Skip to main contentChecking sign-in status

Privacy Policy

Last updated: July 12, 2026

QuickDeploy AI, Inc. ("QuickDeploy AI", "we", "us") is committed to protecting your privacy. This policy describes how we collect, use, and share information when you use our platform for deploying AI agents and capabilities, and our website at quickdeploy.ai (together, the "Service").

Information we collect

We collect the following categories of information:

  • Account and identity data. Name, email address, and authentication identifiers created when you sign up or sign in through our authentication providers (WorkOS single sign-on, or Supabase-managed authentication). We do not store your passwords for SSO sign-ins; those stay with your identity provider.
  • Billing data. Your subscription plan, invoices, and a Stripe customer identifier. Payment card details are collected and stored by Stripe, our payment processor — they never touch our servers.
  • Usage and credit data. A metered ledger of your platform usage (for example compute, storage, and request metering) and the credits consumed by it, used to operate credit-based billing and show you your balance.
  • Customer content. Configuration, deployment definitions, and other content you submit to deploy and run AI agents and capabilities.
  • Logs and security data. Server logs, audit events, and rate-limiting records. Where IP addresses are recorded in audit and rate-limiting data, they are pseudonymized as salted cryptographic hashes rather than stored in the clear.
  • Cookie and consent data. Your cookie-consent choice and essential session cookies, described under "Cookies and Global Privacy Control" below.
  • Communications. Messages you send us, such as support requests, access requests, and form submissions.

How we use your information and our legal bases

We use each category of information for the following purposes:

  • To provide the Service — operating your account, running your deployments, metering usage, maintaining your credit balance, and processing payments. Legal basis: performance of our contract with you.
  • To secure the Service — authentication, fraud and abuse prevention, rate limiting, audit logging, and incident response. Legal basis: our legitimate interest in keeping the platform safe and reliable.
  • To communicate with you — service notices, billing notices, and responses to your requests. Legal basis: performance of our contract and our legitimate interests.
  • To improve the Service — diagnostics and error monitoring. Legal basis: our legitimate interests. Any future non-essential analytics will run only with your consent (see "Cookies and Global Privacy Control").
  • To comply with law — tax, accounting, and responses to lawful requests. Legal basis: compliance with legal obligations.

Cookies and Global Privacy Control

We use only essential cookies today: a session cookie from our authentication provider, and a first-party preference cookie (qdai_consent, kept for one year) that remembers your cookie-consent choice. We don't load analytics, advertising, or other tracking cookies without your consent. We honor Global Privacy Control (GPC) signals: if your browser sends a GPC signal and you have not made an explicit choice, we treat you as opted out of non-essential cookies and trackers and never show you the consent prompt. An explicit choice you make on this site takes precedence over the signal. This section is updated whenever our cookie usage changes.

How we share information — subprocessors

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only with the service providers (subprocessors) below, who process it on our behalf under contractual confidentiality and data-protection obligations, and where required by law.

Subprocessor Purpose
Vercel Website and application hosting, content delivery
Supabase Database, authentication, and serverless functions
WorkOS Single sign-on and authentication
Stripe Payment processing and billing (card data is held by Stripe, not us)
Microsoft Azure Deployment infrastructure and API management for deployed agents
GitHub Source code hosting and CI/CD automation
Pulumi ESC Secrets and environment configuration management
Sentry Application error monitoring and diagnostics
Slack Internal operational alerting (deploy and uptime notifications)

We update this list when our subprocessors change; the "Last updated" date above reflects the most recent revision.

Your privacy rights and how to exercise them

You may request access to, correction of, or deletion of your personal information, and you may opt out of any future sale or sharing of personal information (we currently do neither).

  • Deletion (self-service). You can delete your account yourself at any time from your account settings (Security → Delete account). This permanently deletes or anonymizes the personal data associated with your account; records we must keep (for example billing records required for tax and accounting) are retained in anonymized or aggregate form.
  • Access, correction, and other requests. Email privacy@quickdeploy.ai from the address associated with your account. We will verify your identity before acting on a request and respond within the time required by applicable law (generally 45 days, extendable where the law allows).

We will not discriminate against you for exercising any of these rights. Where applicable law allows, you may use an authorized agent to submit a request on your behalf, and you may appeal a decision we make about your request by replying to our response.

US state privacy rights

If you live in California or another US state with a comprehensive privacy law (including the CCPA as amended by the CPRA), you have the right to know what personal information we collect and how we use it (this policy), to access it, to correct it, to delete it, and to opt out of the sale or sharing of personal information and of targeted advertising. We do not sell personal information or share it for cross-context behavioral advertising. We honor the Global Privacy Control browser signal as a valid opt-out request, as described in "Cookies and Global Privacy Control" above. To exercise any of these rights, use the self-service deletion flow or contact us as described in the previous section.

Data retention

We retain personal information for as long as your account is active or as needed to provide the Service. When you delete your account, personal data is deleted or anonymized as described above. We retain billing and transaction records for as long as required by tax and accounting law, and security logs (with pseudonymized IP hashes) for a limited period for fraud and abuse prevention, after which they are deleted or aggregated.

Children

The Service is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 13 (or under 16 where a higher age applies), and we do not sell the personal information of minors. If you believe a child has provided us personal information, contact us and we will delete it.

International transfers

We are based in the United States and process information there. If you use the Service from outside the US, your information is transferred to and processed in the US and in other countries where our subprocessors operate, which may have different data-protection laws than your own. Where required, we rely on our subprocessors' data-processing agreements and recognized transfer safeguards (such as standard contractual clauses) for these transfers.

Security

We use technical and organizational measures appropriate to the risk, including encrypted connections, access controls, secrets management, pseudonymization of IP addresses in audit data, and append-only audit logging. No system is perfectly secure, and we cannot guarantee absolute security.

Changes to this policy

We may update this policy from time to time. We will post the revised version here and update the "Last updated" date above. For material changes, we will provide additional notice (such as email to account holders or an in-product notice) before the changes take effect.

Contact

Questions about this policy or your personal information? Email privacy@quickdeploy.ai .

Enterprise beta agreements and data-processing terms may provide additional controls for participating customers.