Qorivel
Legal

Privacy Policy

Last updated: 2026-09-15 · v1.0

This policy explains what data Qorivel ("we") collects, how we use it, and the choices you have. Qorivel is built to be private by default: your reflections are yours.

01Data we collect

  • Account data: your name, email address, and profile identifier from your sign-in provider (e.g. Google or Apple), plus basic settings like timezone.
  • Your reflections: daily check-ins, notes, weekly reports generated for you, and the next actions you choose.
  • Feedback you send us: if you rate a report, write a comment about it, or send us feedback about the product, we store what you wrote against your account. It never leaves Qorivel for analytics, logs, or session recordings, exactly as your reflections never do (see §3).
  • Subscription data: your plan (Free/Pro) and subscription status. Payment is processed by Paddle (see §4); we never receive or store your full card details.
  • Usage data: product analytics events (e.g. "check-in saved", "report viewed"), how you arrived at our site (referring site and campaign parameters), device/browser type, and approximate usage patterns. Analytics events never contain the text you write or the reports generated from it.
  • Session recordings: to diagnose problems and improve usability, our analytics provider records how you move through the product: the pages you open, where you click, and how you navigate. All text is masked inside your browser before the recording is sent, so your reflections, notes, and anything else you type are never captured. We do not record the contents of network requests or browser logs.
  • Where you move, click, and scroll: separately from those recordings, our analytics provider also keeps a record of where your pointer moves across a page, where you click or tap, and how far you scroll. Clicks that do nothing, and clicks repeated in the same spot, are marked as such. Each entry holds a position on the page, the kind of interaction, the address of the page as you arrived at it, including any campaign parameters the link carried, the size of your browser window, and the time. Once you are signed in it also carries the identifier your account uses; before that, an identifier your browser is given. It never carries what you write in Qorivel, or anything generated from it. We collect it on the screens inside your account as well as on our public pages. It is part of the product analytics that runs whether or not you accept cookies (see §8), and deleting your account does not remove it (see §5).
  • Approximate location: our error-tracking and analytics providers (see §4) record an approximate location derived from your IP address, to diagnose technical errors and to understand which regions visitors come from. We do not use it to track you, and neither error reports nor analytics events contain what you write.
  • Notification data: if you turn notifications on, the delivery address or device token your browser or device issues for them, and a record of the notifications we sent you.

02How we use your data

  • To provide the Service: store your check-ins, generate your weekly reports, and sync your subscription entitlements.
  • To generate reports with AI: relevant check-in content is sent server-side to our AI provider (currently OpenAI) solely to produce your report. Under our API terms with the provider, this content is not used to train their models.
  • To improve the product: aggregated, event-level analytics (never the text you write) help us understand what works.
  • To bill you: Paddle, as Merchant of Record, processes payments and related data.

We do not sell your personal data, and we do not use your reflections for advertising.

03What we never do with your reflections

  • Never include what you write (check-ins, notes, and feedback) or the reports generated from it in analytics, logs, error reports, or session recordings.
  • Never share them with third parties, except the AI provider processing your report and our hosting infrastructure.
  • Never make them visible to other users. Access is enforced at the database level (row-level security): only your account can read your rows.

04Service providers

We use a small set of processors to run Qorivel: Supabase (authentication and database), Vercel (hosting), OpenAI (AI report generation, server-side), Paddle (payments: as Merchant of Record, Paddle is an independent controller of payment data under its own privacy policy), PostHog (product analytics: we share your email address and name to identify your account, together with usage events, device and browser information, an approximate location derived from your IP address, masked session recordings, and the record of where you move, click, and scroll described in §1; never the text you write or the reports generated from it), Google Analytics (website analytics: Google Analytics sets a cookie-based identifier in your browser and receives how you arrived at Qorivel (referring site and campaign parameters), which pages you view (our landing and pricing pages only, never the screens inside your account), basic interactions with them (scrolling, and clicks on links leading away from Qorivel), sign-up funnel events, device and browser information, and an approximate location derived from your IP address; never your email, name, the text you write, or the reports generated from it. Google keeps this data for no longer than 14 months, the longest retention a standard Analytics property allows, and it is not used for advertising: Google signals, ad personalization, and Google Ads linking are all turned off), and Sentry (error diagnostics: when something goes wrong, we send an error report containing your account identifier, technical error details (message, stack trace, app release, and environment), and an approximate location; never your email, name, the text you write, or the reports generated from it). If you turn push notifications on, they are delivered through the push service built into your browser or device (see §10).

05Data retention and deletion

  • Your data is retained while your account is active.
  • You can delete your account in Settings. Settings will tell you first if there is anything you need to complete before deletion. Deletion permanently removes your profile, check-ins, notes, reports, and actions from our database or, where we are required to keep a record, takes steps to anonymize it so that you can no longer be identified from it.
  • Deleting your account does not reach the record of where you move, click, and scroll described in §1. Our product analytics provider keeps it separately from the profile it holds for you, its deletion tools do not reach it, and we have no way to delete it for a single person, so it stays after your account is gone. We have set no end date for it, so we cannot tell you when it will be gone. Those entries carry the identifier your account used, which afterwards matches no account in our database, and they never held what you write in Qorivel.
  • A small number of records are kept after deletion where the law requires it, with the link to your account removed: payment and subscription records, for 5 years; and your record of consenting to these terms at checkout, for 5 years from the date you consented or 1 year after your subscription ends, whichever is longer. Records of your purchases are also held by our payment processor as financial records under its own policy, and cannot be deleted there.
  • If you tell us why you are cancelling or deleting your account, we keep that answer without your name, account, or any timestamp that could tie it back to you, and we keep anonymous weekly totals (for example, how many accounts were active in a week). These carry no identifier, and we do not attempt to re-identify them.
  • If you turn notifications on, we keep the delivery address or device token until you withdraw the permission, it stops working, or you delete your account; the record of notifications we sent you is removed with your account.

06Security

Data is encrypted in transit (HTTPS). Access is restricted by row-level security so each user can only access their own data. Server-side secrets are never exposed to the client.

07Your rights

Depending on where you live (including under US state privacy laws), you may have the right to access, correct, delete, or receive a copy of your personal data, and to opt out of certain processing. You can delete your account in Settings (see §5, which names what deletion does not reach), or contact us at support@qorivel.com for any request. We will not discriminate against you for exercising your rights.

08Cookies and analytics

We use essential cookies for sign-in and session management. To improve Qorivel, we collect first-party product analytics (PostHog: in-product usage, including the masked session recordings and the record of where you move, click, and scroll described in §1); it does not use advertising identifiers, and is never sold or shared for advertising. Cookie-based analytics identifiers and marketing analytics (Google Analytics, which shows how visitors find and enter our site) run only with your consent. We ask for it via a banner; you can decline, and change your choice anytime in Settings.

09Children

The Service is not directed to children under 13, and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.

10International transfers

We operate from the Republic of Korea, and every provider we rely on is outside it. Each transfer below happens over an encrypted connection: most in real time while you use the Service, as part of the request being served; the notification entries instead at the moment we send you a notification. None of them is a bulk export of our database. For each recipient we list what reaches it, the country it processes in, who it is and how to contact it, why it receives the data, and how long it keeps it.

The four notification entries apply only if you turn notifications on. Which push service delivers them is decided by your browser or device, not by us. In a browser, that service handles a delivery address and a message encrypted so it cannot read it, plus each message's timing and size; in our mobile app, a device token and the notification text itself, which we keep to fixed phrases and identifiers, never what you write or the reports generated from it. We mark every notification to be discarded if it cannot be delivered within 24 hours.

  • Supabase, Inc., United States (us-east-1). Contact: privacy@supabase.com. Receives everything you store in Qorivel: your account email and display name, your check-ins including what you write in them, your reports, actions, and plans. Purpose: authentication and the database the Service runs on. Kept until you delete your account, at which point it is erased on our instruction, except for the limited legally required records described in §5.
  • Vercel Inc., United States (US-East). Contact: privacy@vercel.com, 440 N Barranca Avenue #4133, Covina, CA 91723. Receives the requests your browser makes to Qorivel, including your IP address and technical request data. Purpose: hosting and serving the Service. Vercel holds no copy of your account data; request logs are kept only for the operational period set by its own policy.
  • OpenAI OpCo, LLC, United States. Contact: privacy@openai.com, 1455 Third Street, San Francisco, CA 94158. Receives the check-in text needed to write one weekly report, at the moment you ask for that report. Purpose: generating that report. Under our API terms this content is not used to train their models, and OpenAI keeps API abuse-monitoring logs for up to 30 days.
  • Paddle.com Market Limited, United Kingdom, together with its group companies Paddle.com Inc. (United States), Paddle Payments Limited (Ireland), and Paddle.com Canada Ltd (Canada). Contact: privacy@paddle.com, 30 Old Bailey, London EC4M 7AU. Receives your payment and billing details, which you give to Paddle directly at checkout. Purpose: taking payment as Merchant of Record. Paddle is an independent controller rather than our processor, and keeps transaction records as financial records under its own policy and retention periods, which we cannot shorten. Paddle's Retain service (its payment-recovery tool, also known as ProfitWell) loads on our public home page and, once you are signed in, on the pricing page: it receives your browser's IP address and technical request data, and, only while you are signed in, your Paddle customer identifier, so that Paddle can notice a failed payment and message you about it; its scripts are delivered through Paddle's own hosts and the Cloudflare (cdnjs) and Sentry content-delivery hosts it relies on.
  • PostHog, Inc., United States. Contact: privacy@posthog.com. Receives your email address and display name to identify your account, usage events, device and browser information, an approximate location derived from your IP address, masked session recordings, and the record of where you move, click, and scroll described in §1, but never the text you write or the reports generated from it. Purpose: understanding how the Service is used. Kept while your account is active, and deleting your account deletes the PostHog person, the events recorded against it, and its recordings. The record of where you move, click, and scroll is the exception: PostHog keeps it apart from the person record, and we have no way to delete it, so it stays after your account is gone. We have set no end date for it, so we cannot tell you when it will be gone. It carries the identifier your account used, and never anything you write.
  • Functional Software, Inc., trading as Sentry, United States. Contact: compliance@sentry.io. Receives an error report when something goes wrong: your account identifier, the technical error details (message, stack trace, release, environment), and an approximate location, but never your email, name, the text you write, or the reports generated from it. Purpose: diagnosing faults. Sentry deletes event data after 90 days by default.
  • Google Analytics (Google LLC, United States). Contact: 1600 Amphitheatre Parkway, Mountain View, CA 94043, or Google's published privacy channels. Google states that it operates data centers globally and serves traffic from the one closest to where that traffic starts, so its processing is not limited to a single country. Receives the traffic-source, campaign, page-view, and sign-up funnel data described in §4, but never the text you write or the reports generated from it. Purpose: understanding how visitors find and enter Qorivel. Kept for no longer than 14 months.
  • Apple Inc., United States. Contact: apple.com/legal/privacy/contact. Receives the notification data described above when your notifications are delivered through Apple's push service, for example in Safari or on an Apple device. Purpose: delivering your notifications. Kept no longer than the 24-hour limit we set; Apple keeps its own operational records of its push service under its own policy.
  • Google LLC, United States. Contact: 1600 Amphitheatre Parkway, Mountain View, CA 94043, or Google's published privacy channels. A separate transfer from the Google Analytics entry above. Google states that it maintains servers around the world, so its processing is not limited to a single country. Receives the notification data described above when your notifications are delivered through Google's push service, for example in Chrome or on an Android device. Purpose: delivering your notifications. Kept no longer than the 24-hour limit we set.
  • Mozilla Corporation, United States. Contact: compliance@mozilla.com. Receives the notification data described above when your notifications are delivered through Mozilla's push service, for example in Firefox. Purpose: delivering your notifications. Kept no longer than the 24-hour limit we set.
  • Microsoft Corporation, United States. Contact: Microsoft Privacy, One Microsoft Way, Redmond, WA 98052, USA. Microsoft states it may store and process data in the United States and other countries where it operates facilities. Receives the notification data described above when your notifications are delivered through Microsoft's push service, for example in Microsoft Edge on Windows. Purpose: delivering your notifications. Kept no longer than the 24-hour limit we set.

You can refuse these transfers, and what refusing costs you depends on which one. The two analytics transfers, PostHog's cookie-based tier and Google Analytics, are optional: decline them in the cookie banner, or switch them off later in Settings → Privacy, and nothing else about the Service changes. PostHog's other tier runs without cookies whether or not you accept, and the record of where you move, click, and scroll is part of it, so neither the banner nor the Settings switch stops that record being collected, on our public pages or on the screens inside your account. We offer no separate switch for it today. The notification transfers are optional too: they happen only if you turn notifications on, and stop when you withdraw the notification permission in your browser or device settings. Refusing them costs you only the notifications; everything else keeps working. The rest are not separable. Authentication, the database, hosting, and report generation have no domestic alternative here, so refusing those means the Service cannot be provided to you at all; the way to refuse is to not create an account, or to delete the account you have in Settings. Where data crosses borders we rely on our providers' standard safeguards, including the European Commission's standard contractual clauses where a transfer leaves the EEA.

11Changes and contact

We are the controller for the personal data we collect about users of Qorivel. Our personal information protection officer is NA GIMOON (나기문).

We may update this policy; material changes will be notified in-product or by email. Questions or requests, including anything about your privacy: support@qorivel.com.