Legal

Privacy Policy

What Qyant collects, why, who processes it, how long it is kept, and the choices you have.

Last updated

This policy explains what information Qyant ("Qyant", "we", "us") collects when you use qyant.dev and the Qyant service, why we collect it, who processes it on our behalf, how long it is kept, and the rights you have over it. It is written to be read, not skimmed: if anything is unclear, write to support@qyant.dev.

The short version

  • We collect what is needed to run your account, build and host your apps, bill you, and keep the platform secure — nothing for advertising.
  • We do not sell personal data, run third-party advertising, or use tracking pixels or analytics cookies on qyant.dev.
  • Your project files, chat prompts and generated code are yours. They are used to provide the service to you and are not used to train AI models.
  • Payments are handled by Paddle, our merchant of record; we never see your card number.
  • You can delete your account and its data at any time by asking us.

Information we collect

Account information

When you create an account we store your email address, your display name, an avatar if one is provided by your sign-in provider, and your plan. If you sign in with Google or GitHub we receive the profile fields those providers share (name, email, avatar, provider user id). If you sign up with a password, we store only a salted hash of it.

Content you create

Everything you put into the builder is stored so that we can show it back to you and act on it: project names and descriptions, chat messages and attachments, generated change-sets, project files and their version history, environment variables you set for your app, and the databases we provision for your app's preview and deployments.

Connected services

If you connect GitHub to push code, we store an encrypted OAuth access token scoped to what you granted, the repository you linked, and the time of the last push. You can revoke the token from GitHub at any time.

Usage and billing records

To enforce plan limits and bill fairly we record, per AI request, the model used, token counts and cost, and per project, sandbox and deployment activity. Paddle sends us subscription status, plan and invoice identifiers; it keeps the payment method itself.

Technical and security data

Our servers log requests with IP address, user agent, timestamps, the route called and its status, plus error details when something fails. We keep a security log of sign-ins, password changes and administrative actions. Deployed apps you publish also produce request logs on our edge.

Support requests

If you use the contact form or email us we keep the message, your name and email, and our reply, so we can follow up.

How we use it

  • Providing the service — running the builder, generating code, hosting previews and deployments, syncing to GitHub.
  • Billing — measuring usage against your plan, processing subscriptions through Paddle, and sending receipts.
  • Security and abuse prevention — rate limiting, detecting compromised accounts, blocking misuse of sandboxes, and investigating incidents.
  • Communicating with you — transactional email (sign-in codes, password resets, deploy notifications, billing events) and replies to your support requests. We do not send marketing email unless you have explicitly opted in.
  • Improving Qyant — aggregate, de-identified metrics such as how long generations take or how often a step fails. We do not read your projects to do this.

We do not use your prompts, code, files or chat history to train our own or anyone else's machine-learning models.

Who processes it for us

We use a small number of providers, each only for the purpose listed:

ProviderPurposeWhat they receive
OpenRouter and the model providers it routes toAI generationThe prompt and relevant project context for the request you make. Requests are sent under Qyant's account, without your name or email. We select providers whose terms do not permit training on API traffic.
PaddlePayments, tax and invoicing (merchant of record)Email, billing country, plan and payment method (held by Paddle, never by us).
GitHubRepository sync, and sign-in if you choose itRepository contents you push; profile fields on sign-in.
GoogleSign-in if you choose itProfile fields on sign-in.
Infrastructure and edge providersHosting the web app, API, databases and deployed appsData in transit and at rest on our systems, under contractual confidentiality.
Our own SMTP mail serverTransactional emailThe email address and message content. No third-party email API is used.

We do not share personal data with advertisers or data brokers.

Cookies

Qyant sets only cookies that are strictly necessary:

  • a session cookie (httpOnly, secure) that keeps you signed in for up to 7 days, or 2 days of inactivity;
  • a CSRF token cookie that protects forms and API calls;
  • a short-lived cookie during OAuth sign-in that remembers where to return you.

There are no analytics or advertising cookies, so no cookie banner is shown. Your theme preference is stored in your browser's local storage and never sent to us.

How long we keep it

DataRetention
Account and profileUntil you delete your account.
Projects, files, versions, chatUntil you delete the project or your account.
Preview sandboxesStopped after 30 minutes of inactivity; the container is removed, your files are not.
DeploymentsUntil you remove them or your account.
Usage and billing recordsRetained for the period required for tax and accounting, then deleted or anonymised.
Request and security logsUp to 90 days, longer only if needed for an open investigation.
Support conversationsUp to 24 months after the last message.
BackupsRolling, encrypted, overwritten within 30 days.

When you delete your account we remove your profile, projects, files, environment variables, app databases, deployments and GitHub tokens within 30 days, except records we must keep by law.

Security

All traffic is encrypted in transit. Secrets such as OAuth tokens and app environment variables are encrypted at rest with keys held separately from the data. Generated apps run in isolated sandboxes with no access to other users' data or to our internal network. Access to production systems is limited to the people who operate the service and is logged. If we ever discover a breach that affects your data we will tell you without undue delay.

Your rights and choices

Wherever you live, you can:

  • See and export your data — projects can be pushed to GitHub or downloaded; write to us for a full export.
  • Correct your name and email from Settings.
  • Delete your account and all its data by emailing support@qyant.dev from the account's address. We confirm before deleting.
  • Disconnect GitHub or Google at any time from Settings or from the provider.
  • Object to a use of your data described here, or withdraw consent where consent is the basis for it.

If you are in the EU, UK or another jurisdiction with a data-protection law, these are your statutory rights and you may also lodge a complaint with your local supervisory authority. Our legal bases for processing are performance of our contract with you, our legitimate interest in running a secure and reliable service, compliance with legal obligations, and — for optional things like marketing email — your consent.

International transfers

Qyant serves users worldwide and the providers above may process data outside your country. Where required, transfers rely on recognised safeguards such as standard contractual clauses.

Children

Qyant is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.

Changes to this policy

When we make material changes we will update the date at the top of this page and, for significant changes, notify you by email or in the product before they take effect.

Contact

Privacy questions and requests: support@qyant.dev. General enquiries: contact@qyant.dev. See also our Terms of Service.