[§] Legal

Privacy Policy

Last updated: October 7, 2026

This policy explains what personal data Quorum collects, why, who helps us process it, and how you can have it deleted.

1. Who we are

Quorum is operated by Remo Yukoff, an individual (“we”, “us”), who is responsible for the personal data described here. You can reach us at remo.yukoff@gmail.com.

2. What we collect

Account

When you sign in with Google or GitHub we receive your email address, your name and your profile picture. Your verified email address identifies your account.

Jira connection

The URL of your Jira Cloud site, the email of the Jira account and its API token. The token is stored encrypted and is never shown back to you or sent anywhere except your own Jira site.

Your work in Quorum

The Jira tickets you open (summary, description, acceptance criteria, related tickets), and the sessions you create from them: test cases, questions, answers, chat messages and the record of what was sent to Jira.

Billing

Your Stripe customer ID and the status of your subscription (plan, billing period, renewal, trial and cancellation dates). Your card details and billing address are collected and kept by Stripe; we never see your full card number.

Usage

For each month, how many generations and chat replies you ran and what they cost in AI processing, to apply the fair-use allowance.

Requests and technical data

The messages you send us (for example through “Talk to us”), and the technical logs our hosting provider keeps when you use the site, such as IP address, browser and request times.

3. How we use it

We use your data only to:

  • provide Quorum: sign you in, read your Jira tickets, generate and send test cases;
  • run your subscription, take payments and apply the AI allowance;
  • answer your requests and tell you about changes to your subscription or terms;
  • keep the service secure, prevent abuse and fix problems.

We do not sell your data, we do not use it for advertising, and Quorum has no advertising or analytics trackers. We do not use your Jira content to train AI models.

Where the law asks for a legal basis, we rely on the contract with you (to provide the service and billing), our legitimate interest in keeping Quorum secure and working, and legal obligations (for example, keeping invoices).

4. AI processing

When you generate test cases or chat with the agent, the content of the ticket you are working on, its related tickets and your session are sent to an AI model provider through OpenRouter, only to produce your results. These providers process the data under their own terms and privacy policies. Do not put information into Jira tickets you work on in Quorum that you are not allowed to share with them.

5. Who processes your data

We rely on these service providers (subprocessors) to run Quorum:

  • Vercel: Hosting of the application (United States).
  • Neon: Database hosting (United States, AWS us-east-1).
  • Stripe: Payments, subscriptions, invoices and tax calculation.
  • OpenRouter and the AI model provider it routes to: Generation of test cases, questions and chat replies from the ticket content you work on.
  • Resend: Sending emails, such as replies to your requests.
  • Google and GitHub: Signing in, when you choose that provider.

Your Jira data stays in your Jira site (Atlassian) as well; Quorum only reads it and writes what you approve. Our providers may process data in the United States and other countries. We will update this list when it changes.

6. Cookies and local storage

Quorum sets one essential cookie to keep you signed in (it expires after 7 days). Your browser also remembers a few preferences, such as the light or dark theme and the layout of the work screen. Stripe sets its own cookies on its checkout and billing pages to process payments and prevent fraud.

7. How long we keep it

  • Account, Jira connection and sessions: while your account exists.
  • Disconnecting Jira deletes the stored API token right away. You can also revoke the token in your Atlassian account at any time.
  • Usage records: while your account exists, to show and apply the allowance.
  • Billing records and invoices: as long as tax and accounting laws require, even after your account is deleted. Stripe keeps them under its own policy.
  • Hosting logs: for a short period, as set by our hosting provider.

To delete your account and its data, write to remo.yukoff@gmail.com from the email address you sign in with. We delete it within 30 days, except what we must keep by law. Deleting your account does not cancel a running subscription by itself: cancel it first from the billing page, or ask us to.

8. Security

Data travels over HTTPS. Jira API tokens are encrypted at rest. Every account can only see its own data, and sign-in relies on Google or GitHub. No system is perfectly secure; if we learn of a breach that affects your data, we will tell you without undue delay.

9. Your rights

You can ask us for a copy of your data, to correct it, to delete it, or to stop or limit a use of it, and you can object to how we use it. Write to remo.yukoff@gmail.com; we answer within 30 days. Depending on where you live, you may also complain to your data protection authority.

10. Children

Quorum is a tool for professionals and is not meant for anyone under 18. We do not knowingly collect data from children.

11. Changes to this policy

We will update this policy when Quorum or its providers change. The date at the top shows the latest version. If a change materially affects how we use your data, we will tell you by email or in the app before it applies. See also the Terms of Service.