days; privacy and security audit events for up to 400 days; and stale live-activity tokens for up to 7 days. A deployment may use a shorter period.
Data-export archives are made available through a time-limited link. Billing, tax, transaction, suppression, policy-acceptance, fraud, security, dispute, and legal-request records may be retained for the period required by applicable law or reasonably needed to document compliance and resolve claims.
Backups and provider logs may persist for a limited rolling period before deletion or overwrite. When immediate deletion from a backup is not technically possible, the data is isolated from ordinary use and removed on the provider's normal backup cycle.
- Security
We use administrative, technical, and organizational safeguards designed to protect information, including encryption in transit, access controls, segmentation of systems, monitoring, and vendor controls. No system is perfectly secure, and we cannot guarantee absolute security.
- International Transfers
We and our vendors may process information in countries outside your own, including the United States. Where personal information is transferred out of the European Economic Area, the United Kingdom, or Switzerland, we rely on legally recognized transfer mechanisms: the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions) for vendors certified under it, and the European Commission's Standard Contractual Clauses (SCCs) or equivalent contractual safeguards otherwise.
You can request a copy of the relevant safeguards, or ask which mechanism applies to a specific vendor, by contacting privacy@quad.chat. Our current vendors are listed on the Subprocessors page.
We assess transfer safeguards and supplementary measures for restricted transfers. A vendor's Data Privacy Framework participation is used only while that vendor and the relevant data recipient are covered; otherwise we use applicable standard contractual clauses or another lawful mechanism.
- Your Rights And Choices
Depending on where you live, you may have rights to access, correct, delete, export, restrict, object to, or appeal certain processing of your personal information.
California residents may have rights to know, delete, correct, opt out of sale or sharing, limit sensitive personal information where applicable, and receive non-discriminatory treatment for exercising privacy rights.
EEA, UK, and similar-law residents may have rights to access, rectification, erasure, restriction, portability, and objection. You may withdraw consent at any time and lodge a complaint with the supervisory authority where you live or work, or where you believe an infringement occurred.
To exercise rights, use the privacy and data settings in the product or email privacy@quad.chat. We may need to verify your identity and authority. We respond within the time required by applicable law, generally one month under GDPR and 45 days under many U.S. state laws, subject to lawful extensions. If we deny a request, we will explain why and provide an appeal route where required.
We do not currently use personal information to make solely automated decisions that produce legal or similarly significant effects about users. AI outputs are generated in response to user requests and must not be used as the sole basis for high-impact decisions.
- United States State Disclosures
During the preceding 12 months, we may have collected the categories described in Section 2: identifiers; customer and commercial records; internet or electronic activity; approximate geolocation; professional or organization information supplied for teams; inferences such as saved preferences or memories; and content that may qualify as sensitive personal information when you choose to submit it.
We collect these categories from you, your device, team administrators, and the providers described in Sections 2 and 5. We use and disclose them for the business purposes in Sections 3 and 5. We do not sell personal information for money. Optional advertising measurement may be considered 'sharing' or targeted advertising under some state laws, so it remains off unless you consent and can be disabled through Cookie settings or a supported Global Privacy Control signal.
We do not use or disclose sensitive personal information to infer characteristics about you. We do not knowingly sell or share personal information of consumers under 16.
Where a state law applies to us, residents may use privacy@quad.chat or the in-product privacy controls to submit a request. Authorized agents may submit requests with proof of authority. We will not discriminate against you for exercising a privacy right.
- Children
The service is not directed to children under 13, and you may not use the service if you are below the minimum age required in your jurisdiction to consent to digital services without appropriate permission.
- Third-Party Links And Services
The service may link to third-party sites, documentation, integrations, and providers. We are not responsible for their privacy practices or content.
- Changes To This Policy
We may update this Privacy Policy from time to time. If we make material changes, we may update the effective date, post the revised version, and provide additional notice where required.
- Contact Us
Quad Labs Technologies LLC
1021 E Lincolnway 10208
Cheyenne, WY 82001
United States
(650) 881-2786
support@quad.chat
privacy@quad.chat