Privacy Policy
Version: 2026-01-01
1. Data Controller
QUID S.r.l., Via Example 1, 20100 Milano (MI), Italy.
Email: privacy@quid.app
2. Data Collected
- Account data: email address, name (optional), Google profile picture (if using OAuth).
- Content: notes, tasks, creation and modification dates.
- Technical data: IP address (anonymised — SHA-256 hash), user-agent, session tokens.
3. Legal Basis (Art. 6 GDPR)
- Art. 6.1.b — contract performance: account management, core service delivery.
- Art. 6.1.f — legitimate interest: security, abuse prevention.
- Art. 6.1.a — consent: optional marketing emails (revocable at any time).
4. Data Retention
- Active account: data retained until deletion request.
- Deleted account: all personal data purged within 30 days of the deletion request.
- Anonymised aggregate statistics (if any) may be retained indefinitely.
5. Your Rights (Arts. 15–22 GDPR)
You have the right to:
- Access your data (Art. 15)
- Rectification (Art. 16)
- Erasure ("right to be forgotten", Art. 17)
- Portability (Art. 20)
- Restriction of processing (Art. 18)
- Objection (Art. 21)
To exercise these rights, email privacy@quid.app or use the Account menu in the app.
6. Data Processors
- Convex, Inc. (USA) — database and serverless functions, under EU standard contractual clauses.
- Google LLC — only when using Google OAuth sign-in.
7. Cookies
QUID uses only essential session cookies required for the service to function. No tracking, profiling, or third-party advertising cookies are used.
8. Data Sales
Your data is never sold to third parties.
9. Contact
For any privacy-related enquiry: info@syntheticmess.xyz