Privacy Policy
Effective Date: February 8, 2026 · Last Updated: August 6, 2026
Quantrolix ("we," "us," or "our"), operated by Dustin Newcomb, provides a suite of applications and services (collectively, the "Services"). This Privacy Policy describes how we collect, use, store, share, and protect your personal information when you use any Quantrolix application or visit our websites.
This is a unified privacy policy that applies to all 23 applications in the Quantrolix ecosystem. Certain applications collect specialized data categories and are subject to additional protections. Please review the App-Specific Data Schedules (Section 12) for the applications you use.
Covered Applications: EmberPOS, Grocery Optimizer, Tea Effects, Terpa, YieldVault, PhantomCast, Bourbon Hunter, MenuMentor, Kasa Controller, CouplesCare, MotionForge, Nexus 3D Maps, Qode IDE, Architect 3D, Quantrolix Launcher, Quantrolix SaaS, Comm Hub, Clausely, ML Service, Quantrolix Market Pulse, VacancyFox, BuildHound, and the Quantrolix Landing website.
1. Information We Collect
1.1 Information You Provide Directly
- Account Information: Name, email address, and password when you create an account in an applicable Quantrolix application. Some applications use our centralized Auth Gateway; VacancyFox uses its own application account and authentication flow.
- Profile Information: Optional details such as business name, dietary preferences, health goals, farming data, or other profile data specific to each application.
- Payment Information: When you subscribe to paid tiers, payment processing is handled exclusively by Stripe or Apple In-App Purchase. We do not store, process, or transmit your full credit card number, CVV, or bank account details on our servers.
- User Content: Data you create within our applications, such as POS transactions, recipes, tea blends, investment portfolios, code files, 3D models, relationship wellness entries, or other content.
- Communications: Messages you send to us via email, in-app feedback, or support requests.
- Health and Wellness Data: Self-reported dietary information, mood tracking, supplement effects, relationship wellness entries, and nutritional goals when you choose to use health-related features in Grocery Optimizer, Tea Effects, or CouplesCare.
1.2 Information Collected Automatically
- Usage Data: Where a participating application collects it, feature usage, session duration, interaction patterns, and navigation paths used to operate or improve that application. See the applicable App-Specific Data Schedule; Market Pulse does not collect analytics or tracking data in its current iOS app.
- Device Information: Participating applications may collect operating system, app version, device model, screen resolution, and unique device identifiers as described in their applicable App-Specific Data Schedule. Market Pulse does not collect device information or unique device identifiers in its current iOS app.
- Crash Reports: Participating applications may collect error logs and crash data to diagnose and fix issues, as described in their applicable App-Specific Data Schedule. Market Pulse does not collect crash reports or usage diagnostics in its current iOS app. Terpa sends Apple MetricKit crash reports only—not hang or performance diagnostics—together with app version/build and a random event identifier. Reports are sent without Terpa account credentials, and no user ID or IP address is stored with the crash receipt. Participating apps may use Sentry, with PII scrubbed before transmission.
- Log Data: Where edge, API, or service logging is enabled, standard request metadata such as IP address, request timestamp and path, and user agent where logged may be recorded for security, rate limiting, and operations. This is distinct from in-app analytics or tracking; see the applicable App-Specific Data Schedule.
- Local Network Data: Kasa Controller and PhantomCast perform local network discovery (mDNS/SSDP) to find compatible devices. This data remains on your local device and is not transmitted to our servers.
1.3 Information from Third Parties
- Grocery & Retail Data: When you use integrations with Instacart, Walmart, or other retail services through Grocery Optimizer, we receive product availability and pricing data on your behalf. This occurs only at your explicit request.
- Streaming Metadata: When you use PhantomCast, we receive content metadata from streaming services you connect to facilitate casting.
- Apple App Store: Apple may share aggregated analytics data about your app usage under its own privacy framework.
- Stripe: Stripe shares subscription status and billing event data (but not payment card details) to manage your subscriptions.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Provide and operate the Services: Deliver core functionality, manage your account, process transactions, and maintain service availability.
- Personalize your experience: Generate AI-powered recommendations (e.g., meal plans in Grocery Optimizer, tea blends in Tea Effects, yield projections in YieldVault). Data supplied to an AI provider depends on the feature and application; see the applicable App-Specific Data Schedule. For example, VacancyFox sends property facts supplied for a user-requested listing-content generation to its configured AI Gateway.
- Improve the Services: For applications that collect usage data, analyze trends and patterns in aggregated, anonymized form to improve features and fix issues.
- Process payments: Manage subscriptions, billing cycles, and payment failures through our payment processors.
- Communicate with you: Send service notifications, security alerts, subscription confirmations, and support responses. We do not send marketing emails unless you opt in.
- Ensure security: Detect, prevent, and address fraud, abuse, unauthorized access, and technical issues.
- Train machine learning models: Our ML Service uses anonymized, aggregated data to improve recommendation accuracy. No PII is used in model training. You may opt out of anonymized data inclusion.
- Comply with legal obligations: Respond to legal processes and enforce our Terms of Service.
3. Legal Bases for Processing
We process your personal data under one or more of the following legal bases:
| Legal Basis | Applies To |
|---|---|
| Contract Performance | Providing the Services you signed up for, managing your account, processing subscriptions |
| Consent | Health and wellness data processing, optional AI recommendations, marketing communications, cookies |
| Legitimate Interest | Service improvement for applications that collect analytics, fraud prevention, security monitoring, bug fixing |
| Legal Obligation | Tax record retention, responding to lawful data requests, DMCA compliance |
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out prior to withdrawal.
4. Data Storage & Security
Your data is stored on our self-hosted infrastructure located in the United States (Contabo Cloud VPS). We use PostgreSQL databases for persistent storage and Redis for temporary caching and session management.
Security Measures
- Encryption in Transit: All connections use HTTPS/TLS 1.2+ encryption. No unencrypted HTTP connections are accepted.
- Encryption at Rest: Database storage is encrypted. CouplesCare data receives an additional application-level encryption layer.
- Password Security: All passwords are hashed and salted using bcrypt with a minimum cost factor of 10.
- Authentication: Authentication is implemented per application. VacancyFox uses application-local registration and login routes with bcrypt password hashing and JWT tokens; see the applicable App-Specific Data Schedule for that application's implementation.
- Access Controls: Role-based access controls (RBAC) limit data access to authorized personnel and services.
- Monitoring: Participating apps use Sentry error monitoring with PII scrubbing; Terpa uses anonymous Apple MetricKit crash diagnostics. Server-level logging is used for security event detection.
- Dependency Management: Regular security audits and automated dependency updates to patch known vulnerabilities.
- Payment Isolation: All payment card processing is fully delegated to PCI Level 1 certified processors (Stripe). Cardholder data never touches our servers.
While we implement industry-standard security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security. If we become aware of a security breach affecting your personal data, we will notify you and applicable regulatory authorities as required by law.
5. Data Sharing & Third Parties
We share your information only in the following limited circumstances:
| Third Party | Purpose | Data Shared | Applicable Apps |
|---|---|---|---|
| Stripe | Payment processing | Email, subscription status, billing events | EmberPOS, YieldVault, Grocery Optimizer, Tea Effects, PhantomCast, VacancyFox |
| Apple (App Store / TestFlight) | App distribution, In-App Purchase, reviews | Purchase receipts and, where Apple provides them, aggregated app analytics under Apple's privacy framework | iOS/macOS apps, subject to the applicable App-Specific Data Schedule |
| Sentry | Error & crash reporting | Device info, error traces, stack traces (PII scrubbed) | Participating apps; Terpa does not use Sentry for crash reporting |
| Instacart / Walmart APIs | Grocery price comparison & ordering | Shopping list items (user-initiated only) | Grocery Optimizer |
| Groq / Ollama (AI providers) | AI-powered recommendations and document analysis | For most apps, anonymized prompts containing no personal data. Clausely is an exception: the text of a contract you upload is transmitted for analysis, and that text may contain personal data written in the document (such as names, property addresses, prices and dates). Clausely asks for your permission in the app before any contract text is sent, and you can withdraw that permission at any time. Groq does not retain inference inputs and outputs by default, but may temporarily log them for up to 30 days to troubleshoot reliability issues or investigate suspected abuse unless zero-data-retention controls are enabled. Groq does not use the contract text to train models. CouplesCare is a second exception: the message text a user types to the AI therapist is transmitted to generate the reply, and that text may contain personal information about the user's relationship. CouplesCare asks for permission in the app before any message is sent and the permission can be withdrawn at any time. | Apps that use those providers; Clausely for contract text |
| VacancyFox AI Gateway | User-requested listing-content generation | Property details supplied for the requested generation | VacancyFox |
| Resend | Transactional lead-notification email when configured | Lead contact details and message, property title, and landlord email | VacancyFox |
| Twilio | Optional lead-notification SMS when configured | Landlord phone number, property title, and lead contact details | VacancyFox |
We may also share information when:
- Required by law: In response to a subpoena, court order, or government request.
- Protecting rights: To protect the rights, property, or safety of Quantrolix, our users, or the public.
- Business transfers: In connection with a merger, acquisition, or sale of assets, in which case you will be notified of any change in data controller.
- With your consent: When you explicitly direct us to share data with a third party.
5.1 Equal Protection by Third Parties
Every third party with whom we share user data is required to provide the same or equal protection of that data as is stated in this Privacy Policy. We share personal data only with service providers acting on our instructions, and only under terms that require them to:
- use the data solely to perform the service we requested, and for no independent purpose of their own;
- apply security safeguards at least equivalent to those described in Section 4 of this policy;
- not sell, rent, or otherwise disclose the data, and not use it to train or improve their own models;
- retain the data no longer than needed for that service, and delete or return it on our instruction;
- support the data-subject rights described in Sections 7 and 13, including access and deletion requests we pass through to them.
This applies to the AI inference providers listed above. In particular, contract text that Clausely sends to Groq, Inc. after you grant the in-app permission is processed only to return your analysis: Groq does not use it to train models, does not retain inference inputs and outputs by default, and may temporarily log them for up to 30 days only to troubleshoot reliability issues or investigate suspected abuse. If a provider cannot meet these commitments, we do not send user data to it.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide Services. Our specific retention periods are:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account data (name, email) | Until account deletion | Service delivery |
| Transaction records (EmberPOS) | 7 years | Tax and legal compliance |
| Financial records (YieldVault) | 7 years | Tax and legal compliance |
| Health & wellness data (CouplesCare) | Auto-deleted after 90 days of inactivity | Sensitive data protection |
| Health & dietary data (Grocery Optimizer, Tea Effects) | Until account deletion or manual removal | Service delivery; deletable at any time |
| Crash reports | Sentry reports and Terpa anonymous MetricKit crash records: up to 90 days | Bug diagnosis |
| Usage analytics (where collected) | Aggregated and anonymized after 12 months | Service improvement |
| Edge, API, and service request logs (where logging is enabled) | Service-specific operational retention and applicable legal requirements | Security, rate limiting, and operations |
| Redis cache data | 24 hours maximum | Performance optimization |
| AI model training data | Anonymized; no PII retained | Model improvement |
Account-deletion handling follows the implementation and retention requirements of the application that holds the account; see the applicable App-Specific Data Schedule. For example, VacancyFox confirms cancellation of an active Stripe subscription before deleting that account, then removes the account's related records through its local cascade relationships and attempts to remove that account's stored photo and video outputs. See Section 13 for details on the deletion process.
7. Your Rights (All Users)
Regardless of where you are located, we provide the following rights to all Quantrolix users:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Deletion: Request deletion of your personal data ("right to be forgotten"). We process deletion according to the applicable application's implementation and any legal retention requirements.
- Right to Data Portability: Export your data in a machine-readable format (JSON). Available via in-app settings or by contacting us.
- Right to Restrict Processing: Request that we limit how we use your data.
- Right to Object: Object to processing based on legitimate interests.
- Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time.
- Right to Non-Discrimination: We will not treat you differently for exercising your privacy rights.
To exercise any of these rights, please contact us at privacy@quantrolix.com or submit a request at apps.quantrolix.com/privacy/request. We will verify your identity and respond within 30 days (or 45 days for complex requests, with notice).
8. California Residents (CCPA/CPRA)
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
8.1 Categories of Personal Information Collected
| Category (per CCPA) | Examples | Collected? |
|---|---|---|
| A. Identifiers | Name, email, IP address, device ID | Yes — only for applicable applications and web services; see App-Specific Data Schedules |
| B. Customer records | Billing info (via Stripe), account data | Yes |
| C. Protected classifications | N/A | No |
| D. Commercial information | Purchase history, subscription tiers | Yes |
| E. Biometric information | N/A | No |
| F. Internet activity | Usage data, feature interactions, crash logs | Yes — only for applicable applications and web services; see App-Specific Data Schedules |
| G. Geolocation | IP-derived approximate location (not precise GPS) | Yes — only for applicable web services and applications; see App-Specific Data Schedules |
| H. Sensory data | N/A | No |
| I. Professional/employment | Business name (EmberPOS, YieldVault) | Yes (optional) |
| J. Education information | N/A | No |
| K. Inferences | AI-generated recommendations, macro predictions | Yes |
| L. Sensitive personal info | Health data (CouplesCare, Grocery, Tea Effects) | Yes (with consent) |
8.2 Your CCPA/CPRA Rights
- Right to Know: You may request the categories and specific pieces of personal information we have collected about you in the past 12 months, the sources, the business purpose, and the third parties with whom we shared it.
- Right to Delete: You may request deletion of your personal information, subject to legal exceptions (e.g., tax records).
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: We do not sell or share (as defined by the CCPA/CPRA) personal information for cross-context behavioral advertising. There is no need to opt out.
- Right to Limit Use of Sensitive Personal Information: You may limit our use of sensitive personal information (health data) to what is necessary for the Services.
- Non-Discrimination: We will not deny services, charge different prices, or provide a different quality of service because you exercised your CCPA rights.
To submit a CCPA/CPRA request, email privacy@quantrolix.com with the subject line "CCPA Request." We will verify your identity and respond within 45 days.
Authorized Agents: You may designate an authorized agent to submit requests on your behalf. We will require verification of both the agent's authority and your identity.
9. European Residents (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional protections under the General Data Protection Regulation (GDPR):
9.1 Data Controller
The data controller is Quantrolix, operated by Dustin Newcomb, based in Scottsdale, Arizona, USA. For all GDPR inquiries, contact our Data Protection Contact at privacy@quantrolix.com.
9.2 Your GDPR Rights
In addition to the rights listed in Section 7, GDPR provides you with:
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority if you believe your data has been processed unlawfully.
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format (JSON) and transmit it to another controller.
- Right to Object to Automated Decision-Making: You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significant effects. Our AI recommendations are supplementary and do not constitute sole automated decision-making.
9.3 Lawful Bases
We process personal data under the lawful bases described in Section 3. For health and wellness data (CouplesCare, Grocery Optimizer, Tea Effects), we rely on your explicit consent, which you may withdraw at any time.
9.4 Data Processing Records
We maintain records of processing activities as required under Article 30 of the GDPR. These records are available upon request to supervisory authorities.
10. International Data Transfers
Our servers are located in the United States. If you access our Services from outside the United States, your data will be transferred to and processed in the United States.
We rely on the following legal mechanisms for cross-border data transfers:
- Standard Contractual Clauses (SCCs): For transfers from the EEA/UK to the United States, we rely on the European Commission's Standard Contractual Clauses.
- Consent: By using our Services, you consent to the transfer of your data to the United States.
- Adequacy Decisions: Where applicable, we rely on adequacy decisions issued by the European Commission.
Our third-party processors (Stripe, Sentry, Apple) maintain their own international data transfer mechanisms and certifications.
11. Children's Privacy
Our Services are not directed to children under 13 years of age (or under 16 in the EEA). We do not knowingly collect personal information from children under these age thresholds.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us at privacy@quantrolix.com. We will promptly investigate and delete such data.
CouplesCare, which handles sensitive relationship wellness data, requires users to be at least 18 years old.
12. App-Specific Data Schedules
The following sections describe the specific data practices for each application in the Quantrolix ecosystem. Each application inherits the general policies described above and adds the application-specific practices below.
EmberPOS Payment Data · PCI-DSS
Category: Business / Point of Sale
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Business name & location | Yes | Account setup, multi-location management | None |
| Employee names & roles | Yes | Staff management, role-based POS access | None |
| Transaction data (items, totals, timestamps) | Yes | POS operations, reporting, analytics | None |
| Menu items & pricing | Yes | POS operations | None |
| Payment card data | No | N/A - handled entirely by Stripe | Stripe (PCI L1) |
| Customer tip data | Yes | Tip distribution, reporting | None |
Grocery Optimizer Health & Dietary Data
Category: Health / Nutrition / Consumer
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Dietary preferences & allergies | Yes | Meal planning, allergen filtering | None |
| Nutritional goals & macro targets | Yes | AI macro optimization | Anonymized to AI provider |
| Medication names (optional) | Yes (opt-in) | Food-drug interaction warnings | None |
| Shopping lists | Yes | Price comparison, ordering | Instacart/Walmart (user-initiated) |
| Meal plans & recipes | Yes | Meal planning features | None |
| Purchase history | Yes | Price tracking, budget optimization | None |
You may delete all dietary and health data at any time from your profile settings without deleting your entire account.
Tea Effects Health & Supplement Data
Category: Health / Wellness / Consumer
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Health goals | Yes | Personalized tea recommendations | Anonymized to AI provider |
| Tea preferences & history | Yes | Recommendation engine | Anonymized to AI provider |
| Self-reported effects (mood, energy, sleep) | Yes | Effect tracking, pattern analysis | None |
| Caffeine sensitivity (optional) | Yes (opt-in) | Caffeinated tea filtering | None |
Terpa Grow Tracking & Diagnostics
Category: Productivity / Cultivation Tracking
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Account data (name, email, user ID) | Yes | Account access and cloud synchronization | None |
| Grow, plant, task, and journal records | Yes | Grow tracking, analytics, and exports | None |
| Plant photos and related metadata | Yes | Photo logs and user-requested diagnostics | AI provider only when the user requests analysis |
| Subscription status and receipt metadata | Yes | StoreKit entitlement verification | Apple |
| Apple MetricKit crash reports, app version/build, and random event ID | Yes | Crash diagnosis and app reliability | None |
Terpa sends crash diagnostics without Terpa account credentials and stores no user ID or IP address with the crash receipt. It accepts crash diagnostics only, not hang or performance diagnostics. Anonymous crash records are automatically deleted after 90 days. Account-associated grow records and media are retained while your account is active and are deleted when you delete your account.
CouplesCare Sensitive Health Data
Category: Health / Relationship Wellness
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Relationship wellness entries | Yes | Wellness tracking, pattern identification | None - never shared |
| Mood & emotional state tracking | Yes | Mood pattern analysis | None - never shared |
| Communication exercise responses | Yes | Guided exercises, progress tracking | None - never shared |
| Conflict resolution entries | Yes | Exercise completion tracking | None - never shared |
| AI therapist messages (the text you type) | Yes | Generate the AI therapist's reply | Groq, Inc. — only where the device cannot run the on-device model, and only after you allow it in the app |
Enhanced protections for CouplesCare data:
- All CouplesCare data is encrypted at rest with an additional application-level encryption layer beyond standard database encryption.
- CouplesCare wellness data — relationship entries, mood tracking, exercise responses and conflict-resolution entries — is never shared with any third party, including AI providers, and does not leave our servers. The single exception is the AI therapist conversation described in the table above: with your permission, the message text you type to the AI therapist is sent to Groq, Inc. to generate the reply. Permission is requested before the first message is sent, is never assumed, and can be withdrawn at any time from the therapist screen.
- Sensitive entries are automatically deleted after 90 days of account inactivity.
- Users must be at least 18 years old to use CouplesCare.
- CouplesCare data is stored in an isolated database partition.
PhantomCast Streaming & DMCA
Category: Streaming / Media
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Streaming session metadata (titles, timestamps) | Yes | Session management, history | None |
| Device identifiers (casting targets) | Yes (local) | Device discovery and pairing | None - stays on device |
| Content preferences | Yes | Content organization | None |
| Network scan results (mDNS/SSDP) | Local only | Discover Roku and casting devices | None - stays on device |
| Actual media content | No | N/A | N/A |
YieldVault Financial Data
Category: Business / Agriculture / Financial
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Farm/business information | Yes | Account setup, multi-farm management | None |
| Crop data (types, acreage, yields) | Yes | Yield analysis, predictions | Anonymized to AI provider |
| Financial projections & revenue data | Yes | Financial analysis, forecasting | None |
| Historical yield records | Yes | Trend analysis, benchmarking | None |
Quantrolix Market Pulse Decision Support
Category: Market analysis / decision support
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Account IDs, broker, order, and payment data | No | N/A | N/A |
| Market/reference request parameters | Yes, when you request analysis | Retrieve public market analysis and reference data | Quantrolix-hosted edge/API |
| Standard public API edge/service request metadata (IP address; request timestamp, path, and user agent where logged) | Yes, when you use the public API | Security, rate limiting, and operations | Quantrolix-hosted edge/API |
| Journal entries and selected API-base setting | Local only | Personal journal and app configuration | None |
| Device identifiers, crash diagnostics, app analytics, or tracking data | No | N/A | N/A |
Market Pulse has no account system, brokerage connection, order-execution, or money-movement feature. Its public, unauthenticated analysis and reference-data requests, including read-only GET requests, may generate the standard request logs described above. Its journal and API-base preference are stored in your device's localStorage; they are not synchronized to a Market Pulse account.
Kasa Controller Smart Home · Network Scanning
Category: Smart Home / IoT
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Local network scan results | Local only | Discover TP-Link Kasa devices | None - stays on device |
| Device names & states | Local cache | Display and control devices | None - stays on device |
| Device IP addresses (local network) | Local only | Direct device communication | None - stays on device |
| Automation schedules | Local only | Scheduled device actions | None - stays on device |
Bourbon Hunter General
Category: Lifestyle / Collection Management
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Whiskey collection data | Yes | Collection management | None |
| Tasting notes & ratings | Yes | Personal tasting journal | None |
| Wishlist items | Yes | Wishlist management, availability alerts | None |
| Approximate location (optional) | Opt-in only | Nearby store availability | None |
Location data is only collected if you explicitly opt in to the nearby store availability feature. You may disable location access at any time in your device settings.
MenuMentor General
Category: Restaurant / Business
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Menu items & descriptions | Yes | Menu analysis, optimization suggestions | Anonymized to AI provider |
| Pricing data | Yes | Price optimization, competitor analysis | None |
| Restaurant category/type | Yes | Industry-specific recommendations | None |
MotionForge Creative Tool
Category: Creative / Video Production
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Project files & compositions | Yes (local + cloud sync) | Video/motion graphics creation | None |
| Asset library metadata | Yes | Asset management | None |
| Export settings & preferences | Yes | Workflow optimization | None |
MotionForge project files are stored locally on your device. Cloud sync, when enabled, stores project metadata on our servers. Actual media assets remain on your device unless you explicitly upload them.
Nexus 3D Maps Creative Tool
Category: Mapping / Visualization
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Map projects & layers | Yes (local) | 3D map creation and editing | None |
| Geographic coordinates (user-entered) | Yes | Map positioning and rendering | None |
| Custom markers & annotations | Yes (local) | Map customization | None |
Nexus 3D Maps operates primarily on local data. Map projects are stored on your device. No location tracking of your physical location occurs.
Qode IDE Developer Tool
Category: Development / IDE
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Code files & projects | Local only | Code editing | None |
| Editor preferences & settings | Yes (local + sync) | Personalized development environment | None |
| AI code completion prompts | Yes (when feature used) | AI-assisted coding | Anonymized to AI provider |
| Extension data | Yes (local) | Extension functionality | None |
Your source code files remain on your local device and are never uploaded to our servers unless you explicitly use cloud sync features. AI code completion sends only the relevant code context (anonymized, without file paths or project names) to generate suggestions.
Architect 3D Creative Tool
Category: Architecture / 3D Modeling
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| 3D model files & projects | Local + optional cloud | Architectural modeling | None |
| Measurement & dimension data | Yes (within projects) | Precise architectural rendering | None |
| Material & texture libraries | Yes (local) | Design asset management | None |
Architect 3D project files are stored locally by default. Cloud backup is optional and encrypted in transit and at rest.
Clausely Productivity Tool
Category: Document Analysis / Legal
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Uploaded documents for analysis | Yes (stored by Quantrolix; sent to Groq only after in-app permission) | Clause extraction, contract analysis, and review history | Quantrolix servers and Groq, Inc. (AI inference provider); contract text may include personal data written in the document |
| Analysis results & annotations | Yes | Document review history | None |
| User preferences & templates | Yes | Personalized analysis | None |
Clausely stores uploaded documents, extracted contract text, and analysis results on Quantrolix servers so the contract and its review history remain available in the app. Contract text is sent to Groq, Inc. only after you grant the in-app permission described above; it is not guaranteed to be anonymized and may contain personal data written in the document. Groq does not retain inference inputs and outputs by default, but may temporarily log them for up to 30 days to troubleshoot reliability issues or investigate suspected abuse unless zero-data-retention controls are enabled. Groq does not use contract text to train models. You may withdraw AI permission in the app to stop future AI transmissions. To request deletion of stored Clausely documents or account data, use the contact methods in Section 13.
Quantrolix Launcher General
Category: Utility / App Management
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Installed app list | Yes (local) | App launch management | None |
| App usage frequency | Yes (local) | Quick-launch ordering | None |
| Update check requests | Yes | Keep apps up to date | Our update server only |
The Launcher is a utility application that primarily stores data locally. Update check requests transmit only the app version number and platform to our update server.
VacancyFox Rental Listing & Lead Management
Category: Rental listing / landlord workflow
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Account, contact, and authentication data | Yes | Create and secure a landlord account; sign in and manage account settings | None |
| Property/listing details, generated content, photos, and video outputs | Yes | Create, publish, and manage rental listings and marketing materials | None |
| Property facts submitted for AI content generation | Yes, when you request it | Generate listing descriptions, captions, and flyer copy | Configured VacancyFox AI Gateway |
| Lead name, email, phone, and message | Yes, when submitted through a listing | Deliver and manage a landlord's prospective-renter leads | Resend and Twilio only for configured lead notifications |
| Subscription status and Stripe customer/subscription identifiers | Yes, for a paid subscription | Manage subscription access and billing status | Stripe |
| Full payment-card details | No | N/A | Handled by Stripe |
VacancyFox retains the account and its property, listing-content, lead, subscription-record, and associated media records while the account exists to provide the service. Photos and rendered video outputs are stored under the account's properties. In the current source, passwords are stored as bcrypt hashes and account records are served through authenticated routes; this is a description of the implementation, not a security certification. When configured, Resend sends landlord lead-notification email and Twilio sends landlord lead-notification SMS; lead capture itself does not depend on a notification being sent.
You can delete your VacancyFox account from the in-app Account page. If an active web subscription exists, VacancyFox must confirm its cancellation with Stripe before deletion proceeds. Deletion removes the account and its linked properties, photos, listing content, leads, subscription record, and video-job records through the application's cascade relationships, then attempts to remove that account's stored photo and video outputs. A failed cancellation confirmation leaves the account and records in place.
BuildHound Site Photos & Material Lists
Category: Construction job-site documentation
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Account, name, email, and authentication data | Yes | Create and secure a BuildHound account; sign in and manage account settings | None |
| Job-site photos captured with the camera | Yes, when you capture one | AI product identification and job-site photo documentation. Barcode frames and LiDAR distance readings stay on the device and are never uploaded. | Quantrolix AI Gateway (approved product photos only) |
| Job and material-list data you create | Yes | Organize jobs, material lists, and captured photos by site | None |
| Subscription status and purchase history | Yes, for a paid subscription | Manage DIY Pro / Contractor subscription access | Apple (StoreKit) |
| Full payment-card details | No | N/A | Handled by Apple's In-App Purchase |
The camera is used only when you choose to photograph a product for AI identification, scan a barcode, or estimate a LiDAR distance. Approved product photos are uploaded for identification; barcode frames and LiDAR depth or spatial data stay on your device. BuildHound retains your account, jobs, material lists, and captured photos while your account exists to provide the service. Photos and project data are stored in your account and are never sold.
You can delete your BuildHound account and its associated data from the app's account settings.
Quantrolix SaaS Platform
Category: Platform / Dashboard
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Account & subscription data | Yes | Unified account management | Stripe (billing only) |
| Cross-app preferences | Yes | Unified settings | None |
| Dashboard usage analytics | Yes | Service improvement | None |
Quantrolix SaaS serves as the unified dashboard for managing your Quantrolix account, subscriptions, and cross-application settings.
Comm Hub Internal Service
Category: Internal / Coordination
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Service coordination messages | Yes | Inter-service communication | None (internal only) |
| Task and activity logs | Yes | Development coordination | None (internal only) |
Comm Hub is an internal coordination service. It does not collect end-user personal data. Any operational data is used solely for service coordination and development purposes.
ML Service Internal Service
Category: Internal / Machine Learning
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Anonymized training data | Yes (anonymized) | Model training and improvement | None |
| Prediction request logs | Yes (anonymized) | Model accuracy monitoring | None |
| Model performance metrics | Yes | Quality assurance | None |
The ML Service is our internal machine learning infrastructure. It processes only anonymized, aggregated data for model training. No PII is used in model training or stored by this service. You may opt out of having your anonymized data included in model training by contacting privacy@quantrolix.com.
Quantrolix Landing (Website) Website
Category: Marketing / Website
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Standard web-edge request metadata (IP address; request timestamp, path, and user agent where logged) | Yes, at the Quantrolix-hosted web edge | Security and operations | Quantrolix-hosted web edge |
| Contact form submissions | Yes (if submitted) | Responding to inquiries | None |
The Quantrolix landing website (quantrolix.com) does not use third-party analytics, tracking pixels, or advertising cookies. Its web-edge request logs follow service-specific operational retention and applicable legal requirements.
13. Data Subject Requests & Account Deletion
13.1 How to Submit a Request
You may submit a data subject request through any of the following channels:
- Email: privacy@quantrolix.com
- Web form: apps.quantrolix.com/privacy/request
- In-app: The privacy or account settings provided by the applicable application, where available
13.2 Identity Verification
To protect your privacy, we verify your identity before processing data requests. We will ask you to confirm your identity using information associated with your account (e.g., the email address used to register). We will not request additional sensitive information for verification.
13.3 Response Timeline
- Acknowledgment: Within 3 business days of receipt.
- Fulfillment: Within 30 days (GDPR) or 45 days (CCPA/CPRA). If additional time is needed for complex requests, we will notify you of a 30-day extension with an explanation.
13.4 Data Export Format
Where an export is available, it is provided in JSON format and organized by applicable application. It covers the data associated with the verified account for that application, subject to the implementation and any legal retention requirements. Delivery method depends on the applicable application's verified account or request process.
13.5 Account Deletion Process
When you request account deletion, we apply the verified account's application-specific deletion process and applicable legal retention requirements:
- Account and related records: The applicable application deactivates or deletes the verified account and the records linked to it according to that application's implementation.
- VacancyFox: Before deleting an account with an active web subscription, VacancyFox confirms cancellation with Stripe. Its account deletion then uses its local cascade relationships and attempts to remove that account's stored photo and video outputs.
- Retention and backups: Data handling after deletion follows the applicable application's retention practices and any legal requirements; this policy does not promise a universal deletion timeline across separate applications or data stores.
- Exceptions: Transaction records subject to tax compliance (7-year retention) are anonymized rather than deleted: your name and email are removed, but the transaction amounts and dates are retained in anonymized form as required by law.
Deletion is irreversible. We recommend exporting your data before requesting deletion. The applicable application or request process confirms completion where it provides a confirmation channel.
14. Cookies & Tracking Technologies
14.1 What We Use
Cookie and authentication technologies apply only to the web services and applications that use them; they do not apply to every covered application. Market Pulse does not use account authentication, auth cookies, or JWT refresh tokens in its current iOS app.
| Technology | Purpose | Duration | Required? |
|---|---|---|---|
| Session cookie (auth token; applicable web services/apps) | Maintain a logged-in session where account authentication is used | Session / 7 days | Essential |
| JWT refresh token (applicable web services/apps) | Refresh account authentication without re-login where that mechanism is used | 30 days | Essential |
| User preferences (localStorage) | Store UI preferences (theme, language) | Persistent | Functional |
| Sentry session tracking (participating apps only; not Terpa) | Error reporting and crash diagnosis | Session | Performance |
14.2 What We Do NOT Use
- No third-party analytics cookies (no Google Analytics, no Amplitude, no Mixpanel)
- No advertising cookies or tracking pixels
- No cross-site tracking
- No fingerprinting technologies
- No social media tracking widgets
For web services and applications where we use cookies, we use only essential and functional cookies and no third-party tracking cookies; a cookie consent banner is not required under most frameworks. You may clear browser cookies at any time through your browser settings.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes:
- Minor changes (clarifications, formatting): Updated with a new "Last Updated" date.
- Material changes (new data collection, new third-party sharing, rights changes): We will notify you at least 30 days in advance via email to your registered address, in-app notification, and a prominent notice on this page.
Your continued use of our Services after the changes take effect constitutes acceptance of the updated policy. If you do not agree with the changes, you may delete your account before the changes take effect.
Previous versions of this policy are available upon request.
16. Contact Us
If you have questions about this Privacy Policy, our data practices, or wish to exercise your rights, contact us at:
- Quantrolix
- Operated by Dustin Newcomb
- Scottsdale, AZ, United States
- Privacy & Data Requests: privacy@quantrolix.com
- General Support: support@quantrolix.com
- DMCA Notices: dmca@quantrolix.com
- Legal: legal@quantrolix.com
- Data Subject Request Portal: apps.quantrolix.com/privacy/request
We aim to respond to all privacy-related inquiries within 3 business days.