privacy policy.
Last updated may 4, 2026
1. introduction
This Privacy Policy describes how Quill (“we,” “us”) collects, uses, and shares information when you use the App and Quill. It should be read together with our Terms of Use.
This App is in active development (pre–general availability). Practices may evolve; we will post updates here and, where appropriate, in-product notices.
2. information we collect
Account data: such as email address and authentication identifiers from our identity provider.
Notes and content: text and attachments you save, edit dates, pins, tags, and related metadata needed to sync and display your notes.
Quill & agent data: signals derived from your notes (e.g. embeddings, similarity scores, extracted tasks, suggestions, activity logs) used to power AI features and improve relevance within your workspace.
Device & technical data: app version, diagnostics, and limited usage data needed for reliability, security, and debugging.
Optional integrations: if you connect calendar, contacts, or other services, we process the data those integrations require to provide the feature you turned on.
3. how we use information
We use information to provide, maintain, and improve the App; authenticate you; sync your notes; run Quill features you request; detect abuse and secure the service; communicate service-related messages; and comply with law.
We do not sell your personal information as traditionally defined in U.S. state privacy laws. We do not use your private notes to train public foundation models for unrelated third parties unless we clearly disclose a separate program and obtain appropriate consent.
4. ai processing
When you use Quill, portions of your note content or derived context may be sent to AI providers (e.g. for summarization, extraction, or chat). We configure processing to support your features and enforce access controls; providers process data under their agreements with us and act as subprocessors where applicable.
Embeddings and similarity search may be used to link related notes or retrieve context. Outputs may be cached briefly for performance.
5. legal bases (eea / uk / similar)
Where GDPR or similar laws apply, we rely on: performance of a contract (providing the App); legitimate interests (security, product improvement, fraud prevention) where not overridden by your rights; consent where we ask it (e.g. certain optional features); and legal obligations.
6. sharing & subprocessors
We use service providers for hosting, database, authentication, AI inference, analytics, and operational email. They access information only to perform services for us and are bound by appropriate confidentiality and security obligations.
We may disclose information if required by law, to protect rights and safety, or in connection with a merger or acquisition subject to confidentiality safeguards.
7. retention
We retain account and note data while your account is active and for a reasonable period afterward for recovery, legal compliance, or dispute resolution. Trash or deleted items may be permanently removed after a retention window. Technical logs may be retained for a shorter rolling period.
8. security
We implement administrative, technical, and organizational measures appropriate to the nature of the service (including encryption in transit and access controls). No method of transmission or storage is 100% secure; use strong passwords and device protections.
9. your rights & choices
Depending on where you live, you may have rights to access, correct, delete, or export personal data; object to or restrict certain processing; and withdraw consent where processing is consent-based. You may exercise rights by contacting us; we may verify your identity.
You can manage some data directly in the App (e.g. edit or delete notes, adjust permissions). You may opt out of optional integrations in settings.
10. children
The App is not directed at children under the age required for lawful consent in their region. We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.
11. international transfers
We may process and store information in countries other than where you live. Where required, we use appropriate safeguards (e.g. standard contractual clauses) for transfers from the EEA, UK, or Switzerland.
12. changes & contact
We may update this Privacy Policy; the “Last updated” indicator in the App will change when we do. Material changes may be highlighted in-product.
Questions or requests: use the support contact we publish for Quill. For EU/UK residents, you may also lodge a complaint with your local supervisory authority.