1. Introduction
Quint Ally ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered networking platform for verified business founders.
Please read this Privacy Policy carefully. By using the Service, you consent to the data practices described in this policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: Full name, work email, company name, industry, role, physical business address
- Business Verification: Government business registration documents (processed via our AI verification provider with zero-retention protocol)
- Profile Data: Company logo, avatar, biography, timezone, Ideal Customer Profile (ICP)
- Communications: Chat messages with AI Command Center and P2P conversations with matched founders
- Referral Data: Deal amounts, descriptions, and verification documents (invoices processed via OCR with zero-knowledge verification)
- Sales AI Data: Prospect email addresses, company domains, LinkedIn URLs, and AI-drafted email content
2.2 Information Collected Automatically
- Usage Data: Login timestamps, feature interactions, session duration
- Device Information: Device type, operating system, push notification tokens
- Analytics: Page views, click patterns, conversion funnel events (via PostHog)
- AI Interaction Data: Conversation history with AI assistants for profiling and matchmaking purposes
3. How We Use Your Information
We use your information to:
- Verify Your Business: Process KYB documents via our AI verification provider to authenticate legitimate business entities
- Profile Your Business: Use AI to analyze your conversations and extract business strengths, weaknesses, and stage
- Match You With Founders: Use vector similarity algorithms to find complementary founders based on your business profile
- Generate Sales Leads: Research external prospects matching your ICP using TinyFish agentic web infrastructure
- Dispatch Emails: Send approved AI-drafted emails from your connected Gmail/Outlook account via OAuth
- Track Reputation: Calculate and display your Ally Score based on referrals, deals, and charter compliance
- Prevent Abuse: Enforce the 3-strike moderation system and protect the network from spam or malicious behavior
- Improve the Service: Analyze usage patterns to optimize features and user experience
- Communicate With You: Send transactional emails, push notifications, and support responses
4. AI Processing & Profiling
A core feature of Quint Ally is AI-driven matchmaking. Here's how it works:
- We use LLMs (Minimax m2.5, Grok/xAI) to analyze your Command Center conversations
- We extract structured business data (strengths, weaknesses, stage, constraints)
- We convert this data into mathematical vectors using OpenAI Embeddings API
- We store these vectors in our pgvector database for similarity matching
- We periodically enrich your profile with public company data via TinyFish web agents
- We never share your raw conversation history with other users — only anonymized match pitches
You can request a copy of your stored vector data or delete your account at any time from Settings.
5. Data Sharing & Disclosure
We do NOT sell your personal information. We share data only as follows:
- With Matched Founders: When you accept a match, your name, company, Ally Score, and verified deal badges are shared with the counterparty
- With Service Providers: Stripe (payment processing), Insforge (database hosting), Gmail/Outlook (via your OAuth consent)
- For Legal Purposes: If required by law, court order, or to protect our rights and safety
- With Your Consent: When you explicitly authorize sharing (e.g., connecting your email account)
Important: We NEVER expose a member directory or search interface. The "dark network" principle ensures you cannot browse other users — all connections are AI-initiated.
6. Data Retention
6.1 User Data
- Account Data: Retained for the lifetime of your account, plus 30 days after deletion request for backup recovery
- Chat Messages: Indefinite for active rooms; 1 year after room archival
- KYB Documents: Zero-retention — processed in volatile memory and immediately deleted
- Invoice Verification: Zero-retention — OCR processed in volatile memory and immediately deleted
6.2 Externally Scraped Prospect Data (Sales AI)
- Retention Period: 90 days from generation date
- After 90 Days: All PII (email, domain, LinkedIn URL) is anonymized; only status metadata retained
- Unsubscribe Requests: Permanently recorded in
email_unsubscribes table to prevent future contact
See our Lead Data Retention Policy for detailed compliance documentation.
7. Data Security
- Encryption at Rest: All database storage encrypted via Insforge (PostgreSQL encryption)
- Encryption in Transit: TLS 1.3 for all API and WebSocket connections
- OAuth Token Encryption: AES-256-GCM envelope encryption for Gmail/Outlook refresh tokens
- Backup Encryption: All automated backups (daily + PITR) encrypted at rest
- Access Controls: Row-Level Security (RLS) ensures users can only access their own data
- Zero-Knowledge Processing: KYB and invoice documents never written to storage — processed in memory and purged
- Rate Limiting: API abuse prevention via Upstash Redis rate limiting
8. Your Rights (GDPR, CCPA)
Depending on your location, you have the following rights:
- Right to Access: Request a complete export of your data (available in Settings → Data & Privacy)
- Right to Erasure: Request permanent deletion of your account and all associated data (available in Settings → Data & Privacy)
- Right to Rectification: Update or correct your profile information at any time
- Right to Portability: Download your data in machine-readable JSON format
- Right to Object: Opt out of AI profiling or specific processing activities
- Right to Withdraw Consent: Disconnect your OAuth email account or revoke analytics tracking
- CCPA Rights: California residents may opt out of the "sale" of personal information (we do not sell data)
To exercise these rights, use the in-app Settings panel or contact privacy@quintally.com.
9. Cookies & Tracking
We use cookies and similar technologies for:
- Essential Cookies: Session authentication, security, and basic functionality
- Analytics Cookies: PostHog tracking for product improvement (anonymous usage patterns)
- Preference Cookies: Remember your theme (dark/light) and notification settings
EU/UK visitors will see a cookie consent banner allowing them to opt out of non-essential tracking. You can manage cookie preferences in your browser settings.
11. Children's Privacy
The Service is not intended for individuals under 18 years old. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at privacy@quintally.com.
12. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using the Service, you consent to such transfers.
We implement appropriate safeguards (Standard Contractual Clauses, data processing agreements) for international transfers in compliance with GDPR and other applicable regulations.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we will send you an email or in-app notification.
15. Supervisory Authority
If you are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with your local data protection supervisory authority. For EU residents, you can find your local authority here.