Privacy Policy
Last updated: 21 August 2026
1. What this covers
This policy describes what personal data Qubis OS collects when an organization and its members use the service, why, how long it is kept, and what rights a person has over it. It does not cover data a tenant chooses to connect from a third-party account (Google, Slack) beyond describing that the connection exists — that data remains subject to the third party's own terms as well as this policy.
2. What we collect
| Category | What, specifically |
|---|---|
| Account | Email, name, session tokens |
| Organization profile | Organization name, owner name, industry, country, timezone |
| Membership | Which accounts belong to which organization, and their role |
| Conversation content | Messages sent to Qubis OS and the memory entries derived from them — whatever a user tells the system, including anything volunteered about their business |
| Connector credentials | OAuth tokens for any third-party account a tenant connects, encrypted at rest |
| Usage and billing metadata | Which model handled a request, token counts, computed cost, which user and organization it is attributed to, timestamp |
| Administrative audit trail | Who changed a role, invited or removed a member, erased a former member's data, or (for platform staff) looked at a tenant's account, and when |
| Billing linkage | The identifier Stripe assigns the organization as a customer, and the plan entitlements derived from its subscription |
We do not collect payment card data at all — cards are entered on Stripe's own pages and never pass through Qubis OS; see §8.
3. Why we process it
- Account and organization data: necessary to provide the service the tenant signed up for.
- Conversation content and memory: necessary to provide Qubis OS's core function — an assistant that remembers context across conversations. A tenant that does not want a fact remembered can delete the relevant memory entry through the product; see §7.
- Connector credentials: necessary to perform the actions a tenant explicitly asked a connector to do, never collected without the tenant initiating the connection itself.
- Usage and billing metadata: necessary to operate cost controls and billing.
- Administrative audit trail: so that who did what inside a shared tenant — including platform staff's own access — is accountable rather than invisible.
4. Who we share it with
| Party | What they receive | Why |
|---|---|---|
| Anthropic | Conversation content sent as part of generating a response | Qubis OS's core function runs on Anthropic's Claude models |
| OAuth tokens and API calls, only for a tenant that explicitly connects a Google Calendar or Gmail account | Connector the tenant chose to enable | |
| Slack | OAuth tokens and API calls, only for a tenant that explicitly connects a Slack workspace | Connector the tenant chose to enable |
| Stripe | Billing contact details, subscription and payment state, card data (entered on Stripe's pages, never seen by Qubis OS) | Payment processing — see §8 |
| Our hosting provider | Encrypted data at rest, infrastructure logs | Runs the servers the service is deployed on |
| Google (Gemini) | Conversation content, for whichever requests are routed to it — no requests are routed to it today | Listed so that enabling it is a policy update, not an omission |
Your organization controls a per-vendor allow-list in Settings: an AI vendor you have not allowed is never sent your content. We do not sell personal data, and we do not share it for third-party advertising.
5. How it's protected
- Tenant isolation: every tenant's data is scoped by row-level security enforced at the database layer, not only in application code — the database itself refuses a query that crosses the tenant boundary.
- Connector credentials are encrypted at rest before being written to the database, under a key that is never stored in the database itself.
- Administrative access is audited: a platform-level support account looking at a tenant's data writes an audit record before the read completes.
- Encryption in transit: the hosted service is reached over HTTPS.
6. How long we keep it
Your organization's data is kept for as long as the organization's account exists. You do not have to wait for an expiry: an owner can delete a single memory, a former member's data, or the entire organization at any time (§7), and deletion is permanent.
7. Your rights and how to exercise them
Depending on jurisdiction, a person may have the right to access, correct, export, or delete their personal data, and to object to or restrict certain processing.
- Deleting your organization removes the organization and everything scoped to it — members, conversations, memory, connectors, credentials, usage history — in one action, available to the organization's owner.
- Deleting a specific memory is available from within the product.
- Deleting one person's data while the organization and its other members continue is available on request to the organization's owner, works whether or not the person is still a member, and leaves a pseudonymized record in the audit trail. Removing a member does not trigger it automatically: leaving a team and asking for erasure are different decisions, and the second is never implied by the first.
- Data export is available to an organization's owner — one archive with the organization's messages, current memory, and model-usage history.
- Deleting your individual account while leaving an organization you don't own intact is not yet self-service — ask your organization's owner to raise it with us.
8. Payment information
Payments are processed by Stripe under its own PCI-DSS compliance. Card details are entered on Stripe-hosted pages and never pass through or rest on Qubis OS servers. What Qubis OS keeps is the linkage: the customer identifier Stripe assigns the organization, and the plan entitlements derived from its subscription. Invoice history is fetched from Stripe on demand when an authorized member views it, not stored.
9. Children
The service is intended for business use and is not directed at children.
10. Changes to this policy
We will notify tenants of material changes to this policy before they take effect.