Quiver LogoQuiver
Home/Legal/Global Privacy Policy

Global Privacy Policy

How Quiver Technologies collects, encrypts, processes, and protects your personal data, capability profiles, and client intelligence across all global jurisdictions.

Last Updated: September 5, 2026
Effective: September 5, 2026

1. Overview & Data Philosophy

Quiver Technologies Inc. ("Quiver", "we", "us") is committed to world-class data privacy, radical transparency, and strict cryptographic security.

This Global Privacy Policy explains our practices regarding data collection, processing, and protection when you use our web platform, APIs, and client outreach tools. We operate in compliance with the European General Data Protection Regulation (GDPR), the UK Data Protection Act, the California Consumer Privacy Act (CCPA / CPRA), the Canadian PIPEDA, the Brazilian LGPD, and the Australian Privacy Act.

2. Information We Collect

We collect only the minimum necessary data required to deliver our grounding and proposal generation service:

  • Account & Identity Data: Your name, work email address, hashed password, and organization affiliation.
  • Capability Profile & CV Data: Verified skill tags, past client case studies, GitHub repositories, live demo links, years of experience, work history, and communication tone notes.
  • Opportunity & Intake Text: Job post descriptions, client profiles, stated budgets, and outreach instructions pasted into our intake workbench.
  • Encrypted Provider Credentials: User-supplied API keys for third-party LLM providers (Anthropic, OpenAI, OpenRouter), which are encrypted with AES-256-GCM prior to database persistence.
  • Billing & Payment Data: Stripe Customer IDs, subscription status, and transaction receipts. Credit card details are handled directly by Stripe and are never stored on Quiver servers.
  • Technical Telemetry: Log records, latency metrics, token consumption counts, browser type, and approximate geographic location (IP-based country/region) for security rate-limiting.

3. Legal Bases & Purposes of Processing (GDPR Article 6)

We process your data under the following lawful bases:

Purpose of ProcessingCategory of DataLawful Basis (GDPR / Global)
Generating personalized, grounded proposalsProfile Data, Intake TextPerformance of Contract (Art. 6(1)(b))
Authenticating user logins & enforcing RBACAccount Credentials, JWTPerformance of Contract (Art. 6(1)(b))
Processing payments & invoicesBilling details, Stripe IDLegal Obligation & Contract (Art. 6(1)(c))
Detecting security abuse, spam & DDoSIP address, request logsLegitimate Interests (Art. 6(1)(f))
Product improvements & optional feedbackAggregated telemetryLegitimate Interests / Consent

4. AI & Zero-Training Guarantees

Quiver Zero-Training Architecture Guarantee

1. We NEVER sell your data, capability profiles, CVs, or proposals to any third party.
2. We NEVER use your proprietary information or client job posts to train, retrain, or fine-tune public foundation AI models.
3. All AI completions are executed over enterprise API integrations governed by strict Zero Data Retention and non-training contractual terms with our sub-processors.

5. Disclosures & Third-Party Sub-processors

We do not sell, rent, or trade your personal data. We disclose data solely to vetted infrastructure sub-processors necessary to run the Service:

  • Supabase Inc. — Managed PostgreSQL database, authentication, and Row Level Security isolation.
  • Stripe, Inc. — Payment gateway and subscription management.
  • Anthropic PBC / OpenAI LLC / OpenRouter — LLM inference engines (zero-training API endpoints).
  • Vercel Inc. — Edge hosting and application delivery network.

For a full, real-time list of all processors, see our Sub-processors Directory.

6. International Data Transfers

Quiver operates globally. When personal data originates in the European Economic Area (EEA), United Kingdom, or Switzerland and is transferred to servers in the United States, we ensure equivalent protection through:

  • Standard Contractual Clauses (SCCs): Incorporating the European Commission's approved Standard Contractual Clauses (Module 2 Controller-to-Processor and Module 3 Processor-to-Processor).
  • Supplementary Technical Measures: End-to-end TLS 1.3 encryption in transit, AES-256-GCM encryption at rest, and strict tenant isolation.

7. Data Retention & Account Deletion

We retain your data only for as long as your account remains active. Upon voluntary account deletion or written request to privacy@quiver.app:

  • Your capability profile, CVs, work samples, and opportunity logs are permanently purged within thirty (30) days.
  • Encrypted provider API keys are instantly wiped from the database.
  • Financial transaction records are retained solely as required by statutory tax and accounting laws (typically 7 years).

8. Security & Encryption Standards

We implement rigorous technical and organizational measures (TOMs) as detailed in our Security Overview:

  • AES-256-GCM Cryptographic Vault: LLM provider keys are encrypted with individual authenticated initialization vectors.
  • Database Multi-Tenancy (RLS): PostgreSQL Row Level Security guarantees that no organization or user can read another's records.
  • HTTP-Only Cookie Sessions: Secure, signed JWT authentication cookies protected against cross-site scripting (XSS).

9. Your European Privacy Rights (GDPR & UK GDPR)

Under GDPR Articles 15–22, European and UK residents have the following rights:

  • Right of Access: Obtain a copy of your personal data held by Quiver.
  • Right to Rectification: Correct inaccurate or incomplete capability information.
  • Right to Erasure ("Right to be Forgotten"): Request permanent deletion of all account data.
  • Right to Restriction of Processing: Restrict processing under specific circumstances.
  • Right to Data Portability: Receive your data in a structured, machine-readable JSON format.
  • Right to Object: Object to processing based on legitimate interests.
  • Right to Lodge a Complaint: File a grievance with your national Data Protection Authority (DPA) (e.g., CNIL, BfDI, ICO).

To exercise any right, email privacy@quiver.app. We respond to all verified requests within thirty (30) days with zero fee.

10. California Privacy Rights (CCPA / CPRA)

Under the California Consumer Privacy Act as amended by the CPRA:

  • Right to Know: Request disclosure of categories and specific pieces of personal information collected over the past 12 months.
  • Right to Delete & Correct: Request deletion or correction of personal information.
  • No Sale or Sharing of Personal Information: Quiver does NOT sell or share personal information for cross-context behavioral advertising.
  • Non-Discrimination: We will never discriminate against you (in pricing, access, or quality) for exercising your privacy rights.

11. Canada, Brazil & Asia-Pacific Rights

  • Canada (PIPEDA): Users may request access to and correction of their personal data under the 10 Fair Information Principles.
  • Brazil (LGPD): Brazilian residents enjoy rights of confirmation, access, anonymization, and deletion under Article 18.
  • Australia (Privacy Act 1988): We handle personal information in strict compliance with the 13 Australian Privacy Principles (APPs).
  • Japan (APPI): Data handling adheres to Act on the Protection of Personal Information principles.

12. Cookies & Telemetry

We use strictly necessary cookies for authentication, session integrity, and security rate-limiting. For full details on cookie categories and preference controls, review our Cookie Policy.

13. Children's Privacy

The Service is exclusively intended for professional business use by individuals aged 18 and older. We do not knowingly collect personal data from minors under 16. If we become aware of inadvertent collection, we will delete the data immediately.

14. Data Protection Officer & Contact

For inquiries, data subject access requests, or regulatory communications, contact:

Quiver Technologies Inc. — Data Protection Office

Email: privacy@quiver.app

DPO Direct: dpo@quiver.app

General Legal: legal@quiver.app