Legal

Privacy Policy

What Qaytona collects when you use the service, why, who processes it on our behalf, and how to get it removed.

Effective September 1, 2026

01

What we collect

  • Account details: your email address, and if you sign in with Google, the name and profile image Google shares with us.
  • Session data: sign-in tokens and their expiry, so you stay signed in across visits.
  • Billing details: your Stripe customer ID, plan, and subscription status. Card numbers never reach us; Stripe holds them.
  • Feedback you send: the message, any screenshot you attach, the page you sent it from, and your browser type.
  • Server logs: IP address, browser type, and request timestamps, kept for security and debugging.
02

What we do not collect

Qaytona does not run third-party advertising or analytics trackers, does not sell or rent personal data, and does not ask for patient information. Please do not enter patient identifiers anywhere in the service, including feedback.

03

Why we use it

  • To sign you in, keep your session alive, and enforce the invitation list.
  • To run your free trial and bill your subscription.
  • To answer feedback and fix the problems you report.
  • To keep the service secure and to investigate abuse.
  • To email you about your account, billing, and material changes to the service. We do not send marketing email without asking first.
04

Who processes it for us

We use a small number of providers, each bound by their own privacy terms, to run Qaytona:

  • Convex hosts our database and backend functions, including account, session, and feedback records.
  • Vercel hosts the web application and keeps request logs.
  • Google handles Google sign-in and shares your basic profile with us at your request.
  • Resend delivers sign-in codes and account email.
  • Stripe processes payments and stores your card and invoice history.
05

Cookies and local storage

Qaytona sets cookies only to keep you signed in. Your browser's local storage holds interface preferences such as the theme you chose. There are no advertising or cross-site tracking cookies.

06

How long we keep it

Account and billing records stay for as long as your account exists. Sessions expire automatically. Feedback is kept until it has been addressed and then may be retained for product history. Server logs are kept for a limited period by our hosting providers and then discarded.

07

Your choices

You can view and change your name, email, and billing details from Account settings. To export or delete your data, or to close your account, email hello@qaytona.com from the address on your account and we will complete the request within 30 days. Deleting your account removes your profile, sessions, and feedback; Stripe keeps invoice records for as long as tax and accounting rules require.

If you are in a jurisdiction that grants specific rights over personal data, such as access, correction, portability, or objection, you can exercise them through the same address.

08

Security

Data is encrypted in transit and at rest by our providers. Sign-in tokens are stored in HttpOnly cookies, one-time codes expire after 15 minutes, and access to production systems is limited to the people who operate the service. No system is perfectly secure; if we learn of a breach affecting your data we will tell you without undue delay.

09

Children

Qaytona is built for health practitioners and is not directed at anyone under 18. We do not knowingly collect data from children.

10

Changes to this policy

We will post updates here and change the effective date. For material changes we will also email the address on your account.

Questions about this document go to hello@qaytona.com. See also the Terms of Service.