Introduction
This Privacy Policy describes the types of information we collect, how we use it, and the choices you have regarding your information. We are committed to transparency and to handling your information responsibly.
1. Information We Collect
1.1 Information You Provide to Us
- Create an account: Name, email address, password, and profile information
- Make a purchase: Billing information, payment details (processed securely through Stripe)
- Use our GPT Advisors: Questions, prompts, and conversation inputs
- Participate in our affiliate program: Payment information, tax documentation, referral tracking data
- Contact us: Any information you provide in correspondence or support requests
- Create or sell products: Product descriptions, pricing, content you upload
1.2 Information Automatically Collected
- Device information: IP address, browser type, operating system, device identifiers
- Usage data: Pages visited, time spent, features used, click patterns
- Cookies and tracking technologies: Session data, preferences, authentication tokens
- GPT interaction data: Conversation history, response patterns, personalization preferences
1.3 Information from Third Parties
- Stripe Connect: Payment processing data, transaction history, payout information
- Google Workspace: Email delivery metrics and interaction data
- Affiliate referrals: Information about users referred through affiliate links
2. How We Use Your Information
2.1 Provide and Improve Services
- Operate and maintain our platform
- Process transactions and send transaction confirmations
- Provide access to GPT Advisors and digital products
- Personalize your experience based on your interactions and preferences
- Develop new features and improve existing functionality
2.2 AI Personalization
We store and analyze your GPT Advisor conversations to:
- Provide contextually relevant responses
- Remember your preferences and previous interactions
- Improve the accuracy and helpfulness of AI responses
- Develop better AI models and training data
Important: Your GPT conversations are stored in our database and used to personalize your experience. We do not sell this data to third parties, but we do use it to improve our AI products.
2.3 Affiliate Program Management
- Track affiliate relationships and referral chains (up to one level)
- Calculate and process commission payments
- Monitor product sales and performance metrics
- Detect and prevent fraudulent activity
2.4 Communications
- Send account-related notifications and updates
- Deliver customer support responses
- Send marketing communications (with your consent)
- Provide important service announcements
2.5 Legal and Security
- Comply with legal obligations
- Enforce our Terms of Service
- Protect against fraud, abuse, and security threats
- Resolve disputes and investigate complaints
4. Data Storage and Security
4.1 Where We Store Data
- Supabase databases: Located in US-East-2
- Stripe systems: Governed by Stripe's security and compliance standards
- Google Workspace: Email data stored according to Google's infrastructure
4.2 Security Measures
- Encryption in transit (TLS/SSL) and at rest
- Secure authentication and password hashing
- Regular security audits and monitoring
- Access controls and employee training
- Incident response procedures
However, no method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
4.3 Data Retention
- Your account is active
- Necessary to provide Services
- Required by law or legitimate business purposes
- You have not requested deletion
GPT conversation data is retained indefinitely unless you request deletion or delete your account.
5. Your Privacy Rights
Depending on your location, you may have the following rights:
5.1 Access and Portability
- Request a copy of your personal information
- Download your data in a machine-readable format
- Access your GPT conversation history
5.2 Correction and Updates
- Update or correct inaccurate information
- Modify your profile and preferences
5.3 Deletion
- Request deletion of your personal information
- Delete your account and associated data
- Request deletion of specific GPT conversations
Note: Some information may be retained for legal, security, or legitimate business purposes even after deletion requests.
5.4 Objection and Restriction
- Object to certain data processing activities
- Restrict how we use your information
- Opt out of marketing communications
5.5 Withdraw Consent
- Withdraw consent for data processing where consent is the legal basis
- Disable personalization features
5.6 User Portrait Controls
If you use products that generate briefings, you can view your full User Portrait, reset any section of it, review the audit log of how it has been used, or opt out of Portrait building entirely at /profile/portrait. See section 13 for how this system works and how to request deletion of existing Portrait data.
5.7 How to Exercise Your Rights
To exercise any of these rights, contact us at:
Email: austin@xuberandigital.com
Address: (Available upon request for legal notices)
We will respond to requests within 30 days and may require identity verification.
6. International Data Transfers
Quantum Strategies is based in the United States. If you access our Services from outside the US, your information will be transferred to, stored, and processed in the United States.
The United States may not have the same data protection laws as your jurisdiction. By using our Services, you consent to the transfer of your information to the United States and processing as described in this Privacy Policy.
For users in the European Economic Area (EEA) or United Kingdom, we rely on:
- Standard Contractual Clauses approved by the European Commission
- Your explicit consent for data transfers
- Necessary transfers for contract performance
7. Children's Privacy
Our Services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately, and we will delete such information.
9. Third-Party Links
Our Services may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies before providing any information.
10. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the CCPA:
10.1 Right to Know
- Categories of personal information collected
- Sources of personal information
- Business purposes for collection
- Categories of third parties with whom we share information
- Specific pieces of personal information we hold
10.2 Right to Delete
Request deletion of your personal information, subject to certain exceptions.
10.3 Right to Opt-Out
We do not sell personal information. If our practices change, we will update this policy and provide opt-out mechanisms.
10.4 Non-Discrimination
We will not discriminate against you for exercising your CCPA rights.
10.5 Authorized Agents
You may designate an authorized agent to make requests on your behalf.
11. European Privacy Rights (GDPR)
If you are in the European Economic Area or United Kingdom, you have rights under the General Data Protection Regulation:
11.1 Legal Basis for Processing
- Contract performance: To provide Services you've requested
- Legitimate interests: To improve Services and prevent fraud
- Consent: For marketing communications and AI personalization
- Legal obligations: To comply with applicable laws
11.2 Data Protection Officer
For GDPR-related inquiries, contact our Data Protection Officer at:
Email: austin@xuberandigital.com
11.3 Supervisory Authority
You have the right to lodge a complaint with your local data protection authority.
12. AI and Automated Decision-Making
We use AI (GPT Advisors) to provide personalized recommendations and responses.
- Analyze your conversation history and preferences
- Make automated suggestions based on patterns
- Personalize content and product recommendations
You have the right to:
- Understand how AI decisions are made
- Object to automated decision-making
- Request human review of AI-generated content
Important: Our GPT Advisors are tools for guidance and exploration. They do not make legally binding decisions, and you should not rely solely on AI outputs for critical decisions.
13. Personalized Briefings and the User Portrait
Each product session ends with a written briefing — a markdown document that summarizes what came up for you and what to do with it. We store these briefings in our database so you can return to them later and so future products can build on what you've already worked through, rather than starting from zero each time.
To make that continuity possible, we also maintain a structured summary of what you have told us across products, which we call your User Portrait. The Portrait organizes what we have learned into sections such as identity, values, energy patterns, activity, results, and path. Each section records a current state, prior states for comparison, and any transitions we have detected. Every entry is tied to evidence from your own responses or briefings — we do not store claims about you without a source.
The Portrait is built by a small, narrowly-scoped AI extraction step that runs after a briefing is generated. We send the briefing text and your responses from that session to OpenAI's API (using the gpt-4o-mini model) to extract structured updates, then write those updates back to your Portrait in our database. This is the same usage pattern described in our AI and Automated Decision-Making section: data is sent to OpenAI for inference only, and we do not opt in to OpenAI using your data to train their models.
When a new product generates a briefing for you, the system reads your Portrait and any linked past briefings and prepends that context to the prompt sent to the AI. This is what allows briefings to reference what you've previously surfaced instead of treating each session as isolated. We keep an internal audit log of which briefing read which Portrait fields and which extraction wrote which fields, so the history of how your Portrait has been used is reviewable.
13.1 Your Controls
You can view your full Portrait at any time at /profile/portrait, along with the audit log showing how it has been used. From that page you can reset any section or specific field, and you can opt out of Portrait building entirely with a single toggle. When opted out, your briefings are still generated and stored so you can reread them, but no extraction runs and no cross-product context is injected into future prompts. Existing Portrait data is retained but no longer read or updated; to delete it, contact us at the email below.
13.2 Retention
Briefings and your Portrait are retained for the lifetime of your account and are deleted when you delete your account. The internal audit log of Portrait reads and writes is retained for 24 months from creation.
13.3 Where This Data Lives
Briefings, Portrait data, and audit logs are stored in our Supabase database in the United States, alongside the rest of your account data. The only external service that sees this content is OpenAI, and only at the moment of extraction or generation as described above.
14. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect:
- Changes in our Services or practices
- Legal or regulatory requirements
- Feedback from users
We will notify you of material changes by:
- Posting the updated policy on our website
- Updating the "Last Updated" date
- Sending email notifications for significant changes (if you have an account)
Your continued use of our Services after changes constitutes acceptance of the updated Privacy Policy.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Email: austin@xuberandigital.com
Address: (Available upon request for legal notices)
Business Entity: Xuberan Digital LLC
16. Affiliate Program Specific Privacy
15.1 Affiliate Data Collection
- Referral link tracking data
- Commission calculations and payment history
- Performance metrics (clicks, conversions, sales)
- One level of downline activity (users you refer who become affiliates)
15.2 Transparency
- Your own affiliate performance data
- Commission earnings and payment history
- General statistics about your referred users
You cannot view:
- Personal information of users you refer
- Detailed activity of downline affiliates beyond aggregate metrics
15.3 Tax Reporting
We may share your affiliate earnings information with tax authorities as required by law (e.g., IRS Form 1099 reporting for US affiliates earning over $600).
By using Quantum Strategies, you acknowledge that you have read and understood this Privacy Policy.