Quiet Delta LLC
Privacy Policy
Effective August 24, 2026
1. Scope
This Privacy Policy explains how Quiet Delta LLC (“Quiet Delta,” “we”) collects, uses, shares, and retains personal information when you use our website and the Quiet Delta platform (the “Service”). It applies to visitors, account holders, and purchasers.
2. Information we collect
You provide: name, email address, organization details, account credentials, and anything you submit into the Service (assessment inputs, documents, messages to support). At checkout, payment details are collected directly by Stripe — we receive transaction metadata (amount, tier, status, a customer/payment identifier) but never your full card number.
Collected automatically: IP address, device/browser information, pages viewed, and usage events; reCAPTCHA signals used to distinguish humans from bots; server logs (which may include your email or account ID alongside request outcomes) kept for security, support, and fraud prevention.
From third parties: payment status events from Stripe (including disputes and chargebacks) and email delivery status from Mailgun.
Website analytics: our marketing site uses Cloudflare Web Analytics, which reports aggregate traffic (pages viewed, referrers, approximate location and device type). It is designed not to use cookies and not to fingerprint or track individual visitors across sites.
Cookies and similar technologies: we use a small number of cookies and similar technologies, and we do not use any of them for advertising.
Strictly necessary. Signing in sets a session cookie so you stay signed in as you move between pages. Without it the product cannot keep you authenticated.
Security and abuse prevention. Our sign-up and checkout forms use Google reCAPTCHA Enterprise to tell humans from automated abuse. It runs invisibly — there is no puzzle to solve — and it sets a cookie and reads limited browser and interaction signals in order to score the request. We use it only to protect these forms from abuse, never to profile you or to build an advertising audience.
Analytics. Cloudflare Web Analytics, described above, is designed to work without cookies and does not track visitors across sites.
Your choices. Your browser can block or delete cookies. Blocking the strictly necessary cookie will prevent you from staying signed in, and blocking reCAPTCHA may prevent sign-up or checkout from completing, because we cannot verify the request is not automated. We do not currently use a cookie consent banner: we set no advertising or cross-site tracking cookies, and the cookies we do set are limited to keeping you signed in and protecting our forms.
3. How we use information
We use personal information to: create and secure your account (including email verification); provide the Service and generate the outputs you request; process purchases and verify payments before activating paid plans; deliver transactional email (invites, verification, receipts) via Mailgun; prevent fraud and abuse (including reCAPTCHA verification and payment-verification checks); provide support and respond to refund or billing requests; comply with law; and send occasional product updates, which you can opt out of at any time via the unsubscribe link included in every such message.
We record the version of the Assessment Terms of Use you accepted as part of your account record.
4. AI processing
Part of your report — the written summary of your results — is generated by an AI model. We use Google Vertex AI (Gemini models) running in our own Google Cloud project, in the United States (us-central1).
What we send to the model is deliberately narrow. It receives only your computed results: your overall stage and its label, the stage scale, your per-dimension and per-gateway stage numbers, a confidence indicator, and your industry category. It does not receive your name, your email address, your organization’s name, your account identifiers, or any free text you or your colleagues wrote. Written rationale and respondent comments shown in your report are assembled in your browser from your own data and are never sent to the model.
Under the Google Cloud terms that govern Vertex AI, the data we send is not used to train Google’s models.
5. How we share information
We do not sell personal information.
We share personal information with service providers who process it on our behalf, in the following categories: cloud hosting and data storage; identity and authentication; payment processing; transactional email delivery; abuse and fraud prevention; website hosting and analytics; error monitoring; and AI text generation. We also share it with professional advisors where needed, with authorities when legally required, and with a successor in a merger or asset sale (we would notify you).
Today those providers are Google Cloud Platform (hosting, Firestore data storage, logging), Google Cloud Identity Platform / Firebase (accounts and sign-in), Google Vertex AI (report generation — see section 4), Stripe (payments), Mailgun (email delivery), Google reCAPTCHA Enterprise (abuse prevention), and Cloudflare (website hosting, DNS, and privacy-preserving website analytics). We keep a current list of our service providers and will provide it on request to support@quietdelta.ai — useful if your organization needs it for a vendor review.
6. Data retention and backups
We retain account data while your account is active and as needed for legal, tax, and security purposes afterward. Operational database backups (Firestore exports) are retained for 90 days, after which they expire automatically. Payment records are retained as required for tax and accounting. Server logs are retained per Google Cloud Logging defaults (30 days unless extended).
7. Your rights and choices
You may access and update account information in the product, and you may request a copy, correction, or deletion of your personal information by emailing support@quietdelta.ai. We verify requests against your account email. Deletion requests are honored within 30 days: live records are deleted or anonymized via our documented PII-deletion procedure, and deleted data ages out of backups per the retention window above. We may retain what the law requires us to keep (for example, payment records).
Depending on your state of residence (for example, Texas, California, Colorado, and other states with comprehensive privacy laws), you may have additional rights, including portability and appeal of a denied request.
The Service is operated from the United States and directed to customers in the United States; your information is processed in the US.
8. Security
Data is hosted on Google Cloud Platform with encryption in transit and at rest. Access to production data is limited to authorized operators. Payment credentials are handled by Stripe (PCI-DSS Level 1); they never touch our servers. No system is perfectly secure; if we confirm a breach affecting your personal information, we will notify you as required by law.
9. Children
The Service is for business use by adults 18+. We do not knowingly collect information from children under 13 (or under 18 as a customer). If you believe a child provided us information, contact us and we will delete it.
10. Changes
We will post changes here with a new effective date and, for material changes, notify you by email or in-product.
11. Contact
Privacy requests and questions: support@quietdelta.ai