LEGAL

Privacy Policy

What Quiny collects, why, who sees it, how long we keep it and how to get it back. We do not sell your data and we do not train models on it.
Last updated September 14, 2026·Privacy·Terms

The short version

Quiny needs a small amount of information about you and a fair amount about your business to build your app. We use it for that purpose, we do not sell it, we do not train models on it, and you can see, export and delete it. This page explains the details.

Who is responsible

Quiny, Inc., a Delaware corporation, is the controller of the personal data described here. You can reach us at privacy@quiny.ai.

What we collect

Account information. Your name, email address and, if you sign in with Google or GitHub, the identifier those services give us. If you buy credits, our payment provider collects your card details. We never see the full card number.

Your business content. Everything you give Quiny to build with: descriptions, answers to questions, product names and prices, photographs, logos, links, uploaded files, and data from services you connect. Some of this can include personal data about other people, for example the names of your customers in a Shopify export. You are responsible for having the right to share it with us.

Build history. The conversation in the console, the versions of your app, approvals, credits spent and the steps Quiny took. This is what lets you go back to an earlier version and what lets us refund a step that went wrong.

Usage information. Which parts of the console you use, how long builds take, error reports, your browser type and rough location derived from your IP address. We use a privacy respecting analytics tool that does not set cross site cookies.

Support messages. Anything you send to help@quiny.ai, including build links.

How we use it

  • To build, preview, version and submit your app.
  • To route parts of your content to the model providers that do the building.
  • To connect to third party services you have authorized, within the scope you approved.
  • To charge for credits, refund credits and keep our accounts.
  • To answer support requests.
  • To keep the Service secure and to find and fix faults.
  • To send you service messages, and product notes if you have asked for them. Every product email has a one click unsubscribe.

Where the GDPR or UK GDPR applies, our legal bases are the contract with you, our legitimate interests in running and improving the Service, your consent where we ask for it, and our legal obligations.

Model providers

To build your app Quiny sends the relevant parts of your content and instructions to large language models run by Anthropic, OpenAI, Google and Moonshot. We choose between them for each step. Each provider is bound by a contract that forbids using your data to train their models and requires them to delete it after processing, subject to their short retention windows for abuse monitoring. We do not send more than a step needs.

Who else sees your data

  • Payment processing: Stripe, for buying credits.
  • Hosting and storage: Amazon Web Services and Supabase, in the United States and the European Union.
  • Email: a transactional email provider, for service and support messages.
  • App Store submission: Apple, when you ask Quiny to submit through your connected Apple Developer account. Apple receives the listing, the build and the information Apple requires from every developer, under your account.
  • Connected services you choose, such as GitHub, Shopify, RevenueCat, Instagram or Pinterest. We only read and write what you approved.

We do not sell personal data and we do not share it with advertisers. We disclose data to authorities only when the law requires it, and we tell you when we are allowed to.

Where your data lives

Our servers are in the United States and the European Union. If you are in the EU, the UK or Switzerland, transfers to the United States rely on the EU Standard Contractual Clauses or the UK Addendum, and on the Data Privacy Framework where a provider is certified.

How long we keep it

  • Account information: while your account is open and for ninety days after it closes.
  • Business content and build history: while the workspace exists. Deleting a workspace removes it from our systems within thirty days, and from backups within ninety.
  • Payment records: seven years, because tax law requires it.
  • Support messages: two years.
  • Usage information: fourteen months in identifiable form, then aggregated.

Your rights

Wherever you live you can see the data we hold about you, correct it, export it and delete it, from Settings or by emailing privacy@quiny.ai. If you are in the EU or UK you also have the right to object to processing based on legitimate interests, to restrict processing, and to complain to your supervisory authority. If you are in California you have the rights set out in the CCPA, including the right to know and the right to delete, and we do not sell or share personal information as those terms are defined there.

We answer requests within thirty days.

Cookies

This site sets no cookies of its own, runs no advertising trackers and has no analytics.

The one thing that stores anything is the chat window, which comes from Intercom. It keeps an identifier in your browser so a conversation you start stays with you between pages and visits, and so a reply reaches the right person. We ask before any of that loads. The first time you arrive you can accept or decline, and both choices take one click.

If you decline, the chat never loads and the only thing kept is a note of your answer, so that we do not ask again on every page. Everything else works the same either way. You can change your mind at any time from the Cookie settings link at the bottom of any page, which clears what the chat stored and asks you again.

The console, once you have an account, also uses cookies that are strictly necessary to keep you signed in and to protect against cross site attacks. Those cannot be switched off, because the console cannot work without them.

Security

Data is encrypted in transit and at rest. Access inside Quiny is limited to the people who need it to run the Service and to answer your support requests, and every access is logged. Connected service tokens are stored encrypted and scoped as narrowly as the service allows. If a breach affects your data we will tell you and, where required, the relevant authority, without undue delay.

Children

Quiny is for businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe we have, email privacy@quiny.ai and we will delete it.

Changes

When we change this policy in a material way we will email account holders at least fourteen days before the change takes effect. The date at the top of this page tells you when it was last updated.

Contact

Quiny, Inc. privacy@quiny.ai