This Privacy Policy explains how qbit.me ("Company," "we," "us," or "our") collects, uses, retains, and shares information in connection with the qbit.me platform — this website (the "Site"), the qbit.me cloud dashboard and control plane (the "Cloud Service"), and the qbit agent appliance software that runs on hardware you own or control (the "Agent Software").
A central design principle of qbit.me is that your agent runtime lives on hardware you control, and that you explicitly attest to what your agent may do. This policy describes how that design shapes our data practices.
1. Information We Collect
1.1 Information you provide
- Account information — your email address and a password (stored as a salted hash, never in plaintext) when you register or sign in.
- Workspace information — organization name and operator roles you assign when you invite teammates.
- Device and provider configuration — model provider endpoints and API keys you configure, MCP server endpoints and API keys, and device identifiers for appliances you register.
- Lead and contact information — name, email, organization, and message if you submit a contact or lead form.
- Content you create — agent transcripts, agent outputs, CRM records, calendar events, Kanban projects, applications, and any other content your agents or operators produce through the Service.
1.2 Information collected automatically
- Device telemetry — for appliances you register, we receive health, status, version, and lifecycle events the device emits to the Cloud Service. We do not receive the contents of files on the device.
- Service logs — request logs, error logs, audit events, and rate-limit counters. Logs record identifiers and counts; they do not record the body of your content or your recipient emails.
- Usage analytics — aggregated counts of sessions, tool calls, and dashboard actions, used for capacity planning and product improvement.
- Cookies and local storage — for the dashboard and the Site, we use local storage for theme preference and session tokens. We do not use third-party advertising cookies.
1.3 Information from Integration Proxies
When you connect a third-party Integration Proxy, the proxy operator (the software vendor whose API you expose to your agent) controls what data the proxy returns. We transmit that data through the Cloud Service to your agent. We do not own or control that data and do not use it for our own purposes beyond operating the Service for you.
2. How We Use Information
- operating, maintaining, and securing the Service;
- authenticating you and enforcing roles, scopes, and attestation;
- delivering inbox notifications, email self-forwards, calendar exports, and session transcripts you request;
- monitoring device health, version, and lifecycle so we can surface updates and alerts;
- processing payments for paid plans, hardware, and integration services;
- responding to your support requests;
- detecting and preventing abuse, fraud, and security threats;
- complying with our legal obligations.
We do not sell your personal information. We do not use your content to train models. We do not share your content with model providers except where you explicitly configure a model provider endpoint, in which case prompts and completions flow to that provider under its own terms.
3. Where Your Data Lives
- Agent Runtime data — conversation transcripts, runtime files, and any local cache stay on your Device. We do not host the runtime.
- Cloud Service data — account, identity, configuration, telemetry, collaboration, inbox, CRM, calendar, and Kanban data is stored in our MySQL database on infrastructure we operate in the United States.
- Model provider data — prompts and completions you send to a configured model provider are processed by that provider. We retain only the logs and metadata needed to operate the Service.
- Email delivery — we use a third-party transactional email provider (SendGrid) to deliver inbox notifications and self-forwarded exports you request. The provider receives the recipient email and message body needed to deliver the email.
4. Data Retention
- Account data — retained for the life of your Account, then deleted or anonymized within a reasonable grace period after closure.
- Email notification and self-forward records — terminal records pruned on a rolling 30-day basis.
- Audit events — retained for the operational period required for security investigation and compliance, then pruned.
- Device telemetry — retained for the operational life of the device registration, then pruned.
- Content you create — retained until you or your Workspace Owner deletes it, or until Account closure, after which we may delete it within a reasonable grace period. Export your content before closing your Account.
5. Sharing
We share information only as follows:
- with the operators in your Workspace, to the extent your role and visibility settings allow;
- with model providers and email providers as needed to operate the features you configure;
- with our service providers (cloud infrastructure, email delivery, payment processing) under contracts that limit their use of your information;
- when required by law, court order, or to protect the rights, property, or safety of qbit.me, our customers, or others;
- in connection with a merger, acquisition, or asset sale, with notice where applicable.
We do not sell your personal information to third parties.
6. Your Rights and Choices
Depending on where you live, you may have rights under laws like the California Consumer Privacy Act (CCPA) or the EU/UK General Data Protection Regulation (GDPR), including the right to access, correct, delete, or export your personal information, and to object to or restrict certain processing.
- Access and export — you can view your Account and Workspace data through the dashboard and export your content using the export features provided for sessions, calendar events, Kanban projects, and tasks.
- Deletion — you can request Account deletion through the dashboard or by contacting privacy@qbit.me. We will delete or anonymize your personal information within a reasonable period, subject to legal retention obligations.
- Email preferences — you can opt out of inbox notification emails through the self-service preference endpoint and dashboard toggle. Self-forwarded exports are explicit click actions and are not affected by the opt-out.
- Model provider choice — you decide which model provider endpoints to configure and can remove any of them at any time.
- Integration Proxy choice — you decide which Integration Proxies to connect and can remove any of them at any time.
To exercise any of these rights, contact privacy@qbit.me. We will respond within the timeframes required by applicable law.
7. International Transfers
If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to that transfer. For EU/UK residents, we rely on appropriate safeguards, including standard contractual clauses, where applicable.
8. Security
We protect your information with industry-standard measures: encrypted password hashing, JWT-based authentication, HTTPS in transit, network-scoped databases, role-based authorization, audit logging, and rate limiting. API keys for model providers and MCP servers are hashed at rest. No method of transmission or storage is fully secure, but we work to protect your information and to notify affected Account holders as required by law if a breach occurs.
9. Children
The Service is not directed to children under 18 and we do not knowingly collect information from children. If you believe a child has provided us information, contact privacy@qbit.me and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last updated" date. For material changes, we will also notify Account holders through the dashboard or by email. Your continued use after changes take effect constitutes acceptance of the updated policy.
11. Contact
Questions about this Privacy Policy can be sent to privacy@qbit.me.
Company legal name and registered address: [to be inserted before launch — placeholder pending entity formation or sole-proprietorship designation]