Security & privacy

quickCLIENT.ai · a product of Prism AI Apps LLC · last updated August 13, 2026

quickCLIENT.ai is a product of Prism AI Apps LLC. We hold your client information to a rigorous standard: protect it properly, be transparent about how it works, and maintain clear operational boundaries.

Your data is encrypted

Everything you store is encrypted in transit using Transport Layer Security (TLS) and encrypted at rest on industry-standard cloud infrastructure.

Two-factor authentication, required

Signing in to quickCLIENT.ai requires two-factor authentication — it is on for every account, not optional. You get a one-time email code by default and can add an authenticator app for stronger protection, so a leaked password alone can never open your client records.

Every account is isolated

Your records are fenced off at the database level with row-level security: one account can never read another account's data, and that boundary is enforced on every request — not just hidden in the interface.

A tamper-evident security log

Security-relevant events — sign-ins, two-factor changes, email changes, and data exports — are written to an append-only log that is hash-chained and archived to write-once, immutable storage. The record of what happened to your account cannot be quietly altered after the fact, and you can review your recent account activity any time from your settings.

No audio is ever stored

Voice notes, meetings, and Walkthroughs are transcribed to text and the audio recording is then discarded — on every plan. We keep the transcript you rely on, not a recording of the room.

Your data stays yours

You can export your data whenever you want, and you can close your account and have its data deleted. We never sell your data, and we do not use your client information to train AI models.

Data lifecycle and deletion

Access follows your subscription. Cancelling never deletes your data on the spot, and you can export all of it at any time. Drop one paid module while keeping another and that module’s Campaigns or Walkthroughs data stays viewable in read-only form; end all paid subscriptions and paid features run until the period you paid for ends, after which you can still sign in to export your data or resubscribe. We retain a cancelled workspace for a limited period so you can export or resubscribe; after that period we may permanently delete workspace content and stored files, and you can request deletion sooner. Deletion removes data from our live systems; copies inside encrypted, access-controlled backups age out on our providers’ backup cycle rather than being erased on demand, and a limited set of billing, security, and legal-compliance records is kept separately only as long as legitimately required. Production data access is restricted to a small number of authorized personnel and logged. See the Privacy Policy for category-by-category periods.

Access control and personnel

Access to the production systems that hold your data is strictly limited to authorized personnel. All administrative access requires multi-factor authentication (MFA) and is restricted to system maintenance, security monitoring, or fulfilling your explicit support requests — never casual browsing.

The system processes your text

We are explicitly not a “zero-knowledge” or end-to-end encrypted vault. Because quickCLIENT.ai is designed to power voice capture and search across your records, our system must be able to read and process the text you store in order to perform search matching and retrieval.

Voice transcription

When you record a voice note, the audio is securely transmitted to our third-party transcription provider to convert it into text. Under that provider’s API terms, your content is not used to train its models; it is processed only to provide transcription and power your search. The categories of subprocessors we use are described in our Privacy Policy.

The same applies to meeting and Walkthrough audio — transcribed to text, then the recording is discarded. Walkthrough photos are stored encrypted at rest like any other attachment, and a photo’s location is captured only if you enable it and is stored with that photo. We never capture location in the background, and the resulting report is shared only when you choose to. We do not create biometric identifiers — no voiceprints from your recordings and no facial recognition or facial geometry from your photos.

Public campaign pages

Campaign landing pages are the one part of quickCLIENT.ai that is intentionally public: anyone with the link can see the card and flyer you publish and submit their details. These pages show only what you choose to publish — never your notes, other clients, or your records — and they are served through isolated, rate-limited endpoints. A prospect’s submitted details go only to your account. Your campaign data stays protected by the same per-account access controls as the rest of the Service, and a paused or ended campaign stops displaying its flyer.

Intended professional use

quickCLIENT.ai is purpose-built for business professionals — such as real estate agents, mortgage and insurance advisors, financial professionals, and recruiters — to organize and retrieve operational details about their clients and prospects.

Compliance boundary: no PHI

quickCLIENT.ai is not a medical records provider and is not intended for storing medical records, clinical notes, or Protected Health Information (PHI) governed by HIPAA. You may not upload or record PHI within the application.

Questions

Questions about your data or our security practices? Email support@quickclient.ai. Full details are in our Privacy Policy and Terms of Service.