Skip to content

How QUIRA handles your data

You're about to give a third party read access to your product catalog and your order records. You should ask hard questions about that, and you should get answers that don't hide behind badges.

Read-only, scoped, revocable

  1. Read access only

    QUIRA reads your product, inventory, and order data. It doesn't write to your commerce database, modify products, or change orders.

  2. Scoped to what it needs

    Access is limited to the tables and fields required to answer customer questions. Not your full database.

  3. Revocable at any time

    Cut access from your dashboard. No notice period, no support ticket, no negotiation.

  4. Live queries

    QUIRA reads your data at the moment a question requires it. It doesn't bulk-replicate your catalog onto our servers and work from a copy.

Plainly

Stored, skipped, and off-limits.

Keep

On our side

  • Conversation transcripts, so you can review them and so QUIRA has context within a conversation
  • Your configuration — guardrails, tone settings, escalation rules
  • The documents and policies you connect
  • Usage data for billing

Skip

Not on our servers

  • Payment card details. QUIRA never touches them.
  • A duplicate copy of your product catalog
  • Customer passwords or account credentials

Never

Off limits

  • Use your data or your customers' conversations to train AI models
  • Sell your data
  • Share your data with other merchants, in any form, including aggregated

Encryption and infrastructure

  1. In transit

    All traffic between your store, our servers, and the customer's browser is encrypted.

  2. At rest

    Stored data, including transcripts, is encrypted.

  3. Access control

    Internal access to production systems is limited to team members who need it, and is logged.

The honest version

Most security pages in this category lead with badges. Here is what we actually have and what we don't.

What we do today: read-only scoped access, encryption in transit and at rest, and no model training on your data.

What we don't have yet: we are not SOC 2 certified. We don't hold ISO 27001. We're a small company and those programs take time and money we're currently putting into the product.

If compliance is a hard requirement for you, talk to us before you spend time on an evaluation. We'd rather tell you on a first call that we don't meet your bar than discover it in your security review.

A closed padlock and a key on a stone desk beside a narrow slot

Common questions

Does QUIRA use my data to train AI models?

No. Your conversations and product data are not used to train any model, ours or our vendors'.

Which AI provider do you use?

OpenAI. A full subprocessor list will live on /legal/subprocessors/ once the legal documents are published.

Can QUIRA modify my products or orders?

No. Access is read-only for commerce data.

Where is my data stored?

Hosting region will be published here once confirmed. Until then, ask security@quira.ai and we will answer specifically.

What happens to my data if I cancel?

Deletion timing will be published in the privacy policy. Until that document ships, email security@quira.ai for the current retention period.

Do you offer a DPA?

Not yet — it is in progress. EU merchants should talk to us before an evaluation if a DPA is a hard requirement.

Are you GDPR compliant?

We follow specific practices today — data minimization, no training on customer data, deletion on request — and formal compliance work is underway. We do not claim to be GDPR compliant until that work is done.

Has QUIRA had a security incident?

No. If one occurs, we will disclose it.

Security questions go to a person

Not a form that disappears. security@quira.ai reaches the team directly. If you've found a vulnerability, that's the address — we'll respond and we won't come after you for reporting it.