QuillCaddieLegal center
ConsumerBusiness
Sign up

Legal policy

QuillCaddie Privacy and Cookies Policy

Privacy, cookies, AI processing, connected tools, sharing, retention, and rights requests.

Effective date: May 28, 2026Last updated: May 28, 2026

Related policies

Shared legal policies that apply across consumer and business use.

Privacy and Cookies PolicyPrivacy, cookies, AI processing, connected tools, sharing, retention, and rights requests.AI and Data Use PolicyAI processing, model-training defaults, opt-in controls, human review, and provider boundaries.Data Retention and Deletion PolicyRetention and deletion rules for captures, transcripts, AI outputs, workspaces, and raw audio.Acceptable Use PolicyRules for acceptable use, restricted content, recordings, automation, and enforcement.Audio Recording and Consent PolicyAudio recording, speaker consent, meeting-style capture, raw audio, and transcription boundaries.Integrations and Connected Tools PolicyConnected tools, export actions, MCP, BYOK, and third-party integration boundaries.Billing, Subscriptions, and Refund PolicyBilling, renewals, cancellation, trials, refunds, and taxes.Copyright and DMCA PolicyCopyright notices, counter-notices, repeat-infringer policy, and designated contact.Accessibility StatementAccessibility commitment, current focus areas, feedback, and third-party content boundaries.
Legal CenterConsumer Legal CenterBusiness Legal Center

Version: v1.3 Streamlined
Operator: Bobby Built Ventures LLC d/b/a QuillCaddie

Applies to: All QuillCaddie website visitors, users, customers, workspace members, and workspace administrators.

Quick summary

QuillCaddie handles sensitive idea-capture content, including audio, transcripts, source text, screenshots, links, AI outputs, project context, and exports. We use this information to provide the Service, not to sell it. Customer Content is not used for generalized model training by default. Cookies and local storage support authentication, preferences, offline capture, analytics, and security.

1. Scope

This Policy explains how QuillCaddie collects, uses, discloses, stores, protects, and deletes personal information and Customer Content when you use our website, web app, APIs, exports, integrations, AI-assisted processing, and related services.

This Policy does not apply to third-party services you connect to, visit, export to, or use outside QuillCaddie. Those services are governed by their own terms and privacy policies.

2. Information we collect

2.1 Account and profile information

We may collect your name, display name, username, email address, avatar, bio, timezone, authentication identifiers, account settings, workspace memberships, roles, plan status, billing status, and communication preferences.

2.2 Captures and User Content

Depending on how you use the Service, we may collect and process raw audio, uploaded audio files, transcripts, source text, notes, prompts, screenshots, images, files, filenames, file metadata, links, URLs, page titles, folders, tags, product/project context, vocabulary terms, corrections, generated summaries, prompts, artifacts, action items, exports, share settings, connector data, and related metadata.

2.3 Audio and microphone data

If you record audio in the browser or app, your device may ask for microphone permission. Audio may be saved locally first for offline/slow-network reliability and uploaded if you save or process the capture. Raw audio is temporary by default.

2.4 Workspace and team information

For shared workspaces, we may collect invitations, roles, membership status, admin settings, audit log events, connector settings, retention settings, feature flags, and workspace-level usage.

2.5 Integration information

If you connect third-party services, we may collect provider names, account labels, external account IDs, scopes, token references, expiration metadata, connection status, action logs, selected external files/pages/issues/repos/channels, and content you authorize us to retrieve or send.

OAuth tokens and secrets should be encrypted or stored using a secure secrets mechanism. We do not intentionally log OAuth tokens.

2.6 Usage, device, and log information

We may collect usage events, feature interactions, capture type, processing status, export events, error events, approximate location derived from IP address, IP address or hashed IP, user-agent or hashed user-agent, device type, browser type, operating system, pages viewed, referring URLs, timestamps, session events, performance metrics, and security events.

We design logs to avoid raw audio, raw transcript text, full AI outputs, full prompts, signed URLs, provider keys, OAuth tokens, secrets, and sensitive user content.

2.7 Billing information

Paid subscriptions may be processed by third-party payment processors or app stores. We may receive billing status, plan, transaction identifiers, payment method type, last four digits, billing address, tax information, invoice history, trial status, renewal status, and failed-payment events. We do not store full card numbers.

2.8 Communications

If you contact us, we collect messages, attachments, contact information, support history, feedback, survey responses, and related metadata.

3. How we use information

We use information to:

  • provide, operate, maintain, and improve the Service;
  • create, save, sync, organize, process, search, export, and share captures;
  • transcribe audio and generate AI-assisted outputs;
  • preserve source truth separately from AI-generated outputs;
  • support folders, tags, products/projects, templates, vocabulary, corrections, and builder workflows;
  • provide offline capture, local draft recovery, and sync reliability;
  • process payments, trials, subscriptions, taxes, and billing support;
  • authenticate users, manage accounts, enforce roles, and maintain workspace access controls;
  • provide integrations when authorized;
  • provide support and communicate about the Service;
  • monitor usage limits, costs, abuse, fraud, security, and reliability;
  • debug, test, secure, and improve product performance;
  • comply with law and enforce agreements; and
  • improve the product using content-free analytics, synthetic examples, internal dogfood examples, public/non-sensitive examples, and optional user-submitted feedback or model-contribution content as described in the AI and Data Use Policy.

4. AI, transcription, and model training

QuillCaddie uses AI and transcription providers to process captures and generate outputs. Customer Content is not used for generalized QuillCaddie model training by default. Operational processing to provide requested features is not model training.

See the AI and Data Use Policy for details about provider processing, model-contribution opt-ins, human review, support access, BYOK, and data-use controls.

5. How we disclose information

We may disclose information to:

5.1 Service providers and subprocessors

We use vendors for hosting, storage, database, authentication, transcription, AI processing, analytics, observability, email, billing, support, security, and infrastructure. These providers process information on our behalf under applicable contracts or terms.

5.2 Third-party integrations you authorize

If you connect a third-party service or trigger an outbound action, we may disclose User Content and metadata to that service according to your authorization, workspace settings, and the connector design.

5.3 Workspace members and administrators

Content in a shared workspace may be visible to other members depending on roles, permissions, folder settings, share settings, and admin controls. Workspace owners and administrators may access workspace content, audit logs, settings, usage, exports, and member information.

5.4 Public or shared links

If you create a public or shared link, people with access to the link may see the content you choose to share.

5.5 Legal, safety, and compliance

We may disclose information if reasonably necessary to comply with law or legal process, enforce our terms, protect rights and safety, investigate fraud or abuse, protect the Service, or respond to emergencies.

5.6 Business transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, information may be transferred as part of that transaction, subject to appropriate protections.

6. Cookies, local storage, and similar technologies

We may use cookies, localStorage, sessionStorage, IndexedDB, service workers, pixels, tags, SDKs, email pixels, and similar technologies.

6.1 Essential technologies

Essential technologies support authentication, account security, CSRF protection, session management, workspace routing, billing, load balancing, fraud prevention, service availability, and privacy choices.

6.2 Offline capture and local storage

QuillCaddie may use IndexedDB and related browser storage to save local drafts, audio blobs, offline capture queues, sync metadata, and app settings before upload. Clearing browser storage, using private browsing, switching devices, uninstalling the app, or disabling local storage may delete unsynced local captures.

6.3 Preferences

Preference technologies may remember theme, background, language, timezone, default workspace, raw audio retention preference, and capture settings.

6.4 Analytics and performance

Analytics and performance tools may help us understand usage, detect errors, improve onboarding, monitor reliability, and prioritize features. Analytics events should not contain raw audio, raw transcripts, full AI outputs, OAuth tokens, provider keys, signed URLs, or sensitive content.

6.5 Marketing and advertising

QuillCaddie does not need advertising pixels to provide the core Service. If we enable advertising pixels, cross-context behavioral advertising, referral tracking, or affiliate tracking, we will update this Policy and provide legally required consent or opt-out controls.

7. Sale, sharing, and targeted advertising

QuillCaddie does not sell personal information for money. If QuillCaddie later uses advertising pixels, cross-context behavioral advertising, targeted advertising, or affiliate/referral tracking, those activities may be considered “sharing,” “targeted advertising,” or similar terms under some laws. We will provide required choices before enabling those activities where legally required.

8. Data retention

We retain information as described in the Data Retention and Deletion Policy. Raw audio is temporary by default. Source text, transcripts, AI outputs, metadata, folders, tags, products, and exports generally remain until deleted by you, your workspace admin, or account/workspace deletion flows, unless a retention setting says otherwise. Logs, audit records, billing records, security records, and backups may be retained for different periods.

9. Security

We use reasonable technical and organizational measures designed to protect information, such as private storage, signed URLs, access controls, row-level security for workspace-scoped tables, encryption in transit, limited access, provider-key protection, and logging restrictions. No system is completely secure.

10. Your choices and rights

Depending on your location, plan, and workspace settings, you may have rights to access, correct, export, delete, restrict, object to, or opt out of certain processing of your personal information. You may also have rights related to targeted advertising, sale, sharing, profiling, sensitive information, and optional model-contribution uses.

You can exercise rights through in-product settings where available or by contacting privacy@quillcaddie.com. We may need to verify your identity. If you are in a shared workspace, some content may be controlled by the workspace owner or administrator.

11. Notice at collection

At or before collection, QuillCaddie may collect the categories described above, including identifiers, account/profile information, customer records, internet/network activity, approximate geolocation, audio/voice content you provide, User Content, professional or employment-related information if included in content or business workspaces, commercial information, and inferences generated by the Service.

We collect this information for the purposes described in this Policy, retain it according to our retention rules, and disclose it as described in this Policy.

12. U.S. state privacy notice

Residents of certain U.S. states may have additional privacy rights. These may include rights to know/access, correct, delete, port, opt out of targeted advertising/sale/sharing/profiling where applicable, limit certain sensitive-information uses, and appeal a privacy-rights decision.

Contact privacy@quillcaddie.com to exercise rights. Where legally required, we will honor recognized opt-out preference signals for sale/sharing/targeted advertising if those activities are enabled.

13. European, UK, Swiss, and other international users

Where GDPR, UK GDPR, Swiss law, or similar law applies, our legal bases may include performance of a contract, legitimate interests, consent, compliance with legal obligations, and vital interests in emergencies. You may have rights to access, rectify, erase, restrict, object, port data, withdraw consent, and lodge a complaint with a supervisory authority.

We may process and store information in the United States and other countries where we or our subprocessors operate. Where required, we use appropriate transfer mechanisms.

14. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Contact privacy@quillcaddie.com if you believe a child under 13 provided personal information.

15. Communications

We may send service communications, security notices, product updates, billing messages, support replies, and marketing communications where permitted. You can unsubscribe from marketing emails using the unsubscribe link. You may still receive service, billing, security, and legal messages.

16. Law-enforcement and legal requests

We require valid legal process before disclosing non-public user information unless an emergency or legal exception applies. We review requests for facial validity and narrowness, and where allowed, we may notify affected users.

17. No regulated-data commitment without agreement

QuillCaddie is not designed for HIPAA-covered protected health information, PCI cardholder data, classified information, or similarly regulated data unless QuillCaddie signs a specific written agreement covering that use.

18. Changes

We may update this Policy from time to time. If changes are material, we will provide notice by email, in-app notice, website notice, or another reasonable method. The updated Policy becomes effective when posted unless a later date is stated.


Contact

Support: support@quillcaddie.com
Privacy requests: privacy@quillcaddie.com
Security reports: security@quillcaddie.com
Legal notices: legal@quillcaddie.com
DMCA notices: dmca@quillcaddie.com
Mail: Bobby Built Ventures LLC d/b/a QuillCaddie, 1500 N Grand St, STE R, Denver, CO 80203