Last updated: 2024-05-28
The Policy
This Privacy Policy describes how Quilt (the "Site", "we", "us", or "our") collects, uses, and discloses your personal information when you visit, use our services, or make a purchase from quilt.app or any subdomains (the "Site") or otherwise communicate with us (collectively, the "Services"). For purposes of this Privacy Policy, "you" and "your" means you as the user of the Services, whether you are a customer, website visitor, or another individual whose information we have collected pursuant to this Privacy Policy.
Please read this Privacy Policy carefully. By using and accessing any of the Services, you agree to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree to this Privacy Policy, please do not use or access any of the Services.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time, including to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will post the revised Privacy Policy on the Site, update the "Last updated" date and take any other steps required by applicable law.
How We Collect and Use Your Personal Information
To provide the Services, we collect and have collected over the past 12 months personal information about you from a variety of sources, as set out below. The information that we collect and use varies depending on how you interact with us.
In addition to the specific uses set out below, we may use information we collect about you to communicate with you, provide the Services, comply with any applicable legal obligations, enforce any applicable terms of service, and to protect or defend the Services, our rights, and the rights of our users or others.
What Personal Information We Collect
The types of personal information we obtain about you depends on how you interact with our Site and use our Services. When we use the term "personal information", we are referring to information that identifies, relates to, describes or can be associated with you. The following sections describe the categories and specific types of personal information we collect.
Information We Collect Directly from You
Information that you directly submit to us through our Services may include:
Basic contact details including your name, address, phone number, email.
Order information including your name, billing address, shipping address, payment confirmation, email address, phone number.
Account information including your username, password, security questions.
Customer support information including the information you choose to include in communications with us, for example, when sending a message through the Services.
Documents including documents shared with us through Google Drive, Google Docs, Microsoft Office 365, or other services.
Questions and answers in documents you share with us in order to answer questions on your behalf, including Google Sheets, Excel files, or other documents containing questions and answers.
Some features of the Services may require you to directly provide us with certain information about yourself. You may elect not to provide this information, but doing so may prevent you from using or accessing these features.
User Documents We Collect
We take special care in handling your documents, including any documents you share with us through Google Drive or Google Docs. We only use user documents to provide or improve user-facing features that are prominent in the Site's user interface. We only access specific documents that have been explicitly shared with us through the Site UI.
We only transfer your data:
To provide or improve appropriate access and user-facing features that are visible and prominent in the Site's user interface and only with the user's consent;
For security purposes (for example, investigating abuse);
To comply with applicable laws; or
As part of a merger, acquisition, or sale of assets of the developer after obtaining explicit prior consent from the user.
We do not allow humans to read user documents, unless:
We have first obtained the user's affirmative agreement to view specific messages, files, or other data;
It is necessary for security purposes (for example, investigating a bug or abuse);
It is necessary to comply with applicable law; Or
The data (including derivations) is aggregated and used for internal operations in accordance with applicable privacy and other jurisdictional legal requirements.
All other transfers, uses, or sales of user data are prohibited, including:
Transferring or selling user data to third parties like advertising platforms, data brokers, or any information resellers.
Transferring, selling, or using user data for serving ads, including retargeting, personalized or interest-based advertising.
Transferring, selling, or using user data to determine credit-worthiness or for lending purposes.
How We Use Your Documents for AI and Machine Learning
We take special care when using your documents for Artificial intelligence and machine learning. We do not use any user documents to train generalized AI models, non-personalized models, or models that are generally useful outside of delivering your product experience. Your documents are not used to train any generative AI models that are used outside of Quilt or by any other Quilt user.
In particular, Google Workspace APIs are not used to develop, improve, or train generalized AI and/or ML models.
What We Share With Third Parties (Our Subprocessors)
We share your documents and data with third parties in order to implement core functionality of the application. All of our subprocessors are located in the USA. We share data with the following third parties.
Google
When you share a document with us by adding to your list of indexed documents, we store encrypted indices of your documents in various Google storage services, including Google Cloud Storage, Firebase Firestore, and on disks attached to Google Compute Engine instances. We do not share any documents that you have not explicitly shared with us.
Small text portions of those documents may be included in logs and error reports in Google's system in places that are not visible to any human outside the Quilt Engineering team.
When you request that we answer a question for you, we share the contents of the spreadsheet or form containing the question with Google in order to determine which relevant documents to use for that question.
Based on the question asked, we may retrieve a small amount of text (10 - 1000 words, depending on the question) from documents you have shared with us, and share that text with Google in order to rephrase the text as an answer to your question.
We may share other information about you with Google, including the name of your company, the title of the document in which you are answering questions, and any other metadata that you have explicitly shared with us about yourself and your company.
In addition, we share your email address and metadata about your app usage with Google for the purposes of analytics, marketing, and fraud detection.
OpenAI
When you request that we answer a question for you, we share the contents of the spreadsheet or form containing the question with OpenAI in order to determine which relevant documents to use for that question.
Based on the question asked, we retrieve a small amount of text (10 - 1000 words, depending on the question) from documents you have shared with us, and share that text with OpenAI in order to rephrase the text as an answer to your question.
We may share other information about you with OpenAI, including the name of your company, the title of the document in which you are answering questions, and any other metadata that you have explicitly shared with us about yourself and your company.
Anthropic
When you request that we answer a question for you, we may share the contents of the spreadsheet or form containing the question with Anthropic in order to determine which relevant documents to use for that question.
Based on the question asked, we may retrieve a small amount of text (10 - 1000 words, depending on the question) from documents you have shared with us, and share that text with Anthropic in order to rephrase the text as an answer to your question.
We may share other information about you with Anthropic, including the name of your company, the title of the document in which you are answering questions, and any other metadata that you have explicitly shared with us about yourself and your company.
Stripe
We share your name, email address, and access metadata with Stripe in order to process payments. We do not share any documents, questions, or answers content with Stripe.
Amazon AWS
We use Amazon AWS services to access LLMs and to extract text from certain types of documents.
CustomerIO
We use CustomerIO to send emails and notifications. We share your name, email address, and high level event information about your site usage with CustomerIO. We do not share any documents, questions, or answers with CustomerIO.
Meta Platforms, Inc
We share anonymous usage information with Meta in order to monitor traffic to our application from various Meta marketing surfaces.
Amplitude
We use Amplitude for internal reporting and business operations. We share your user ID and high level event information about your site usage with Amplitude. We do not share any documents, questions, or answers with Amplitude.
Slack
We use Slack for internal communications and debugging, and for premium customer support tiers. Slack stores the messages you send us on slack, and we will occasionally share the anonymized content of these messages with our internal support staff. We also use Slack to investigate issues with our product and may store high level usage information and anonymized questions and answers using Slack.
If you use our Slack Application, your messages are stored in Slack, including any questions you send to Slack and any answers you receive via Slack.
Groq
When you use the Live Assistant or interactive real time messaging capabilities of the Knowledge Assistant, we may share the contents of your question and conversation context with Groq in order to quickly answer the question.
We may share other information about you with Groq, including the name of your company, the title of the document in which you are answering questions, and any other metadata that you have explicitly shared with us about yourself and your company.
Sentry
When a problem occurs in our systems, we send information about the error to Sentry
We share information necessary to understand and fix the problem, including information about the user who experienced the problem. No document contents or other similar sensitive information is sent to Sentry.
We do not intentionally share your documents or any portion of your documents with any other AI tools or service providers.
Information We Collect through Cookies
We also automatically collect certain information about your interaction with the Services ("Usage Data"). To do this, we may use cookies, pixels and similar technologies ("Cookies"). Usage Data may include information about how you access and use our Site and your account, including device information, browser information, information about your network connection, your IP address and other information regarding your interaction with the Services.
Information We Obtain from Third Parties
Finally, we may obtain information about you from third parties, including from vendors and service providers who may collect information on our behalf, such as:
Our payment processors, who collect payment information (e.g., bank account, credit or debit card information, billing address) to process your payment in order to fulfill your orders and provide you with products or services you have requested, in order to perform our contract with you.
When you visit our Site, open or click on emails we send you, or interact with our Services or advertisements, we, or third parties we work with, may automatically collect certain information using online tracking technologies such as pixels, web beacons, software developer kits, third-party libraries, and cookies.
Any information we obtain from third parties will be treated in accordance with this Privacy Policy. We are not responsible or liable for the accuracy of the information provided to us by third parties and are not responsible for any third party's policies or practices. For more information, see the section below, Third Party Websites and Links.
How We Use Your Personal Information
Providing Products and Services. We use your personal information to provide you with the Services in order to perform our contract with you, including to process your payments, fulfill your orders, to send notifications to you related to you account, purchases, returns, exchanges or other transactions, to create, maintain and otherwise manage your account, to arrange for shipping, facilitate any returns and exchanges and to enable you to post reviews.
Marketing and Advertising. We use your personal information for marketing and promotional purposes, such as to send marketing, advertising and promotional communications by email, text message or postal mail, and to show you advertisements for products or services. This may include using your personal information to better tailor the Services and advertising on our Site and other websites.
Security and Fraud Prevention. We use your personal information to detect, investigate or take action regarding possible fraudulent, illegal or malicious activity. If you choose to use the Services and register an account, you are responsible for keeping your account credentials safe. We highly recommend that you do not share your username, password, or other access details with anyone else. If you believe your account has been compromised, please contact us immediately.
Communicating with you. We use your personal information to provide you with customer support and improve our Services. This is in our legitimate interests in order to be responsive to you, to provide effective services to you, and to maintain our business relationship with you.
Cookies
Like many websites, we use Cookies on our Site. We use Cookies to power and improve our Site and our Services (including to remember your actions and preferences), to run analytics and better understand user interaction with the Services (in our legitimate interests to administer, improve and optimize the Services). We may also permit third parties and services providers to use Cookies on our Site to better tailor the services, products and advertising on our Site and other websites.
Most browsers automatically accept Cookies by default, but you can choose to set your browser to remove or reject Cookies through your browser controls. Please keep in mind that removing or blocking Cookies can negatively impact your user experience and may cause some of the Services, including certain features and general functionality, to work incorrectly or no longer be available. Additionally, blocking Cookies may not completely prevent how we share information with third parties such as our advertising partners.
How We Disclose Personal Information
In certain circumstances, we may disclose your personal information to third parties for legitimate purposes subject to this Privacy Policy. Such circumstances may include:
With vendors or other third parties who perform services on our behalf (e.g., IT management, payment processing, data analytics, customer support, cloud storage, fulfillment and shipping).
When you direct, request us or otherwise consent to our disclosure of certain information to third parties, such as to ship you products or through your use of social media widgets or login integrations, with your consent.
With our affiliates or otherwise within our corporate group, in our legitimate interests to run a successful business.
In connection with a business transaction such as a merger or bankruptcy, to comply with any applicable legal obligations (including to respond to subpoenas, search warrants and similar requests), to enforce any applicable terms of service, and to protect or defend the Services, our rights, and the rights of our users or others.
We have, in the past 12 months disclosed the following categories of personal information and sensitive personal information (denoted by *) about users for the purposes set out above in "How we Collect and Use your Personal Information" and "How we Disclose Personal Information":
Category
Identifiers such as basic contact details and certain order and account information
Commercial information such as order information, shopping information and customer support information
Internet or other similar network activity, such as Usage Data
Categories of recipients:
Vendors and third parties who perform services on our behalf (such as Internet service providers, payment processors, fulfillment partners, customer support partners and data analytics providers)
Our data processors, including but not limited to OpenAI and Anthropic
Business and marketing partners
Affiliates
We do not use or disclose sensitive personal information for the purposes of inferring characteristics about you.
User Generated Content
The Services may enable you to post product reviews and other user-generated content. If you choose to submit user generated content to any public area of the Services, this content will be public and accessible by anyone.
We do not control who will have access to the information that you choose to make available to others, and cannot ensure that parties who have access to such information will respect your privacy or keep it secure. We are not responsible for the privacy or security of any information that you make publicly available, or for the accuracy, use or misuse of any information that you disclose or receive from third parties.
Third Party Websites and Links
Our Site may provide links to websites or other online platforms operated by third parties. If you follow links to sites not affiliated or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such sites, including the accuracy, completeness, or reliability of information found on these sites. Information you provide on public or semi-public venues, including information you share on third-party social networking platforms may also be viewable by other users of the Services and/or users of those third-party platforms without limitation as to its use by us or by a third party. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators, except as disclosed on the Services.
Children's Data
The Services are not intended to be used by children, and we do not knowingly collect any personal information about children. If you are the parent or guardian of a child who has provided us with their personal information, you may contact us using the contact details set out below to request that it be deleted.
As of the Effective Date of this Privacy Policy, we do not have actual knowledge that we "share" or "sell" (as those terms are defined in applicable law) personal information of individuals under 16 years of age.
Security and Retention of Your Information
Please be aware that no security measures are perfect or impenetrable, and we cannot guarantee "perfect security." In addition, any information you send to us may not be secure while in transit. We recommend that you do not use unsecure channels to communicate sensitive or confidential information to us.
How long we retain your personal information depends on different factors, such as whether we need the information to maintain your account, to provide the Services, comply with legal obligations, resolve disputes or enforce other applicable contracts and policies.
Your Rights and Choices
Depending on where you live, you may have some or all of the rights listed below in relation to your personal information. However, these rights are not absolute, may apply only in certain circumstances and, in certain cases, we may decline your request as permitted by law.
Right to Access / Know. You may have a right to request access to personal information that we hold about you, including details relating to the ways in which we use and share your information.
Right to Delete. You may have a right to request that we delete personal information we maintain about you.
Right to Correct. You may have a right to request that we correct inaccurate personal information we maintain about you.
Right of Portability. You may have a right to receive a copy of the personal information we hold about you and to request that we transfer it to a third party, in certain circumstances and with certain exceptions.
Right to Limit and/or Opt out of Use and Disclosure of Sensitive Personal Information. You may have a right to direct us to limit our use and/or disclosure of sensitive personal information to only what is necessary to perform the Services or provide the goods reasonably expected by an average individual.
Restriction of Processing: You may have the right to ask us to stop or restrict our processing of personal information.
Withdrawal of Consent: Where we rely on consent to process your personal information, you may have the right to withdraw this consent.
Appeal: You may have a right to appeal our decision if we decline to process your request. You can do so by replying directly to our denial.
Managing Communication Preferences: We may send you promotional emails, and you may opt out of receiving these at any time by using the unsubscribe option displayed in our emails to you. If you opt out, we may still send you non-promotional emails, such as those about your account or orders that you have made.
You may exercise any of these rights where indicated on our Site or by contacting us using the contact details provided below.
We will not discriminate against you for exercising any of these rights. We may need to collect information from you to verify your identity, such as your email address or account information, before providing a substantive response to the request. In accordance with applicable laws, You may designate an authorized agent to make requests on your behalf to exercise your rights. Before accepting such a request from an agent, we will require that the agent provide proof you have authorized them to act on your behalf, and we may need you to verify your identity directly with us. We will respond to your request in a timely manner as required under applicable law.
Complaints
If you have complaints about how we process your personal information, please contact us using the contact details provided below. If you are not satisfied with our response to your complaint, depending on where you live you may have the right to appeal our decision by contacting us using the contact details set out below, or lodge your complaint with your local data protection authority.
International Users
Please note that we may transfer, store and process your personal information outside the country you live in, including the United States. Your personal information is also processed by staff and third party service providers and partners in these countries. If we transfer your personal information out of Europe, we will rely on recognized transfer mechanisms like the European Commission's Standard Contractual Clauses, or any equivalent contracts issued by the relevant competent authority of the UK, as relevant, unless the data transfer is to a country that has been determined to provide an adequate level of protection.
Contact
Should you have any questions about our privacy practices or this Privacy Policy, or if you would like to exercise any of the rights available to you, please email us at michael@quilt.app or contact us at 991 Haight St, San Francisco, CA, 94117, United States.