Privacy Policy

Last updated: July 14, 2026

1. Data We Collect

  • Account data: email, name, workspace name.
  • Prospect data you upload: names, business emails, company info, tags.
  • Usage data: feature interactions, email delivery events (sent, bounced, replied).
  • Billing data: handled by Stripe; we store customer/subscription IDs only.

2. How We Use Data

To operate the Service, deliver outbound email on your behalf, triage replies with AI, provide analytics, prevent abuse, and comply with law. We do not sell personal data.

3. Subprocessors

  • Lovable Cloud (Supabase) — database, auth, edge functions
  • Stripe — payment processing
  • Lovable AI Gateway — model inference for AI features
  • Lovable Managed Email — transactional email delivery

4. Security

Data is encrypted in transit (TLS) and at rest. Access is scoped per workspace via row-level security. Secrets are stored in an encrypted vault.

5. Retention

We retain workspace data while your account is active and for up to 30 days after cancellation, after which it is deleted from primary systems. Backups age out within 90 days.

6. Your Rights

You may access, export, correct, or delete your data at any time. Contact hello@quotaforge.org for GDPR/CCPA requests.

7. Email Compliance

Every outbound email includes an unsubscribe link and physical sender information as required by CAN-SPAM. Suppression lists are enforced at send time.

8. Cookies

We use only strictly necessary cookies for authentication. We do not use third-party ad trackers.

9. Contact

hello@quotaforge.org