This policy explains how Qiu Technologies LLC, the controller of the information described here, handles Q Chat and qchat.site data. It describes the hosted text-only beta and identifies separate records from earlier versions. It is a notice about processing, not blanket consent to optional processing.
Current scope: Q Chat: Connect, Help, Belong (com.q.qchat) version 2.0.0 is designed as a text-only open beta for people 16 years and older. It offers four fixed rooms for friends, communities, business, and local buy/sell conversations. This next beta is in development; public release and end-to-end validation are not yet confirmed. The existing Play listing covers earlier releases. Media uploads, private matching, posts, referrals, Q Coins, passes, subscriptions, and purchases are unavailable in this beta.
1. Accounts and eligibility
We process your email or Google sign-in information, authentication identifiers, chosen username, and session information. Sign-in is required. A pseudonym hides your real name from other members; it does not make you anonymous to Q Chat or its service providers.
Room admission records your 16+ self-attestation, accepted beta Terms version, account identifier, and timestamp. This is self-attestation, not identity or age verification. The hosted beta does not collect identity documents or selfies for verification. Do not misstate your age. We do not knowingly permit under-16 accounts; contact support if you suspect one.
2. Messages, membership, reports, and blocks
Messages are encrypted on your device before ciphertext enters a temporary Supabase relay. Q Chat and Supabase can access the server-readable room key, so the beta is not end-to-end encrypted. Outgoing plaintext is processed by temporary Supabase Edge rule checks before encryption, alongside on-device checks; received text is checked again on-device. These reduced checks can miss harmful content and are not specialist safety-provider approval.
We process room and sender identifiers, device-generated installation identifiers, message event IDs, sequence numbers, timestamps, membership state, and block lists to authenticate access and deliver text. Membership has no automatic expiry. Leaving a room revokes future relay access for that device; it does not erase previous copies or rotate keys already received. Treat these as shared rooms, not private conversations.
Long-press a received message to report its sender or block the account. Plaintext report evidence is off by default; include it only if you choose. Reports include reporter and target identifiers, category, details you supply, and any evidence you opt to attach. They are stored in a private safety queue. A receipt confirms storage, not reviewer action or a guaranteed response time. If submission fails, retry or contact support. For a non-CSAM enforcement error, email support to request review.
3. Device services and permissions
Release builds initialize Firebase Analytics and Crashlytics for app usage and crash diagnostics, App Check/Play Integrity for integrity signals, Remote Config for configuration, and Firebase Cloud Messaging for notification services. These services may receive app-instance identifiers, device and operating-system details, usage events, error reports, IP addresses, integrity information, and notification tokens. The Android manifest removes Advertising ID permissions and disables Advertising ID collection.
Notification permission is optional and can be changed in Android settings. User-uploaded avatars, images, GIFs, camera/photo sharing, audio, video, documents, and arbitrary attachments are disabled in this beta. Bundled artwork and locally rendered avatars do not enable user media uploads.
4. Website and optional updates
When you visit qchat.site, hosting and network providers receive connection information such as IP address, browser details, requested pages, and timestamps to serve and secure the site. Fonts are self-hosted; loading them does not contact Google Fonts. The theme preference is stored in your browser’s localStorage; clear site data to reset it. The site does not embed an advertising or analytics tracking script.
If you choose the optional newsletter or launch-list signup, we receive your email address, signup source, campaign variant, and consent timestamp. The form also uses an anti-spam field. Signup is separate from app use. We use that consent only for product and beta availability updates; it does not create an account reservation, payment, investment, or donation commitment. Email support@qiutechnologies.com to unsubscribe or request deletion of newsletter information. Following links to Google Play, social platforms, or other websites is subject to those services’ own privacy practices.
5. Purposes and legal grounds
We use this information to authenticate accounts, deliver room conversations, apply rules, investigate reports, prevent abuse, provide support, and diagnose reliability problems. Where applicable data-protection law requires a legal basis, core account and messaging processing is necessary to perform the service contract; security, proportionate moderation, and reliability processing rely on legitimate interests; required preservation and disclosures rely on legal obligations. Optional marketing and other processing requiring consent rely on consent. You may withdraw that consent without affecting earlier lawful processing.
We enforce the same universal halal conduct policy for Muslim and non-Muslim members without asking for or inferring religion for enforcement. The service prohibits dating and harmful conduct while welcoming respectful discussion across religion, nationality, race, ethnicity, caste, disability, sex, gender, sexual orientation, age, and other protected characteristics.
7. Retention and deletion
- Relay messages: expire from relay retrieval after about 24 hours. Expiry is not a promise that every stored copy is erased at that instant; expired rows are cleaned up during relay activity.
- Account records: kept while needed to provide your account. A successful hosted beta deletion removes your Supabase authentication account, beta profile, age/Terms attestation, device bindings, memberships, blocks, and your relay envelopes from active storage.
- Safety reports and review audit records: kept separately from account deletion, including pseudonymous identifiers and submitted evidence, for as long as needed to investigate reports, prevent abuse, resolve disputes, and meet legal obligations. There is no automatic deletion deadline implemented for these beta records. Safety evidence may be preserved when required by law or legal hold.
- Other copies: messages already cached on your device or another participant’s device may remain after leaving a room, signing out, relay expiry, or deleting an account. We cannot remotely erase someone else’s copies. Provider backups and service logs follow their separate retention lifecycles.
- Support and website records: kept while needed to answer requests, provide opted-in updates, maintain security, and document the outcome or withdrawal of a request. Retention depends on the request, unresolved disputes, and applicable recordkeeping duties.
See account deletion instructions for the in-app and email routes. Hosted beta deletion has no recovery period. It does not automatically identify a separate account or newsletter record from an earlier service; tell support which records your request covers.
8. Your controls and privacy rights
For access, a portable copy, correction, deletion, restriction, objection, or withdrawal of optional consent, email support at support@qiutechnologies.com. Depending on where you live, you may also have rights to opt out of sale, sharing, or targeted advertising, to use an authorized agent, to appeal a refusal, and to complain to a data-protection authority. We may ask for proportionate proof that you control the account or have authority to act for its owner. Do not send passwords, sign-in codes, or payment-card details.
Self-service export, consent-history, sale/sharing opt-out, and deactivation controls are not available in the hosted beta. Use support for these requests; do not rely on instructions for a different app version. You can sign out or delete your account in Hosted beta privacy & account. We respond within applicable legal time limits and do not retaliate for exercising privacy rights.
9. Earlier versions and unavailable features
Earlier or separately enabled versions may hold additional profile fields, social relationships, posts, verification references, referral and contribution activity, Q Coin ledgers, and Google Play purchase tokens, product IDs, transaction states, or pass expiry records. These features are unavailable in the hosted beta; this policy does not claim they are active. Payment-card information stays with the billing provider. Earlier records may remain for outstanding support, refunds, fraud prevention, accounting, or legal obligations. Contact support for access or deletion requests covering them. Materially different future features require updated disclosures.
10. Security and changes
We use transport security, authenticated access, access restrictions, and device-side encryption. No system is perfectly secure. The beta is not end-to-end encrypted, and neither encryption nor automated checks guarantee confidentiality or safety from other room members. Avoid sharing sensitive information.
We will update the date on this page when this policy changes and provide appropriate notice of material changes. We will obtain consent where required; continued use alone does not substitute for consent to optional processing.
11. Contact
Qiu Technologies LLC
1209 Mountain Road PL NE, Ste R
Albuquerque, NM 87110, USA
Email: support@qiutechnologies.com
Phone: +1 (505) 585-3030