Privacy Policy

Effective Date: March 20, 2026

JJLabsio ("we," "us," or "our") operates Quova (https://quova.ai), an AI Brand Intelligence platform. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our website and services.

By using Quova, you agree to the practices described in this policy. If you do not agree, please do not use our services.

1. Information We Collect

1.1 Account Information

When you create an account via Google OAuth, we collect your email address, name, and profile image as provided by Google.

1.2 Brand & Business Data

To provide our services, we collect brand-related information you enter, including your brand name, website URL, competitor URLs, industry category, target audience description, and search queries you configure for AI visibility tracking.

1.3 Usage & Session Data

We automatically collect your IP address, browser user agent, and session information when you access Quova. We also collect page views and web performance metrics through Vercel Analytics and Speed Insights.

1.4 Payment Information

Payment processing is handled by our third-party provider, Polar. We do not directly collect or store your payment card details. We receive and store your subscription status, plan type, and billing identifiers from Polar.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain Quova's services
  • Process your search queries through AI engines (ChatGPT, Perplexity) to generate brand visibility reports
  • Analyze AI responses using natural language processing to produce narrative analysis, mention rates, and analysis results
  • Process subscriptions and manage billing
  • Send transactional emails such as trial notifications and account updates
  • Monitor and fix errors in our application
  • Improve our services and user experience

3. Legal Basis for Processing (GDPR)

If you are in the European Economic Area (EEA), we process your personal data based on the following legal grounds:

  • Contract performance: Processing necessary to provide Quova's services to you (account management, AI scans, reporting)
  • Legitimate interests: Improving our services, preventing fraud, and ensuring security
  • Consent: Where required, such as for marketing communications
  • Legal obligation: Compliance with applicable laws

4. Third-Party Services & Data Sharing

We share your information with the following categories of service providers to operate Quova:

4.1 AI Processing Providers

Your configured search queries are sent to OpenAI (ChatGPT) and Perplexity to retrieve AI search results. AI responses are further analyzed by Anthropic (Claude) for narrative analysis. These providers process data under their respective privacy policies.

4.2 Authentication

We use Google OAuth for account authentication. Google provides us with your basic profile information upon your authorization.

4.3 Payment Processing

Polar handles all subscription billing and payment processing. Your payment information is collected and managed directly by Polar under their privacy policy.

4.4 Email Communications

We use Resend to send transactional emails. Your email address is shared with Resend for this purpose.

4.5 Infrastructure & Analytics

  • Neon: Hosts our PostgreSQL database where your account and brand data is stored
  • Vercel: Hosts our application and provides analytics and performance monitoring
  • Sentry: Monitors application errors and performance (may receive session context and error details)

We do not sell your personal information to third parties. We only share data with service providers as necessary to operate our services.

5. Cookies & Tracking Technologies

Quova uses the following technologies:

  • Session cookies: Essential cookies for authentication and maintaining your logged-in session
  • Vercel Analytics: Collects anonymized page view and web performance data

We do not use advertising cookies or third-party tracking cookies.

6. Data Retention

We retain your personal data for as long as your account is active. When you delete your account, all associated data — including your profile, brands, search queries, scan results, and analyses — is permanently deleted.

Session data expires automatically based on session timeout periods. We may retain anonymized, aggregated data that cannot identify you for analytical purposes.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

7.1 All Users

  • Access: Request a copy of your personal data
  • Deletion: Request deletion of your account and all associated data
  • Correction: Request correction of inaccurate data

7.2 EEA Residents (GDPR)

  • Portability: Request your data in a portable format
  • Restriction: Request restriction of processing
  • Objection: Object to processing based on legitimate interests
  • Withdraw consent: Where processing is based on consent
  • Lodge a complaint with your local data protection authority

7.3 California Residents (CCPA)

  • Right to know what personal information is collected and how it is used
  • Right to delete personal information
  • Right to opt out of the sale of personal information
  • Right to non-discrimination for exercising your rights

We do not sell personal information as defined under the CCPA.

To exercise any of these rights, contact us at support@quova.ai.

8. International Data Transfers

Quova is a global service. Your data may be transferred to and processed in countries outside your country of residence, including the United States. Our third-party service providers (including AI processing providers, database hosting, and error monitoring) may process data in various jurisdictions.

Where required, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms to ensure your data is protected in accordance with this policy and applicable law.

9. Security

We implement reasonable technical and organizational measures to protect your information, including encrypted connections (HTTPS), secure authentication via OAuth, and environment-level access controls for sensitive credentials. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

10. Children's Privacy

Quova is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected data from a child under 16, we will take steps to delete it promptly. If you believe a child has provided us with personal information, please contact us at support@quova.ai.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the "Effective Date" at the top of this page. We encourage you to review this policy periodically. Your continued use of Quova after any changes constitutes your acceptance of the updated policy.

12. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:

JJLabsio
Email: support@quova.ai