Privacy Policy
Last updated July 14, 2026
Quorbzy is built around a simple idea: your habit data belongs to you, not to us. No tracking scripts, no ad networks, no selling your data. This page explains exactly what we collect, why, and how to get it back.
What we collect
- Account info: your username, email address, and a securely hashed password (we never store your actual password — not even we can see it).
- Your Quorbs: the habits/hobbies you track, their frequency, streak counts, and check-in timestamps.
- Sparks: any text updates you post to the community feed.
- Follows and encouragements:who you follow, and which Sparks you've encouraged.
- Your avatar seed:a random string used to generate your pixel-pattern avatar. It isn't derived from any personal information, and no photo is ever uploaded or stored — see Avatars below.
- Subscription status:whether you have an active Quorbzy Pro subscription, your billing period's renewal date, and Stripe reference IDs for your customer/subscription record. We never see or store your card number — Stripe handles that directly.
What we don't collect
- No photos or biometric data — Quorbzy avatars are procedurally generated shapes, never uploads.
- No third-party analytics, advertising, or cross-site tracking scripts.
- No location tracking.
- We never sell or rent your data to anyone.
Public vs. private
Your username, avatar, active Quorb Cluster, streaks, Trophy Vault, and Sparksare public by design — that's how the community feed and profile pages work, and they're visible to anyone, logged in or not. Your email address and password are never public and are never shown to other users.
Cookies
Quorbzy sets exactly one cookie: a session token that keeps you logged in. It's essential to the site working (there's no way to use an account without it) and isn't used for tracking or advertising. We don't use any other cookies.
Who else sees your data
We use a small number of service providers to run Quorbzy, each with access only to what they need to do their job:
- Stripe — processes Quorbzy Pro subscription payments and billing.
- Neon — hosts our Postgres database.
- Resend — sends Quorbzy's automated emails: a nudge when one of your Quorbs enters its 48-hour grace period, and a password reset link if you request one.
- Hostinger — hosts the Quorbzy web application.
None of them are permitted to use your data for their own marketing or advertising purposes.
Your rights: export and deletion
From Settings, you can at any time, with no need to email support:
- Export a complete copy of your data (JSON or CSV).
- Permanently delete your account — this immediately and irreversibly removes every Quorb, streak log, Spark, and follow relationship tied to it, with no recovery window.
These are the same rights guaranteed under GDPR (access, portability, erasure) — we just built them as normal buttons instead of a request you have to file.
How long we keep data
We keep your data as long as your account exists. Deleting your account deletes it immediately, not on some future cleanup schedule.
Security
Passwords are hashed (never stored in plain text). Login sessions are revocable tokens, not long-lived tokens that stay valid after you log out — logging out or deleting your account invalidates them immediately. All traffic to Quorbzy is encrypted (HTTPS).
Children's privacy
Quorbzy isn't directed at children under 16, and we don't knowingly collect data from anyone under that age. If you believe a child has created an account, contact us and we'll delete it.
Changes to this policy
If this changes materially, we'll update the date at the top of this page.
Contact
Questions about your data? Use the Support form in the app, or email hello@quorbzy.com.