Privacy Policy

Effective [effective date] · QuickStark.Ai

What we collect, why we process it, who else touches it, and what you can ask us to do with it.

This document is not final and has not been reviewed by a lawyer.

7 details still to be filled in, marked below. Set them in src/lib/legal.ts and this notice disappears.

1Who controls your data

[legal entity name], [registered address], is the controller of the personal data described here. Contact us about privacy at [privacy email].

This policy covers the QuickStark.Ai service. It does not cover applications that other people build and publish with QuickStark — for those, the person who built the application is the controller, and their own policy applies.

2What we collect

  • Account — email address or phone number, display name, avatar image, and which sign-in provider you used.
  • Projects — project names, the descriptions and prompts you write, generated code, and project status.
  • Usage and credits — your credit balance and a ledger of every credit movement: the action, the amount, when it happened, and which project it belonged to.
  • Connections — details of integrations you configure, including server names, URLs and access keys.
  • Billing — plan, subscription status and payment history. Card details are held by our payment processor, not by us.
  • Support — messages you send us through in-product chat or email.
  • Technical — IP address, browser and device information, and server logs.

We do not ask for special category data — health, biometrics, political opinions and the like — and you should not put it into prompts or project descriptions.

3Why we process it

  • Creating your account and signing you in — to perform our contract with you.
  • Generating, previewing and publishing your applications — to perform our contract with you.
  • Metering credits, enforcing plan limits and taking payment — to perform our contract with you.
  • Keeping records for tax and accounting — because the law requires it.
  • Preventing abuse, fraud and multiple-account credit farming — our legitimate interest in running the service sustainably.
  • Security monitoring and debugging — our legitimate interest in keeping the service safe.
  • Product emails you have asked for — with your consent, withdrawable at any time.

We do not sell personal data, and we do not use it for advertising or share it with advertisers.

4Prompts and generated code

To generate an application we send your description, and relevant context from your project, to [AI model provider]. That provider processes it to produce the output and returns it to us.

Your prompts and generated code are stored against your account so you can return to a project. They are visible to you, and to our staff only where necessary to operate the service, investigate a support request you have raised, or respond to a security or abuse issue.

We do not use your prompts or your generated code to train or improve any model. We use our model provider under terms that exclude training on customer content, so your descriptions and the code produced from them are used to answer your request and for nothing else. If that ever changes we will ask for your consent first; we will not switch it on by default.

5Who else processes it

  • Supabase — database and authentication. Sees account, project, credit and connection data.
  • Vercel — hosting and deployment. Sees technical and log data, and published project code.
  • [AI model provider] — code generation. Sees prompts and project context.
  • GitHub — repository creation when you publish, if you connect it. Sees generated code.
  • Google, Apple and Facebook — sign-in, if you choose it. See your email address and basic profile.
  • [payment provider] — payments and subscriptions. Sees billing details and payment history.

We may also disclose data where the law requires it, or to establish or defend legal claims. If the business is sold or merged, data may transfer with it, and we will tell you before that happens.

6Where it is stored

Our database and authentication run in the European Union. Some processors listed above operate outside the EU and the UK, so data may be transferred there. Where it is, those transfers rely on the European Commission’s Standard Contractual Clauses or an adequacy decision.

7How long we keep it

  • Account and project data — while your account is open, and for 30 days after you close it.
  • Credit ledger and billing records — 6 years, because tax and accounting law requires it.
  • Support messages — two years.
  • Server logs — 90 days.
  • Abuse records — as long as needed to stop the abuse recurring.

8How it is protected

Data is encrypted in transit and at rest. Every table in our database enforces row-level security, so one account’s records are not readable by another. Credit balances cannot be written from a browser at all — only the server can move credits, and every movement is recorded in an append-only ledger.

Access keys you store for integrations are write-only: they can be set and replaced but never read back, including by you.

No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and tell you without undue delay where the law requires it.

9Your rights

Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, give it to you in a portable format, or withdraw consent where consent is the basis.

Ask at [privacy email]. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.

If you are unhappy with how we handled it, you can complain to your local data protection authority. If you are in California, you also have rights under the CCPA and CPRA, including to know, delete and correct, and not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined there.

10Cookies

We set cookies that are strictly necessary to run the service — principally to keep you signed in and to keep your session secure. These do not require consent, and we do not use advertising cookies.

11Children

The service is not for children under 16. We do not knowingly collect their data, and if we learn we have, we will delete it. If you believe a child has given us data, contact [privacy email].

12Changes and contact

We will post any change here and update the date at the top. For material changes we will tell you by email or in the product before they take effect.

Questions, requests and complaints: [privacy email], or write to [registered address].