Privacy Policy
Last updated: 19 July 2026
This Privacy Policy explains how QuickTane ("QuickTane", "we", "us") collects, uses, and protects personal data when you use our website, dashboard, API, and sandbox services (the "Service"). We are the data controller for the personal data described here. Our infrastructure is hosted in the European Union.
1. Data we collect
- Account data — name, email, hashed password (or your Google/GitHub identifier if you sign in with them), team membership.
- Usage data — API keys (stored as a hash), sandbox runs and sessions metadata (language, status, duration, timestamps), rate-limit and abuse signals, dashboard activity.
- Code & inputs you submit — the code and data you send to a sandbox and the outputs it returns ("Your Content"). Sandboxes are ephemeral; run output may be retained to show you results and for billing/abuse purposes.
- Billing data — plan, subscription status, and payment card details. Card details are collected and processed by Stripe; we store only limited information (e.g. card brand and last four digits).
- Support data — messages you send via contact forms or support tickets.
- Technical & analytics data — IP address, device/browser, pages viewed, and interaction events collected via cookies and similar technologies (see §7).
2. How we use data & legal bases
- To provide the Service (run your code, manage your account, deliver results) — performance of our contract with you.
- To bill you and prevent payment fraud — contract and legitimate interests.
- To secure the Service — abuse detection, rate limiting, and isolation — legitimate interests and legal obligation.
- To communicate transactional messages (e.g. ticket replies, billing) — contract; product updates — legitimate interests or consent.
- To improve the Service via analytics — consent where required, otherwise legitimate interests.
We do not sell your personal data, and we do not use Your Content to train machine-learning models or for advertising.
3. Processors & third parties
We share data with service providers acting on our behalf under data-processing agreements:
- Stripe — payment processing and billing.
- Email provider (SendGrid) — transactional and support email.
- Google Analytics / Google Tag Manager — website and product analytics.
- Amplitude — product analytics and Session Replay (records interactions within the app; sensitive fields are masked where configured).
- Sentry — error and performance monitoring.
- Hosting and infrastructure providers for our EU-based cluster.
We may disclose data where required by law or to protect our rights, users, or the public.
4. Data location & international transfers
Sandboxes and core application data are hosted in the EU. Some processors (e.g. analytics) may process data outside the EU; where they do, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
5. Retention
We keep account and billing data for as long as your account is active and as required to meet legal, tax, and accounting obligations. Sandbox workloads are ephemeral and destroyed after execution; run metadata and stored output are retained for a limited period to provide history and support. We delete or anonymise data when it is no longer needed.
6. Security
We apply technical and organisational measures to protect data, including sandbox isolation (gVisor), network egress controls, encryption in transit, hashed credentials and API keys, and least-privilege access. No system is perfectly secure; we cannot guarantee absolute security.
7. Cookies & similar technologies
We and our analytics providers use cookies and similar technologies to keep you signed in and to understand how the Service is used (including Google Analytics, Google Tag Manager, and Amplitude, which powers Session Replay). Essential cookies (sign-in, security) are needed to run the Service and are always active. Non-essential analytics cookies load only after you opt in via our consent banner — nothing is set beforehand. You can change or withdraw your choice at any time using the Cookie settings link in the footer, or through your browser settings.
8. Your rights
Subject to applicable law (including the GDPR), you may have the right to access, correct, delete, restrict, or object to processing of your personal data, to data portability, and to withdraw consent. You may also lodge a complaint with your local supervisory authority. To exercise your rights, contact us using the details below.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data.
10. Changes
We may update this Policy. Material changes will be notified via the Service or email, and the "last updated" date above will change.
11. Contact
For privacy questions or to exercise your rights, email [email protected].