Who operates Quorum
Quorum is operated by Pool Labs LLC. Privacy and data requests can be sent to contact@poollabsllc.com.
Information we collect
- Account information: your email address, user ID, display name, authentication metadata, and session information when you create or use an account. Authentication is provided by Supabase.
- Documents: text you paste; files you upload in PDF, DOCX, Markdown, or plain-text format; the text extracted from uploaded files; document titles; and word counts.
- Review data: selected reviewers, review mode and status, model/provider assignments, model findings, verdicts, rationales, error states, synthesized reports, and timestamps.
- Billing data: credit balance and ledger entries, Stripe customer and checkout identifiers, bundle purchased, and payment-related metadata. Stripe processes payment-card details; Quorum does not store full card numbers.
- Usage and device data: page views, page exits, review and checkout actions, report exports, application errors, and associated properties such as review mode, panel size, word count, verdict, bundle, and credit quantity. For abuse prevention, Quorum stores a keyed hash of the requesting network address for up to 30 days rather than storing the raw address in its abuse ledger. PostHog also receives the signed-in user ID, email address, and available name when a user is identified.
- Network and security data: cookies used for authentication, request metadata, and server/provider error logs.
Quorum's custom analytics events do not intentionally include document text. However, document content is processed by the review systems described below, and application or infrastructure providers may process technical request data under their own configurations.
How we use information
We use this information to authenticate users; accept and extract documents; select reviewers; run individual AI reviews and synthesis; save and display results; enforce quotas and rate limits; fulfill purchases; prevent abuse; troubleshoot failures; measure product usage; and improve the service.
Do not submit information you are not authorized to disclose. Quorum is not designed as a repository for regulated health information, payment-card data, government identification numbers, account credentials, export-controlled material, or other data requiring specialized compliance safeguards.
Where information is stored and processed
- Supabase: account profiles, extracted document text, review state, individual model outputs, reports, quotas, credits, and purchase ledger data are stored in Supabase Postgres. Original uploads from signed-in users are also stored in a private Supabase Storage bucket. Row-level security limits client access, while Quorum's server uses a service-role credential and performs its own ownership checks.
- AI providers: the document title and extracted text are sent to one or more configured providers—currently Anthropic, OpenAI, and Google—together with reviewer instructions. Individual findings and a copy or truncated copy of the document may be sent again for synthesis. A provider receives the content needed for the calls assigned to it. Provider handling and retention are also governed by our account configuration and that provider's terms and policies; Quorum does not control a provider's internal logs or legal retention obligations.
- Inngest: Quorum uses Inngest to enqueue and coordinate durable review jobs. Review identifiers and job execution metadata pass through Inngest; the application loads the document content from Supabase while executing the job.
- PostHog: Quorum uses PostHog for product analytics and client-side exception capture, including the usage, identity, and error data described above.
- Stripe: Stripe hosts checkout and processes payments. Quorum sends Stripe your email address, Quorum user ID, purchase selection, and related billing identifiers.
- Cloudflare Turnstile: Cloudflare processes browser and device signals used to distinguish people from automated sign-in attempts.
- Hosting and infrastructure: the service's hosting, database, queue, analytics, rate-limiting, AI, and payment vendors process data where their infrastructure operates, which may be outside your state or country.
Retention and deletion
Signed-in accounts: account information, extracted text, original uploaded files, reviews, model outputs, reports, and billing ledger data currently have no automatic expiration. They remain until removed by us or the underlying account/data is deleted. Quorum does not currently provide a self-service document or account deletion control.
You may request deletion by emailing contact@poollabsllc.com from the address associated with your account. We may need to verify your identity. We will delete data we control unless retention is required for security, fraud prevention, billing, dispute resolution, tax, or other legal obligations. Deleting database records does not by itself guarantee immediate removal from backups, provider systems, logs, or previously completed AI-provider processing.
Cookies and analytics
Quorum uses essential cookies for Supabase authentication. PostHog is initialized when configured and captures page views and page exits without a separate cookie-consent control in the current product. Browser or network-level blocking may prevent some analytics collection but may also affect functionality.
Disclosure and security
We disclose information to the service providers named above to operate Quorum, and may disclose it when required by law, to protect users or the service, or as part of a merger, financing, acquisition, or sale of assets. We do not state that Quorum sells personal information.
Quorum uses private storage, access checks, row-level database security, encrypted HTTPS connections in production, signed job requests, and rate limits. No system is perfectly secure, and we cannot guarantee that unauthorized access or loss will never occur.
Children and changes
Quorum is not directed to children under 13, and we do not knowingly collect their personal information. We may update this policy as the product and its vendors change. Material changes will be reflected by a new effective date and, when appropriate, an in-product notice.
More detail
See the AI & document retention disclosure for a shorter, document-focused explanation and the Terms of Service for rules governing use.