Qua
MultiplayerWhy QuaHow it worksProofCompareSkillsDeployment
Login →
MultiplayerWhy QuaHow it worksProofCompareSkillsDeploymentLogin →
Legal

Privacy Policy

What Qua collects, why we collect it, who it reaches, how long we keep it, and how to get it back or get rid of it. Written to satisfy the GDPR and UK GDPR, the California CCPA/CPRA and the other US state privacy laws, and India's Digital Personal Data Protection Act.

Last updated: August 25, 2026Applies to: qua.dev and the Qua application
  1. 1. Who we are and what this policy covers
  2. 2. Personal data we collect
  3. 3. How and why we use personal data
  4. 4. AI model processing and automated decisions
  5. 5. Who we share personal data with
  6. 6. International transfers
  7. 7. Retention
  8. 8. Your privacy rights
  9. 9. Deleting your data
  10. 10. Security
  11. 11. Cookies and similar technologies
  12. 12. Children
  13. 13. Changes and contact

1. Who we are and what this policy covers

Qua ("Qua", "we", "us") provides an enterprise AI workspace that routes work across multiple AI models, records a cost and outcome receipt for every session, and gives administrators governance controls over how those models are used. This Privacy Policy explains how we handle personal data on the qua.dev website and in the Qua application.

Two different roles. For visitors to our website, people who sign up directly, and our own account records, Qua is the controller (in India, the Data Fiduciary) of that personal data. For content that a customer organization's users put into the workspace — prompts, uploaded documents, sessions, artifacts — Qua acts as a processor (Data Processor) on the instructions of that organization, which is the controller. Where an organization's own privacy notice conflicts with this one in respect of workspace content, theirs governs the purposes of processing and ours governs how we operate as processor. Our processor commitments are set out in the Data Processing Agreement.

2. Personal data we collect

Data you give us

  • Account data — name, email address, authentication identifiers, the organization and department you belong to, your role, and login timestamps. If you sign in with Google, we receive your name, email address and profile image from Google; we do not receive your Google password.
  • Workspace content — prompts and conversation messages, documents and files you upload as knowledge sources, notes, saved memory entries, generated artifacts, and the acceptance and outcome ratings you record on a session.
  • Organization configuration — policies, budgets, model approvals, connector settings, invitations and access requests.
  • Communications — messages you send to our support, sales or privacy addresses.

Data generated by using the service

  • Session and receipt metadata — which resolution tier answered, which model was used, token counts, latency, measured cost, estimated cost avoided, task class, and the derived value band.
  • Audit and security logs — administrative actions, policy decisions, moderation events, IP address, browser and device information, and error diagnostics.
  • Embeddings and indexes — vector representations of your knowledge sources and of verified cached answers, used for retrieval.

We do not sell personal data and we do not share it for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act, and we have not done so in the preceding twelve months. We do not use customer workspace content to train our own or any third party's models.

3. How and why we use personal data

PurposeData usedLegal basis (GDPR / UK GDPR)
Providing the workspace — resolving prompts through the answer waterfall, retrieval over your sources, generating artifactsAccount data, workspace content, embeddingsPerformance of a contract; for enterprise users, our customer's legitimate interests as controller
Receipts, ledger and analytics — measuring cost, deflection and outcome value at user, department and organization levelSession metadata (never prompt content in admin analytics)Legitimate interests in measuring and governing AI spend
Security, abuse prevention and moderationLogs, IP address, device data, flagged contentLegitimate interests; legal obligation
Billing and plan managementAccount data, usage countsPerformance of a contract
Service communications and supportAccount data, correspondencePerformance of a contract; legitimate interests
Marketing emails and product updatesName, emailConsent (opt-in), withdrawable at any time
Improving reliability and quality of the serviceAggregated and de-identified metricsLegitimate interests

Where we rely on legitimate interests we have carried out a balancing assessment; you can request a summary of it at privacy@qua.dev.

4. AI model processing and automated decisions

When a prompt cannot be answered from your own saved knowledge or your organization's verified cache, Qua sends the prompt — together with any source excerpts selected for that turn — to the model chosen for the turn. The provider that receives it is named on the receipt for that session and listed on our subprocessor page.

  • Private or unselected sources are never sent to an external provider without an explicit confirmation step in the interface.
  • Model providers act as our subprocessors and are contractually prohibited from training on inputs submitted through their APIs.
  • Answers resolved at the zero-cost tiers (Personal Knowledge and Enterprise Search) are produced inside our perimeter and are not sent to any model provider.
  • Qua does not make decisions producing legal or similarly significant effects about you through solely automated means. Routing, scoring and moderation are operational and reviewable, and every routing decision is recorded with its reason.

5. Who we share personal data with

  • Your organization. If you use Qua through an employer or other organization, its administrators can see your account details, session metadata, cost and outcome measurements, and content you save to shared or department scopes. Administrator analytics are designed around outcomes, not surveillance, and do not expose the text of your prompts.
  • Subprocessors. Hosting, database, model, retrieval and speech providers, listed in full — with location and the categories of data each receives — on the subprocessor page.
  • Professional advisers, auditors and insurers under confidentiality.
  • Authorities, where required by valid legal process. We assess every request, narrow it where we can, and notify the affected customer unless legally prohibited.
  • A successor in a merger, acquisition or asset sale, subject to this policy continuing to apply.

6. International transfers

Qua operates across the United States, the European Economic Area, the United Kingdom and India, and our processors are located in several countries. The primary application database is hosted in Australia (AWS ap-southeast-2); model inference, retrieval and speech providers are primarily in the United States.

For transfers of personal data out of the EEA or the UK we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) together with a transfer impact assessment, or on an adequacy decision where one exists.

Models processed outside the US and EU. Some open-weight models in the Open Models tier are served from mainland China or Singapore. Qua never routes to them automatically: a user must name the model explicitly, and an organization administrator can switch the tier off entirely. If your organization needs those providers excluded, disable the Open Models tier in the admin console.

7. Retention

CategoryRetention
Sessions, messages and artifactsRetained for the life of the account, or until deleted by the user or an administrator; purged within 30 days of deletion
Knowledge sources and embeddingsDeleted with the source; the derived index entry is removed in the same operation
Verified cache entriesTime-limited by task class, re-verified on a set cadence, and retired on rework or administrator action
Account recordsDeleted within 30 days of account closure, other than records we must keep
Audit, security and moderation logsUp to 24 months, then deleted or de-identified
Billing and tax recordsUp to 7 years, as required by law
BackupsRolling encrypted backups expire within 35 days; deleted data does not return to the live system

8. Your privacy rights

EEA and UK (GDPR / UK GDPR)

You have the right to access your personal data, to rectification, to erasure, to restriction of processing, to object to processing based on legitimate interests, to data portability, and to withdraw consent at any time without affecting prior processing. You may lodge a complaint with your supervisory authority, or with the UK Information Commissioner's Office.

California (CCPA/CPRA) and other US states

California residents have the right to know what personal information we collect, use and disclose; to delete it; to correct it; to opt out of sale or sharing (we do neither); and to limit the use of sensitive personal information (we do not use personal information for purposes requiring that limit). We will not discriminate against you for exercising a right. Comparable rights, including the right to appeal a denied request, are available to residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws, and we honour them for all US residents regardless of state. We recognise the Global Privacy Control signal on qua.dev.

You may use an authorised agent; we will verify the agent's authority and your identity before acting.

India (Digital Personal Data Protection Act, 2023)

Data Principals in India may request access to a summary of their personal data and our processing, correction, completion, updating and erasure, may nominate another individual to exercise rights on their behalf in the event of death or incapacity, and may raise a grievance with our Grievance Officer at grievance@qua.dev before approaching the Data Protection Board of India. We respond to grievances within 30 days.

How to exercise a right

Email privacy@qua.dev from the address on your account, or use the deletion controls in the application. We acknowledge requests within 10 days and respond within 30 days (45 days in California, extendable once where permitted, with notice). There is no charge unless a request is manifestly unfounded or excessive.

If you use Qua through an employer, send requests about workspace content to that organization; we will refer such requests to them and assist them in responding.

9. Deleting your data

  • Delete a session, artifact or knowledge source from the item's menu in the application. The record, its messages and its derived embeddings are removed immediately from the live system.
  • Delete your account by asking an organization administrator to remove you, or by emailing privacy@qua.dev. Personal data is deleted within 30 days; aggregated, de-identified cost and outcome statistics that cannot be linked back to you may remain in organization reporting.
  • Organization deletion. On termination, and at the customer's option, all workspace data is deleted or returned within 30 days, after which backups expire on the schedule above.

10. Security

We encrypt data in transit with TLS and at rest with AES-256. Access to customer data is governed by row-level security in the database, role-based access control in the application, and least-privilege administrative access with audit logging of every privileged action. Secrets are held in managed secret storage and never in source code. We maintain an incident response process and will notify affected customers without undue delay, and within 72 hours where the GDPR requires it. Report a vulnerability to security@qua.dev.

11. Cookies and similar technologies

We use strictly necessary cookies and local storage for authentication, session continuity, theme and text-size preferences, and bot mitigation on public demo forms. These are required for the service to function. We do not run advertising cookies or third-party ad trackers. Any analytics we operate are first-party and privacy-preserving. You can clear cookies and local storage in your browser at any time; signing in again will be required. Our Cookie Policy lists every item we store, the consent category it belongs to, and how to control it.

12. Children

Qua is a workplace product and is not directed to children. We do not knowingly collect personal data from anyone under 18 (or under 16 in the EEA/UK, and under 18 in India for purposes requiring verifiable parental consent). If you believe a child has provided us personal data, contact privacy@qua.dev and we will delete it.

13. Changes and contact

We will update this policy as the product and our processors change, and will post the new effective date here. Material changes are notified by email or in the application at least 14 days in advance. This policy was last updated on August 25, 2026.

Privacy enquiries: privacy@qua.dev · Data protection contact: dpo@qua.dev · Grievance Officer (India): grievance@qua.dev · Security: security@qua.dev · Legal: legal@qua.dev

See also the Terms of Service, the Data Processing Agreement and the subprocessor list.

Qua
Pioneering enterprise-scale multiplayer AI.
QUA — Quantified · Unified · Autonomy.
Try Qua·Compare·Skills·Deployment·Open the app
Privacy Policy·Terms of Service·Cookie Policy·Data Processing Agreement·Subprocessors