Version 2026-08-02 · Last updated 2 August 2026
quiet. is a Low-Key Loud product. Low-Key Loud is the data controller for the personal data described here. For anything in this policy, including data-rights requests, contact privacy@lowkeyloud.co.
Where a workspace is created by an organisation, that organisation controls the workspace content its members put into quiet., and we process that content on its behalf.
| Account | Name (optional), email address, a bcrypt hash of your password (never the password itself), profile image URL if your sign-in provider supplies one, and the date you signed up. |
|---|---|
| Sign-in with Google, Microsoft or Apple | The provider name and your account identifier at that provider, so we can recognise you on the next sign-in. We deliberately discard the OAuth access, refresh and ID tokens instead of storing them, because we never call those providers on your behalf. |
| Workspace and team | Workspace name, URL slug, your website address, inferred business type, your role, and the per-feature access your admins grant you. Invitations store the invitee's email address, the role offered, and a hash of the invite token. |
| Brand profile | Your answers to the profile questionnaire, kept as a version history so earlier answers can be restored, along with who answered and when. |
| Uploads and imports | Brand-guideline documents (we store the extracted text, an AI-written digest of it, and the file name), logos, reference images, video and audio you upload, and the readable text of any website URL you ask us to analyse. |
| Generated output | Brand kits (palette, typography, photography direction, exports), audience profiles, competitor research and its source citations, market-radar snapshots, audits and campaign plans, Studio images and video, captions and copy, the prompts and briefs behind them, scheduled calendar posts, and notifications. |
| Brand Assistant chat | The messages you and the assistant exchange, stored against your workspace so the conversation persists. |
| Waitlist | If you join the waitlist from the public site: your email address, optional name and company, which form you used, and the fact and version of the consent you gave. |
| Consent records | Which policy version you accepted, when, and the IP address and browser user-agent at that moment, kept as proof of consent and used for nothing else. |
| Security and abuse prevention | Your IP address is used as a short-lived rate-limiting key on sign-in, sign-up, invite and waitlist requests. These counters expire with their time window. |
| Usage and cost metering | One internal record per AI provider call: the provider and model, token counts or quantity, derived cost, and the workspace and user it belongs to. It is used for cost visibility, not profiling. |
| Plan and billing | Your workspace's plan, how much of each allowance it has used in the current period, its Studio credit balances, and a ledger of every credit movement with the reason for it. Also a history of plan changes: who changed it, when, and why. We do not hold card details. |
| Hosting logs | Our host records standard request logs (IP address, user agent, path, timestamp) for operating and securing the service. |
We do not run advertising or analytics trackers, we do not buy personal data from brokers, and we do not sell your data.
We use a small number of processors. Each receives only what it needs to do its job.
| Anthropic (Claude) | Receives the prompts and the brand context behind every generation (your profile answers, brand-guideline digest, audience and competitor data, briefs, and assistant messages) to produce the output. |
|---|---|
| fal.ai | Receives image and video prompts and any reference media you upload, generates the result, and stores both. |
| Tavily | Receives search queries and the URLs you ask us to read (typically competitor names, your location and your website) when live web research is enabled. |
| Neon | Database hosting. |
| Vercel | Application hosting, edge network, request logs, and Blob asset storage. |
| Email delivery | A transactional email provider receives your email address and message content when we send waitlist or workspace email. |
| Google, Microsoft, Apple | Only if you choose to sign in with them, and only to authenticate you. |
We may also disclose data where the law requires it, or to a successor if the business is transferred, in which case this policy travels with it.
We do not make decisions with legal or similarly significant effects about you by automated means.
quiet.exists to generate content, so your workspace content is routinely sent to the AI providers in §5 to produce output. We do not use your workspace content to train our own models. Our AI providers process it under their API terms, which do not permit training on API inputs by default; we cannot warrant a provider's conduct beyond its published terms.
Please do not put payment-card numbers, government identifiers, health information or other special-category personal data into profile answers, uploads or assistant messages. The product is not designed to hold them.
You can delete your account yourself, from Settings. Because a workspace can outlive the person who created it, what happens depends on your role in each one:
Deletion is immediate and cannot be undone. What we keep afterwards, and in what form, is set out in §10: financial records with the workspace name detached, and consent evidence identified only by a one-way hash of your email address.
You can also delete a whole workspace without deleting your account, if you own it.
Depending on where you live, you have some or all of these rights: access a copy of your data, correct it, delete it, restrict or object to processing, take it elsewhere in a portable form, and withdraw consent at any time (which does not undo processing already carried out).
Email privacy@lowkeyloud.co from your account address and we will respond within one month. If you are in the UK or EEA and are unhappy with our response, you may complain to your local supervisory authority.
No system is perfectly secure, and we cannot guarantee absolute security.
quiet.is a business tool and is not directed at children. Do not use it if you are under 16. If we learn that we hold a child's data, we will delete it.
Our processors operate in several countries, including the United States. Where personal data leaves the UK or EEA, we rely on the transfer mechanisms our processors offer, typically Standard Contractual Clauses, to keep the protection with the data.
When this policy changes materially, we bump its version and ask you to accept the new one the next time you open quiet.. Older acceptances stay on record, so what you agreed to and when is never overwritten.
privacy@lowkeyloud.co for privacy and data-rights requests, hello@lowkeyloud.co for everything else.