Privacy Policy
Last updated: August 26, 2026
[Company Legal Name] ("Quzaic", "we") provides the Quzaic feedback-to-build orchestration platform (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices available to you.
1. Who this covers
- Customers — the builders/agencies who hold Quzaic accounts.
- Reviewers — the clients and testers who submit feedback through the Quzaic Review Agent on a Customer's application. Reviewers may be anonymous or may provide a name/email.
- Visitors — people who browse our website.
2. Information we collect
- Account data: name, work email, password (stored hashed), organization details, and role.
- Billing data: subscription tier and status, and billing identifiers. Card details are collected and stored by our payment processor, Stripe — Quzaic never receives or stores full card numbers.
- Reviewer feedback & context: the feedback text a reviewer submits and page context (such as the URL/route and the element referenced), plus an optional reviewer name/email if provided. This is submitted at the direction of the Customer who operates the reviewed application.
- Usage & device data: log data, IP address, browser/user-agent, and product usage needed to operate and secure the Service.
- Cookies: we use strictly necessary cookies for authentication and session management.
3. How we use information
We use information to: provide and operate the Service (capture, interpret, route, build hand-off, and verify feedback); authenticate users; process subscriptions and payments (via Stripe); send transactional and lifecycle communications (e.g., verification links, trial and billing notices); provide support; maintain security and prevent abuse; comply with law; and improve the Service. AI features process feedback text as data to structure it into change requests; feedback content is treated as data, not as instructions.
4. How we share information
We share information with: service providers/subprocessors who help us run the Service (e.g., our cloud/database provider, Stripe for payments, and our email provider Resend for transactional email), under appropriate confidentiality and data-protection terms; integrations you connect (e.g., your own build tools) at your direction; and as required by law or to protect rights and safety. We may share information in connection with a merger, acquisition, or asset sale. We do not sell personal information.
5. Roles (controller/processor)
For Customer accounts and our website, Quzaic acts as a controller. For reviewer feedback submitted through a Customer's application, the Customer is the controller and Quzaic acts as a processor handling that data on the Customer's behalf and instructions. Customers are responsible for providing any required notices to, and obtaining any required consents from, their reviewers.
6. Data retention
We retain personal data for as long as needed to provide the Service and for legitimate business or legal purposes. Feedback notes are retained for the Customer as part of their workspace. After a Customer cancels, we retain workspace data for a limited grace period (currently 30 days), after which projects are archived and may be deleted in the ordinary course, unless a longer period is required by law.
7. Security
We use technical and organizational measures to protect personal data, including row-level access controls, encryption in transit, hashed credentials, and scoped access. No system is perfectly secure; we cannot guarantee absolute security.
8. Your rights & choices
Depending on your location, you may have rights to access, correct, delete, or port your personal data, or to object to or restrict certain processing. Reviewers who submitted feedback to a Customer's application should contact that Customer; we will assist Customers in responding. To exercise rights or ask questions, contact us at [privacy@quzaic.com]. You can also manage account and billing data in-product.
9. International transfers
We may process data in the United States and other countries. Where required, we use appropriate safeguards for international transfers.
10. Children
The Service is not directed to children under 18 and we do not knowingly collect their personal data.
11. Changes
We may update this Policy; material changes will be communicated by reasonable means and the "Last updated" date revised.
12. Contact
[Company Legal Name], [Mailing Address], [privacy@quzaic.com].
This document is a starter template pending review by legal counsel and completion of the bracketed items.