quiet.Legal

Privacy Policy

Version 2026-08-02 · Last updated 2 August 2026

This policy explains what quiet. collects when you use it, where that data is stored, which third parties process it, and what you can ask us to do with it. It covers the quiet. web app, the public site, and the waitlist.

01Who is responsible

quiet. is a Low-Key Loud product. Low-Key Loud is the data controller for the personal data described here. For anything in this policy, including data-rights requests, contact privacy@lowkeyloud.co.

Where a workspace is created by an organisation, that organisation controls the workspace content its members put into quiet., and we process that content on its behalf.

02The two kinds of data

  • Account data: who you are. The details needed to create your login, put you in a workspace, and keep the service secure.
  • Workspace content: what you make. Your brand profile answers, uploaded documents and images, generated copy and media, assistant conversations, and the research generated around them. This is visible to the other members of your workspace, according to their role.

03What we collect

AccountName (optional), email address, a bcrypt hash of your password (never the password itself), profile image URL if your sign-in provider supplies one, and the date you signed up.
Sign-in with Google, Microsoft or AppleThe provider name and your account identifier at that provider, so we can recognise you on the next sign-in. We deliberately discard the OAuth access, refresh and ID tokens instead of storing them, because we never call those providers on your behalf.
Workspace and teamWorkspace name, URL slug, your website address, inferred business type, your role, and the per-feature access your admins grant you. Invitations store the invitee's email address, the role offered, and a hash of the invite token.
Brand profileYour answers to the profile questionnaire, kept as a version history so earlier answers can be restored, along with who answered and when.
Uploads and importsBrand-guideline documents (we store the extracted text, an AI-written digest of it, and the file name), logos, reference images, video and audio you upload, and the readable text of any website URL you ask us to analyse.
Generated outputBrand kits (palette, typography, photography direction, exports), audience profiles, competitor research and its source citations, market-radar snapshots, audits and campaign plans, Studio images and video, captions and copy, the prompts and briefs behind them, scheduled calendar posts, and notifications.
Brand Assistant chatThe messages you and the assistant exchange, stored against your workspace so the conversation persists.
WaitlistIf you join the waitlist from the public site: your email address, optional name and company, which form you used, and the fact and version of the consent you gave.
Consent recordsWhich policy version you accepted, when, and the IP address and browser user-agent at that moment, kept as proof of consent and used for nothing else.
Security and abuse preventionYour IP address is used as a short-lived rate-limiting key on sign-in, sign-up, invite and waitlist requests. These counters expire with their time window.
Usage and cost meteringOne internal record per AI provider call: the provider and model, token counts or quantity, derived cost, and the workspace and user it belongs to. It is used for cost visibility, not profiling.
Plan and billingYour workspace's plan, how much of each allowance it has used in the current period, its Studio credit balances, and a ledger of every credit movement with the reason for it. Also a history of plan changes: who changed it, when, and why. We do not hold card details.
Hosting logsOur host records standard request logs (IP address, user agent, path, timestamp) for operating and securing the service.

We do not run advertising or analytics trackers, we do not buy personal data from brokers, and we do not sell your data.

04Where it is stored

  • Database: a managed PostgreSQL database hosted by Neon. Everything in §3 that is not a file lives there, encrypted in transit.
  • Application hosting: Vercel. The app and its API routes run there, and request logs are held under Vercel's retention.
  • Media files: images, video and audio you upload or generate are stored by fal.ai on fal.media, and brand-kit assets may additionally be stored in Vercel Blob. Media URLs are unguessable but are not individually access-controlled: anyone with the exact link can open the file.

05Who else processes it

We use a small number of processors. Each receives only what it needs to do its job.

Anthropic (Claude)Receives the prompts and the brand context behind every generation (your profile answers, brand-guideline digest, audience and competitor data, briefs, and assistant messages) to produce the output.
fal.aiReceives image and video prompts and any reference media you upload, generates the result, and stores both.
TavilyReceives search queries and the URLs you ask us to read (typically competitor names, your location and your website) when live web research is enabled.
NeonDatabase hosting.
VercelApplication hosting, edge network, request logs, and Blob asset storage.
Email deliveryA transactional email provider receives your email address and message content when we send waitlist or workspace email.
Google, Microsoft, AppleOnly if you choose to sign in with them, and only to authenticate you.

We may also disclose data where the law requires it, or to a successor if the business is transferred, in which case this policy travels with it.

06Why we process it, and on what basis

  • To provide the service you asked for. This is performance of our contract with you.
  • To generate content and research using AI providers. This rests on your consent, given when you registered, together with performance of the contract. See the AI Content Notice.
  • To keep the service secure with rate limiting, abuse prevention and logging, on our legitimate interest in a service that is not attacked or abused.
  • To run the business through internal cost metering and support, on our legitimate interest in operating sustainably.
  • To contact waitlist subscribers about access. This rests on your consent, withdrawable at any time.

We do not make decisions with legal or similarly significant effects about you by automated means.

07AI processing of your content

quiet.exists to generate content, so your workspace content is routinely sent to the AI providers in §5 to produce output. We do not use your workspace content to train our own models. Our AI providers process it under their API terms, which do not permit training on API inputs by default; we cannot warrant a provider's conduct beyond its published terms.

Please do not put payment-card numbers, government identifiers, health information or other special-category personal data into profile answers, uploads or assistant messages. The product is not designed to hold them.

08Sharing and visibility

  • Inside a workspace, content is shared with every member. Owners and admins can invite people, set roles, and change what each member can reach.
  • Public share links: publishing a brand kit creates a link that anyone holding it can view without signing in. Treat it as public.
  • Downloaded or published output leaves our control once you use it elsewhere.

09Cookies

We set only what the app needs to work, so there is no cookie banner to click through:

  • A session cookie set at sign-in, which keeps you signed in.
  • A workspace cookie (qw) holding the ID of the workspace you last switched to.

No advertising, cross-site tracking or analytics cookies are set.

10How long we keep it

  • Account data: for as long as the account exists. Deleting your account erases your login, name, profile image and membership of every workspace.
  • Workspace content: for as long as the workspace exists, which may be longer than your account. See §11 for exactly what happens to each workspace when you delete yourself.
  • Consent records: kept while your account exists. On deletion we keep a copy identified only by a one-way hash of your email address, so the evidence that consent was given survives without identifying you.
  • Billing records: your tier, credit balances, the credit ledger and the history of plan changes. Retained for accounting after a workspace is deleted, with the workspace name detached from the live record.
  • Rate-limit counters: minutes to hours; they expire with their window.
  • Usage and cost records: retained for financial record-keeping.
  • Waitlist entries: until you ask to be removed or unsubscribe.
  • Media files: held by our storage provider. When a workspace is deleted we queue every image, video and audio file it holds for erasure and ask the provider to remove them. Our current media provider does not offer a deletion API, so in practice those files stop being reachable through quiet. but we cannot promise the provider has destroyed them. Backups may persist for a short period regardless.

11Deleting your account

You can delete your account yourself, from Settings. Because a workspace can outlive the person who created it, what happens depends on your role in each one:

  • Workspaces you belong to but do not own are not affected. Your membership is removed and your name is detached from anything you contributed, but the workspace and its content belong to the organisation and remain with it.
  • Workspaces you owneach need a decision from you before we proceed. You either transfer the workspace to another member, in which case it survives under them, or delete it outright, in which case all of its content goes with it. We will not guess: guessing would either destroy other people's work or leave a workspace nobody can reach.

Deletion is immediate and cannot be undone. What we keep afterwards, and in what form, is set out in §10: financial records with the workspace name detached, and consent evidence identified only by a one-way hash of your email address.

You can also delete a whole workspace without deleting your account, if you own it.

12Your rights

Depending on where you live, you have some or all of these rights: access a copy of your data, correct it, delete it, restrict or object to processing, take it elsewhere in a portable form, and withdraw consent at any time (which does not undo processing already carried out).

Email privacy@lowkeyloud.co from your account address and we will respond within one month. If you are in the UK or EEA and are unhappy with our response, you may complain to your local supervisory authority.

13How we protect it

  • Passwords are stored only as bcrypt hashes.
  • OAuth provider tokens are discarded rather than stored.
  • Invite links are stored as hashes, expire, and are single-use.
  • Sign-in, sign-up, invite and upload endpoints are rate limited.
  • URLs you submit are checked before fetching, so the app cannot be pointed at private network addresses.
  • Traffic runs over TLS, and access to production data is limited to the people who operate the service.

No system is perfectly secure, and we cannot guarantee absolute security.

14Children

quiet.is a business tool and is not directed at children. Do not use it if you are under 16. If we learn that we hold a child's data, we will delete it.

15International transfers

Our processors operate in several countries, including the United States. Where personal data leaves the UK or EEA, we rely on the transfer mechanisms our processors offer, typically Standard Contractual Clauses, to keep the protection with the data.

16Changes

When this policy changes materially, we bump its version and ask you to accept the new one the next time you open quiet.. Older acceptances stay on record, so what you agreed to and when is never overwritten.

17Contact

privacy@lowkeyloud.co for privacy and data-rights requests, hello@lowkeyloud.co for everything else.

Privacy Policy·AI Content Notice·Back to quiet.