Scope and responsible service
This policy applies to QFOXAI websites, customer accounts, chat and image tools, API services, developer products, support channels, public galleries, referral or marketplace features, and related services that link to it. A customer may separately control personal data placed into its own application using the QFOXAI API; in that case, the customer is responsible for its own notices, permissions, and instructions.
Information collected
- Account data: name, email address, password hash, verification status, profile and security settings.
- Commercial data: package, orders, transaction references, invoice details, wallet and referral-credit records, marketplace purchases, and payment status. QFOXAI does not need to store complete card credentials when a payment provider processes them.
- Service content: prompts, chat messages, generated output, files, images, project context, role-pack settings, workflow content, and publication choices.
- API and usage data: API-key identifier, endpoint, public model alias, timestamps, tokens, requests, latency, status, errors, limits, IP controls, and request IDs.
- Support data: contact forms, support messages, replies, attachments, and information supplied to investigate an issue.
- Device and security data: IP address, user agent, session information, login and security events, rate-limit signals, cookies, and fraud or abuse indicators.
Sources of information
Information comes directly from customers and visitors, from use of QFOXAI services, from enabled payment or communication providers, from an organization that invites a team member, and from connected software acting under a customer's instruction. Public gallery information may come from the creator who chooses to publish an image and optional public profile name.
How information is used
- Provide, personalize, and maintain requested chat, image, file, workflow, gallery, marketplace, developer, and API features.
- Authenticate accounts, protect API credentials, enforce plans, calculate usage, process orders, create invoices, and apply credits.
- Route model requests, return output, save requested history, support downloads, and keep customer settings.
- Monitor reliability, debug errors, prevent spam and abuse, investigate security events, and protect customers.
- Respond to support, contact, privacy, billing, partnership, and legal requests.
- Comply with law, resolve disputes, enforce policies, and maintain necessary business records.
- Send service messages such as verification, purchase confirmation, quota alerts, expiry reminders, security notices, and support replies when email delivery is configured.
Legal grounds where required
Depending on location and context, QFOXAI may process personal data to perform a contract, take requested pre-contract steps, comply with legal obligations, protect legitimate interests such as service security and fraud prevention, or act with consent. Where processing relies on consent, it may be withdrawn for future processing. A withdrawal does not make earlier lawful processing invalid.
AI prompts, files, images, and output
Content submitted for an AI task is processed to provide the requested result. It may be transmitted to enabled infrastructure or service components necessary to complete the task. Chat history and generated assets may be stored when the customer uses a saved workspace or gallery. Temporary or anonymous experiences may use shorter retention and browser, session, IP, or device signals to enforce limits.
Do not submit passwords, full API secrets, payment credentials, highly sensitive personal data, or information you are not authorized to process.
Optional AI improvement contributions
QFOXAI does not use account conversations, repositories, attachments, or API content for model-improvement datasets by default. Selected products may offer a separate opt-in. When enabled, eligible examples may be redacted, encrypted, screened for credentials and sensitive content, reviewed before export, and retained for a limited period. A customer can withdraw future participation and request deletion through available privacy controls.
Temporary chat, anonymous free chat, failed requests, raw files, detected secrets, hidden reasoning, and content excluded by product rules are not eligible for that optional contribution flow.
Service providers and disclosures
QFOXAI may share limited information with providers that supply hosting, storage, networking, payment, email, security, analytics, support, or AI-processing functions. They receive only the information reasonably needed for their role and operate under their own obligations and applicable agreements. Information may also be disclosed when required by valid law, to protect rights and safety, to investigate abuse or fraud, or as part of a business transaction subject to appropriate safeguards.
QFOXAI does not sell personal data and does not disclose customer prompts or API content for third-party behavioral advertising.
Public gallery and creator information
Content explicitly published to the public gallery can be viewed, indexed, shared, and downloaded according to the selected free or premium settings. Public information may include a generated title, category, summary, publication date, metrics, and a creator name when the creator enables it. Removing a public listing stops future gallery access where reasonably possible, but cannot recall copies previously downloaded or shared by others. Purchased marketplace media may remain available to the buyer as described at purchase.
International processing
QFOXAI and its service providers may process information in countries different from the customer's location. Where applicable law requires it, QFOXAI uses recognized contractual, legal, or organizational safeguards for those transfers. The protections available can vary by provider and jurisdiction.
Retention and deletion
Information is kept only as long as reasonably needed for the purposes described here, including active service, customer instructions, billing records, security, fraud prevention, legal obligations, disputes, and backups. Different records have different retention windows. Operational targets for selected logs are published on the Data Retention page and may be controlled by platform settings.
Deletion from active systems may not immediately remove limited backup copies, fraud records, financial records, or data that must be retained by law. Those records remain protected and are removed or isolated according to their applicable lifecycle.
Security
QFOXAI uses measures such as authentication, password hashing, CSRF protection, bearer authentication, hashed API-key storage, access control, rate limits, activity records, IP controls, secret redaction, and operational monitoring. No online service can guarantee absolute security. Customers must protect credentials, use server-side key storage, review account activity, and report suspected compromise promptly.
Cookies and similar storage
QFOXAI uses cookies or local storage needed for sessions, security, theme preferences, free-chat limits, and interface state. Optional analytics or advertising technologies, if introduced and legally required, should be subject to appropriate notice or choice. Blocking essential storage may prevent login or other requested features from working.
Your choices and privacy rights
Depending on applicable law, a person may have rights to be informed, access personal data, correct it, request deletion, restrict or object to processing, receive portable data, withdraw consent, and complain to a data-protection authority. Some requests may be limited by identity verification, other people's rights, fraud prevention, legal duties, or technical feasibility.
Use available dashboard privacy tools or contact support@qfoxai.com. Include the account email and a clear description, but do not send passwords or API secrets. QFOXAI may request reasonable verification before acting.
Automated processing and AI decisions
QFOXAI uses automated systems for tasks such as generating output, enforcing usage limits, detecting spam or abuse, routing requests, and identifying security risk. Customers must not use QFOXAI as the sole decision-maker for legally or similarly significant decisions about people without the safeguards, human review, notices, and rights required by applicable law.
Children
QFOXAI is not directed to children who cannot legally consent to the service or data processing in their location. A parent, guardian, school, or organization using QFOXAI with young people is responsible for appropriate authorization, supervision, configuration, and notices. Contact support if you believe a child's data was submitted without proper authority.
Policy changes and contact
This policy may be updated when services, practices, or legal requirements change. Material changes will be posted with a revised effective date and may be communicated through the account or email where appropriate.
For privacy, account-data, or security questions, contact support@qfoxai.com. For commercial questions, contact hello@qfoxai.com.