1. Who is the data controller
Quelle OS is the controller for personal data processed about members and visitors of the QEcosystem. Contact: privacy@qcore-os.com.
2. What we collect
- Account data: email address, password (hashed), display name, sign-in timestamps, role.
- Membership data: tier, plan history, payment status (we do not store full card numbers — those stay with our payment processor).
- Usage data: pages viewed, applications opened, drops downloaded, actions taken inside member apps, device and browser metadata, IP address.
- Member content: anything you save, upload, or generate through the QEcosystem applications.
- Support & communications: emails, support tickets, feedback.
3. Why we process it (lawful bases)
- Contract — to provide the Quelle OS service and your QEcosystem Pass.
- Legitimate interests — to keep the platform secure, prevent abuse, measure usage in aggregate, improve features, communicate service updates.
- Consent — for non-essential cookies, marketing emails, and any processing where consent is the appropriate basis. You can withdraw consent at any time.
- Legal obligation — to keep tax records, respond to lawful requests, and meet regulatory duties.
4. Processors we use
We work with vetted processors to deliver the service:
- Hosting & database: cloud infrastructure providers in the EU/UK and the United States (Supabase / Lovable Cloud).
- Authentication: Supabase Auth.
- Payments: Paddle or equivalent processor (declared at checkout).
- Transactional email: managed email-sending services.
- AI model providers: Google (Gemini), OpenAI (GPT family) and similar, accessed via Lovable AI Gateway. Prompts and member content may be transmitted to these providers solely to generate the response. We do not authorise providers to train models on your data where contracts permit opt-out.
- Analytics: privacy-conscious product analytics for aggregate usage only.
Where personal data is transferred outside the UK/EEA, we rely on UK/EU Standard Contractual Clauses or an adequacy decision.
5. How long we keep it
- Account data: while your account is active and up to 12 months after closure.
- Member content: until you delete it or your account is closed.
- Payment records: at least 6 years to satisfy tax law.
- Server logs: up to 90 days for security and debugging.
- Backups: rotated on a maximum 35-day cycle.
6. Your rights (UK / EU GDPR)
- Access — request a copy of your data.
- Rectification — correct inaccurate data.
- Erasure (“right to be forgotten”) — request deletion. You can submit this from the member dashboard or by emailing us.
- Restriction — ask us to pause processing.
- Portability — receive your data in a portable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent at any time without affecting prior lawful processing.
- Complain to a supervisory authority — in the UK, the Information Commissioner’s Office (ico.org.uk).
7. Security
Data is encrypted in transit (HTTPS/TLS) and at rest on our managed backend. Access to production systems is restricted, logged and reviewed. Passwords are hashed; we never see them in plain text. We will notify affected members and the relevant regulator of any confirmed personal-data breach within the required timelines.
8. Children
Quelle OS is not directed at children under 16. We do not knowingly collect their data.
9. Automated decisions
We do not use automated decision-making with legal or similarly significant effects on you. AI features generate informational content under your control.
10. Changes to this policy
We will update this page when our practices change. Material changes will be notified in advance by email or in-app.
11. Contact
Privacy questions or rights requests: privacy@qcore-os.com.
This policy is a working template for Quelle OS. Review with qualified counsel before commercial launch in your jurisdiction.
