Privacy policy
This policy explains how Quorpi processes the personal data and technical data needed to run, secure and improve the app.
1. Data controller
Quorpi is published by PrysmaLab. For any question about privacy or about exercising your rights, you can contact us at [email protected].
2. Data processed
Depending on the features you use, Quorpi may process the following categories of data:
- Account data: email address, technical account identifier and information needed for authentication.
- Profile data: display name and the settings of the avatar chosen in the app.
- Group and event data: groups created or joined, events, participation, invitations and other information entered to organize the group.
- Notification data: installation identifier, notification token, platform (Android or iOS) and device language, used to send the notifications you have turned on.
- Data entered by an organizer: name, optional email address and note about a substitute, used to offer them a session. If that address matches a Quorpi account, the request is linked to that account.
- Technical usage data: random session identifier, app version and build, platform, operating system version, app environment and screens viewed. This telemetry does not include your name, email address or user identifier.
- Diagnostic data: technical information about errors and crashes, used to identify and fix malfunctions. Quorpi configures its diagnostic tool not to send personal data by default.
3. Purposes
This data is used only to:
- create and secure your account;
- provide the features for creating and managing groups, events, participation and invitations;
- synchronize your data between the app and its infrastructure;
- measure app usage in a limited way in order to improve how it works;
- detect, diagnose and fix technical errors;
- prevent fraudulent or abusive use and keep the service secure.
4. Service providers and recipients
Quorpi does not sell your personal data and does not use it for targeted advertising. Some data is processed by technical service providers that are strictly necessary to run the service, including:
- Supabase, for authentication, the database and some product telemetry;
- Sentry, for tracking technical errors and crashes;
- Expo and related services used to distribute the app and for some of its technical functions;
- the Apple and Google notification services, through which notifications sent via Expo are delivered.
These providers may process technical data under their own terms and data protection commitments.
5. Legal basis
Processing needed to create your account and run Quorpi is mainly based on providing the service you requested. Processing related to security, diagnostics and service improvement is based on PrysmaLab's legitimate interest in maintaining a reliable and secure app, subject to the rights that apply to users.
6. Data retention
Each category of data is kept for as long as its purpose requires:
- Account, profile, groups, sessions, answers and substitutes: for as long as your account or the group concerned exists.
- Inactive account: deleted after 3 years without use, following a warning email.
- Anonymous usage telemetry: 13 months.
- Error diagnostics: 90 days at most.
- History of notifications sent: 90 days.
- Disabled notification tokens: 90 days after they are disabled.
- Expired or revoked invitations: 90 days after they end.
- Support conversations: 3 years after the last message.
Some information may be kept longer when a legal obligation, fraud prevention or the resolution of a dispute requires it.
7. Deleting your account and data
You can request the deletion of your account directly in the app, in the account settings, using the dedicated deletion action. This deletion removes or anonymizes the personal data associated with the account, subject to legal obligations and to data that must be kept temporarily for security reasons or to preserve the integrity of the service. Database backups, which cannot be edited, are gone no later than 30 days after the deletion.
A detailed procedure is also available on the account deletion page. You can contact [email protected] for any request about your data.
8. Security
Quorpi implements technical and organizational measures designed to protect data against unauthorized access, loss, alteration or disclosure. Communication with remote services uses encrypted connections where the infrastructure supports them. Access to data is limited to the technical and functional needs of the service.
9. Your rights
Under applicable regulations, including the GDPR in the European Union, you may have rights of access, rectification, erasure, restriction, objection and, where applicable, data portability.
To exercise these rights, contact [email protected]. You may also lodge a complaint with the competent data protection authority, such as the CNIL in France.
10. Minors
Quorpi is not specifically designed as a service for children. If the app is used by a minor in a jurisdiction that requires parental consent for the processing of personal data, that consent must be obtained in accordance with applicable regulations.
11. The quorpi.app website
The quorpi.app website is hosted by Cloudflare, which processes technical connection data (IP address, browser) to display the pages and keep them secure. The website does not use audience measurement or advertising cookies.
12. Changes
This policy may be updated when Quorpi's features, its service providers or regulatory obligations change. The last updated date shown at the top of this page identifies the version that applies.