Privacy Policy
Effective August 18, 2026
This policy explains what personal data Quillstream processes, why, who processes it with us, and the rights you have over it. The data controller is Shiftclawco, reachable for any privacy matter at shiftclawco@gmail.com.
1. Data we process
- Account data — name, email address, the organizations you belong to and your role in them, plus sign-in events.
- Workspace content — the documents, drafts, comments and review decisions created in your organization, and the Markdown files of the GitHub repositories you connect.
- Integration data — the GitHub installation and repository metadata needed to read and write on your behalf, and the agent API tokens you mint.
- Billing data — plan, subscription status and billing contact. Card numbers are handled by Stripe and never reach our servers.
- Technical data — IP address, user agent, and request and error logs produced when you use the service.
2. Why we process it
We process account, workspace, integration and billing data to perform the contract with you: to run the service, sync your repositories, generate the drafts you request, apply plan limits and take payment. We process technical data on our legitimate interest in keeping the service secure, available and free of abuse, and we keep billing records to meet our legal accounting obligations. Where we ever rely on consent — for optional product email, for example — you can withdraw it at any time.
3. AI processing
When you or one of your agents ask for a generated draft, the relevant document content and prompt are sent to our AI provider to produce a response, and that response comes back as a proposal a human still has to approve. Your content is not used to train models, neither by us nor — under our agreement with them — by the provider. If you do not want content processed this way, do not use the AI features.
4. Sub-processors
We do not sell personal data and we do not share it for advertising. We rely on the following processors, each bound by a data-processing agreement and each limited to the purpose shown:
WorkOS
Authentication, organization membership and session management
Data: Name, email address, organization membership and sign-in events
Convex
Application database and backend functions
Data: Account records, organization data, documents, drafts and review history
Stripe
Subscription payments, invoicing and the billing portal
Data: Billing contact, subscription and payment status. Card details go to Stripe directly and never reach our servers
Groq
AI inference for agent-generated drafts and suggestions
Data: The document content and prompt text submitted for a generation, transmitted at the moment of the request
GitHub
Repository connection, file synchronisation and direct commits to the default branch of the repositories you connect
Data: Repository metadata and the Markdown files of the repositories you connect
Vercel
Application hosting, edge delivery and request logging
Data: IP address, user agent and request metadata in operational logs
5. International transfers
Some of these providers process data outside the European Economic Area, principally in the United States. Those transfers are covered by the European Commission’s standard contractual clauses or another lawful transfer mechanism offered by the provider.
6. Retention
Account and workspace data is kept while your organization is active. When you delete a document it is removed from the active workspace; when an organization is deleted, its account and workspace data is deleted within 30 days, except where we must keep something longer. Billing records are kept for the period required by tax and accounting law (normally ten years). Operational logs are kept for up to 90 days. Content in your own GitHub repositories stays there and is under your control.
7. Security
Access to the service requires authentication, data is encrypted in transit, and access to an organization’s data is restricted to its members and to the small number of people who operate the service. Agent API tokens are scoped to a single organization and can be revoked at any time. No system is perfectly secure; if a breach affects your personal data we will notify you and the supervisory authority as the law requires.
8. Your rights
Under the GDPR you can request access to your personal data, its correction or erasure, the restriction of or objection to its processing, and a portable copy of the data you provided. Write to shiftclawco@gmail.com and we will respond within one month. You also have the right to lodge a complaint with your supervisory authority — in Italy, the Garante per la protezione dei dati personali.
9. Cookies
We use a minimal set of strictly necessary cookies and no advertising or cross-site tracking. They are described in our Cookie Policy.
10. Children
The service is intended for professional use and is not directed at children under 16. We do not knowingly collect their personal data; if you believe we have, contact us and we will delete it.
11. Changes to this policy
We update this policy when our processing changes. The effective date at the top of the page always reflects the current version, and material changes are announced to account owners before they take effect.
12. Contact
Privacy questions and data-subject requests go to Shiftclawco at shiftclawco@gmail.com. Our Terms of Service govern the rest of the relationship.