Privacy Policy
The short version: We collect the minimum needed to run an invite-only community: your Google account identifier, email address, and display name; your invitations; your desk's encrypted state; any files you upload to share with a room; purchase and sticker records if you buy anything; and short-lived connection logs. Rooms are end-to-end encrypted and we cannot read them. We never collect voice recordings, video, screen captures, face data, or any biometric. We do not sell data and we do not run advertising or analytics. You can delete your account and its data at any time.
1. Who we are
The QCOS Online (the "Service", the "App") is a desktop application and its supporting online services, developed and operated by Quarantine Collective ("we", "us", "our") in Québec, Canada, and published at arhizo.me/qcos. This policy describes what personal information the Service collects, why it collects it, how it is handled, and what choices you have. It covers the desktop application, the viewer web client, and the account, invitation, and purchase systems behind them.
For the purposes of Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Québec's Act respecting the protection of personal information in the private sector as amended by Law 25, the person responsible for the protection of personal information can be reached at b@arhizo.me.
2. Information we collect
Information reaches us in four ways: what you provide when you sign in and use the App; what other members generate about you (an invitation, a sticker); what your device must send our servers for the App to function; and records of purchases.
2.1 Account and identity
- Google account identifier. A stable, opaque ID issued by Google, used as the key for your account.
- Email address. The address on your Google Account, used to match you to an invitation, to contact you about your account, and to send purchase receipts.
- Name and profile picture. Your Google name becomes the default display name, which you can change in the App. A Google profile picture, if present, is used only as an optional avatar and can be removed.
- Participant ID and display name. Inside rooms you are represented only by an internal participant ID and your chosen display name. Your email address and legal name are never shown to other members.
2.2 Invitations
- The invitation code you redeemed, who issued it, when it was issued and expires, and the role it grants (broadcaster, guest, or viewer).
- Invitations you issue to others and whether they have been redeemed. Invitations are traceable to their issuer by design, because vouching for someone carries responsibility here.
2.3 Desk and room data
- Encrypted desk state. Your desk's layout, object positions, open books and current pages, highlights, bookmarks, and stickers placed on it, stored as encrypted snapshots under a per-room key we do not hold.
- Encrypted notebooks and annotations, synchronised as encrypted collaborative documents.
- Encrypted room events. Cursor positions, presence, knocks, page turns, and speech that your own device has already turned into text are relayed as encrypted events. Ephemeral events — cursors, presence, knocks — are not persisted at all. Speech, as text, may be retained in a desk's encrypted history where its owner has enabled that.
- Transparency log. A hash chain over the encrypted event stream, containing hashes and timestamps of ciphertext blocks rather than readable content. It lets participants later prove what was said and in what order without our being able to read any of it.
2.4 Uploaded files
- Books, documents, media, and sticker artwork you upload to share with a room. These are stored unencrypted on our servers, addressed by a hash of their contents, so they can be delivered to the members of your room. They are the one category of your content we can see. See section 6.
2.5 Purchases and the sticker ledger
- If you buy credits or stickers, or make a patronage contribution, we record the transaction — what was bought, when, for how much, the resulting balance — and the stickers you hold, place, trade, or retire.
- Payments are processed by Stripe. We receive a transaction identifier, the brand and last four digits of the card, the billing country, and the payment status. Full card numbers never reach us.
- If you sell sticker packs and receive payouts, Stripe collects the identity and tax information the law requires directly from you, under Stripe's own privacy policy.
2.6 Technical and connection data
- IP address, connection timestamps, App version, operating system, and error reports, held in short-lived server logs for operation, debugging, and abuse prevention.
- We use no third-party analytics, no advertising SDKs, and no behavioural tracking of any kind, in the App or on these pages. These pages set no cookies; the App stores only a session token and your local preferences on your own device.
3. Data received from Google
The QCOS Online uses Google Sign-In as its identity provider. When you sign in we request the basic OpenID Connect scopes — openid, email, and profile — and through them receive your Google account identifier, your email address and whether it is verified, your name, and a profile picture URL. We do not request access to Gmail, Google Drive, Calendar, Contacts, or any other Google service data, and we have no ability to read them.
Information received from Google is used only to create and authenticate your account, match you to an invitation, show a name in rooms, contact you about your account, and send purchase receipts. It is not used for advertising, not sold, and not transferred to anyone except as described in section 7.
The QCOS Online's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including its Limited Use requirements.
You can revoke the App's access to your Google Account at any time from your Google Account permissions page. Revoking access signs you out and blocks further sign-in until you grant it again; on its own it does not delete your account with us. For that, see section 9.
4. What we never collect
None of the following is collected, transmitted, or stored by any part of the Service. This is enforced by the architecture rather than by policy alone: the App contains no code path that sends them to us.
- Microphone audio or voice recordings. Speech is transcribed to text on your own device; only that text and coarse prosody markers leave it, encrypted, and are re-synthesised as an audibly synthetic voice on each listener's machine.
- Voiceprints, speaker models, or any voice biometric.
- Video, webcam frames, or face data.
- Screen captures or screen recordings.
- Biometric identifiers of any kind.
- Plaintext room content on our servers. See section 6.
- Location data, beyond the country-level inference an IP address in a server log permits.
- Contacts, files, or browsing activity from your device other than what you explicitly upload.
5. How we use information
- To provide the Service: authenticate you, enforce invitations and roles, relay and persist your desk, deliver uploaded files to room members, and process purchases.
- To keep the community workable: trace invitations, enforce the interaction budget that rate-limits spam by construction, act on takedown notices for uploaded files, and detect abuse of the relay servers.
- To communicate with you: account and security notices, purchase receipts, and replies to your requests. We send no marketing email.
- To meet legal obligations: tax and payment record-keeping, copyright notice handling, and responding to lawful requests.
Our basis for this processing is your consent, given when you accept an invitation and sign in, together with what is reasonably necessary to provide a service you asked for and to comply with law. We make no automated decisions about you with legal or similarly significant effects, and we build no profiles of you for any purpose.
6. Encryption and what we can see
Rooms are end-to-end encrypted under a per-room key held by their participants. Our relay server orders encrypted events, stamps them with a logical clock, and echoes them onward. It never decrypts them and we do not hold the keys. Stated plainly: we cannot read your notebooks, your annotations, what you say, or what sits on your desk, and we cannot moderate the inside of a room we host. Moderation rests with desk owners, who can kick, ban, mute, and hide objects instantly, and with the invitation chain that traces every member to whoever vouched for them.
Two things sit deliberately outside that encryption, and you should know which:
- Uploaded files — books, media, sticker art — are stored unencrypted so they can be shared. We can see them, we may scan them by hash against known illegal material, and we will remove them in response to valid notices under the Terms of Service.
- Server-authoritative records — your account, invitations, purchase ledger, sticker holdings — are stored in readable form in our database, because they need an authority that clients cannot be trusted to supply. They are protected by access controls and encryption at rest, not by end-to-end encryption.
Where an AI participant such as the Librarian is present in a room, it joins as a participant under a key granted by the desk owner, on the same footing as a human member. Its presence does not give us server-side access to room contents.
8. Retention
- Account data: kept while your account exists; deleted within 30 days of a deletion request.
- Invitation records: kept while the issuer's or redeemer's account exists, since they underpin the community's trust model; on account deletion they are retained only in a form that no longer identifies you.
- Encrypted desk state and room history: kept while the desk exists; deleted within 30 days of the desk's deletion. The transparency log retains hashes of encrypted blocks indefinitely, and hashes cannot be reversed into content.
- Uploaded files: kept while at least one desk references them; deleted within 30 days once none does, or sooner on a valid takedown.
- Purchase and ledger records: kept seven years, as Canadian tax and payment law requires, then deleted.
- Server logs containing IP addresses: kept no longer than 30 days.
9. Deleting your data
To delete your account and its associated data, email b@arhizo.me from the address on your account, or use the account-deletion option in the App where available. We confirm and complete deletion within 30 days, subject only to the exceptions in section 8 (tax records, and de-identified invitation records), and purge it from backups within a further 60 days.
You may also revoke the App's access to your Google Account at any time at myaccount.google.com/permissions. Inside the App you can delete individual uploaded files, notebooks, and desk objects whenever you like, and uninstalling the App removes all locally stored data from your device.
10. Your rights
Wherever you live, you may ask us to access, correct, port, or delete the personal information we hold about you, withdraw your consent, and raise questions or complaints about how we handle it. Residents of Québec have further rights under Law 25, including to be informed of collection and to receive your data in a structured, commonly used technological format. Residents of the European Economic Area and the United Kingdom have the corresponding rights under the GDPR and UK GDPR. Residents of California have rights under the CCPA/CPRA; note that we neither "sell" nor "share" personal information as those terms are defined there.
To exercise any of this, email b@arhizo.me; we respond within 30 days. You also have the right to complain to the Office of the Privacy Commissioner of Canada, the Commission d'accès à l'information du Québec, or your local supervisory authority.
11. Security
Room content is protected by end-to-end encryption. Traffic between the App and our servers is protected by TLS. Server-side records are encrypted at rest and access is restricted to the operator. Card data is handled entirely by Stripe, a PCI DSS Level 1 provider. No system is perfectly secure; if we learn of a breach of your personal information presenting a real risk of serious harm, we will notify you and the appropriate authorities as the law requires.
12. Data stored on your device
The App stores locally: your desk and notebooks, so they are available offline; cached copies of uploaded files, fetched once and kept by hash; the speech-recognition and speech-synthesis models it runs on your machine; your voice and display preferences; and a session token. None of it is sent to us except as described above. Uninstalling the App, or deleting its data directory, removes all of it.
13. Age requirements
The QCOS Online is an invite-only community for adults. You must be at least 18, or the age of majority where you live if that is higher, to hold an account. We do not knowingly collect personal information from anyone under 18. If you believe a minor holds an account, contact us and we will remove it.
14. International transfers
Our servers are in Canada. Google and Stripe may process data in the United States and elsewhere under their own safeguards. Using the Service from outside Canada means your information is transferred to and processed in Canada, whose privacy laws may differ from those where you live. Where the law requires it, we rely on contractual safeguards for such transfers.
15. Changes to this policy
Any revised policy is posted at this address with an updated date. Where a change materially expands what we collect or how we use it, we will notify account holders by email or in the App before it takes effect, and will seek your consent again where the law requires that.
16. Contact
Quarantine Collective
Québec, Canada
Email: b@arhizo.me
Web: arhizo.me/qcos