PRIVACY

Privacy policy

What we collect, where it lives, and how to take it back.

Effective 2026-04-19

Who we are

“quik.md” (“quik”, “we”, “our”) runs the web and mobile app at quik.md. This policy covers every visitor and every signed-in user. Questions: [email protected].

What we collect

Account: your email address, and an optional display name.

Content you create: items, projects, tags, focus sessions, dashboard preferences.

Voice: we process the audio you record into a transcript and immediately discard the audio. We do not retain voice recordings.

AI metadata: timestamps, token counts, and a short reason per AI run. We do not retain the prompts or completions themselves.

Auth cookies: first-party essential cookies set by Supabase so you stay signed in. No advertising or analytics cookies.

Network metadata: IP address and user-agent, attached to legal-consent records only so we can prove you agreed to the terms.

What we don’t collect

No third-party analytics (no Google Analytics, Mixpanel, PostHog, Segment, or similar).

No advertising cookies. No cross-site trackers. No fingerprinting.

We do not sell personal information. We do not share personal information with data brokers.

Where it lives

Supabase (EU region): account, items, projects, focus sessions.

Polar: payment and subscription records if you buy Pro. We don’t store card details.

OpenAI (Whisper): temporary audio transcription. Audio is discarded after the response.

OpenRouter: AI routing for text-only organize calls. No audio ever leaves us there.

Your rights (GDPR / CCPA)

Access: download a JSON export of everything tied to your account from Settings → Data & privacy.

Erasure: delete your account and all associated data from Settings → Data & privacy. Deletion is immediate and irreversible.

Correction: edit your name and email in Settings → General.

Objection or restriction: email [email protected] and we’ll respond within 30 days.

California residents (CCPA): we do not sell or share personal information as defined by CPRA. You have the same export and deletion rights listed above.

Retention

Account data lives until you delete your account. When you delete, we remove your rows from every user-owned table and then remove your auth record.

Legal consent records (your agreement to these terms) are kept after deletion for compliance audit only, with no content attached.

Backups roll off within 30 days.

International transfers

Our primary data store is in the EU. Some sub-processors (OpenAI, OpenRouter, Polar) may process data in the US. We rely on standard contractual clauses where applicable.

Children

quik is not directed to children under 13. Do not create an account if you are under 13.

Changes

We’ll revise this policy if what we collect or who processes it materially changes. On material changes we’ll prompt you to re-accept. The date below reflects the current version.