Privacy Policy
Effective Date: February 8, 2026 · Last Updated: October 5, 2026
Quantrolix ("we," "us," or "our"), operated by Dustin Newcomb, provides a suite of applications and services (collectively, the "Services"). This Privacy Policy describes how we collect, use, store, share, and protect your personal information when you use any Quantrolix application or visit our websites.
This is a unified privacy policy that applies to all 24 applications in the Quantrolix ecosystem. Certain applications collect specialized data categories and are subject to additional protections. Please review the App-Specific Data Schedules (Section 12) for the applications you use.
Covered Applications: EmberPOS, Grocery Optimizer, Tea Effects, Terpa, YieldVault, PhantomCast, Bourbon Hunter, MenuMentor, Kasa Controller, CouplesCare, MotionForge, Nexus 3D Maps, Qode IDE, Architect 3D, Quantrolix Launcher, Quantrolix SaaS, Comm Hub, Clausely, ML Service, Quantrolix Market Pulse, VacancyFox, BuildHound, ScheduleHub, and the Quantrolix Landing website.
1. Information We Collect
1.1 Information You Provide Directly
- Account Information: Name, email address, and password when you create an account in an applicable Quantrolix application. Some applications use our centralized Auth Gateway; VacancyFox uses its own application account and authentication flow.
- Profile Information: Optional details such as business name, dietary preferences, health goals, or other profile data specific to each application.
- Payment Information: When you subscribe to paid tiers, payment processing is handled exclusively by Stripe or Apple In-App Purchase. We do not store, process, or transmit your full credit card number, CVV, or bank account details on our servers.
- User Content: Data you create within our applications, such as POS transactions, recipes, tea blends, investment portfolios, code files, 3D models, relationship wellness entries, or other content.
- Communications: Messages you send to us via email, in-app feedback, or support requests.
- Health and Wellness Data: Self-reported dietary information, mood tracking, supplement effects, relationship wellness entries, and nutritional goals when you choose to use health-related features in Grocery Optimizer, Tea Effects, or CouplesCare.
1.2 Information Collected Automatically
- Usage Data: Where a participating application collects it, feature usage, session duration, interaction patterns, and navigation paths used to operate or improve that application. See the applicable App-Specific Data Schedule; Market Pulse collects no analytics or tracking data; its limited usage data (daily signal-refresh counts) is described in its schedule.
- Device Information: Participating applications may collect operating system, app version, device model, screen resolution, and unique device identifiers as described in their applicable App-Specific Data Schedule. Market Pulse (version 1.1 and later) uses one app-generated random device identifier for Pro entitlement and usage limits, as described in its schedule; it collects no other device information.
- Crash Reports: Participating applications may collect error logs and crash data to diagnose and fix issues, as described in their applicable App-Specific Data Schedule. Market Pulse does not collect crash reports or usage diagnostics in its current iOS app. Terpa sends Apple MetricKit crash reports only—not hang or performance diagnostics—together with app version/build and a random event identifier. Reports are sent without Terpa account credentials, and no user ID or IP address is stored with the crash receipt. Participating apps may use Sentry. Ordinary error events are configured to scrub personal information; Clausely's opt-in crash minidumps may include unscreened process memory, as described in its schedule below.
- Log Data: Where edge, API, or service logging is enabled, standard request metadata such as IP address, request timestamp and path, and user agent where logged may be recorded for security, rate limiting, and operations. This is distinct from in-app analytics or tracking; see the applicable App-Specific Data Schedule.
- Local Network Data: Kasa Controller and PhantomCast perform local network discovery (mDNS/SSDP) to find compatible devices. This data remains on your local device and is not transmitted to our servers.
1.3 Information from Third Parties
- Grocery & Retail Data: When you use integrations with Instacart, Walmart, or other retail services through Grocery Optimizer, we receive product availability and pricing data on your behalf. This occurs only at your explicit request.
- Streaming Metadata: When you use PhantomCast, we receive content metadata from streaming services you connect to facilitate casting.
- Apple App Store: Apple may share aggregated analytics data about your app usage under its own privacy framework.
- Stripe: Stripe shares subscription status and billing event data (but not payment card details) to manage your subscriptions.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Provide and operate the Services: Deliver core functionality, manage your account, process transactions, and maintain service availability.
- Personalize your experience: Generate AI-powered recommendations (e.g., meal plans in Grocery Optimizer, tea blends in Tea Effects, waste-reduction and food-cost suggestions in YieldVault). Data supplied to an AI provider depends on the feature and application; see the applicable App-Specific Data Schedule. For example, VacancyFox sends property facts supplied for a user-requested listing-content generation to its configured AI Gateway.
- Improve the Services: For applications that collect usage data, analyze trends and patterns in aggregated, anonymized form to improve features and fix issues.
- Process payments: Manage subscriptions, billing cycles, and payment failures through our payment processors.
- Communicate with you: Send service notifications, security alerts, subscription confirmations, and support responses. We do not send marketing emails unless you opt in.
- Ensure security: Detect, prevent, and address fraud, abuse, unauthorized access, and technical issues.
- Train machine learning models: Our ML Service uses anonymized, aggregated data to improve recommendation accuracy. No PII is used in model training. You may opt out of anonymized data inclusion.
- Comply with legal obligations: Respond to legal processes and enforce our Terms of Service.
3. Legal Bases for Processing
We process your personal data under one or more of the following legal bases:
| Legal Basis | Applies To |
|---|---|
| Contract Performance | Providing the Services you signed up for, managing your account, processing subscriptions |
| Consent | Health and wellness data processing, optional AI recommendations, marketing communications, cookies |
| Legitimate Interest | Service improvement for applications that collect analytics, fraud prevention, security monitoring, bug fixing |
| Legal Obligation | Tax record retention, responding to lawful data requests, DMCA compliance |
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out prior to withdrawal.
4. Data Storage & Security
Your data is stored on our self-hosted infrastructure located in the United States (Contabo Cloud VPS). We use PostgreSQL databases for persistent storage and Redis for temporary caching and session management.
Security Measures
- Encryption in Transit: All connections use HTTPS/TLS 1.2+ encryption. No unencrypted HTTP connections are accepted.
- Encryption at Rest: Database storage for other app services is encrypted. CouplesCare storage and sharing are described separately in its app-specific schedule below; this policy does not promise an additional application-level encryption layer for every CouplesCare storage path.
- Password Security: All passwords are hashed and salted using bcrypt with a minimum cost factor of 10.
- Authentication: Authentication is implemented per application. VacancyFox uses application-local registration and login routes with bcrypt password hashing and JWT tokens; see the applicable App-Specific Data Schedule for that application's implementation.
- Access Controls: Role-based access controls (RBAC) limit data access to authorized personnel and services.
- Monitoring: Participating apps use Sentry error monitoring with personal-information scrubbing for ordinary events. Clausely's optional crash minidumps may contain unscreened process memory. Terpa uses anonymous Apple MetricKit crash diagnostics. Server-level logging is used for security event detection.
- Dependency Management: Regular security audits and automated dependency updates to patch known vulnerabilities.
- Payment Isolation: All payment card processing is fully delegated to PCI Level 1 certified processors (Stripe). Cardholder data never touches our servers.
While we implement industry-standard security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security. If we become aware of a security breach affecting your personal data, we will notify you and applicable regulatory authorities as required by law.
5. Data Sharing & Third Parties
We share your information only in the following limited circumstances:
| Third Party | Purpose | Data Shared | Applicable Apps |
|---|---|---|---|
| Stripe | Payment processing | Email, subscription status, billing events | EmberPOS, YieldVault (web; iOS and macOS subscriptions are sold only through Apple In-App Purchase), Grocery Optimizer, Tea Effects, PhantomCast, VacancyFox |
| Apple (App Store / TestFlight) | App distribution, In-App Purchase, reviews | Purchase receipts and, where Apple provides them, aggregated app analytics under Apple's privacy framework | iOS/macOS apps, subject to the applicable App-Specific Data Schedule |
| Sentry | Error & crash reporting | Device info, error traces, and stack traces (personal information scrubbed for ordinary events); Clausely opt-in crash minidumps may contain process memory, including document text | Participating apps, including Nexus 3D Maps and YieldVault macOS builds with crash reporting enabled; Terpa does not use Sentry for crash reporting |
| Instacart / Walmart APIs | Grocery price comparison & ordering | Shopping list items (user-initiated only) | Grocery Optimizer |
| Groq / OpenAI / Ollama (AI providers) | AI-powered recommendations and document analysis | For most apps, anonymized prompts containing no personal data. YieldVault, Clausely and CouplesCare are exceptions. YieldVault: an invoice or label photo you choose for Chef's Desk capture, and the kitchen evidence you choose for "Prioritize with AI", are sent through our server to OpenAI; the waste, yield and recipe-cost data behind an AI Insight you open is sent through our AI gateway to Groq. Your name, email and account ID are not sent to either provider, but the content you capture can include text printed on the document. OpenAI may keep API inputs for up to 30 days for abuse monitoring, and neither provider uses them to train models by default. Clausely: the text of a contract you upload is transmitted for analysis, and that text may contain personal data written in the document (such as names, property addresses, prices and dates). Clausely asks for your permission in the app before any contract text is sent, and you can withdraw that permission at any time. Groq does not retain inference inputs and outputs by default, but may temporarily log them for up to 30 days to troubleshoot reliability issues or investigate suspected abuse unless zero-data-retention controls are enabled. Groq does not use the contract text to train models. CouplesCare: the hosted AI chat text you write, which may contain personal and relationship details, is sent to our backend and Groq after in-app consent (see below), and Partner Session Room responses are relayed through our server. CouplesCare sharing depends on platform and feature: In Mac builds whose Home screen identifies Local conversation practice, Conversation Practice uses curated local prompts. The messages typed in that feature are not sent to an AI provider. This statement does not cover older Mac builds without that local-practice feature. On supported iPhones, an available on-device model can generate AI companion replies locally. When on-device processing is unavailable, hosted AI conversation text is sent to Quantrolix and processed by Groq, Inc. or a model on our own servers only after you grant the in-app AI-sharing permission. You can decline or withdraw that permission; it governs the hosted AI conversation, not Partner Session Room. Partner Session Room is a separate online feature. It sends room information and submitted responses to the Quantrolix session service for sharing with your partner. The room supports client-side encryption, but if that encryption is unavailable or fails the service may receive the content of your response. Do not assume every room response is unreadable by the service. Room responses are not sent to an AI provider by this feature. | Apps that use those providers; YieldVault for Chef's Desk captures and AI Insights; Clausely for contract text; CouplesCare for hosted AI chat text |
| VacancyFox AI Gateway | User-requested listing-content generation | Property details supplied for the requested generation | VacancyFox |
| Resend | Transactional lead-notification email when configured | Lead contact details and message, property title, and landlord email | VacancyFox |
| Twilio | Optional lead-notification SMS when configured | Landlord phone number, property title, and lead contact details | VacancyFox |
We may also share information when:
- Required by law: In response to a subpoena, court order, or government request.
- Protecting rights: To protect the rights, property, or safety of Quantrolix, our users, or the public.
- Business transfers: In connection with a merger, acquisition, or sale of assets, in which case you will be notified of any change in data controller.
- With your consent: When you explicitly direct us to share data with a third party.
5.1 Equal Protection by Third Parties
Every third party with whom we share user data is required to provide the same or equal protection of that data as is stated in this Privacy Policy. We share personal data only with service providers acting on our instructions, and only under terms that require them to:
- use the data solely to perform the service we requested, and for no independent purpose of their own;
- apply security safeguards at least equivalent to those described in Section 4 of this policy;
- not sell, rent, or otherwise disclose the data, and not use it to train or improve their own models;
- retain the data no longer than needed for that service, and delete or return it on our instruction;
- support the data-subject rights described in Sections 7 and 13, including access and deletion requests we pass through to them.
This applies to the AI inference providers listed above. In particular, contract text that Clausely sends to Groq, Inc. after you grant the in-app permission is processed only to return your analysis: Groq does not use it to train models, does not retain inference inputs and outputs by default, and may temporarily log them for up to 30 days only to troubleshoot reliability issues or investigate suspected abuse. If a provider cannot meet these commitments, we do not send user data to it.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide Services. Our specific retention periods are:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account data (name, email) | Until account deletion | Service delivery |
| Transaction records (EmberPOS) | 7 years | Tax and legal compliance |
| Kitchen records (YieldVault) | Until account deletion; deleting your account in Settings deletes your store's records from our servers | Service delivery |
| Personal entries and account data (CouplesCare) | Local entries remain in local app storage until removed. Server-held data follows the relevant service and account-deletion handling; no universal 90-day inactivity-deletion promise is made. | Provide the features you use; use the contact methods in Section 13 for server-data deletion requests. |
| Health & dietary data (Grocery Optimizer, Tea Effects) | Until account deletion or manual removal | Service delivery; deletable at any time |
| Crash reports | Sentry reports and Terpa anonymous MetricKit crash records: up to 90 days | Bug diagnosis |
| Usage analytics (where collected) | Aggregated and anonymized after 12 months | Service improvement |
| Edge, API, and service request logs (where logging is enabled) | Service-specific operational retention and applicable legal requirements | Security, rate limiting, and operations |
| Redis cache data | 24 hours maximum | Performance optimization |
| AI model training data | Anonymized; no PII retained | Model improvement |
Account-deletion handling follows the implementation and retention requirements of the application that holds the account; see the applicable App-Specific Data Schedule. For example, VacancyFox confirms cancellation of an active Stripe subscription before deleting that account, then removes the account's related records through its local cascade relationships and attempts to remove that account's stored photo and video outputs. See Section 13 for details on the deletion process.
7. Your Rights (All Users)
Regardless of where you are located, we provide the following rights to all Quantrolix users:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Deletion: Request deletion of your personal data ("right to be forgotten"). We process deletion according to the applicable application's implementation and any legal retention requirements.
- Right to Data Portability: Export your data in a machine-readable format (JSON). Available via in-app settings or by contacting us.
- Right to Restrict Processing: Request that we limit how we use your data.
- Right to Object: Object to processing based on legitimate interests.
- Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time.
- Right to Non-Discrimination: We will not treat you differently for exercising your privacy rights.
To exercise any of these rights, please contact us at privacy@quantrolix.com or submit a request at apps.quantrolix.com/privacy/request. We will verify your identity and respond within 30 days (or 45 days for complex requests, with notice).
8. California Residents (CCPA/CPRA)
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
8.1 Categories of Personal Information Collected
| Category (per CCPA) | Examples | Collected? |
|---|---|---|
| A. Identifiers | Name, email, IP address, device ID | Yes — only for applicable applications and web services; see App-Specific Data Schedules |
| B. Customer records | Billing info (via Stripe), account data | Yes |
| C. Protected classifications | N/A | No |
| D. Commercial information | Purchase history, subscription tiers | Yes |
| E. Biometric information | N/A | No |
| F. Internet activity | Usage data, feature interactions, crash logs | Yes — only for applicable applications and web services; see App-Specific Data Schedules |
| G. Geolocation | IP-derived approximate location (not precise GPS) | Yes — only for applicable web services and applications; see App-Specific Data Schedules |
| H. Sensory data | N/A | No |
| I. Professional/employment | Business name (EmberPOS, YieldVault) | Yes (optional) |
| J. Education information | N/A | No |
| K. Inferences | AI-generated recommendations, macro predictions | Yes |
| L. Sensitive personal info | Health data (CouplesCare, Grocery, Tea Effects) | Yes (with consent) |
8.2 Your CCPA/CPRA Rights
- Right to Know: You may request the categories and specific pieces of personal information we have collected about you in the past 12 months, the sources, the business purpose, and the third parties with whom we shared it.
- Right to Delete: You may request deletion of your personal information, subject to legal exceptions (e.g., tax records).
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: We do not sell or share (as defined by the CCPA/CPRA) personal information for cross-context behavioral advertising. There is no need to opt out.
- Right to Limit Use of Sensitive Personal Information: You may limit our use of sensitive personal information (health data) to what is necessary for the Services.
- Non-Discrimination: We will not deny services, charge different prices, or provide a different quality of service because you exercised your CCPA rights.
To submit a CCPA/CPRA request, email privacy@quantrolix.com with the subject line "CCPA Request." We will verify your identity and respond within 45 days.
Authorized Agents: You may designate an authorized agent to submit requests on your behalf. We will require verification of both the agent's authority and your identity.
9. European Residents (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional protections under the General Data Protection Regulation (GDPR):
9.1 Data Controller
The data controller is Quantrolix, operated by Dustin Newcomb, based in Scottsdale, Arizona, USA. For all GDPR inquiries, contact our Data Protection Contact at privacy@quantrolix.com.
9.2 Your GDPR Rights
In addition to the rights listed in Section 7, GDPR provides you with:
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority if you believe your data has been processed unlawfully.
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format (JSON) and transmit it to another controller.
- Right to Object to Automated Decision-Making: You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significant effects. Our AI recommendations are supplementary and do not constitute sole automated decision-making.
9.3 Lawful Bases
We process personal data under the lawful bases described in Section 3. For health and wellness data (CouplesCare, Grocery Optimizer, Tea Effects), we rely on your explicit consent, which you may withdraw at any time.
9.4 Data Processing Records
We maintain records of processing activities as required under Article 30 of the GDPR. These records are available upon request to supervisory authorities.
10. International Data Transfers
Our servers are located in the United States. If you access our Services from outside the United States, your data will be transferred to and processed in the United States.
We rely on the following legal mechanisms for cross-border data transfers:
- Standard Contractual Clauses (SCCs): For transfers from the EEA/UK to the United States, we rely on the European Commission's Standard Contractual Clauses.
- Consent: By using our Services, you consent to the transfer of your data to the United States.
- Adequacy Decisions: Where applicable, we rely on adequacy decisions issued by the European Commission.
Our third-party processors (Stripe, Sentry, Apple) maintain their own international data transfer mechanisms and certifications.
11. Children's Privacy
Our Services are not directed to children under 13 years of age (or under 16 in the EEA). We do not knowingly collect personal information from children under these age thresholds.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us at privacy@quantrolix.com. We will promptly investigate and delete such data.
CouplesCare, which handles sensitive relationship wellness data, requires users to be at least 18 years old.
12. App-Specific Data Schedules
The following sections describe the specific data practices for each application in the Quantrolix ecosystem. Each application inherits the general policies described above and adds the application-specific practices below.
EmberPOS Payment Data · PCI-DSS
Category: Business / Point of Sale
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Business name & location | Yes | Account setup, multi-location management | None |
| Employee names & roles | Yes | Staff management, role-based POS access | None |
| Transaction data (items, totals, timestamps) | Yes | POS operations, reporting, analytics | None |
| Menu items & pricing | Yes | POS operations | None |
| Payment card data | No | N/A - handled entirely by Stripe | Stripe (PCI L1) |
| Customer tip data | Yes | Tip distribution, reporting | None |
Grocery Optimizer Health & Dietary Data
Category: Health / Nutrition / Consumer
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Dietary preferences & allergies | Yes | Meal planning, allergen filtering | None |
| Nutritional goals & macro targets | Yes | AI macro optimization | Anonymized to AI provider |
| Medication names (optional) | Yes (opt-in) | Food-drug interaction warnings | None |
| Shopping lists | Yes | Price comparison, ordering | Instacart/Walmart (user-initiated) |
| Meal plans & recipes | Yes | Meal planning features | None |
| Purchase history | Yes | Price tracking, budget optimization | None |
You may delete all dietary and health data at any time from your profile settings without deleting your entire account.
Tea Effects Health & Supplement Data
Category: Health / Wellness / Consumer
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Health goals | Yes | Personalized tea recommendations | Anonymized to AI provider |
| Tea preferences & history | Yes | Recommendation engine | Anonymized to AI provider |
| Self-reported effects (mood, energy, sleep) | Yes | Effect tracking, pattern analysis | None |
| Caffeine sensitivity (optional) | Yes (opt-in) | Caffeinated tea filtering | None |
Terpa Grow Tracking & Diagnostics
Category: Productivity / Cultivation Tracking
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Account data (name, email, user ID) | Yes | Account access and cloud synchronization | None |
| Grow, plant, task, and journal records | Yes | Grow tracking, analytics, and exports | None |
| Plant photos and related metadata | Yes | Photo logs and user-requested diagnostics | AI provider only when the user requests analysis |
| Subscription status and receipt metadata | Yes | StoreKit entitlement verification | Apple |
| Apple MetricKit crash reports, app version/build, and random event ID | Yes | Crash diagnosis and app reliability | None |
Terpa sends crash diagnostics without Terpa account credentials and stores no user ID or IP address with the crash receipt. It accepts crash diagnostics only, not hang or performance diagnostics. Anonymous crash records are automatically deleted after 90 days. Account-associated grow records and media are retained while your account is active and are deleted when you delete your account.
CouplesCare Sensitive Relationship Data
Category: Relationship Wellness
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Personal reflection entries and self-reported mood check-ins | When entered | Record your own experiences | These fields are not automatically included in hosted AI requests. Server storage and sharing depend on the feature used. |
| Guided-exercise and participation entries | When entered | Exercise and activity participation | These fields are not automatically included in hosted AI requests; Partner Session Room sharing is described separately below. |
| Mac Conversation Practice message text | In the local-practice feature | Curated listening prompts | No AI provider for Mac builds that identify Local conversation practice |
| Optional AI companion conversation text on other supported paths | When you use that path | Generate an AI companion reply | Available on-device model, or Quantrolix and Groq, Inc. / a model on our servers after in-app permission; not anonymized, because the text you write is sent as written |
| Partner Session Room information and submitted responses | When you use the online room | Synchronize the shared room and show responses to your partner | Quantrolix session service and your partner; no AI provider by this feature |
Feature-specific CouplesCare data handling:
- In Mac builds whose Home screen identifies Local conversation practice, Conversation Practice uses curated local prompts. The messages typed in that feature are not sent to an AI provider. This statement does not cover older Mac builds without that local-practice feature.
- On supported iPhones, an available on-device model can generate AI companion replies locally. When on-device processing is unavailable, hosted AI conversation text is sent to Quantrolix and processed by Groq, Inc. or a model on our own servers only after you grant the in-app AI-sharing permission. You can decline or withdraw that permission; it governs the hosted AI conversation, not Partner Session Room.
- Partner Session Room is a separate online feature. It sends room information and submitted responses to the Quantrolix session service for sharing with your partner. The room supports client-side encryption, but if that encryption is unavailable or fails the service may receive the content of your response. Do not assume every room response is unreadable by the service. Room responses are not sent to an AI provider by this feature.
- Local entries remain in local app storage until removed. For data held by our online services, use the contact methods in Section 13 to request deletion; handling follows the relevant service and legal requirements. This policy does not promise automatic deletion after a universal inactivity period.
- Users must be at least 18 years old to use CouplesCare.
PhantomCast Streaming & DMCA
Category: Streaming / Media
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Streaming session metadata (titles, timestamps) | Yes | Session management, history | None |
| Device identifiers (casting targets) | Yes (local) | Device discovery and pairing | None - stays on device |
| Content preferences | Yes | Content organization | None |
| Network scan results (mDNS/SSDP) | Local only | Discover Roku and casting devices | None - stays on device |
| Actual media content | No | N/A | N/A |
YieldVault: Food Cost & Waste Kitchen Operations
Category: Restaurant / Food Service / Business Productivity
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Account data (name, email address, business name, user ID) | Yes | Account login, store setup, account and billing emails | Resend (transactional email delivery) |
| Kitchen records: products, yield and butcher tests, waste logs, catch weights, receiving records, purchases, stock counts, recipes and recipe costs, bar and wine entries, notes | Yes | Food-cost, yield and waste tracking and reports | None |
| Vendor directory (supplier names, contact names, phone numbers, email addresses, addresses, notes) | Yes | Supplier management and receiving | None |
| Owner Group membership and summaries (Enterprise) | Yes | Multi-store owner view and digest emails | Resend (digest emails) |
| Invoice or label photo and invoice text you choose for Chef's Desk capture | Yes, only when you choose "Extract for review" | Extract invoice and label fields for you to review | OpenAI (via our server and Quantrolix AI gateway); the photo is not stored in your records |
| Kitchen evidence for "Prioritize with AI" | Yes, only when you choose it | Order follow-up checks | OpenAI (via Quantrolix AI gateway) |
| Waste, yield and recipe-cost summaries for AI Insights (Pro) | Yes, only when you open an AI Insight | Generate waste-reduction, yield and pricing suggestions | Groq (via Quantrolix AI gateway) |
| AI feature usage count (per store, per day) | Yes | Enforce the plan's daily AI allowance | None |
| Subscription records (Apple transaction ID, product, expiry, purchase account token) | Yes | Unlock and restore your plan | Apple (iOS and macOS); Stripe (web subscriptions) |
| Crash reports (error type and stack location only; no account identity, form data or message text) | Yes, macOS builds with crash reporting enabled | Find and fix crashes | Sentry |
| Bluetooth scale readings | Local only (weights are saved only when you save a record) | Read weights from a connected scale | None |
| Precise location, device contacts, health data, advertising identifiers, tracking | No | N/A | N/A |
YieldVault is a kitchen food-cost, yield and waste tool for restaurants and food-service businesses. Our AI providers (OpenAI and Groq) receive only the content described above, without your name, email or account ID. They may keep API inputs for a limited period (OpenAI: up to 30 days) for abuse monitoring, and do not use them to train models by default. Subscriptions on the web are processed by Stripe, and we never receive full card numbers. Subscriptions in the iOS and macOS apps are sold only through Apple In-App Purchase. Deleting your account in Settings deletes your store's records from our servers.
Quantrolix Market Pulse Decision Support
Category: Market analysis / decision support
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Account, broker, order, and card/payment data | No (purchases are processed by Apple; we never receive card details) | N/A | N/A |
| Market/reference request parameters | Yes, when you request analysis | Retrieve public market analysis and reference data | Quantrolix-hosted edge/API |
| Standard public API edge/service request metadata (IP address; request timestamp, path, and user agent where logged) | Yes, when you use the public API | Security, rate limiting, and operations | Quantrolix-hosted edge/API |
| Journal entries and selected API-base setting | Local only | Personal journal and app configuration | None |
| Pro subscription records: Apple transaction identifiers, product, status, and expiry (version 1.1 and later) | Yes, only if you buy Market Pulse Pro or restore a purchase | Verify your purchase with Apple and unlock Pro features (App Functionality) | Apple (purchase verification) and Quantrolix-hosted API |
| App-generated random device identifier (a UUID created on first use and stored in the app; version 1.1 and later) | Yes, sent with Pro and usage requests; also passed to Apple StoreKit as the purchase account token | Link your Pro entitlement to your device and enforce the daily free usage limit (App Functionality); not used for tracking or advertising | Apple (as the StoreKit purchase account token) and Quantrolix-hosted API |
| Per-device daily counts of live signal refreshes (version 1.1 and later) | Yes | Enforce the free-tier daily limit (App Functionality) | Quantrolix-hosted API |
| Crash diagnostics, app analytics SDKs, advertising identifiers, or tracking data | No | N/A | N/A |
Market Pulse has no account system, brokerage connection, order-execution, or money-movement feature. Version 1.1 adds an optional Pro subscription: the app creates a random identifier on your device and sends it, together with Apple purchase transaction identifiers, to our server so we can confirm your subscription with Apple and apply the free-tier daily limit. These records are retained while your subscription is active and for as long as needed to operate and secure the service; to ask for deletion, contact privacy@quantrolix.com. The identifier is also passed to Apple as the StoreKit purchase account token. The app sends it to our server in the web address of the Pro status request, and market-data request addresses (for example the symbol you look up) can carry it too, so our edge web-server logs record it together with your IP address, request time, and the requested symbol; those logs are kept for a limited time (about 14 days, rotated daily) and are used only for security, rate limiting, and operations. We do not use these records for tracking, advertising, or sale. Its public, unauthenticated analysis and reference-data requests, including read-only GET requests, may generate the standard request logs described above. Its journal and API-base preference are stored in your device's localStorage; they are not synchronized to a Market Pulse account.
Kasa Controller Smart Home · Network Scanning
Category: Smart Home / IoT
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Local network scan results | Local only | Discover TP-Link Kasa devices | None - stays on device |
| Device names & states | Local cache | Display and control devices | None - stays on device |
| Device IP addresses (local network) | Local only | Direct device communication | None - stays on device |
| Automation schedules | Local only | Scheduled device actions | None - stays on device |
Bourbon Hunter General
Category: Lifestyle / Collection Management
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Whiskey collection data | Yes | Collection management | None |
| Tasting notes & ratings | Yes | Personal tasting journal | None |
| Wishlist items | Yes | Wishlist management, availability alerts | None |
| Approximate location (optional) | Opt-in only | Nearby store availability | None |
Location data is only collected if you explicitly opt in to the nearby store availability feature. You may disable location access at any time in your device settings.
MenuMentor General
Category: Restaurant / Business
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Menu items & descriptions | Yes | Menu analysis, optimization suggestions | Anonymized to AI provider |
| Pricing data | Yes | Price optimization, competitor analysis | None |
| Restaurant category/type | Yes | Industry-specific recommendations | None |
MotionForge Creative Tool
Category: Creative / Video Production
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Project files & compositions | Yes (local + cloud sync) | Video/motion graphics creation | None |
| Asset library metadata | Yes | Asset management | None |
| Export settings & preferences | Yes | Workflow optimization | None |
MotionForge project files are stored locally on your device. Cloud sync, when enabled, stores project metadata on our servers. Actual media assets remain on your device unless you explicitly upload them.
Nexus 3D Maps Creative Tool
Category: Mapping / Visualization
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Map projects, layers, routes, markers and imported GeoJSON/CSV files | Local only | 3D map creation and editing | None (stored on your device) |
| Place-search text you type (including autocomplete) | Yes, when you search | Find places and addresses | OpenStreetMap Foundation (Nominatim) and Komoot (Photon) geocoding services |
| Coordinates of points you choose for a route | Yes, when you request a road route | Calculate turn-by-turn routes | OSRM public routing server (FOSSGIS) |
| Coordinates sampled between two points you choose | Yes, when you request an elevation profile | Return terrain elevation | Open-Meteo (elevation API) |
| Coordinates of a place you select | Yes, when you open nearby points of interest | Find nearby restaurants, hotels and similar places | Overpass API (OpenStreetMap data) servers |
| Crash reports and app-launch session counts (no account or identity; may include recent request URLs such as search text) | Yes | Find and fix crashes; count app launches per release | Sentry |
| Your physical location / device GPS | No. The app never requests or reads your location. | N/A | N/A |
| Account data, contacts, advertising identifiers, tracking | No | N/A | N/A |
Nexus 3D Maps has no account and stores your projects on your device. When you search, route, request elevation or browse nearby places, the text or coordinates you chose are sent to the public mapping services listed above. Those services receive your IP address and may keep request logs under their own privacy policies. Current-conditions weather uses a fixed list of major-city stations, not your location. We do not link any of this data to your identity, and we do not track you or use it for advertising.
Qode IDE Developer Tool
Category: Development / IDE
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Code files & projects | Local only | Code editing | None |
| Editor preferences & settings | Yes (local + sync) | Personalized development environment | None |
| AI code completion prompts | Yes (when feature used) | AI-assisted coding | Anonymized to AI provider |
| Extension data | Yes (local) | Extension functionality | None |
Your source code files remain on your local device and are never uploaded to our servers unless you explicitly use cloud sync features. AI code completion sends only the relevant code context (anonymized, without file paths or project names) to generate suggestions.
Architect 3D Creative Tool
Category: Architecture / 3D Modeling
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| 3D model files & projects | Local + optional cloud | Architectural modeling | None |
| Measurement & dimension data | Yes (within projects) | Precise architectural rendering | None |
| Material & texture libraries | Yes (local) | Design asset management | None |
Architect 3D project files are stored locally by default. Cloud backup is optional and encrypted in transit and at rest.
Clausely Productivity Tool
Category: Document Analysis / Legal
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Uploaded documents for analysis | Yes (stored by Quantrolix; sent to Groq only after in-app permission) | Clause extraction, contract analysis, and review history | Quantrolix servers and Groq, Inc. (AI inference provider); contract text may include personal data written in the document |
| Analysis results & annotations | Yes | Document review history | None |
| User preferences & templates | Yes | Personalized analysis | None |
| Crash data (from macOS 1.0.7 build 1.0.19) | Only after you opt in; off by default | Diagnose and fix app crashes | Sentry, our crash-report processor; a minidump may include contract text or other personal information in app memory |
Clausely stores uploaded documents, extracted contract text, and analysis results on Quantrolix servers so the contract and its review history remain available in the app. Contract text is sent to Groq, Inc. only after you grant the in-app permission described above; it is not guaranteed to be anonymized and may contain personal data written in the document. Groq does not retain inference inputs and outputs by default, but may temporarily log them for up to 30 days to troubleshoot reliability issues or investigate suspected abuse unless zero-data-retention controls are enabled. Groq does not use contract text to train models. You may withdraw AI permission in the app to stop future AI transmissions. To request deletion of stored Clausely documents or account data, use the contact methods in Section 13.
Beginning with Clausely for macOS version 1.0.7 build 1.0.19, optional crash reporting is off until you opt in. After Clausely automatically restarts with your choice enabled, a crash may send a minidump to Sentry with the app version/build, operating system, process type, and a random report identifier. This opt-in covers only that app launch: sharing switches off when Clausely quits, and you must opt in again to share crashes during another launch. A minidump is a snapshot of process memory and may contain contract text or personal information that was open in the app; we cannot scrub that memory before transmission. We do not intentionally attach your account ID, email address, or contract as separate crash-report fields. Reports collected before you opt in stay local and are not uploaded. Turning crash reporting off stops future uploads immediately; reports already sent remain subject to the crash-report retention and deletion terms in Section 6. Our current Sentry plan retains Clausely crash reports for 30 days. We use these reports only to diagnose crashes, not for advertising or tracking.
Quantrolix Launcher General
Category: Utility / App Management
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Installed app list | Yes (local) | App launch management | None |
| App usage frequency | Yes (local) | Quick-launch ordering | None |
| Update check requests | Yes | Keep apps up to date | Our update server only |
The Launcher is a utility application that primarily stores data locally. Update check requests transmit only the app version number and platform to our update server.
VacancyFox Rental Listing & Lead Management
Category: Rental listing / landlord workflow
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Account, contact, and authentication data | Yes | Create and secure a landlord account; sign in and manage account settings | None |
| Property/listing details, generated content, photos, and video outputs | Yes | Create, publish, and manage rental listings and marketing materials | None |
| Property facts submitted for AI content generation | Yes, when you request it | Generate listing descriptions, captions, and flyer copy | Configured VacancyFox AI Gateway |
| Lead name, email, phone, and message | Yes, when submitted through a listing | Deliver and manage a landlord's prospective-renter leads | Resend and Twilio only for configured lead notifications |
| Subscription status and Stripe customer/subscription identifiers | Yes, for a paid subscription | Manage subscription access and billing status | Stripe |
| Full payment-card details | No | N/A | Handled by Stripe |
VacancyFox retains the account and its property, listing-content, lead, subscription-record, and associated media records while the account exists to provide the service. Photos and rendered video outputs are stored under the account's properties. In the current source, passwords are stored as bcrypt hashes and account records are served through authenticated routes; this is a description of the implementation, not a security certification. When configured, Resend sends landlord lead-notification email and Twilio sends landlord lead-notification SMS; lead capture itself does not depend on a notification being sent.
You can delete your VacancyFox account from the in-app Account page. If an active web subscription exists, VacancyFox must confirm its cancellation with Stripe before deletion proceeds. Deletion removes the account and its linked properties, photos, listing content, leads, subscription record, and video-job records through the application's cascade relationships, then attempts to remove that account's stored photo and video outputs. A failed cancellation confirmation leaves the account and records in place.
ScheduleHub Workforce Scheduling
Category: Business / Employee Scheduling
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Employee name, optional email and phone, employee/account and business identifiers | Yes, when provided by your business | Staff roster, sign-in, tenant access, and scheduling | Your authorized business managers; Quantrolix-hosted application backend |
| Business/location names and workplace addresses | Yes, when provided by your business | Location management and shift assignment | Your authorized business managers; Quantrolix-hosted application backend |
| Hourly pay rates, assigned shifts, availability, time-off and shift-swap requests, and time records | Yes, when entered or imported | Workforce scheduling, request handling, labor reporting, and time records | Your authorized business managers; Quantrolix-hosted application backend |
| Authentication credentials and security request metadata, including IP address | Yes | Sign-in, access control, rate limiting, and security auditing | Quantrolix-hosted application backend |
| Mac app error and crash reports, stack traces, diagnostic breadcrumbs, app version, and device/operating-system context | Yes, in release builds with error reporting enabled | Diagnose and repair application failures | Sentry |
| Advertising identifiers or cross-app tracking data | No | N/A | N/A |
Workforce records are associated with the employee and business that provided them. Your business controls roster entries and scheduling information; contact its manager to request corrections. For application-data access or deletion requests, contact us as described in Section 13. Error reporting is configured not to send default personal information; error messages and diagnostic context can nevertheless contain information about the action that failed. We do not describe those reports as anonymous. ScheduleHub does not send workforce records to an AI provider or collect advertising tracking data.
BuildHound Site Photos & Material Lists
Category: Construction job-site documentation
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Account, name, email, and authentication data | Yes | Create and secure a BuildHound account; sign in and manage account settings | None |
| Job-site photos captured with the camera | Yes, when you capture one | AI product identification and job-site photo documentation. Barcode frames and LiDAR distance readings stay on the device and are never uploaded. | Quantrolix AI Gateway (approved product photos only) |
| Job and material-list data you create | Yes | Organize jobs, material lists, and captured photos by site | None |
| Subscription status and purchase history | Yes, for a paid subscription | Manage DIY Pro / Contractor subscription access | Apple (StoreKit) |
| Full payment-card details | No | N/A | Handled by Apple's In-App Purchase |
The camera is used only when you choose to photograph a product for AI identification, scan a barcode, or estimate a LiDAR distance. Approved product photos are uploaded for identification; barcode frames and LiDAR depth or spatial data stay on your device. BuildHound retains your account, jobs, material lists, and captured photos while your account exists to provide the service. Photos and project data are stored in your account and are never sold.
You can delete your BuildHound account and its associated data from the app's account settings.
Quantrolix SaaS Platform
Category: Platform / Dashboard
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Account & subscription data | Yes | Unified account management | Stripe (billing only) |
| Cross-app preferences | Yes | Unified settings | None |
| Dashboard usage analytics | Yes | Service improvement | None |
Quantrolix SaaS serves as the unified dashboard for managing your Quantrolix account, subscriptions, and cross-application settings.
Comm Hub Internal Service
Category: Internal / Coordination
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Service coordination messages | Yes | Inter-service communication | None (internal only) |
| Task and activity logs | Yes | Development coordination | None (internal only) |
Comm Hub is an internal coordination service. It does not collect end-user personal data. Any operational data is used solely for service coordination and development purposes.
ML Service Internal Service
Category: Internal / Machine Learning
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Anonymized training data | Yes (anonymized) | Model training and improvement | None |
| Prediction request logs | Yes (anonymized) | Model accuracy monitoring | None |
| Model performance metrics | Yes | Quality assurance | None |
The ML Service is our internal machine learning infrastructure. It processes only anonymized, aggregated data for model training. No PII is used in model training or stored by this service. You may opt out of having your anonymized data included in model training by contacting privacy@quantrolix.com.
Quantrolix Landing (Website) Website
Category: Marketing / Website
| Data Type | Collected | Purpose | Shared With |
|---|---|---|---|
| Standard web-edge request metadata (IP address; request timestamp, path, and user agent where logged) | Yes, at the Quantrolix-hosted web edge | Security and operations | Quantrolix-hosted web edge |
| Contact form submissions | Yes (if submitted) | Responding to inquiries | None |
The Quantrolix landing website (quantrolix.com) does not use third-party analytics, tracking pixels, or advertising cookies. Its web-edge request logs follow service-specific operational retention and applicable legal requirements.
13. Data Subject Requests & Account Deletion
13.1 How to Submit a Request
You may submit a data subject request through any of the following channels:
- Email: privacy@quantrolix.com
- Web form: apps.quantrolix.com/privacy/request
- In-app: The privacy or account settings provided by the applicable application, where available
13.2 Identity Verification
To protect your privacy, we verify your identity before processing data requests. We will ask you to confirm your identity using information associated with your account (e.g., the email address used to register). We will not request additional sensitive information for verification.
13.3 Response Timeline
- Acknowledgment: Within 3 business days of receipt.
- Fulfillment: Within 30 days (GDPR) or 45 days (CCPA/CPRA). If additional time is needed for complex requests, we will notify you of a 30-day extension with an explanation.
13.4 Data Export Format
Where an export is available, it is provided in JSON format and organized by applicable application. It covers the data associated with the verified account for that application, subject to the implementation and any legal retention requirements. Delivery method depends on the applicable application's verified account or request process.
13.5 Account Deletion Process
When you request account deletion, we apply the verified account's application-specific deletion process and applicable legal retention requirements:
- Account and related records: The applicable application deactivates or deletes the verified account and the records linked to it according to that application's implementation.
- VacancyFox: Before deleting an account with an active web subscription, VacancyFox confirms cancellation with Stripe. Its account deletion then uses its local cascade relationships and attempts to remove that account's stored photo and video outputs.
- Retention and backups: Data handling after deletion follows the applicable application's retention practices and any legal requirements; this policy does not promise a universal deletion timeline across separate applications or data stores.
- Exceptions: Transaction records subject to tax compliance (7-year retention) are anonymized rather than deleted: your name and email are removed, but the transaction amounts and dates are retained in anonymized form as required by law.
Deletion is irreversible. We recommend exporting your data before requesting deletion. The applicable application or request process confirms completion where it provides a confirmation channel.
14. Cookies & Tracking Technologies
14.1 What We Use
Cookie and authentication technologies apply only to the web services and applications that use them; they do not apply to every covered application. Market Pulse does not use account authentication, auth cookies, or JWT refresh tokens in its current iOS app.
| Technology | Purpose | Duration | Required? |
|---|---|---|---|
| Session cookie (auth token; applicable web services/apps) | Maintain a logged-in session where account authentication is used | Session / 7 days | Essential |
| JWT refresh token (applicable web services/apps) | Refresh account authentication without re-login where that mechanism is used | 30 days | Essential |
| User preferences (localStorage) | Store UI preferences (theme, language) | Persistent | Functional |
| Sentry session tracking (participating apps only; not Terpa) | Error reporting and crash diagnosis | Session | Performance |
14.2 What We Do NOT Use
- No third-party analytics cookies (no Google Analytics, no Amplitude, no Mixpanel)
- No advertising cookies or tracking pixels
- No cross-site tracking
- No fingerprinting technologies
- No social media tracking widgets
For web services and applications where we use cookies, we use only essential and functional cookies and no third-party tracking cookies; a cookie consent banner is not required under most frameworks. You may clear browser cookies at any time through your browser settings.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes:
- Minor changes (clarifications, formatting): Updated with a new "Last Updated" date.
- Material changes (new data collection, new third-party sharing, rights changes): We will notify you at least 30 days in advance via email to your registered address, in-app notification, and a prominent notice on this page.
Your continued use of our Services after the changes take effect constitutes acceptance of the updated policy. If you do not agree with the changes, you may delete your account before the changes take effect.
Previous versions of this policy are available upon request.
16. Contact Us
If you have questions about this Privacy Policy, our data practices, or wish to exercise your rights, contact us at:
- Quantrolix
- Operated by Dustin Newcomb
- Scottsdale, AZ, United States
- Privacy & Data Requests: privacy@quantrolix.com
- General Support: support@quantrolix.com
- DMCA Notices: dmca@quantrolix.com
- Legal: legal@quantrolix.com
- Data Subject Request Portal: apps.quantrolix.com/privacy/request
We aim to respond to all privacy-related inquiries within 3 business days.