Security & privacy

quickCLIENT.ai · a product of Prism AI Apps LLC · last updated October 9, 2026

quickCLIENT.ai is a product of Prism AI Apps LLC. We hold your client information to a rigorous standard: protect it properly, be transparent about how it works, and maintain clear operational boundaries.

Your data is encrypted

Everything you store is encrypted in transit using Transport Layer Security (TLS) and encrypted at rest on industry-standard cloud infrastructure.

Two-factor authentication, required

Signing in to quickCLIENT.ai requires two-factor authentication — it is on for every account, not optional. You get a one-time email code by default and can add an authenticator app for stronger protection, so a leaked password alone can never open your client records.

Every account is isolated

Your records are fenced off at the database level with row-level security: one account can never read another account's data, and that boundary is enforced on every request — not just hidden in the interface.

A tamper-evident security log

Security-relevant events — sign-ins, two-factor changes, email changes, and data exports — are written to an append-only log that is hash-chained and archived to write-once, immutable storage. The record of what happened to your account cannot be quietly altered after the fact, and you can review your recent account activity any time from your settings.

No audio is ever stored

Voice notes, meetings, and Walkthroughs are transcribed to text and the audio recording is then discarded — on every plan. We keep the transcript you rely on, not a recording of the room.

Your data stays yours

You can export your data whenever you want, and you can close your account and have its data deleted. We never sell your data, and we do not use your client information to train AI models.

Data lifecycle and deletion

Access follows your subscription. Cancelling never deletes your data on the spot, and you can export all of it at any time. Drop one paid module while keeping another and that module’s Campaigns or Walkthroughs data stays viewable in read-only form; end all paid subscriptions and paid features run until the period you paid for ends, after which you can still sign in to export your data or resubscribe. We retain a cancelled workspace for a limited period so you can export or resubscribe; after that period we may permanently delete workspace content and stored files, and you can request deletion sooner. Deletion removes data from our live systems; copies inside encrypted, access-controlled backups age out on our providers’ backup cycle rather than being erased on demand, and a limited set of billing, security, and legal-compliance records is kept separately only as long as legitimately required. Production data access is restricted to a small number of authorized personnel and logged. See the Privacy Policy for category-by-category periods.

Access control and personnel

Access to the production systems that hold your data is strictly limited to authorized personnel. All administrative access requires multi-factor authentication (MFA) and is restricted to system maintenance, security monitoring, or fulfilling your explicit support requests — never casual browsing.

The system processes your text

We are explicitly not a “zero-knowledge” or end-to-end encrypted vault. Because quickCLIENT.ai is designed to power voice capture and search across your records, our system must be able to read and process the text you store in order to perform search matching and retrieval.

Voice transcription

When you record a voice note, the audio is securely transmitted to our third-party transcription provider to convert it into text. Under that provider’s API terms, your content is not used to train its models; it is processed only to provide transcription and power your search. The categories of subprocessors we use are described in our Privacy Policy.

The same applies to meeting and Walkthrough audio — transcribed to text, then the recording is discarded. Walkthrough photos are stored encrypted at rest like any other attachment, and a photo’s location is captured only if you enable it and is stored with that photo. We never capture location in the background, and the resulting report is shared only when you choose to. We do not create biometric identifiers — no voiceprints from your recordings and no facial recognition or facial geometry from your photos.

What is public — and what isn’t

Almost everything in quickCLIENT.ai is private to your account. A few surfaces are intentionally public so you can share them by link: your Smart QR business card and its capture page, your public card, your Professional Page (only while it is published and its subscription is active), your “Refer me” cards, and campaign landing pages (only while the campaign is active and its subscription is current). Each of these shows only what you choose to put on it — never your notes, other clients, or your records — and they are served through isolated, rate-limited endpoints.

People who open these pages can submit their details to you. Those submissions, and every record they create, go only to your account and are not public — a page or form being reachable by link does not make the information it collects public. Your data stays protected by the same per-account access controls as the rest of the Service, and a Professional Page or campaign stops displaying when it is unpublished, paused, ended, or its subscription lapses.

What quickCLIENT.ai is

quickCLIENT.ai is a general-purpose customer relationship management (CRM) service for organizing and retrieving operational details about your clients and prospects. Customers are responsible for determining whether its documented features and safeguards meet their intended use and any applicable professional, regulatory, or employer requirements. quickCLIENT.ai does not provide an industry-specific compliance program or a regulated recordkeeping system unless expressly agreed in writing.

Compliance boundary: no PHI

quickCLIENT.ai is not a medical records provider and is not intended for storing medical records, clinical notes, or Protected Health Information (PHI) governed by HIPAA. You may not upload or record PHI within the application.

Questions

Questions about your data or our security practices? Email support@quickclient.ai. Full details are in our Privacy Policy and Terms of Service.