Skip to content
QUICK AI SEARCH
LEGAL

Privacy Policy

Effective 26 August 2026

1. What this covers

This policy describes what QuickAISearch stores when you visit the site, run searches or hold a subscription, and how long it is kept. It applies together with the Terms of Service.

2. Account data

When you subscribe we store your email address, display name, a salted hash of your password (never the password itself), the plan you chose, and the subscription state reported by PayPal (status, next charge date, PayPal subscription identifier). Payment details such as card or bank information are handled by PayPal and are never sent to or stored by us. A session cookie keeps you signed in; it contains no personal data beyond an opaque session identifier.

3. Searches and runs

Every search creates a run. For each run we store the query text, mode, timing, the events emitted while it executed, the retrieved source metadata (URL, domain, title, snippet, reputation and freshness scores, security flags), extracted evidence excerpts, claims and verdicts, entities and relationships, the synthesized answer, and usage counters. Full page bodies are not stored. Runs are associated with your account when you are signed in.

Anonymous preview searches are stored in the same way but are not linked to a person; they are associated only with a hashed network identifier (see section 5).

4. Monitors and email

A monitor stores its query, schedule and, if you provide one, the notification email address. Emails are sent only to that address, only when a monitored topic changes, and only through the configured email provider. Deleting a monitor removes it; the topic's snapshots remain as part of the knowledge store.

5. Network identifiers and rate limiting

We do not store raw IP addresses. For rate limiting and abuse prevention we compute a salted SHA-256 hash of the client IP address and keep only the first 24 hexadecimal characters. This hash is used to enforce per-day preview limits for anonymous visitors and is recorded in the audit log for a small set of actions (for example creating or deleting a monitor).

6. Knowledge store

Claims, source metadata, entities and relationships extracted from public web content are retained as long-lived knowledge with provenance (which run, loop and model produced them). This store does not contain account data. Queries appear in it only as labels of run nodes, truncated to 120 characters.

7. Retention

  • Runs, their events, retrieval records, evidence excerpts and timing spans are deleted 90 days after the run by a daily purge.
  • Account data is kept while the account exists. After cancellation, the account and its subscription record are retained so you can resubscribe; you may request deletion at any time.
  • Source metadata, claims, contradictions, graph records, metrics, audit entries, topics, monitors and topic snapshots are retained as part of the knowledge store and operational telemetry.
  • Structured logs contain identifiers, error messages, domains and counts; secrets are redacted and prompts and page bodies are never logged.

8. Third parties that receive data

Depending on server configuration, the following parties receive data in order to run the service: the model provider (your query, sub-questions, evidence excerpts and claims for reasoning and synthesis); the embeddings provider (query and evidence text); search providers (search queries); the websites we fetch (the request itself, with our user agent); the email provider (your notification address and the update text); and PayPal (your email and the plan, for billing). We do not use analytics or advertising trackers.

9. Your rights

You can view your plan and usage on the account page, cancel your subscription there, and delete monitors yourself. To export or delete your account data, or to ask what we hold about you, contact the operator; requests are answered within 30 days. Where the law of your country gives you additional rights (for example under the GDPR or CCPA), those rights apply.

10. Security

Data is stored in a managed database with encryption at rest provided by the hosting provider, transmitted over TLS, and protected by hashed passwords and signed session cookies. Retrieved web content is treated as untrusted: requests to private networks are blocked, active content is stripped, and text that looks like an instruction to the system is isolated and flagged.

11. Changes

Updates to this policy are published on this page with a new effective date. Material changes are announced at least 14 days in advance.