Privacy Policy
Last updated 31 July 2026
This policy explains what QuillClose (“QuillClose”) collects when you use our service, why, and what control you have over it. QuillClose is the data controller for that information.
1.What we collect
Account data. Your email address. We use email sign-in links, so we never collect or store a password.
Content you create. The project notes you submit and the proposals generated from them, including client name, scope, budget and timeline as you enter them.
Billing data. If you subscribe, Stripe collects and stores your payment details. We never see or store full card numbers. We keep your Stripe customer ID, plan, subscription status and renewal date.
Usage data. Standard server logs (IP address, browser user agent, timestamps, pages requested) and, for shared proposals, a count of how many times the page was opened. We do not use third-party analytics or advertising trackers.
Cookies. Only strictly necessary ones — a session cookie that keeps you signed in. No advertising or analytics cookies, which is why you are not shown a cookie banner.
2.Why we use it, and our legal basis
- To provide the service — creating your account, generating and storing proposals, serving shared links. Basis: performance of a contract.
- To take payment — processing subscriptions and preventing payment fraud. Basis: contract and legal obligation.
- To keep the service secure and working — logging, debugging, rate limiting and abuse prevention. Basis: legitimate interests.
- To contact you about the service — sign-in links, billing notices, material changes. Basis: contract.
We do not send marketing email without your consent, and we do not sell your personal data or share it with advertisers.
3.AI processing
When you generate a proposal, the project details you entered are sent to Google’s Gemini API to produce the draft. Do not paste material you are contractually forbidden from disclosing to a third-party processor, and do not paste sensitive personal data.
We do not use your content to train AI models. Our use of the Gemini API is governed by Google’s terms for paid API services, under which submitted content is not used to improve their models.
4.Who we share it with
We use the following sub-processors. Each is bound by contract to protect your data and use it only on our instructions.
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication and file storage | Email address, account record, proposal content |
| Vercel | Application hosting and content delivery | Request logs, IP address |
| Google (Gemini API) | AI generation of proposal drafts | The project details you submit for a generation |
| Stripe | Subscription billing and payment processing | Email, billing details, payment card data (held by Stripe) |
We may also disclose data where legally required, or to establish or defend legal claims. If we are ever involved in a merger or acquisition, we will notify you before your data becomes subject to a different privacy policy.
5.International transfers
Some sub-processors are located in the United States. Where data leaves the UK or EEA, transfers are made under appropriate safeguards — typically the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.
6.How long we keep it
- Account and proposals — until you delete them, or until you close your account.
- After account deletion — removed from live systems immediately and purged from encrypted backups within 30 days.
- Billing records — retained for up to 7 years, as tax law requires.
- Server logs — typically 30 days.
7.Your rights
Depending on where you live, you have the right to access a copy of your data, correct it, delete it, restrict or object to processing, port it elsewhere, and withdraw consent where processing relies on it. If you are in California, you also have the right not to be discriminated against for exercising these rights — and note that we do not sell or share personal information as those terms are defined by the CCPA.
You can exercise most of these directly in the app: edit or delete any proposal, and delete your account. For anything else, email mohdmaahir786@gmail.com and we will respond within 30 days.
If you are in the UK or EEA and are unhappy with our response, you may complain to your local supervisory authority.
8.Security
Data is encrypted in transit (TLS) and at rest. Database access is enforced by row-level security so one account cannot read another’s data. Payment card details are handled entirely by Stripe, a PCI-DSS Level 1 provider, and never reach our servers.
No system is perfectly secure. If a breach affects your personal data and poses a risk to you, we will notify you and the relevant regulator without undue delay, and in any case within 72 hours of becoming aware.
9.Children
The service is not intended for anyone under 18 and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
10.Changes
We will update this policy as the service evolves. Material changes will be notified by email or in the app before they take effect, and the date at the top of this page will change.
11.Contact
QuillClose
1 Example Street, London, EC1A 1AA, United Kingdom
mohdmaahir786@gmail.com