Privacy Policy

The QCOS Online · Effective September 3, 2026 · Last updated September 3, 2026

The short version: We collect the minimum needed to run an invite-only community: your Google account identifier, email address, and display name; your invitations; your desk's encrypted state; any files you upload to share with a room; purchase and sticker records if you buy anything; and short-lived connection logs. Rooms are end-to-end encrypted and we cannot read them. We never collect voice recordings, video, screen captures, face data, or any biometric. We do not sell data and we do not run advertising or analytics. You can delete your account and its data at any time.


1. Who we are

The QCOS Online (the "Service", the "App") is a desktop application and its supporting online services, developed and operated by Quarantine Collective ("we", "us", "our") in Québec, Canada, and published at arhizo.me/qcos. This policy describes what personal information the Service collects, why it collects it, how it is handled, and what choices you have. It covers the desktop application, the viewer web client, and the account, invitation, and purchase systems behind them.

For the purposes of Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Québec's Act respecting the protection of personal information in the private sector as amended by Law 25, the person responsible for the protection of personal information can be reached at b@arhizo.me.

2. Information we collect

Information reaches us in four ways: what you provide when you sign in and use the App; what other members generate about you (an invitation, a sticker); what your device must send our servers for the App to function; and records of purchases.

2.1 Account and identity

2.2 Invitations

2.3 Desk and room data

2.4 Uploaded files

2.5 Purchases and the sticker ledger

2.6 Technical and connection data

3. Data received from Google

The QCOS Online uses Google Sign-In as its identity provider. When you sign in we request the basic OpenID Connect scopes — openid, email, and profile — and through them receive your Google account identifier, your email address and whether it is verified, your name, and a profile picture URL. We do not request access to Gmail, Google Drive, Calendar, Contacts, or any other Google service data, and we have no ability to read them.

Information received from Google is used only to create and authenticate your account, match you to an invitation, show a name in rooms, contact you about your account, and send purchase receipts. It is not used for advertising, not sold, and not transferred to anyone except as described in section 7.

The QCOS Online's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including its Limited Use requirements.

You can revoke the App's access to your Google Account at any time from your Google Account permissions page. Revoking access signs you out and blocks further sign-in until you grant it again; on its own it does not delete your account with us. For that, see section 9.

4. What we never collect

None of the following is collected, transmitted, or stored by any part of the Service. This is enforced by the architecture rather than by policy alone: the App contains no code path that sends them to us.

5. How we use information

Our basis for this processing is your consent, given when you accept an invitation and sign in, together with what is reasonably necessary to provide a service you asked for and to comply with law. We make no automated decisions about you with legal or similarly significant effects, and we build no profiles of you for any purpose.

6. Encryption and what we can see

Rooms are end-to-end encrypted under a per-room key held by their participants. Our relay server orders encrypted events, stamps them with a logical clock, and echoes them onward. It never decrypts them and we do not hold the keys. Stated plainly: we cannot read your notebooks, your annotations, what you say, or what sits on your desk, and we cannot moderate the inside of a room we host. Moderation rests with desk owners, who can kick, ban, mute, and hide objects instantly, and with the invitation chain that traces every member to whoever vouched for them.

Two things sit deliberately outside that encryption, and you should know which:

Where an AI participant such as the Librarian is present in a room, it joins as a participant under a key granted by the desk owner, on the same footing as a human member. Its presence does not give us server-side access to room contents.

7. How we share information

We do not sell personal information and we share none of it with advertisers or data brokers. Information is shared only in these cases:

8. Retention

9. Deleting your data

To delete your account and its associated data, email b@arhizo.me from the address on your account, or use the account-deletion option in the App where available. We confirm and complete deletion within 30 days, subject only to the exceptions in section 8 (tax records, and de-identified invitation records), and purge it from backups within a further 60 days.

You may also revoke the App's access to your Google Account at any time at myaccount.google.com/permissions. Inside the App you can delete individual uploaded files, notebooks, and desk objects whenever you like, and uninstalling the App removes all locally stored data from your device.

10. Your rights

Wherever you live, you may ask us to access, correct, port, or delete the personal information we hold about you, withdraw your consent, and raise questions or complaints about how we handle it. Residents of Québec have further rights under Law 25, including to be informed of collection and to receive your data in a structured, commonly used technological format. Residents of the European Economic Area and the United Kingdom have the corresponding rights under the GDPR and UK GDPR. Residents of California have rights under the CCPA/CPRA; note that we neither "sell" nor "share" personal information as those terms are defined there.

To exercise any of this, email b@arhizo.me; we respond within 30 days. You also have the right to complain to the Office of the Privacy Commissioner of Canada, the Commission d'accès à l'information du Québec, or your local supervisory authority.

11. Security

Room content is protected by end-to-end encryption. Traffic between the App and our servers is protected by TLS. Server-side records are encrypted at rest and access is restricted to the operator. Card data is handled entirely by Stripe, a PCI DSS Level 1 provider. No system is perfectly secure; if we learn of a breach of your personal information presenting a real risk of serious harm, we will notify you and the appropriate authorities as the law requires.

12. Data stored on your device

The App stores locally: your desk and notebooks, so they are available offline; cached copies of uploaded files, fetched once and kept by hash; the speech-recognition and speech-synthesis models it runs on your machine; your voice and display preferences; and a session token. None of it is sent to us except as described above. Uninstalling the App, or deleting its data directory, removes all of it.

13. Age requirements

The QCOS Online is an invite-only community for adults. You must be at least 18, or the age of majority where you live if that is higher, to hold an account. We do not knowingly collect personal information from anyone under 18. If you believe a minor holds an account, contact us and we will remove it.

14. International transfers

Our servers are in Canada. Google and Stripe may process data in the United States and elsewhere under their own safeguards. Using the Service from outside Canada means your information is transferred to and processed in Canada, whose privacy laws may differ from those where you live. Where the law requires it, we rely on contractual safeguards for such transfers.

15. Changes to this policy

Any revised policy is posted at this address with an updated date. Where a change materially expands what we collect or how we use it, we will notify account holders by email or in the App before it takes effect, and will seek your consent again where the law requires that.

16. Contact

Quarantine Collective
Québec, Canada
Email: b@arhizo.me
Web: arhizo.me/qcos