Privacy Policy
quickCLIENT.ai · operated by Prism AI Apps LLC, a California limited liability company
Version 1.7 · Effective and last updated: August 13, 2026
This Privacy Policy describes how Prism AI Apps LLC (“we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with quickCLIENT.ai (the “Service”). It is part of, and incorporated into, our Terms of Service. By creating an account or using the Service, you agree to this Policy. If you do not agree, do not use the Service.
1. Our roles: who controls what
The Service lets you store information about your own clients and contacts (“Client Data”). For that Client Data, you are the controller (you decide what to collect and why) and we are a processor acting on your instructions. For your own account and usage information (for example, your email, profile, and log data), we act as the controller. You are responsible for having the rights and consents needed to collect and store Client Data, as described in our Terms of Service.
2. Information we collect
Information you provide.
- Account information: your email address and login credentials.
- Profile / Business Card: details you add to your shareable card, such as your name, company, title/profession, phone, email, website, city/state, photo, specialties, and bio, plus your unique QuickClient Code.
- Your Content: notes and their transcripts, images, PDFs, documents, reminders, to-dos, tags, and events, and any text within them. When you record a voice note — or record a meeting or call using the meeting feature, or talk through a site using the Walkthrough feature — we transcribe it to text and do not store the underlying audio recording after transcription; only the transcript is kept, as a note on the relevant client. A Walkthrough also saves the photos you take (and, if you enable it, their location, described below) to that client’s record; the resulting report is shared only when you choose to export or save it — we never send it to your client for you. You are responsible for obtaining any consent the law requires before recording or photographing anyone.
- Client Data: the names, phone numbers, email addresses, and other details of your clients, prospects, and contacts that you choose to enter, capture, or upload.
- Location data (optional): if you use the Walkthrough feature and grant location permission, we attach your device’s location to each photo you take during that walk, so you can see where on a site a photo was captured. This is optional — deny or turn off location and photos are saved without it — and we do not track your location continuously or in the background. A photo’s location is stored with the photo and deleted when you delete the photo or the walkthrough.
Information collected through referrals and prospect capture — see Section 6 for detail — including referral provenance (which client a captured lead came from) and information a prospect submits to you through a shared capture link, a client-shared “Refer me” link, QR profile card, or a public Campaign landing page.
Campaign activity. When you run a Campaign, we record aggregate interaction events on its public pages — scans, flyer downloads, and form submissions, together with a truncated IP prefix used only for rate-limiting and abuse prevention — so you can see how the campaign is performing. Details a prospect submits on a Campaign page (name and an email or phone) are stored to your account as Client Data and are visible only to you.
Email nudge (optional). If you turn on the email nudge, you set up your own mailbox to forward messages from your clients to a unique address we give you. We record only the sender’s email address, the subject line, and the time received — we do not read or store the body of the message — so we can flag on your home screen that a client may be waiting for a reply. You control this: it works only for the addresses you choose to forward, and you can turn it off at any time by removing the forwarding rule in your mailbox.
Waitlist and marketing. If you join the waitlist on our marketing site, we collect your email address and, if you provide it, the industry you work in, so we can notify you about availability and updates. You can ask us to remove you at any time by contacting support@quickclient.ai.
Information collected automatically. Basic technical and usage data needed to operate and secure the Service, such as log data, device and browser type, IP address, timestamps, and aggregate page-view analytics. We use only essential cookies and local storage required for authentication and app preferences; we do not use advertising or cross-site tracking cookies. See Section 15 for the specific cookies and storage we use.
Push notifications (optional). If you turn on notifications, we register a push token or subscription for your device or browser so we can deliver the reminders you asked for. The token identifies the device to notify, not you, and you can revoke it any time by turning notifications off. Delivery goes through the platform’s push service (Apple, Google, or your browser’s web-push service) — see Section 4.
Device permissions (optional). Some features ask your device for access: the microphone (to record audio we transcribe), the camera (to take photos during a Walkthrough), and location (to note where a Walkthrough photo was taken). You grant these through your device and can revoke them at any time in your device settings; a feature that needs a permission you’ve denied simply won’t run. We access these only while you’re actively using the feature.
Text-message (SMS) verification codes (optional). Two-factor authentication is required on your account, and the default second factor is a code sent to your own email — no phone number is needed. If you separately choose to turn on text-message codes, you add and confirm your own mobile number in your account settings (Profile → Text-message codes); from then on we send a one-time sign-in code by SMS when you sign in or re-verify your identity. This is strictly opt-in and used only to authenticate you — never for marketing. Message frequency depends on your own sign-in activity (typically one code per sign-in on a new device), and message and data rates may apply. You can turn it off at any time by removing your number in settings or by replying STOP to a message; reply HELP for help. Your number is used only to deliver these codes through our SMS provider (Section 4).
Help and support questions (product help only). When you type a question into in-app Help or contact support, we store the question text, the app area you were on, your plan, and device type so we can answer you and improve our help content. In-app Help answers only how to use quickCLIENT.ai — it does not read your notes, documents, or other Client Data, and we do not store client data with your question.
2A. Categories of personal information (California)
For California residents, the categories of personal information we collect, why, and where they go. We do not sell or share (for cross-context behavioral advertising) any category, and none is disclosed for those purposes.
| Category | Examples | Purpose |
|---|---|---|
| Identifiers | Name, email, login credentials, phone (if you add SMS codes), IP address, device/push token, QuickClient Code | Create and secure your account; provide the Service; prevent abuse |
| Customer records / commercial | Subscription and billing status (held by our payment processor), profile/business-card details | Manage subscriptions; run your public card and features |
| Internet / network activity | Log data, usage, page-view analytics, campaign interaction events with a truncated IP prefix, Help/support questions | Operate, secure, and improve the Service and its help |
| Geolocation (precise — sensitive) | Location attached to a Walkthrough photo, only with your opt-in permission | Show where on a site a photo was taken |
| Audio / visual | Photos you take; audio is transcribed to text and the recording is then discarded | Build notes and Walkthrough reports you create |
| Professional / employment | Your profession, company, and specialties on your profile | Populate your business card and profile |
| Client Data (about third parties) | Names, phone, email, and details of your clients and contacts that you enter or capture | Processed on your behalf, on your instructions, as your processor |
Sources: you and your use of the Service; your device (with permission); and prospects who submit their details to you. Who we disclose to for a business purpose: the service providers (Sub-Processors) listed in Section 4. Retention: by category, as described in Section 9. Sensitive personal information: the only sensitive category is precise geolocation, collected only with your consent and used only to place your Walkthrough photos — see Section 11.
3. How we use information
We use information to: provide and maintain the Service; transcribe audio, extract text from images and PDFs, generate summaries and key facts, and power search and question-answering; create and deliver reminders; capture referrals and prospect details you collect; secure accounts and prevent abuse; provide support; process and manage subscriptions if you have a paid plan; and comply with legal obligations. We do not sell your personal information, and we do not use the content of Your Content or Client Data to serve advertising.
What we compute versus what we store. Some of what you see is worked out at the moment you look at it and is not kept. Relationship views (for example, whether you are currently working with a client or have lost touch) and stage suggestions are calculated from your own notes and contact dates each time a page loads, shown to you, and discarded — we do not store them, build a profile from them, or share them. Values we do store about a client are ones you entered or confirmed yourself, together with the AI-generated summaries and key facts described above, which are derived from Your Content and kept with the client record until you delete it.
Product improvement (optional, opt-in). The Service always learns from your own corrections — the edits you make to transcripts, summaries, and suggestions — to improve your own experience; that stays within your account. Separately, and only if you opt in (this is off by default), we use a pooled, de-identified set of those corrections to improve suggestion quality for professionals like you. Before pooling we strip identifiers, we do not include the content of Your Content or Client Data, and we never share your client details. You can turn this on or off at any time in Settings → Privacy & data; turning it off stops any further use of your corrections for this purpose.
4. AI processing and service providers (Sub-Processors)
To deliver core features, information is processed by trusted third-party providers acting on our behalf. Our current providers, by the service they perform, are named below. We update this Policy and its date when this list changes:
- AI processing — OpenAI. Transcription (speech to text), image/PDF text extraction, summaries, and embeddings for search. Content sent to this provider is, per its API terms, not used to train its models.
- Cloud database and file storage — Supabase and Cloudflare R2. Supabase hosts the database, authentication, and file storage for your notes, files, and metadata; Cloudflare R2 holds object storage and encrypted backups.
- Application hosting and delivery — Vercel. Running and serving the Service.
- DNS, content delivery, and security — Cloudflare. Protecting and delivering the Service’s traffic.
- Email delivery — Google Workspace (SMTP). Sending account and notification emails to your own address (sign-in codes, email-change confirmations, reminders you asked for), and processing messages you send to our support address. We do not send email to your clients on your behalf: when you follow up or share a document, the message opens in your own email app, so it goes from your address and lands in your Sent folder.
- Inbound email processing (optional). If you enable the email nudge, our email-routing provider receives the messages you forward and passes us only the sender and subject; we keep just that metadata (never the message body).
- SMS delivery — Twilio (only if enabled). If you turn on text-message two-factor authentication, sending one-time sign-in verification codes by text message to your own mobile number. The provider receives your number and the code needed to deliver the message, and is contractually barred from using them for any other purpose.
- Payment processing — Stripe. Subscription billing on the web, if you purchase a paid plan.
- Mobile in-app purchases — RevenueCat. If you subscribe inside our mobile app, RevenueCat manages the purchase together with the Apple App Store or Google Play; the app store processes your payment under its own terms.
- Push-notification delivery — Apple and Google. To send the reminders you turn on, we pass a device or browser push token and the notification to the platform’s push service (Apple’s APNs, Google’s Firebase Cloud Messaging, or your browser’s web-push service). They receive the token and message needed to deliver the notification, not your account content.
- Error monitoring — Sentry. When the Service hits a fault, a diagnostic report (the error, where in the code it happened, and the browser or server type) is sent to Sentry so we can fix it. These reports are stripped of personal information before they leave: no request bodies, no cookies, no headers, no search terms, no account identifier, and we do not record or replay your screen. They tell us what broke, not who you are or what you were writing.
- In-app help and support (AI-assisted) — OpenAI. Answers your product-help questions in the app, grounded in approved help content. It does not access your Client Data; the question text you submit is stored to answer you and improve our help content (see Section 2).
These providers are bound to use information only to provide services to us. We do not sell or rent personal information to third parties.
As the Service grows, we may engage additional providers in the following categories. We will update this Policy and its date when we do:
- Product analytics — to understand how features are used and improve the Service.
5. How we share information
We share information only as follows: with the Sub-Processors above; to comply with law, enforce our Terms, or protect the rights, safety, and security of users, the public, or us; in connection with a merger, acquisition, financing, or sale of assets (with notice where required); and otherwise with your consent. We do not “sell” or “share” personal information for cross-context behavioral advertising as those terms are defined under California law.
Text-messaging (SMS) consent is never shared. If you turn on text-message verification codes, we do not share or sell your mobile phone number, your SMS opt-in, or your text-messaging consent with any third party, and we do not disclose them to anyone for their own marketing or promotional purposes. Your number is disclosed only to our SMS delivery provider (Section 4) for the single purpose of sending the sign-in codes you asked for.
6. Referrals and prospect capture
The Service lets your clients refer new people to you and lets prospects share their details with you. Because this involves information about other people, please note:
- Your responsibility. You may collect and store information about prospects and referred contacts only where you have a lawful basis to do so, and you remain the controller of that information.
- Referral provenance. When a lead arrives through a client’s “Refer me” link, we record which client it came from (“referred by”) so you can see who is referring you. This is shown only to you, not published publicly.
- Your public card. Information you place on your Business Card / public profile is accessible to anyone with your card link, QR code, or QuickClient Code.
- Prospect capture. When a prospect submits their contact details to you through a shared capture link, your QR card, or a “Refer me” link one of your clients passed along, that information is added to your account as Client Data, and you become the controller of it. For a “Refer me” link, we also count how many times the link was opened and how many leads it produced, and attribute a captured lead to the client who shared it, so you can see which clients are referring you. These counts are stored to your account and shown only to you.
7. Legal bases for processing (EEA/UK users)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Service you request); your consent (which you may withdraw at any time, for example for optional emails); our legitimate interests (securing and improving the Service); and compliance with legal obligations. Where you use the Service to process the personal data of others, you are responsible for establishing your own legal basis.
8. Your rights and choices
You can access and export all of your data, and permanently delete your account and all associated data, at any time from Settings → Privacy & data. Depending on your location, you may also have rights to access, correct, delete, restrict, or port your personal data, to object to certain processing, and to lodge a complaint with a supervisory authority (GDPR/UK GDPR), or to know, access, delete, correct, and limit the use of your information and to not be discriminated against for exercising these rights (CCPA/CPRA). We do not “sell” or “share” personal information as defined under the CCPA/CPRA. To make a request, use the in-app tools or contact us at support@quickclient.ai. If your request concerns Client Data held on behalf of a business customer, we will refer it to, or act on the instructions of, that customer as the controller.
We will respond within the time your law allows (for example, within 45 days under U.S. state privacy laws, extendable where permitted). You may use an authorized agent to submit a request for you, and we may take reasonable steps to verify your identity and the agent’s authority. Appeals: if we decline your request, we will tell you why and how to appeal; to appeal, reply to our decision or contact support@quickclient.ai, and we will respond within the period your law requires. Because we do not sell or share personal information or use it for targeted advertising, there is no opt-out for us to apply, and we do not need to act on Global Privacy Control or other opt-out preference signals.
California “Shine the Light.” California Civil Code § 1798.83 lets California residents ask about personal information shared with third parties for those third parties’ own direct marketing. We do not share personal information with third parties for their direct marketing, so there is nothing to disclose; you may confirm this by contacting us at support@quickclient.ai.
Other U.S. state privacy rights. If you are a resident of a state with a comprehensive consumer-privacy law — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana, among others — you have the right to confirm whether we process your personal information and to access it, to correct it, to delete it, and to obtain a portable copy, as well as to opt out of its sale, of targeted advertising, and of profiling that produces legal or similarly significant effects. quickCLIENT.ai does not sell personal information, does notshare it for targeted advertising, and does not use it for that kind of profiling, so those opt-outs do not apply to us. You can exercise your access, correction, and deletion rights with the in-app tools or by contacting support@quickclient.ai, and you may appeal a decision as described above. We do not use your personal information to make decisions that produce legal or similarly significant effects about you.
9. Data retention
We retain your content for as long as your account is active or as needed to provide the Service. When you delete content or your account, we remove it from our active systems promptly; residual copies in encrypted backups, if any, are purged on a rolling cycle as those backups age out (timing follows our infrastructure providers’ backup lifecycle). To help you understand how long specific categories are kept, our current retention practices are:
What happens when a subscription ends. Cancelling does not immediately delete your data. You can export all of your data — including your clients, notes, and documents — at any time from account settings. If you cancel one paid module but keep another, your Campaigns and Walkthroughs data from the inactive module stays viewable in read-only form while your account remains paid, and creating, editing, AI processing, transcription, and other paid processing for that module stop, and any public Campaign QR pages or forms stop accepting submissions. If all of your paid subscriptions end, paid features continue until the end of the period you have paid for; after that you cannot add or edit records, run AI or transcription, or capture new public QR submissions, but you can still sign in to export your data or resubscribe. We retain a cancelled workspace for a limited period so you can export your data or resubscribe, after which it may be permanently deleted, subject to our backup lifecycle and any legal exceptions below. Simply signing in does not extend that period, and you can request permanent deletion at any time. We keep each category of data only as long as described below.
Categories we keep separate. We distinguish (a) your account and business data; (b) personal data about your clients and prospects, which we process on your behalf as your processor; (c) billing, security, and compliance records; and (d) anonymized, aggregate telemetry that contains no personal data. Billing, security, and compliance records are kept only as long as legitimately required (for billing, tax, fraud prevention, security, disputes, or legal compliance) and are stored separately from, and more restricted than, your operational workspace data. A verified account-deletion request may require us to delete sooner than the periods here, where applicable law requires; we then keep only what we are legitimately required to retain.
- Account content and Client Data — for as long as your account is active; removed from active systems when you delete it or close your account.
- Encrypted backups — retained for disaster recovery and purged on a rolling cycle as backups age out, per our infrastructure providers’ backup lifecycle. Deleted content may persist in backups until that cycle completes.
- Page-view analytics — pseudonymous, first-party, no IP; retained up to 24 months, then deleted or aggregated.
- Email-nudge signals (sender, subject, and time only) — retained while the related client is active and pruned on a rolling basis (generally within 90 days); deleted with the client.
- Waitlist entries — kept until you ask us to remove you or we complete launch outreach, whichever comes first.
- Dismissed reminders and action items — marking something “won’t do” records it as dropped rather than erasing it, so it stops appearing but remains part of the client’s history until you delete the item or the client.
- Security, sign-in, and access logs — retained up to 24 months to detect and investigate abuse and to meet legal obligations.
- Tamper-evident audit records — retained in an immutable archive for the period required for security and compliance, which may be longer than 24 months.
- Records of consent (including to auto-renewal) and support correspondence — retained as required to comply with legal obligations, resolve disputes, and enforce agreements.
Retention after account deletion. When you close your account, we delete your content and Client Data from active systems. A limited set of records — security, sign-in, and audit logs, records of consent, referral records, and support correspondence — may be retained for the periods above where we have a legal, security, or dispute-resolution basis to keep them. These are minimized and are not used to re-identify you for any other purpose.
10. Security
We use reasonable administrative, technical, and organizational measures to protect information, including encryption in transit and at rest, per-user access isolation, and access controls, and we do not store voice-note audio after transcription. No system is 100% secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal information, we will notify you and any regulators as required by applicable law.
11. Sensitive information
You control what you store. We recommend you avoid storing highly sensitive identifiers (such as government ID numbers, financial account numbers, passwords, or health information) unless necessary, and you remain responsible for the content you choose to upload. Do not upload others’ personal information without a lawful basis to do so.
Sensitive data we collect. The only sensitive-category data we collect is precise location, and only for the Walkthrough feature, only if you grant your device’s location permission — so it is collected with your opt-in consent. You can withhold or turn it off at any time, and you may ask us to limit our use of sensitive information. Biometrics: we do not collect or create biometric identifiers — we do not generate voiceprints from your recordings (audio is transcribed to text and then discarded), and we do not run facial recognition or derive facial geometry from your photos.
12. Where your data is processed
The Service is offered to users in the United States, and your data is processed and stored in the United States by us and our providers. If you access the Service from outside the United States, you understand that your information will be processed here, and where a cross-border transfer safeguard is required we rely on appropriate mechanisms (such as Standard Contractual Clauses).
13. Children’s privacy
The Service is a professional tool intended for adults and is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact us and we will delete it.
14. Third-party links and services
The Service may link to or interoperate with third-party sites and services we do not control. Their privacy practices are governed by their own policies, and we are not responsible for them.
15. Cookies and local storage
We use only what the Service needs to work. We do not use advertising cookies, cross-site or third-party tracking, or analytics that build a profile of you. Specifically:
- Essential cookies. A session cookie is set when you sign in so the app knows you are logged in. The Service will not function without it.
- Functional local storage. Your browser’s local storage keeps app preferences and interface state (for example, filters, tab, and layout choices) on your own device. It is not shared with advertisers and is not used to track you across sites.
- Referral cookie (first-party). If you arrive through a referral link, we set a first-party cookie (qc_ref, and optionally a source tag) so that if you sign up, we can credit the person who referred you. It is first-party only, is not used for cross-site tracking or advertising, and expires on its own.
- Error monitoring. Our error-monitoring provider may set a minimal identifier to group crash reports. Those reports are stripped of personal information before they leave and we do not record or replay your screen (see Section 4).
Because we set only essential and functional storage — and no tracking or advertising cookies — a cookie-consent banner is not required to use the Service. If we ever add non-essential analytics or advertising technologies, we will update this Policy and, where the law requires, ask for your consent first. You can clear or block cookies and local storage in your browser at any time; note that sign-in may not work without the session cookie.
16. Changes to this Policy
We may update this Policy from time to time. Material changes will be indicated by updating the “Effective and last updated” date and, where appropriate, by additional notice. Continued use after changes take effect constitutes acceptance.
17. Contact
For privacy questions or to exercise your rights, contact Prism AI Apps LLC at support@quickclient.ai, or by mail at 2108 N St, Ste N, Sacramento, CA 95816. Governing law for this Policy is the State of California, United States, as further described in our Terms of Service.