Home/Privacy Policy
Privacy Policy
Effective date: · Controller: PromptQuorum · Contact: hello@promptquorum.com
1.Who we are
PromptQuorum ("we", "us", or "our") is a software product available at https://www.promptquorum.com. PromptQuorum is developed by Hans Kuepper (the "data controller" for the purposes of GDPR).
We operate a multi-model AI dispatch and consensus analysis tool. The product itself processes no personal data — prompts, API keys, and AI responses are handled entirely within your browser and transmitted directly from your device to the AI providers you choose. PromptQuorum servers never receive, store, or process your prompts or API keys.
This Privacy Policy covers only the personal data we collect through the PromptQuorum website — specifically the waitlist form at https://www.promptquorum.com.
2.Data we collect and why
We collect the following personal data:
| Data | How collected | Purpose | Lawful basis |
|---|---|---|---|
| Email address | Waitlist form on homepage | Beta launch notification; product update emails | Consent (Art. 6(1)(a) GDPR) |
| Anonymous usage analytics | Cookieless analytics (Umami, Vercel Analytics, Microsoft Clarity) | Understand which pages are visited; improve the site | Legitimate interest (Art. 6(1)(f) GDPR) — see §7 |
We do not collect names, phone numbers, payment information, IP addresses stored beyond session-level aggregation, or any special-category data under Art. 9 GDPR.
3.Lawful basis for processing
Consent — email address
When you enter your email and click "Join Waitlist", you give us explicit consent to contact you with beta launch announcements and product updates. Consent is the lawful basis under Art. 6(1)(a) GDPR. You may withdraw consent at any time by clicking the unsubscribe link in any email we send, or by emailing hello@promptquorum.com. Withdrawal of consent does not affect the lawfulness of processing before withdrawal.
Legitimate interest — analytics
We use privacy-friendly analytics — Umami, Vercel Analytics, and Microsoft Clarity (in cookieless mode) — to understand how visitors use the site in aggregate. Device access (ePrivacy): these tools set no cookies and neither read from nor write to your terminal device, so they require no consent under the ePrivacy Directive. Data processing (GDPR): only aggregated, non-identifying usage data is processed, on the basis of our legitimate interest under Art. 6(1)(f) GDPR; you can object to this processing at any time by emailing us.
4.Data processors and third parties
We use the following third-party processors. Each is bound by a Data Processing Agreement (DPA) and GDPR-compliant data handling obligations:
| Processor | Role | Data shared | Location |
|---|---|---|---|
| Resend (Resend Inc.) | Waitlist signup handler — stores subscriber email addresses and sends confirmation and launch emails on our behalf | Email address | United States |
| Umami Analytics (Umami Software, Inc.) | Privacy-friendly, cookieless website analytics — page views and aggregate referrers (loaded only with your analytics consent) | Aggregated traffic data, hashed visitor fingerprint (no cookies) | European Union |
| Microsoft Clarity (Microsoft Corporation) | Session replay and heatmaps — loaded only with your analytics consent | Interaction events and viewport data (set only after you grant analytics consent) | United States |
| Vercel Analytics (Vercel Inc.) | Page-view metrics — measures visit counts without setting cookies (loaded only with your analytics consent) | Aggregated page-view counts, hashed visitor key (no cookies) | United States |
| Vercel Speed Insights (Vercel Inc.) | Core Web Vitals measurement — page performance metrics (loaded only with your analytics consent) | Performance timings only (no personal data, no cookies) | United States |
We do not sell your data to any third party. We do not share your email address with advertisers.
5.International data transfers
Some of our processors are based in the United States. Transfers of personal data from the European Economic Area (EEA) or the United Kingdom (UK) to the United States are subject to appropriate safeguards:
- Resend: Resend: Transfer is covered by Standard Contractual Clauses (SCCs) adopted by the European Commission under GDPR Art. 46(2)(c). Resend's Data Processing Agreement is available at resend.com/legal/dpa.
- Analytics: Microsoft Clarity (Microsoft Corporation) and Vercel Analytics / Speed Insights (Vercel Inc.) are US-based and operate cookielessly. Transfers are safeguarded by Standard Contractual Clauses (SCCs) under GDPR Art. 46; Microsoft additionally participates in the EU–US Data Privacy Framework. Umami is hosted in the EU, so no transfer occurs.
You may request a copy of the applicable SCCs by emailing hello@promptquorum.com.
6.Data retention
We retain your email address for 24 months from the date of submission, or until you unsubscribe — whichever comes first. After this period, your email address is permanently deleted from all systems, including our email service provider's list.
Our cookieless analytics tools store only aggregated, non-identifying data; no personal data that identifies you is retained. Microsoft Clarity stores anonymised session data in line with its standard retention period.
Resend retains transactional email logs for up to 30 days. Audience contact records (your email address and subscription status) are retained for as long as your subscription is active, or until you request deletion.
7.Cookies and tracking
The PromptQuorum website uses the following cookies:
| Cookie | Set by | Purpose | Duration |
|---|---|---|---|
localStorage | PromptQuorum (product only) | Stores your API keys and settings locally in your browser — never transmitted to us | Until you clear browser data |
analytics_consent | PromptQuorum (localStorage) | Stores your cookie consent choice (granted, denied, or per-category) so we do not ask again on every page | 12 months (re-prompts after expiry) |
We do not use tracking pixels, fingerprinting, or third-party advertising cookies. Our analytics tools (Umami, Vercel Analytics, Microsoft Clarity) operate cookielessly and set no cookies on your device; no consent is required for them.
Consent under the ePrivacy Directive (2002/58/EC): our analytics tools (Umami, Vercel Analytics, Microsoft Clarity) are cookieless and neither read from nor write to your terminal device, so they require no consent. For any non-essential device storage, we request your consent beforehand; you can change or withdraw it at any time via the "Cookie Settings" link in the footer. The competent supervisory authority is the Hessian Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, HBDI).
8.Your rights under GDPR
If you are in the EEA, UK, or Switzerland, you have the following rights regarding your personal data. We will respond to all requests within 30 days of receipt.
Right of access (Art. 15)
Request a copy of the personal data we hold about you and information about how it is processed.
Right to rectification (Art. 16)
Ask us to correct inaccurate or incomplete personal data.
Right to erasure / "right to be forgotten" (Art. 17)
Request deletion of your personal data. We will erase your email from all systems within 30 days, including our email service provider's list.
Right to restriction of processing (Art. 18)
Ask us to pause processing of your data while a dispute is resolved.
Right to data portability (Art. 20)
Receive a copy of your personal data in a structured, machine-readable format (JSON or CSV) to transfer to another controller.
Right to object (Art. 21)
Object to processing based on legitimate interest (analytics). We will cease that processing unless we can demonstrate compelling legitimate grounds.
Right to withdraw consent
Withdraw consent for email communications at any time by unsubscribing from any email we send, or by emailing us directly. Withdrawal does not affect prior lawful processing.
Right not to be subject to automated decisions (Art. 22)
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
To exercise any of these rights, email hello@promptquorum.com with the subject line "Data Subject Request". We may ask you to verify your identity before processing the request. There is no fee for exercising your rights.
9.Right to lodge a complaint
If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with your local supervisory authority. Our competent supervisory authority is the Hessian Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, HBDI). In the EU, you can also find your national authority at edpb.europa.eu. In the UK, the supervisory authority is the Information Commissioner's Office (ICO).
We would appreciate the opportunity to address your concern directly before you escalate to a supervisory authority — please contact us at hello@promptquorum.com first.
10.California privacy rights (CCPA)
If you are a California resident, you have the right to know what personal information we collect, the right to delete it, and the right to opt out of its sale. We do not sell personal information. To exercise your rights, email hello@promptquorum.com.
11.Children's privacy
The PromptQuorum website is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected such data, email hello@promptquorum.com and we will delete it immediately.
12.Changes to this policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. When we do, we will update the effective date at the top of this page. Material changes — such as collecting new categories of data or changing the lawful basis — will be communicated by email to waitlist subscribers at least 14 days before taking effect.
13.Contact
For all privacy-related questions, data subject requests, or to withdraw consent:
PromptQuorum — Data Controller
Email: hello@promptquorum.com
Website: https://www.promptquorum.com
Response time: within 30 days of receipt