Legal
Privacy Policy
Effective September 14, 2026
This policy explains what information Quirna collects when you use the API, the Console, the mobile app, the Slack app and this website, why we collect it, who helps us process it, and how long we keep it. Words like “Service”, “Organization” and “Approval Request” mean what they mean in our Terms of Service.
1. Two roles
- For your Organization’s content (Approval Requests, decisions, the audit record, the users and Policies admins set up), your Organization decides what goes in and who can see it. We process that data on its behalf. If you are an approver, questions about why your data is there go first to your Organization’s admins.
- For our own purposes (running accounts, sign-in, security, billing, the website and waitlist), we decide how the data is used, as described below.
2. What we collect
Account and sign-in
- Email address, name and role in an Organization.
- The Organization’s name and plan.
- One-time sign-in codes, invite links and session tokens. We store only hashes of these, and they expire.
- If you sign in with Google: the email and name in the identity token Google gives us. We do not get your Google password or access to your Google account.
Approvals and the audit record
- What your systems send in an Approval Request: its kind, message, identifiers, environment, requester and the callback URL.
- Each decision: who made it, what it was and when, with Quirna’s signature over that record.
- Audit events describing what happened to each request (created, notified, reminded, decided, expired, exported) and to integrations such as Slack and webhook deliveries.
Mobile app
- A device record with a name and a push notification token, so approvals reach your phone.
- Face ID, Touch ID or your device passcode are checked by your phone’s operating system. Quirna never receives biometric data.
Slack
- When an Organization connects Slack: the workspace’s id and name, and the bot token Slack issues.
- When someone requests approval from Slack: their Slack user id and display name, the channel, and the message text used for the request.
Systems and API keys
- Names, environments and allowed kinds you give your systems, and when their keys were last used.
- We store hashes of API keys, not the keys themselves.
Website and waitlist
- If you join the waitlist: your email, and optionally your name and company.
- This website sets no cookies and uses no analytics or advertising trackers. Its fonts load from Google Fonts, which receives your IP address when the page loads.
Technical data
- IP addresses are used in memory to rate-limit sign-in and public endpoints, and pass through our network provider. Our own request logs record the path, status and timing of a request, not its body, query string or your IP address.
- The Console keeps your session and preferences in your browser’s local storage; Quirna sets no cookies. The Console’s sign-in page loads Google’s sign-in script, which Google may use to set its own cookies.
3. How we use it
- To provide the Service: route requests, notify approvers, record decisions, call your webhooks.
- To sign you in and keep accounts, keys and records secure, and to prevent abuse.
- To send service email: sign-in codes, invites and plan limit notices.
- To answer you when you write to us, and to follow up on waitlist signups.
- To meet legal obligations.
We do not sell personal data, use it for advertising, or use your Organization’s content to train machine learning models.
4. Who processes it for us
We share data only with the providers needed to run the Service:
| Provider | What for | Data involved |
|---|---|---|
| UpCloud | Servers and storage (United States) | All Service data |
| Cloudflare | DNS, TLS and network protection | Traffic to our domains, including IP addresses |
| Resend | Sending email | Recipient address and message content |
| Expo, Apple and Google | Delivering push notifications | Push token and notification text |
| Slack | The Slack integration, when an Organization connects it | Messages and user ids in that workspace |
| Sign in with Google, when you choose it; website fonts | Identity token; IP address | |
| Polar | Payments, when paid plans are offered | Billing details you give Polar |
Webhook callbacks go to the URLs your Organization configures; what happens to the data there is up to that Organization. We may also disclose data when the law requires it, or to protect the Service and its users.
5. International transfers
The Service is hosted in the United States and some providers operate in other countries. By using the Service, your data will be processed outside the country where you live.
6. How long we keep it
- Approval Requests, decisions and audit events are kept for as long as the Organization exists. They are a tamper-evident record, and removing parts of it would break that. Removing a user deletes their account, devices and sessions, but the decisions they made stay in the record with their identity.
- Sign-in codes expire after 10 minutes; invites and enroll links after 7 days.
- Sessions are deleted on sign-out or when they expire.
- Waitlist entries are kept until you ask us to remove them.
- When an Organization is closed, we delete its data from the live Service. Copies can remain in backups for a limited period before they are overwritten.
7. Your choices and rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, or to object to or restrict how we use it. Write to [email protected] and we will respond within 30 days.
For data inside an Organization, we will usually involve its admins, since they control it. Deletion requests are limited by section 6: we can remove your account, but not rewrite decisions already in an Organization’s record. You can also complain to your local data protection authority.
8. Security
Traffic is encrypted in transit. Codes, session tokens and API keys are stored as hashes. Decisions are signed so changes can be detected. Access to production is limited to the people who operate the Service. No system is perfectly secure; if a breach affects your data, we will tell you as the law requires.
9. Children
The Service is for work use and is not directed at anyone under 18.
10. Changes
We will update the date at the top when this policy changes, and tell admins by email or in the Console before material changes take effect.
11. Contact
Privacy questions and requests: [email protected].