Privacy Policy.
We built Quorum so we would not need to see your data — it lives on your machine. This policy spells out exactly what we do and do not collect.
⌘⇧N).1. Who we are
LiC Company sp. z o.o. (operating the Quorum brand), Warsaw, Poland. Polish company, KRS 0001207472, VAT PL9592088245. Data controller for the purposes of GDPR.
Contact: [email protected]. Security: [email protected].
2. What data we collect
From your account (only if you have one)
- Email address (required for account, license, support)
- Billing details (only when you upgrade to Pro/Team — processed by Stripe, not stored on our servers)
- Country and VAT ID (for invoicing within EU)
From the app on your machine
- Update checks: once per hour, the app makes a
HEADrequest toreleases.quorumkairos.ai. We see your IP and version. We do not log this beyond what is necessary for rate-limiting (24-hour retention). - License validation: once per launch, if you have a Pro/Team license, the app validates the license key with our server. Same IP/version pattern, same retention.
- Anonymous opt-in telemetry: if you explicitly enable it during onboarding, we collect anonymized event names (e.g.
terminal_opened,agent_launched) — never content, never identifiers. Off by default.
What we never collect
- Your code, ever
- Your prompts, your AI responses, or your chat history
- Your AI provider API keys (stored in macOS Keychain locally)
- Your Git history, branches, or commit messages
- Your terminal session content
- Device fingerprinting (analytics and ad tags load only with your consent — see §8)
3. Legal basis (GDPR)
- Contract: processing email + license data is necessary to provide you the service you bought (Art. 6(1)(b) GDPR).
- Legitimate interest: update checks and license validation are necessary for software integrity (Art. 6(1)(f)).
- Consent: optional analytics, marketing emails, and advertising measurement — including server-side conversion tracking that shares a hashed (SHA-256) email and ad-click identifiers with Google and Meta — only with your explicit opt-in via the cookie banner (Art. 6(1)(a)).
4. Sub-processors
We use minimal third-party processors:
- Stripe (payments) — Ireland, GDPR-compliant
- Cloudflare (CDN for downloads + landing, bot protection) — global, GDPR-aligned
- MailerLite (newsletter + waitlist emails) — EU (Lithuania), GDPR-compliant
- Google (Analytics 4 + Google Ads conversion measurement) — US, SCCs + Google Ads Data Processing Terms
- Meta (Conversions API, advertising — optional) — US, SCCs
- Server-side GTM — self-hosted on our own EU infrastructure (an
sgtmsubdomain, rolling out); the gateway that forwards consented conversion events to Google/Meta - Account database & transactional email — EU-hosted providers; final selection is being completed and this list will be updated before those services go live
Full sub-processor list with DPA on request to [email protected].
5. Data retention
- Account data: kept as long as your account is active, then 6 months after closure (for audit), then deleted.
- Update check logs: 24 hours, then deleted.
- Anonymized telemetry (if opted in): 90 days rolling, then aggregated and deidentified.
- Marketing attribution + ad consent (ad-click ids, GA client id, consent state): kept while your account is active, deleted with the account.
- Billing records: 5 years (Polish tax law requires this).
6. Your rights
Under GDPR, you have the right to:
- Access the data we hold about you
- Correct it if wrong
- Delete it ("right to be forgotten") — we honor within 14 days
- Export it in machine-readable format
- Object to processing
- Lodge a complaint with the Polish DPA (UODO)
Email [email protected] for any of these.
7. International transfers
Most processors are EU-based. Where data flows outside EU (e.g. Google in the US), we rely on Standard Contractual Clauses (SCCs) and supplementary measures per the EDPB recommendations.
8. Cookies and analytics
We use Google Consent Mode v2: by default no analytics or advertising cookies are set. The cookie banner lets you accept or reject Functional, Analytics, and Advertising independently; quorum.consent stores your choice and quorum_region your consent region. Strictly-necessary cookies set by our CDN Cloudflare (__cf_bm, cf_clearance) keep the service secure and need no consent. With your consent we load Google Tag Manager and set first-party Google cookies (_ga, _ga_*, _gid, _gcl*). The full per-category cookie list, with purposes and expiries, is in the banner's "Customize" view.
Server-side conversions. If you consent to advertising, when you reach a key milestone (start a trial, subscribe) our server sends that conversion to Google/Meta through our self-hosted server-side GTM — including a hashed (SHA-256) email and your ad-click identifier (gclid) so the ad platforms can measure which campaigns work. Without advertising consent we send no personal identifiers. You can revoke consent any time via the footer "Privacy" link; we then stop sharing further conversions.
9. Changes to this policy
We will notify you by email at least 30 days before any material change. Minor edits (typos, clarifications) we publish without notice, with a changelog at the bottom.
10. Contact
Privacy queries: [email protected]
Security issues: [email protected]
General: [email protected]
Changelog
2026-05-23 — Initial version.
2026-06-16 — Added GA4 / Google Ads / Meta and consent-gated server-side conversion tracking; updated sub-processors (§4), retention (§5), and cookies (§8).
2026-07-06 — Updated company details (§1) and sub-processor list (§4).