Legal

Privacy Policy

This Policy explains how Quark Labs, Inc. collects, uses, discloses, and protects personal information when you access or use the Quark Platform.

Effective July 22, 2026

1. Scope and our role

This Policy applies to personal information Quark Labs handles for the Service, including its hosted interface, APIs, support, and related business communications.

When an organization uses the Service to process Customer Content, that organization generally determines why and how the content is processed. In that context, the organization is the controller or business and Quark Labs acts as its processor or service provider. Requests about Customer Content should first be directed to the organization that provided your access.

Quark Labs acts as a controller or business for account, relationship, security, and operational data it uses for its own legitimate business purposes. An applicable enterprise agreement or data processing addendum may provide additional terms.

2. Personal information we collect

Account and identity information

Name, business email address, profile image, organization, authentication identifiers, roles, permissions, and information supplied by your organization or identity provider.

Customer Content

Files, documents, prompts, messages, schemas, extraction results, source-system records, and other content submitted to or generated through the Service. Customer Content may contain personal information selected by your organization.

Usage, device, and log information

IP address, browser and device information, timestamps, pages and features used, API activity, diagnostic events, audit records, performance data, and security signals.

Communications and relationship information

Support requests, feedback, meeting notes, contract and billing contacts, and other communications with Quark Labs.

3. Sources of information

We collect personal information:

  • directly from you when you use or contact the Service;
  • from your organization, workspace administrators, and connected source systems;
  • from identity providers such as Google or another configured OIDC provider; and
  • automatically from the Service, devices, browsers, APIs, and security infrastructure.

4. How we use personal information

We use personal information to:

  • provide, operate, maintain, and support the Service;
  • authenticate users and administer accounts and permissions;
  • process Customer Content and provide requested workflows, AI features, exports, and integrations;
  • secure the Service, prevent abuse, investigate incidents, and maintain audit records;
  • troubleshoot, analyze performance, and improve reliability and usability;
  • communicate about service changes, support, security, and the business relationship;
  • comply with law, enforce agreements, and protect rights, safety, and property; and
  • create aggregated or de-identified information that cannot reasonably identify an individual.

Where required, our legal bases include performing a contract, complying with legal obligations, protecting legitimate interests in operating and securing the Service, and consent where requested.

5. AI features and connected providers

When you or your organization uses an AI-enabled feature, relevant prompts, Customer Content, and technical context may be sent to the model provider selected or configured by your organization. The provider and deployment can vary by workspace. Your organization should review its configuration, enterprise agreement, and the selected provider's applicable data terms.

This Policy does not promise that every provider handles data in the same way. Workspace administrators are responsible for selecting providers appropriate for the data submitted.

6. How we disclose personal information

We may disclose personal information to:

  • your organization, workspace administrators, and authorized users;
  • vendors and subprocessors that provide hosting, identity, observability, support, communications, storage, security, or AI services;
  • integration providers at your or your organization's direction;
  • professional advisers, auditors, and insurers subject to appropriate duties;
  • authorities or other parties when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or enforce agreements; and
  • a successor in connection with a merger, financing, reorganization, bankruptcy, or transfer of all or part of the business.

Quark Labs does not sell personal information for money or share it for cross-context behavioral advertising as those terms are defined by applicable California privacy law.

7. Cookies and local storage

The Service uses cookies and similar local storage necessary for authentication, security, session continuity, and user preferences such as color scheme. The authenticated Service is not supported by third-party behavioral advertising.

Blocking necessary storage may prevent sign-in or other Service features from working. Your identity provider may use its own cookies under its privacy policy.

8. Retention

We retain personal information for as long as reasonably necessary to provide the Service, satisfy the organization's configuration and instructions, maintain security and audit records, resolve disputes, and comply with legal obligations. Retention periods depend on the data type, sensitivity, purpose, workspace settings, contract, and legal requirements.

Customer Content is deleted or returned as described in the applicable enterprise agreement. Limited copies may remain temporarily in backups or where retention is legally required.

9. Security

We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, or alteration. No system is completely secure, and we cannot guarantee absolute security. You are responsible for protecting credentials and configuring workspace access appropriately.

10. International data transfers

Quark Labs and its providers may process information in countries other than the country where it was collected. Where required, we use recognized transfer mechanisms and contractual safeguards. A workspace's hosting and provider configuration may further determine processing locations.

11. Your choices and privacy rights

Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, portability, or an appeal, and to withdraw consent where processing relies on consent. You may also have the right to complain to a data protection authority. These rights may be subject to exceptions under applicable law.

For Customer Content, contact the organization that provided your account. For Quark Labs account or relationship data, submit a request through your workspace administrator or Quark Labs account representative using the established support channel. We may need to verify your identity and authority before completing a request.

12. Children

The Service is intended for business users age 18 or older and is not directed to children. We do not knowingly collect personal information directly from children through the Service.

13. Changes and contact

We may update this Policy to reflect changes in the Service, our practices, or law. We will post the revised Policy with a new effective date and provide additional notice where required.

Questions about this Policy should be directed to your organization's workspace administrator or Quark Labs account representative. They can route privacy requests through the support and legal contact channel established for your organization.