Privacy & data policy
Stateless by construction
Your documents and reports are never stored. This policy explains exactly what we do and do not hold, who processes data on our behalf, and your rights.
§1. Overview & core philosophy
TechBoola Ltd, trading as Quaestio ("Quaestio", "we", "us", or "our"), operates the web platform at quaestio.cloud. We provide automated dialectical audit reports that examine documents for omitted baselines, secondary confounders, and unhedged uncertainty.
Our architecture is built on a foundational principle: stateless by construction. We believe the most secure way to handle your sensitive documents, financial disclosures, and policy papers is never to store them at all.
§2. What we collect and why
We operate on strict data minimisation under the UK Data Protection Act 2018 and the UK/EU General Data Protection Regulation (GDPR):
| Category | Specific data | Purpose | Storage & retention |
|---|---|---|---|
| Account data | Email address, unique account identifier | Authenticating you into your account and associating your credits. | Stored securely in our encrypted database until you close or delete your account. |
| Billing & subscription metadata | Paddle Customer ID, Subscription ID, active plan tier, purchase timestamps, credit grant balances and expiry dates | Managing your audit allowance, renewals, and pack expiries. | Stored in our database. We never collect, process, or store your credit card or payment account details. Payment processing is handled entirely by Paddle as Merchant of Record. |
| Usage metadata | Action type (e.g. audit), runtime execution duration in milliseconds, token consumption count, timestamp | Monitoring service availability, platform health, and credit consumption accounting. | Retained as anonymous operational logs without document content or titles. |
| Document content & reports | None — zero retention | Generating your dialectical audit report. | Never stored. All text submitted via paste, file upload, or web URL exists strictly in volatile server memory for the duration of the audit request and is permanently discarded the instant the response returns. |
§3. How we process documents (the ephemeral pipeline)
- 01Client-side file parsing: PDF and text files uploaded through the web interface are extracted locally inside your web browser using JavaScript. The original binary files are never uploaded to our servers or saved to storage buckets.
- 02De-identification & entity scrubbing (Stage A): before any external verification takes place, our pipeline identifies and scrubs proprietary identifiers, company names, specific litigation parties, and individuals into abstract analytical queries.
- 03Targeted search retrieval (Stage B): scrubbed, de-identified queries are sent to search indexes to retrieve published empirical baselines and counter-evidence.
- 04Dialectical synthesis (Stage C): an objective audit report is synthesised and streamed directly to your browser.
- 05Immediate memory clearance: the server holds no copies of the input text or the resulting report in any database, cache, or persistent log. If you close your browser tab without saving or downloading the PDF/JSON, that report cannot be recovered by you or by us.
- 06No AI model training: we access foundational AI models exclusively through commercial enterprise API endpoints. The terms governing these enterprise connections explicitly forbid using client inputs or generated outputs to train, fine-tune, or improve any AI foundation models.
§4. Third-party subprocessors
We rely on trusted third-party service providers to deliver the platform:
- ·Database & authentication hosting: cloud-hosted encrypted PostgreSQL and authentication services in secure European/UK data centres.
- ·Payments & Merchant of Record: Paddle.com Market Ltd (Judd House, 18–29 Mora Street, London, EC1V 8BT, UK). Paddle acts as the legal reseller and merchant of record, handling tax calculation, payment processing, fraud prevention, invoicing, and subscription management. Paddle processes your payment details under its own privacy policy.
- ·AI inference: foundational AI models are accessed through commercial enterprise API endpoints bound by zero-retention and no-training terms. Only scrubbed, de-identified analytical queries are transmitted.
- ·Evidence retrieval: search index queries containing only scrubbed, de-identified claim parameters are sent to independent search providers; no document content is transmitted.
§6. Your rights under UK & EU GDPR
- ·Right of access: you can inspect your active plan, remaining credits, and recent audit runtime logs anytime in your Account dashboard.
- ·Right to erasure ("right to be forgotten"): you can request the permanent deletion of your profile and authentication records at any time.
- ·Right to rectification: you can update your account email or billing details at any time.
To exercise any of these rights, contact our data protection representative at support@quaestio.cloud.
Questions? Write to support@quaestio.cloud