<!-- Script ID: SHARED-LEGAL-PRIVACY-CANONICAL --> <!-- File: SHARED_ACCESS/Legal/Privacy-Policy-CANONICAL.md --> <!-- Purpose: Canonical Privacy Policy prose for all Qensai Services. --> <!-- Owner: Qensai --> <!-- Tags: legal, privacy, canonical, consent --> <!-- Created: 2026-08-28 --> <!-- Last-Reviewed: 2026-09-26 --> <!-- FR-ID: PENDING_FR — canonical legal source; register during the next governed FR allocation pass. -->
Privacy Policy
Qensai — operating the Qensai platform and its products, including Qensai (qensai.dev), our AI Assembly Governance Framework; KPBI (vault.qensai.dev), Knowledge-Powered Business Intelligence; Crown Ledger (crownledger.io), cashflow and budgeting; Qensai Control Plane (ops.qensai.dev), operations control; System Logic Kit (api.qensai.dev), an API and logic platform; Qensai Blog (bots.qensai.dev), our blog and community; and Sys Secure Ops (lab.qensai.dev), security operations (each a "Service," together the "Services").
Last updated: 2026-09-26 Version: 1.4
This Policy states our practices as of the date above. Optional technologies remain disabled unless and until the applicable choice permits them. The current disclosures and available choices are described below and in Cookie Settings.
1. Our core commitment
Your content, in brief
- Your content is yours. We use it only to provide the service you asked for, and we never sell it.
- Where a Service is designed to process your files in your browser, they are processed on your device. We store your content on our servers only as each Service needs in order to work, or when you choose a feature that stores or sends it — for example publishing a Power BI report for you.
- We do not send your content to AI tools unless you choose an AI feature, and we never use it to train AI models.
- We keep the structure of your work and the project details you enter (such as table and column names, settings, project names and notes) so you can pick up where you left off — never the content from your tables used in the local session.
- We do not use your content to market to you. We delete what we hold when you ask, or when you close your account, except what the law requires us to keep (see Section 7).
We do not sell personal information for money. We may use cookies, pixels, local storage, SDKs, tags, server-side identifiers, and similar technologies for security, functionality, analytics, performance measurement, advertising measurement, and, where enabled, advertising personalization. We provide controls over optional technologies as described in this Privacy Policy and our Cookie Settings. Where applicable law treats certain disclosures to advertising or measurement providers as a "sale," "sharing," or processing for targeted advertising, we provide the applicable opt-out mechanisms and honor qualifying universal privacy signals such as Global Privacy Control. Consent-dependent technologies remain disabled until the required choice has been made.
If you only read one section, read this one — the rest of this Policy explains it in detail.
2. Who we are
The Services are operated by Qensai ("we," "us," "our"). This Policy applies to every Service listed above. For privacy questions or to exercise your rights, contact privacy@qensai.com.
3. Information we collect
We keep collection to a minimum. Depending on which Service you use, we may collect:
- Account and authentication data. Your email address, a hashed-and-salted password (we never see your plaintext password), optional multi-factor authentication (MFA) credentials, an internal account identifier, and your session token. Authentication is handled by our provider, Supabase Auth.
- Subscription and billing data. When you purchase a subscription or product, our payment processor (Stripe) handles your card details — we never receive, store, or have access to your card number. We see only Stripe-generated identifiers, the email you provided, and which plan you bought.
- Content you choose to enter into a Service. Some Services let you enter or upload data (for example, budgeting records, data files, prompts, or business records). How that content is handled depends on what you are doing:
- Processed locally. Where a Service is designed to process content in your browser (such as KPBI's in-browser file processing), the file and its rows are processed on your device and are not transmitted to or stored on our servers. - Metadata about that content. If you are signed in, we store a description of the *structure* of what you processed — for example file name, project names, table and column names, data types, inferred roles, and row and column counts — so that your past uploads are listed when you return or use another device. This description is derived from your content and is held on our servers. It excludes the content itself: we do not store your rows, your individual cell values, sample values, most-frequent values, or minimum and maximum values. The description can also include measure and filter formulas you write, which may contain values you type, and a count-level summary of how tables relate. - Project records you create. If you are signed in, project details you enter — for example project and client names, client contact details, notes and decisions — are stored with your account so they are available on other devices. These are not file rows. - Content you explicitly choose to store with us. Where you separately and explicitly elect cloud storage for your content, we store that content to provide the feature you asked for, isolated to your account and shared only with those you authorize. Signing in does not upload your file rows. Content other than project records and structural metadata is stored with us only where you explicitly choose a feature that stores it. - Content you send to a connected service. If you connect a Service to another system, content moves between them as that connection requires — for example exporting query results to Crown Ledger. That transmission is the purpose of the connection you configured, and is not covered by the local-processing description above. When you ask us to publish your model to Power BI, we send it — including up to 5,000 rows per table — through our servers to the Microsoft Power BI workspace we use to publish it for you.
Separately, storing your content never permits us to use it to improve or train any model (see Section 4.A).
- Material we hold under an engagement with you. Where you engage us for analysis, reporting or proposal work, we store the materials you authorize us to use for that engagement, within our own organization and the applicable project. Access is limited to the people and automated agents authorized to work on that engagement. This material is not made available to other customers or to other organizations through the Services, and it is held under the terms of that engagement rather than under the general product terms.
- Marketplace orders. If you buy through a third-party marketplace, we receive the order details and messages that marketplace shares with us.
- Online activity and device information. Depending on your choices and the Service configuration, this may include pages or features used, referral information, browser and device type, operating system, approximate region derived from network information, performance and diagnostic events, advertising or campaign identifiers, and interactions with content or contextual sponsorships.
- Limited operational logs. Standard server, security, fraud-prevention, networking, and governance/audit logs needed to run, secure, and debug the Services. Operational security logging is treated separately from optional product analytics or advertising measurement.
- Contact-form messages. If you contact us, we receive the name, email, and message you send so we can reply.
The precise optional technologies enabled on a Service are listed in that Service's Cookie Details page. The existence of a consent control does not authorize any vendor: a vendor must be registered, disclosed, configured, assigned to a category, and permitted by the user's applicable choice before it may execute.
4. How we use information
We use personal information only to:
- Provide, operate, secure, and maintain the Services;
- Authenticate you and keep you signed in;
- Process your payments and manage your subscription and feature access;
- Respond to your messages and support requests;
- Send transactional and operational emails (for example, welcome, password-reset, billing, and security notices) through our email provider (Resend);
- Maintain audit and governance records needed to operate our products responsibly;
- With your permission, understand use, measure performance, improve the Services, measure campaigns, or personalize advertising where enabled; and
- Comply with law and protect the rights, safety, and security of our users and the Services.
Optional analytics, advertising measurement, and personalization are used only when the applicable consent or opt-out state permits them. Contextual advertisements or sponsorships may be displayed without advertising tracking or personalization.
4.A AI model training
We do not train any underlying third-party AI model (such as Anthropic, OpenAI, xAI, or open-source models) on your personal content. Where a Service routes a prompt to an AI provider, that provider's own terms govern its handling; by default those providers do not train on API data, and we do not enable any opt-in training-data sharing. Any product that learns from usage does so only from system-derived signals — such as which checks fired, how a request was interpreted (intent), and the response methods and process used — never from your prompt text, outputs, financial records, uploaded files, or other content — and any such learning is disclosed in-product and, where applicable, is off by default and requires your explicit opt-in.
5. How we share information
We share personal information only with service providers who help us run the Services, and only so they can perform that function for us under contract. They are not permitted to use your information for their own purposes. Our providers include:
| Provider | Purpose | |---|---| | Supabase | Authentication and database hosting | | Stripe | Payment and subscription processing | | Resend | Transactional email delivery | | Vercel | Application hosting | | AI inference providers (e.g., Anthropic, OpenAI, xAI, RunPod) | AI features, where you use them — they receive what the feature needs to answer: what you type and, depending on the feature, context such as table and column names, row counts and measure formulas | | Microsoft | Power BI publishing we do at your request, and integrations you connect to your own tenant | | Airtable | Only where you connect your own account to an optional integration |
We may also disclose information (a) to comply with law or a lawful request, (b) to protect the rights, safety, or security of any person or our Services, or (c) in connection with a merger, acquisition, financing, or sale of assets (in which case we will notify you of any transfer that materially affects this Policy).
Because our products share a single billing account and identity layer, if you use more than one Service your account and entitlement records may be associated across our products. This co-location does not make your data available to anyone outside Qensai.
We do not sell personal information for money. Certain disclosures to advertising or measurement providers may be classified as a "sale," "sharing," or targeted-advertising processing under some privacy laws even when money is not exchanged for personal information. Where applicable, Qensai provides the required opt-out rights.
6. Security
We protect personal information with: HTTPS/TLS encryption in transit; encryption at rest for sensitive stored data (AES-256-GCM where applicable); salted password hashing handled by our authentication provider; optional multi-factor authentication; and row-level security so each user can access only their own data. No method of transmission or storage is perfectly secure, but we use commercially reasonable measures and will notify you and the appropriate authorities of a security incident affecting your personal information to the extent required by law.
7. Data retention
We keep personal information only as long as we have a lawful basis to do so:
- Account data — for the life of your account; deleted after account closure (subject to a short rollback window).
- Billing/subscription records — retained as required by tax and accounting law (typically up to 7 years).
- Content processed in your browser — the file and its rows are not retained by us; they live only on your device. Structural metadata about a processed file (names, types, roles and counts — not your cell values) is retained with your account for as long as the reference exists in the Service. Content you have explicitly elected to store with us, and material we hold under a separate engagement with you, is retained for as long as that arrangement is in effect. Retention and deletion mechanics for stored content are described in Section 8 (Your rights and choices).
- Audit / governance logs — retained for a limited period for security and integrity, then purged.
- Contact-form messages — retained only as long as needed to handle your inquiry.
Payment records held by Stripe and email-delivery logs held by Resend follow those providers' own retention policies.
8. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, export (data portability), or restrict/object to the processing of your personal information, to withdraw consent, and to not be discriminated against for exercising these rights. Residents of California (CCPA/CPRA), other U.S. states with comprehensive privacy laws (Virginia, Colorado, Connecticut, Utah, Texas, and others), the EU/EEA and UK (GDPR/UK GDPR), Canada, and Brazil have rights under their respective laws.
To exercise any right, email privacy@qensai.com with a short description of your request (for example, "Data Subject Request — Deletion"). Please use the email address associated with your account so we can verify your identity. We respond within the time required by applicable law (generally 30–45 days). If we deny a request, you may appeal by replying with the subject line "Appeal."
Many controls are also available directly in-product, including updating your account, managing MFA, canceling your subscription, and clearing locally-stored data.
9. Do Not Sell or Share / Global Privacy Control
We do not sell personal information for money. Certain disclosures to advertising or measurement providers may be classified as a "sale," "sharing," or targeted-advertising processing under some privacy laws even when money is not exchanged for personal information. Where applicable, Qensai provides the required opt-out rights through Do Not Sell or Share and Privacy Choices.
We honor qualifying universal opt-out signals such as Global Privacy Control (Sec-GPC: 1). When GPC is detected, advertising, sale/share, and targeted-advertising processing covered by the signal is disabled. The Advertising & Measurement choice remains disabled while the signal is active.
10. Cookies and similar technologies
The Services may use cookies, pixels, local storage, SDKs, tags, server-side identifiers, and similar technologies. We separate them into these categories:
- Strictly Necessary — Always Active. Authentication, security, fraud prevention, session state, consent choices, networking, and functionality genuinely required to supply the requested Service.
- Functional — Optional. Non-essential saved preferences and enhanced functionality.
- Analytics & Performance — Optional. Page and feature usage, performance, diagnostics, and product analytics that are not operational security logging.
- Advertising & Measurement — Optional. Campaign attribution, advertising pixels, impression or click measurement, conversion measurement, and personalization.
Necessary technologies may operate immediately. Functional, Analytics & Performance, and Advertising & Measurement technologies remain off unless you affirmatively enable the applicable category. If your preference has not resolved, all optional categories are treated as disabled.
You may change or withdraw optional cookie choices at any time through the Privacy Choices control available on the applicable Service. Rejecting optional technologies is itself stored as a necessary preference so the Service can honor that choice. Terms acceptance is not consent to optional cookies, and cookie consent is not acceptance of the Terms.
Each Service's Cookie Details page identifies its configured technologies, purposes, categories, data types, parties, retention, and provider privacy links. A listed vendor may execute only after it is configured, enabled, assigned to the correct category, disclosed, and permitted by the effective choice.
11. International transfers
Our service providers are primarily located in the United States. If you use the Services from outside the U.S. (including the EEA, UK, Switzerland, Canada, or Brazil), your personal information will be transferred to and processed in the U.S. and other countries where our providers operate. For transfers from the EEA/UK/Switzerland we rely on Standard Contractual Clauses or an equivalent transfer mechanism maintained by each provider.
12. AI transparency
Several of our Services use AI. When you interact with an AI system, that fact is disclosed, and AI-generated output is presented as such. AI output may be inaccurate or incomplete and is provided for your information only — you are responsible for reviewing it before relying on it. Our Services do not make legally or similarly significant decisions about you automatically.
13. Children's privacy
The Services are not intended for anyone under 18. We do not knowingly collect personal information from anyone under 18. A one-time age confirmation is presented at signup. If you believe a minor has provided us personal information, contact privacy@qensai.com and we will delete it.
14. Changes to this Policy
We may update this Policy to reflect changes in our practices or the law. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you by email or an in-product notice. Cookie disclosures and cookie-choice categories are versioned independently so a Terms wording change does not by itself require you to reselect optional technology preferences.
15. Contact us
Qensai Privacy inquiries: privacy@qensai.com (A postal address is available on request.)
If you are in the EEA, UK, or Switzerland, you also have the right to lodge a complaint with your local data-protection supervisory authority.
Last updated: 2026-09-26 · Qensai