Privacy Policy

Last updated: 21 August 2026

1. What this covers

This policy describes what personal data Qubis OS collects when an organization and its members use the service, why, how long it is kept, and what rights a person has over it. It does not cover data a tenant chooses to connect from a third-party account (Google, Slack) beyond describing that the connection exists — that data remains subject to the third party's own terms as well as this policy.

2. What we collect

CategoryWhat, specifically
AccountEmail, name, session tokens
Organization profileOrganization name, owner name, industry, country, timezone
MembershipWhich accounts belong to which organization, and their role
Conversation contentMessages sent to Qubis OS and the memory entries derived from them — whatever a user tells the system, including anything volunteered about their business
Connector credentialsOAuth tokens for any third-party account a tenant connects, encrypted at rest
Usage and billing metadataWhich model handled a request, token counts, computed cost, which user and organization it is attributed to, timestamp
Administrative audit trailWho changed a role, invited or removed a member, erased a former member's data, or (for platform staff) looked at a tenant's account, and when
Billing linkageThe identifier Stripe assigns the organization as a customer, and the plan entitlements derived from its subscription

We do not collect payment card data at all — cards are entered on Stripe's own pages and never pass through Qubis OS; see §8.

3. Why we process it

4. Who we share it with

PartyWhat they receiveWhy
AnthropicConversation content sent as part of generating a responseQubis OS's core function runs on Anthropic's Claude models
GoogleOAuth tokens and API calls, only for a tenant that explicitly connects a Google Calendar or Gmail accountConnector the tenant chose to enable
SlackOAuth tokens and API calls, only for a tenant that explicitly connects a Slack workspaceConnector the tenant chose to enable
StripeBilling contact details, subscription and payment state, card data (entered on Stripe's pages, never seen by Qubis OS)Payment processing — see §8
Our hosting providerEncrypted data at rest, infrastructure logsRuns the servers the service is deployed on
Google (Gemini)Conversation content, for whichever requests are routed to it — no requests are routed to it todayListed so that enabling it is a policy update, not an omission

Your organization controls a per-vendor allow-list in Settings: an AI vendor you have not allowed is never sent your content. We do not sell personal data, and we do not share it for third-party advertising.

5. How it's protected

6. How long we keep it

Your organization's data is kept for as long as the organization's account exists. You do not have to wait for an expiry: an owner can delete a single memory, a former member's data, or the entire organization at any time (§7), and deletion is permanent.

7. Your rights and how to exercise them

Depending on jurisdiction, a person may have the right to access, correct, export, or delete their personal data, and to object to or restrict certain processing.

8. Payment information

Payments are processed by Stripe under its own PCI-DSS compliance. Card details are entered on Stripe-hosted pages and never pass through or rest on Qubis OS servers. What Qubis OS keeps is the linkage: the customer identifier Stripe assigns the organization, and the plan entitlements derived from its subscription. Invoice history is fetched from Stripe on demand when an authorized member views it, not stored.

9. Children

The service is intended for business use and is not directed at children.

10. Changes to this policy

We will notify tenants of material changes to this policy before they take effect.