// privacy.policy
Last updated: July 2026
Introduction
Quilon ("we", "us", "our", or "Company") operates the Quilon application and website. This Privacy Policy explains how we collect, use, disclose, and safeguard your information.
We are committed to protecting your privacy. If you have questions about this Privacy Policy, please contact us at privacy@quilon.dev.
Products and Client Availability
This policy covers Quilon Core and Quilon Ops, the only products in the launch scope. Legacy, Play, and Dev remain parked and are not offered as supported launch products. The authenticated browser companion is available now; native Windows, Apple, and Android clients are not described as publicly available until verified release artifacts are listed on the download page. Live Tunnel is disabled for this launch.
What Information We Collect
Account Information
When you create a Quilon account, we collect your email address and receive your password over TLS to authenticate you. We store a bcrypt password hash, not the plaintext password.
Clipboard Data
Quilon syncs clipboard content across your devices. This data is encrypted end-to-end (AES-256) and relayed through our servers. Encrypted delivery state may be retained for bounded retry and idempotency handling, but Quilon does not keep clipboard plaintext or provide server-side clipboard history.
Deal Room Data (Quilon Ops)
Quilon Ops message bodies and file bytes are encrypted end-to-end on your device before upload. Our servers store those ciphertext payloads and readable operational metadata such as room and file names, MIME types, sizes/digests, membership, invites, audit events, and expiry state. We do not hold the room keys needed to decrypt message bodies or file bytes. When a room expires or a kill-switch is activated, its data is scheduled for purge and remains in cleanup state until required storage-provider deletion has completed.
Device Information
We may collect device type, OS version, and app version for service reliability, debugging, and compatibility support.
Usage Analytics
We may collect service usage signals (for example: feature usage counts and operational error logs) to improve performance, stability, and product quality.
Payment Information
Payments are processed by the Apple App Store or Google Play via RevenueCat. Web checkout is disabled. We never see or store your credit card or payment information.
Private Share & File Transfer
Files shared via Private Share or encrypted file transfer are end-to-end encrypted and relayed through our servers without storage. The server does not hold the link key needed to decrypt the file bytes. Share sessions expire automatically after 30 minutes. Live Tunnel is not part of the Core + Ops launch; tunnel creation is rejected and the public tunnel route returns HTTP 404.
How We Use Your Information
- Authenticate your account and provide clipboard sync services
- Process payments and manage your subscription
- Send transactional emails (password resets, receipts, etc.)
- Improve our service through anonymized analytics
- Debug and resolve technical issues
- Comply with legal obligations
- Prevent fraud and abuse
Zero-Knowledge Architecture
Quilon is built with privacy as the core principle. Your clipboard data is encrypted on your device before leaving it. Here's how it works:
- Your clipboard data is encrypted with AES-256 on your device
- Only the encrypted data is sent to Quilon servers
- Our servers cannot decrypt this data—only your devices have the keys
- Clipboard sync and Private Share use encrypted relay and bounded delivery state; Quilon does not keep plaintext content or server-side clipboard history
- Quilon Ops deal-room data is stored as encrypted blobs and metadata until expiry or kill-switch cleanup completes; the server cannot decrypt protected message bodies or file bytes
Important: A server compromise would expose account and operational metadata, password hashes, and ciphertext. Protected content payloads remain encrypted because Quilon does not hold the client keys needed to decrypt them.
Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties.
Third-Party Services
We use the following third parties to deliver our service:
- Apple App Store / Google Play (via RevenueCat): In-app subscription management. See Apple Privacy Policy and Google Privacy Policy
- Render: Cloud hosting provider. See Render Privacy Policy
- GitHub: Application release and installer distribution. See GitHub Privacy Statement
Legal Requests
We may disclose your information if required by law, court order, or government request. We will attempt to notify you before disclosing your information, unless legally prohibited.
Data Retention
- Account data: Retained until you delete your account
- Clipboard data: Plaintext is not stored by Quilon. Encrypted delivery state is kept only for bounded delivery, retry, and idempotency handling, then expires. Client history is local.
- Deal room data: Retained as encrypted blobs and metadata until room expiry, kill-switch, or account-deletion cleanup has completed
- Payment information: Retained by Apple/Google via RevenueCat per their policies
- Operational analytics data: Collected only when enabled and retained according to the verified service configuration; Quilon does not claim a fixed retention period for this release
- Logs: Retained only as configured for security and reliability operations; Quilon does not claim a fixed retention period for this release
Your Rights
Depending on your location, you may have the following rights:
GDPR (Europe)
- Right to access your personal data
- Right to rectification (correct inaccurate data)
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
CCPA (California)
- Right to know what personal data is collected
- Right to delete personal data
- Right to opt-out of sale of personal data
- Right to non-discrimination for exercising CCPA rights
To exercise these rights, email us at privacy@quilon.dev.
Security
We implement industry-standard security measures to protect your data, including end-to-end encryption, secure password hashing, and TLS for data in transit. However, no method of transmission over the Internet is 100% secure.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last updated" date above. Your continued use of Quilon signifies your acceptance of the updated Privacy Policy.
Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us at:
Email: privacy@quilon.dev
Website: quilon.dev