Privacy Policy
Last updated: July 2026
Overview
FixMyQuad is a closed alpha product. This policy explains what data we collect, how we use it, and your rights. We keep things simple — no advertising, no data selling.
What We Collect
- •Account information — your name and email address, provided during registration.
- •Conversations — the messages you send and the assistant's responses, stored to maintain conversation history.
- •Uploaded images — images you attach to messages are stored securely in Vercel Blob storage for the purpose of visual diagnostics.
- •Usage analytics — anonymous counts of messages sent, token usage, and estimated API cost. Used solely for platform monitoring.
Why We Collect It
We collect data under two legal bases: to perform our contract with you (running your account and conversation history) and our legitimate interest in keeping the platform working and secure (usage analytics, abuse prevention). We do not use your data for advertising, do not sell it, and do not share it beyond the processors listed below.
You're Talking to an AI
FixMyQuad's responses are generated by an AI language model, not a human technician. This is disclosed here and in the product itself, as required under the EU AI Act's transparency rules for AI systems that interact directly with people.
Where Data Is Stored
Data is stored in a Railway-hosted PostgreSQL database and Vercel Blob storage. Uploaded images may persist in Blob storage after conversation deletion until a deletion request is processed. Some of our processors (see below) are based outside the EU/EEA; where that applies, transfers are covered by Standard Contractual Clauses and, where certified, the EU-US Data Privacy Framework.
Data Sharing
We use a small number of processors to run the service: OpenAI (generates assistant responses; API traffic is retained up to 30 days for abuse monitoring and is not used to train OpenAI's models), Vercel (hosting and image storage), Railway (database hosting), and Google (only if you sign in with Google). We do not share your data with anyone else, and we do not sell it.
Staff Access to Conversations
A limited number of authorized staff may review conversation content for customer support, security, debugging, and service-quality improvement. Every time a conversation is opened this way, that access is logged (who, when, which conversation) — conversation content itself is never included in that log.
Retention
Account and conversation data is kept for as long as your account is active. Usage analytics are retained in aggregate form for platform monitoring. If you delete your account (see below), your data is removed within 30 days, except where we're legally required to keep it longer.
Cookies
We only use cookies that are strictly necessary to keep you signed in: a session cookie and a CSRF-protection cookie, both set by our authentication provider. We don't use analytics, advertising, or tracking cookies, so no cookie consent banner is needed for these — they exist purely to run the login you asked for.
Your Rights
If you're in the EU/EEA, GDPR gives you the following rights over your data. To exercise any of them, contact us below — we'll respond within one month.
- •Access — request a copy of the personal data we hold about you.
- •Rectification — ask us to correct inaccurate or incomplete data.
- •Erasure — ask us to delete your account and associated data (see Deletion Requests below).
- •Restriction — ask us to limit how we process your data in certain circumstances.
- •Portability — request your data in a structured, machine-readable format.
- •Objection — object to processing based on our legitimate interest.
Deletion Requests
You can request deletion of your account and associated data at any time by contacting us. We will delete your account, conversations, and uploaded images within 30 days.
Contact
For privacy questions or deletion requests, contact: vojtinisko@gmail.com