Privacy Policy
How QXONI processes personal data under the Swiss FADP and, where applicable, the GDPR.
1. Controller
QXONI, an association under Articles 60 et seq. Swiss Civil Code, Bühler AR, Switzerland; support@qxoni.com; see the Imprint.
2. Data, purposes and legal bases
| Data | Purpose | Legal basis |
|---|---|---|
| Account, profile and age information | Provide accounts, age limits and permissions | Contract; legal obligations |
| Content, searches and inputs | Provide requested features | Contract; consent where required |
| IP, device, access and security logs | Operation, abuse prevention and troubleshooting | Legitimate interest in security and stability |
| Support and email data | Requests, login, recovery and notices | Contract; legitimate interest |
| Consent records | Record and manage choices | Legal obligation and consent |
Required fields are marked; without them the relevant feature cannot be provided.
3. Recipients and hosting
QXONI APIs and databases run at Hetzner in Germany; Cloudflare protects and routes web traffic, Supabase stores certain profile data, Brevo sends system emails, and Groq processes inputs when text-based AI is used; details are in Hosting & Providers and AI Use.
4. Retention
Account data remains until account deletion or the end of legal obligations; security logs are retained only while required for protection, troubleshooting or legal claims and are reviewed regularly; recovery and one-time codes expire quickly, while deleted data may remain in encrypted backups until scheduled overwrite.
5. Security and transfers
QXONI uses TLS, access controls, password hashing, limited sessions, logging and backups; transfers outside Switzerland or the EEA use applicable adequacy, contractual or other required safeguards.
6. Your rights
You may request access, correction, deletion, restriction or portability, object to processing, withdraw consent for the future, and complain to the FDPIC or a competent EU supervisory authority, subject to legal exceptions.
Contact support@qxoni.com; identity verification may be required.
7. Children, changes and incidents
Accounts are generally available from age 13; parental approval is required where law demands it; material policy changes are announced appropriately, and reportable personal-data breaches are documented and notified to authorities or affected people as required.