Privacy Policy
Last updated: February 2026
1. Introduction
QuoterAgent ("we", "our", "us") is committed to protecting your privacy. This policy explains how we collect, use, and protect your personal data when you use our AI-powered proposal generation service at quoteragent.com.
2. Data We Collect
- Account data: Email address, name, and authentication credentials (managed by Supabase Auth).
- Business data: Company name, logo, website, industry, and footer text you provide for branding.
- Proposal data: Project descriptions, generated proposal content, pricing, and client information you enter.
- Acceptance records: Signer name, title, IP address, user-agent, and timestamp when a proposal is accepted.
- Usage data: Pages visited, features used, and analytics events (if you consent to analytics cookies).
- Payment data: Processed securely by Stripe. We do not store credit card numbers.
3. How We Use Your Data
- To provide and improve the QuoterAgent service
- To generate AI-powered proposals using Anthropic Claude
- To process payments via Stripe
- To send transactional emails (proposal delivery)
- To maintain an immutable audit trail for proposal acceptances
- To analyze usage patterns and improve our product
4. Third-Party Services
| Service | Purpose | Data Region |
|---|---|---|
| Supabase | Database, Auth, Storage | EU (Frankfurt) |
| Vercel | Hosting | Global CDN |
| Anthropic Claude | AI proposal generation | US |
| Stripe | Payments | US/EU |
| Resend | Email delivery | EU |
Your proposal data sent to Anthropic Claude is not used for AI training per their commercial API terms.
5. Cookies
- Essential cookies: Required for authentication and session management. Cannot be disabled.
- Analytics cookies (optional): Google Analytics and PostHog for usage insights. Only enabled with your consent.
6. Your Rights (GDPR)
If you are in the EU/EEA, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Object to processing
- Withdraw consent at any time
To exercise any of these rights, contact us at hello@quoteragent.com. We will respond within 30 days.
7. Data Security
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). We use Row Level Security (RLS) in our database to ensure users can only access their own data. All secrets are stored as environment variables and never exposed to the client.
8. Data Processing Agreement
We offer a Data Processing Agreement (DPA) for enterprise customers. Contact hello@quoteragent.com to request one.
9. Contact
For privacy-related inquiries, email us at hello@quoteragent.com.