Privacy Notice
In one line
What personal data we collect, why, who helps us process it, how long we keep it, and how you use your rights, with annexes for each country we serve.
The short version
This short version helps you understand the full text. Read the full text for the complete terms.
- We collect what we need to run qypu: account details, the content you give us, data from channels you connect, and security logs. (Full text, section 3)
- For your workspace content, your business decides how it is used and we follow your instructions. For our own website and accounts, we decide. (Section 2)
- We never sell personal data. We do not use it for targeted advertising, and we do not use your content to train AI models. (Section 5)
- AI providers process content to produce drafts. They are bound by contract and listed on our Subprocessors page. (Sections 4 and 6)
- We keep data only as long as we need it. When you disconnect a channel, we delete its access tokens straight away. (Section 8)
- You can ask to see, correct, delete, or move your data, and to object. We reply within the time your local law sets. (Section 10)
- Some data is stored outside your country. We use legal safeguards for those transfers. (Section 9)
- Country-specific rights are in the annexes at the end. (Annexes A to H)
Full text
Read the full text (about 10 minutes)
1. Who we are
[ENTITY NAME], of [REGISTERED ADDRESS], runs qypu at qypu.ai and app.qypu.ai. Contact our privacy team at [CONTACT EMAIL]. [DATA PROTECTION OFFICER / PRIVACY OFFICER — name and contact, see Counsel flags.] [EU, UK, AND SWISS REPRESENTATIVES — if required.]
2. Our role
2.1 Controller. We are the controller for personal data about website visitors, people who contact us, and the account owners and Authorised Users of our customers (account, billing, and security data).
2.2 Processor or service provider. For personal data inside a customer's workspace (for example, names in brand content, comments on the customer's channels, or staff names), the customer is the controller and we are its processor (in US state law terms, its service provider). The Data Processing Addendum governs that processing. If you are a customer of one of our customers, contact that business first; we will help them respond.
3. What we collect
- Account data: name, work email, business name, role, sign-in records (through WorkOS), and billing details (through our payment provider).
- Workspace content: Brand Kit answers, hard facts, never-say lists, uploaded images, audio, and video, drafts, edits, comments, signatures, and Authorisation records.
- Connected channel data: access tokens and the profile, page, post, comment, and insight data covered by the permissions you grant on Meta (Facebook and Instagram), TikTok, LinkedIn, Google (YouTube), and other platforms you choose.
- Voice and likeness data: only if you choose to use voice or likeness features and give the consent described in our Voice and Likeness Consent Policy.
- Usage and security data: IP address, device data, browser data, audit logs, error reports (Sentry), and rate-limit records (Upstash).
- Communications: messages you send us, and support notes.
- Website data: strictly necessary cookies only, unless you accept optional cookies (see the Cookie Notice).
We do not ask for sensitive data (such as health, religion, or political opinions) and our Content Policy forbids using qypu to target people on those grounds.
4. Why we use it (and our legal bases)
| Purpose | Legal basis (where the law asks for one) |
|---|---|
| Provide the service you signed up for | Contract |
| Draft content with AI, run Checks, and publish signed posts | Contract; for workspace content, the customer's instructions |
| Keep qypu secure, prevent abuse, and debug errors | Legitimate interests (security); legal obligation |
| Bill you and keep tax records | Contract; legal obligation |
| Send service and security notices | Contract; legitimate interests |
| Send product news | Consent, or legitimate interests where the law allows, with a one-click opt-out |
| Comply with law and defend legal claims | Legal obligation; legitimate interests |
5. What we do not do
- We do not sell personal data, or "share" it for cross-context behavioural advertising as US state laws define those terms.
- We do not use workspace content or platform data to train or fine-tune AI models.
- We do not use platform data for advertising profiles, data brokering, or surveillance.
- We do not make decisions about people using AI alone that have legal or similarly significant effects on them.
6. Who we share it with
- Subprocessors that host, store, secure, or process data for us (listed with locations on our Subprocessors page).
- The platforms you instruct us to publish to. Once a post is published, the platform's own privacy policy applies.
- Professional advisers under confidentiality.
- Authorities, only where the law requires it (see our Government Requests page).
- A buyer of our business, under equal protections, with notice to you.
7. Google, YouTube, Meta, TikTok, and LinkedIn data
7.1 Our use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. By connecting YouTube you also agree to the YouTube Terms of Service, and Google's handling is described in the Google Privacy Policy. You can revoke access in your Google security settings.
7.2 We use platform data only to provide the features you use, we keep it no longer than the platform allows, and we delete it when you disconnect or when the platform requires (see the Data Retention and Deletion Policy).
8. How long we keep it
See the Data Retention and Deletion Policy for the full table. In short: access tokens are deleted when you disconnect; workspace content is deleted within 30 days after you close your workspace; billing records are kept as long as tax law requires (usually 6 to 10 years); security logs are kept for up to 12 months.
9. International transfers
9.1 Our main processing locations are listed on the Subprocessors page. [CURRENT DATABASE REGION: Singapore; TARGET REGION: to be decided — see Security Overview.]
9.2 When we transfer personal data out of the EU, EEA, UK, or Switzerland, we use an adequacy decision (including the EU–US Data Privacy Framework and its UK and Swiss extensions where the recipient is certified), or the EU Standard Contractual Clauses with the UK Addendum or Swiss amendments, plus a transfer risk assessment.
9.3 For other countries, we use contracts that give comparable protection, as the annexes describe.
10. Your rights
10.1 Depending on where you live, you can ask us to: confirm whether we hold your data and give you a copy; correct it; delete it; restrict or object to its use; give it to you or another provider in a portable format; and withdraw consent at any time.
10.2 Send requests to [CONTACT EMAIL]. We may need to verify your identity. We will not charge you unless the law allows a fee for clearly excessive requests.
10.3 We reply within the time your local law sets (for example, 1 month in the EU and the UK, 30 days in Canada and Switzerland, 20 working days in New Zealand, and 45 days in California), and tell you if we need an extension the law permits.
10.4 You can complain to us, and you can complain to your data protection authority at any time (see the annexes).
11. Security
We protect data with the measures in our Security Overview. If a breach puts your rights at risk, we will tell you and the regulator as the law requires (see the Incident and Breach Notification Policy).
12. Children
qypu is not for children. We do not knowingly collect children's personal data, except where a customer includes a child in content with a parent's or guardian's consent, as our Children and Minors Policy requires.
13. Changes
We will post changes here with a new version number and record them in the change log. For material changes, we will email account owners at least 30 days in advance.
Annex A — United States
- Who this covers: residents of California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other states with similar laws, where those laws apply to us.
- Categories collected (last 12 months): identifiers; commercial information (plan and billing); internet activity (logs); audio and visual information (media you upload); professional information (role); and inferences limited to service features (for example, best posting times for your channel).
- Sources: you, your business, platforms you connect, and our service providers.
- Sale and sharing: we do not sell personal information or share it for cross-context behavioural advertising, and we have not done so in the last 12 months. We honour Global Privacy Control signals as an opt-out.
- Sensitive personal information: we do not use it to infer characteristics. Voice data used for voice features is handled only with consent (and, where Illinois, Texas, or Washington biometric laws apply, with the written release those laws require).
- Your rights: know, access, correct, delete, portability, opt out of sale, sharing, targeted advertising, and profiling, and limit use of sensitive data; appeal a refusal by replying to our decision. We do not discriminate against you for using your rights. An authorised agent may act for you with proof.
- Children (COPPA): we do not set out to collect personal information online from children under 13.
Annex B — Canada (including Quebec)
- PIPEDA and provincial laws (Alberta and British Columbia PIPA, and Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25) apply.
- Our person in charge of the protection of personal information is [NAME AND TITLE] at [CONTACT EMAIL].
- We collect with consent appropriate to the sensitivity of the data. You may withdraw consent subject to legal and contractual limits.
- Quebec: we tell you when we use technology that can identify, locate, or profile you, and how to turn it off; we conduct a privacy impact assessment before transferring personal information outside Quebec; and you can ask for computerised personal information in a structured, commonly used format.
- Complaints: the Office of the Privacy Commissioner of Canada, or the Commission d'accès à l'information du Québec.
- Our marketing emails follow Canada's Anti-Spam Legislation (CASL): we send them only with consent, identify ourselves, and include an unsubscribe link that works within 10 business days.
Annex C — United Kingdom
- UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR) apply, as amended by the Data (Use and Access) Act 2025.
- Our UK representative under UK GDPR Article 27: [NAME AND ADDRESS, if required].
- You can complain to us first; we acknowledge complaints within 30 days. You can also complain to the Information Commissioner's Office (ico.org.uk).
Annex D — European Union and EEA
- The GDPR and national laws implementing the ePrivacy Directive apply.
- Our EU representative under GDPR Article 27: [NAME AND ADDRESS, if required].
- You can complain to the supervisory authority where you live or work, or where the alleged breach occurred.
- AI transparency obligations under the EU AI Act are covered in our AI Transparency and Disclosure Policy.
Annex E — Switzerland
- The revised Federal Act on Data Protection (revFADP) applies.
- Our Swiss representative under Article 14 revFADP: [NAME AND ADDRESS, if required].
- Transfers follow the Federal Council's list of adequate countries, the Swiss–US Data Privacy Framework, or the EU Standard Contractual Clauses with Swiss amendments.
- You can complain to the Federal Data Protection and Information Commissioner (FDPIC).
Annex F — Singapore
- The Personal Data Protection Act 2012 (PDPA) applies.
- Our Data Protection Officer: [NAME] at [CONTACT EMAIL].
- We notify the Personal Data Protection Commission within 3 calendar days of assessing that a notifiable breach occurred, and affected people where the PDPA requires.
- We check the Do Not Call Registry before sending marketing messages to Singapore telephone numbers.
- You can complain to the PDPC.
Annex G — Australia
- The Privacy Act 1988 and the Australian Privacy Principles (APPs) apply, including the 2024 amendments.
- You can access and correct your personal information under APPs 12 and 13.
- Overseas recipients: our subprocessors are located in the countries listed on the Subprocessors page. We take reasonable steps under APP 8 to ensure they handle your data consistently with the APPs.
- Automated decisions: we do not use computer programs to make decisions that significantly affect your rights or interests without human involvement. If this changes, we will describe it here before the APP 1.7 obligations commence on 10 December 2026.
- Breaches: we follow the Notifiable Data Breaches scheme.
- Complaints: contact us first. If you are not satisfied within 30 days, contact the Office of the Australian Information Commissioner (oaic.gov.au).
- Our marketing emails follow the Spam Act 2003.
Annex H — New Zealand
- The Privacy Act 2020 and its Information Privacy Principles (IPPs) apply.
- Our Privacy Officer: [NAME] at [CONTACT EMAIL].
- When we collect personal information about you from someone else (for example, a customer naming you in content), we take reasonable steps under IPP 3A to make sure you know, unless an exception applies.
- Cross-border disclosures follow IPP 12.
- Breaches likely to cause serious harm are notified to the Privacy Commissioner and affected people as soon as practicable.
- Complaints: the Office of the Privacy Commissioner (privacy.org.nz).
Change log
- 2026-10-10 · 0.1.0 · First draft for counsel review, replacing the earlier draft at /legal/privacy.
Open questions for counsel
We publish these while the page is a draft, so you can see what is not settled yet.
- Representatives: EU Art. 27 GDPR, UK Art. 27 UK GDPR, and Swiss Art. 14 revFADP may be required depending on where the entity is established; confirm the "occasional processing" exemption does not apply.
- DPO: mandatory in Singapore (PDPA s.11(3)); Quebec requires a person in charge (defaults to the CEO); NZ requires a privacy officer; assess GDPR Art. 37.
- Database region: the current Supabase database is in Singapore and shared with another product; transfer mechanisms from the EU, UK, and Switzerland to Singapore need SCCs and a transfer risk assessment.
- US state law thresholds: most state laws will not apply to qypu as a controller at launch; confirm which apply and whether to keep the annex voluntary.
- Biometric laws (Illinois BIPA, Texas CUBI, Washington): confirm whether voice-cloning features create "voiceprints".
- Response times in section 10.3: confirm each figure for each jurisdiction before publishing.
- UK complaints-handling duty under the Data (Use and Access) Act 2025: confirm commencement date.
- NZ IPP 3A commencement (1 May 2026) and Australian APP 1.7 to 1.9 commencement (10 December 2026): confirm.
Useful for: Business owners, Your staff, IT and security reviewers, Platform reviewers. To save this page as a PDF, use your browser's Print command. Back to the trust centre.