iOS version
Privacy Policy
Quen AI for iPhone and iPad · Effective 25 August 2026 · Last updated 25 August 2026
Using Quen AI on Android? The Android build includes advertising and push notifications and is covered by a separate privacy policy.
1. Who we are
Quen AI (the "Application", "Quen AI", "we", "us") is provided by:
For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, Igor Czupryniak is the data controller for the personal data described in this policy. We are a small independent developer and have not appointed a Data Protection Officer, because we are not required to. Write to the address or email above with any privacy question and we will handle it personally.
2. What this policy covers
This policy applies to the iOS version of Quen AI distributed through the Apple App Store, and to the parts of www.quenai.app that support it. The iOS build differs from the Android build in ways that matter for your privacy:
- No advertising. The iOS build contains no advertising SDK at all. Google AdMob and its mediation partners ship only in the Android build and are excluded from the iOS build at compile time.
- No tracking. We do not access the Advertising Identifier (IDFA), we do not track you across apps or websites owned by other companies, and we therefore never show you the App Tracking Transparency prompt.
- No push notifications. Marketing and re- engagement push notifications are an Android-only feature and are not part of the iOS build.
- No third-party analytics. We do not use Google Analytics, Firebase Analytics, Meta SDK, or any similar behavioural analytics product.
3. What Quen AI does
Quen AI is an AI assistant. You type a message, optionally attach an image or a document, and an artificial intelligence model produces a reply. The Application can also extract text from images, generate and edit images, and search the web when a question needs current information. You can use it as a guest without an account, or create an account so your conversations are saved and available across sessions. A paid subscription removes the free daily message limit and unlocks additional models and features.
Because the core of the product is an AI model, understanding Section 6 is the most important part of this policy: it explains exactly what leaves our servers when you send a message.
4. Information we collect
4.1 Account information
If you create an account we store your name and email address, the sign-in method you used (email and password, Google, or Apple), a cryptographic hash of your password if you signed up with email (we never store the password itself), your subscription status, and the dates your account was created and last updated.
If you use Sign in with Apple and choose to hide your email, we receive and store only Apple's private relay address, never your real one. If you use Google Sign-In, we receive your name and email address from Google.
4.2 The content you create
We store the content of your use of the Application on our servers:
- the messages and prompts you write, and the replies the AI produces;
- conversation titles and any projects you organise conversations into;
- files and images you attach, including the original file name, type and size;
- text extracted from images you upload for text recognition;
- images the Application generates or edits for you;
- which model produced a reply, alternative versions of a reply you regenerated, and suggested follow-up questions;
- a flag on any message that has been reported through the in-app reporting tools.
4.3 Personalisation settings
In Settings → Customization you can optionally tell the assistant your preferred name, your role or occupation, traits you want it to have, a personality style, and any additional information you want it to remember. These settings are stored on your device, not in our database, but they are sent to our servers and on to the AI provider with each message so that the reply can be adapted to them. Please do not put sensitive information into these fields.
4.4 Guest mode
You can use Quen AI without an account. In that case your device generates a random guest session identifier, and the conversations, attachments and usage counters created in that session are stored against that random identifier. We do not know your name or email address in guest mode. The identifier is not used to profile you and is not shared with advertisers, because the iOS build has none.
4.5 Subscription and purchase data
Subscriptions are sold by Apple and managed on our side through RevenueCat. We never receive your card number, bank details or billing address. Apple processes the payment and shares a purchase receipt with RevenueCat, which tells us whether your subscription is currently active. We store only a premium flag on your account and, in guest mode, on your device. RevenueCat also assigns an app user identifier used to restore purchases.
4.6 Technical and diagnostic data
- IP address - used transiently to enforce rate limits, prevent abuse and protect the service. We do not use it to determine your precise location.
- Device and app information - device model, operating system version, app version, language and the platform identifier the app sends with requests.
- Usage counters - a count of how many messages and image edits you have made today, so the free daily allowance can be enforced. These counters are stored in a cache and expire automatically at midnight UTC.
- Crash and error reports - when the app or our API fails, Sentry records the error, a stack trace, the app version and the device state. Diagnostic reports can incidentally contain fragments of the data being processed at the moment of the failure.
4.7 Reports and correspondence
If you report objectionable content or an abusive user, we receive the description you write, where the content appeared, the type of content, and your email address if you are signed in. If you email us, we keep the correspondence so we can answer and, if necessary, prove how a complaint was handled.
4.8 Photos
When you attach an image, iOS presents the system photo picker. The picker runs outside our app and gives us only the specific photo you choose - the Application never gets access to your photo library, and iOS does not ask you for library permission for this. If you save a generated image, iOS asks for add-only permission so the file can be written to your library; we still cannot read it.
4.9 What we never collect
We do not collect precise or coarse geolocation, your contacts, your calendar, health or fitness data, biometric data, financial account data, audio from your microphone, video from your camera, your browsing history in other apps, or the Advertising Identifier. We do not build advertising profiles, we do not sell personal data, and we do not share personal data for cross-context behavioural advertising.
5. How we use it and why we are allowed to
Where the GDPR applies, we must have a legal basis for each use of your personal data. This is ours:
| Purpose | Data used | Legal basis |
|---|---|---|
| Delivering the assistant - producing replies, generating and editing images, extracting text, searching the web | Messages, attachments, personalisation settings, conversation history | Performance of our contract with you (Art. 6(1)(b)) |
| Saving your conversations so you can return to them | Account identifier, messages, attachments | Performance of our contract (Art. 6(1)(b)) |
| Creating and securing your account, resetting passwords | Name, email, password hash, sign-in provider | Performance of our contract (Art. 6(1)(b)) |
| Managing subscriptions and restoring purchases | Purchase receipt data from Apple, subscription status | Performance of our contract (Art. 6(1)(b)) |
| Enforcing free daily limits, rate limiting, preventing fraud and abuse | IP address, account or guest identifier, usage counters | Our legitimate interest in keeping the service available and affordable (Art. 6(1)(f)) |
| Reviewing reports of objectionable content and enforcing our Terms | Reported message, reporter email, description | Our legitimate interest in a safe service (Art. 6(1)(f)); legal obligation where reporting is required (Art. 6(1)(c)) |
| Fixing crashes and improving reliability | Error reports, device and app version | Our legitimate interest in a working product (Art. 6(1)(f)) |
| Sending you optional product news | Email address | Your consent (Art. 6(1)(a)) - withdrawable at any time |
| Complying with law and responding to lawful requests | Whatever the request covers | Legal obligation (Art. 6(1)(c)) |
Service messages that are necessary to operate your account - password resets, security notices, changes to these terms, notice that a subscription price is changing - are sent on the basis of our contract with you and cannot be opted out of while you hold an account.
6. AI processing of your content
Read this section before you use the Application. Quen AI does not run AI models on your device or on our own hardware. To answer you, the content of your conversation is transmitted over an encrypted connection to an external AI provider.
6.1 Our AI provider
Our AI provider is NavyAI, reachable at api.navy. NavyAI operates an API gateway: it receives our request and routes it to the underlying AI model provider that serves the model you selected, which generates the response. NavyAI states that it complies with the GDPR, the CCPA and other applicable data protection laws, and that each underlying model provider has its own privacy policy and data handling practices.
- NavyAI Privacy Policy: api.navy/privacy
- NavyAI Terms of Service: api.navy/terms
6.2 What is sent
When you send a message, the following leaves our servers:
- the text of your message;
- enough earlier messages from the same conversation for the model to keep track of the context;
- your personalisation settings from Settings → Customization (preferred name, role, traits, personality, additional information);
- any image or document you attached, or text extracted from it, when the request needs it;
- your prompt and, for image editing, the source image, when you ask for an image to be generated or edited;
- the identifier of the model you selected.
We do not send your name, your email address, your account identifier, your IP address or your subscription status to the AI provider along with the request.
6.3 How images reach the provider
Some image operations require the provider to fetch the file rather than receive it inline. For those requests we expose the file at a URL containing a long random identifier, so the provider can download it. The identifier is unguessable and the storage cannot be browsed or listed, but the link is not password-protected for the time the operation runs. Anyone who obtained that exact link would be able to open the file, so please treat images you upload accordingly.
6.4 Web search
When a question needs current information, the assistant may run a web search. A search query derived from your message is sent to our own self-hosted search instance, and the Application may fetch and read the resulting web pages. Those third-party websites and search sources receive the query and see the request coming from our server, not from your device or your IP address.
6.5 Training
We do not train, fine-tune or evaluate any AI model on your conversations, and we do not sell or license your content to anyone for that purpose. What the AI provider and the underlying model providers do with data submitted through their API is governed by their privacy policy, which we encourage you to read.
6.6 What you should not send
Do not enter into the Application: passwords, API keys or other credentials; payment card or bank details; national identification numbers; health or medical records; other special categories of personal data under Art. 9 GDPR; confidential material belonging to your employer; or personal data about other people that you are not entitled to share.
6.7 Accuracy
AI-generated responses can be incomplete, outdated or simply wrong, and they are not professional advice. You are interacting with an automated system, not a human. Verify anything that matters before acting on it.
7. Service providers we share data with
We use a small number of processors to run the service. Each is bound to use the data only to provide their service to us.
| Provider | What it does | What it receives | Policy |
|---|---|---|---|
| NavyAI (api.navy) | AI model access - replies, image generation and editing, text extraction | Message text, conversation context, personalisation settings, attachments and prompts | Privacy |
| Contabo GmbH (Germany) | Object storage for uploaded and generated files, and server hosting | Attachment files and generated images | Privacy |
| Apple | App distribution, in-app purchases, Sign in with Apple | Purchase and subscription data; your Apple ID or private relay email if you sign in with Apple | Privacy |
| RevenueCat, Inc. | Subscription state and purchase restoration | App user identifier, receipt and entitlement data from Apple | Privacy |
| Google LLC | Google Sign-In, only if you choose it | Your name and email address from your Google account | Privacy |
| Functional Software, Inc. (Sentry) | Crash and error reporting | Error reports, stack traces, app and device version | Privacy |
| Resend | Transactional email - password resets and account notices | Your email address and the content of the message | Privacy |
The iOS build shares no data with any advertising network. Google AdMob and its mediation partners appear only in the Android build.
8. Other disclosures
Beyond the providers listed above, we may disclose information:
- when the law requires it - for example in response to a court order, a subpoena or a valid request from a public authority;
- when we believe in good faith that disclosure is necessary to investigate suspected fraud or abuse, to enforce our Terms, or to protect the rights, property or safety of you, of us or of the public;
- to a buyer or successor if the Application is sold, merged or otherwise transferred - in which case we will tell you before your data becomes subject to a different privacy policy.
9. International data transfers
Our servers and object storage are located in the European Union. Some of the providers listed in Section 7 - notably the AI provider and the underlying model providers it routes to, RevenueCat, Sentry, Apple and Google - process data outside the European Economic Area, including in the United States.
Where we transfer personal data outside the EEA, we rely on the European Commission's adequacy decisions where they apply, including the EU-US Data Privacy Framework for certified US providers, and otherwise on the European Commission's Standard Contractual Clauses together with supplementary technical measures such as encryption in transit. You can ask us for details of the safeguards used for a particular provider by writing to contact@quenai.app.
10. How long we keep data
| Data | Retention |
|---|---|
| Account information | Until you delete your account. Deletion is immediate in our live database; residual copies in encrypted backups are overwritten within 30 days. |
| Conversations, messages and generated images | Until you delete the conversation or your account, whichever comes first. Deleting your account deletes all of them. |
| Attachments you uploaded | Until you delete the conversation or your account. The underlying files are then removed from object storage as well. |
| Guest-mode conversations and attachments | Kept against the random session identifier until you ask us to delete them, or until you sign in and continue with an account. See Section 11 for how to request deletion. |
| Daily message and image-edit counters | Expire automatically at midnight UTC. |
| Crash and error reports | Retained by Sentry under its default retention period, typically up to 90 days. |
| Content reports and moderation records | Up to 2 years, so that repeat abuse can be recognised and so we can show a report was handled. |
| Email correspondence with support | Up to 2 years from the last message in the thread. |
| Records we must keep by law | For the period the relevant law requires - for example accounting records under Polish tax law. |
11. Your choices and your rights
11.1 Deleting your account in the app
You can delete your account at any time, from inside the Application, without contacting us:
Settings → Account → Delete account
You will be asked for your password, or to type DELETE if you signed in with Google or Apple. Deleting your account permanently removes your profile, all of your conversations and messages, your projects, and your uploaded and generated files, including the copies held in object storage. This cannot be undone. Deleting your account does not cancel your Apple subscription - see Section 5 of the Terms of Service for how to cancel that in your Apple ID settings.
11.2 Deleting individual content
You can delete a single conversation from the conversation list at any time, which removes its messages and attachments.
11.3 Guest mode
Because guest data is not tied to an account, we cannot identify it from your name or email. Email us at contact@quenai.app and we will explain how to retrieve your guest session identifier from the app so we can delete the associated data.
11.4 Withdrawing consent
You can unsubscribe from optional product emails using the unsubscribe link in any such email, or by writing to us. Withdrawing consent does not affect processing that already took place. You can stop all further collection at any time by deleting your account and removing the Application from your device.
11.5 Your rights under the GDPR
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the right to: access your personal data and obtain a copy of it; have inaccurate data corrected; have your data erased; restrict how we process it; object to processing based on our legitimate interests; receive the data you provided in a structured, machine-readable format and have it transmitted to another controller; and withdraw any consent you have given.
To exercise any of these rights, email contact@quenai.app. We answer within one month, and will tell you if we need to extend that period as the GDPR allows. We may need to verify your identity before acting on a request. Exercising your rights is free unless a request is manifestly unfounded or excessive.
You also have the right to lodge a complaint with a supervisory authority. Ours is the Polish authority:
Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office)
ul. Stawki 2, 00-193 Warszawa, Poland
If you are in the EEA or the UK you may also complain to the supervisory authority where you live or work.
11.6 California residents
If you live in California, you have the right to know what personal information we collect, use and disclose, to request deletion or correction of it, and not to be discriminated against for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. The categories we collect and the purposes we collect them for are set out in Sections 4 and 5. Use the same email address to make a request.
12. Children
Quen AI is not directed at children. You must be at least 13 years old to use the Application, and at least 16 if you are in a country in the European Economic Area that sets the age of digital consent at 16 - which includes Poland. If you are under 18, you may use the Application only with the involvement and consent of a parent or guardian.
We do not knowingly collect personal data from children below these ages. If we learn that we have, we delete the account and its data promptly. If you are a parent or guardian and believe your child has provided us with personal data, contact us at contact@quenai.app and we will remove it.
13. Security
All traffic between the Application and our servers, and between our servers and our providers, is encrypted with TLS. Passwords are stored only as salted cryptographic hashes. Access to production systems is restricted and authenticated. Attachment links use long random identifiers, and storage cannot be listed or browsed. Rate limits protect accounts against automated attacks.
No system is perfectly secure, and we cannot guarantee absolute security. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and we will notify you without undue delay where the law requires it.
14. Changes to this policy
We may update this policy as the Application changes. When we do, we update the "last updated" date at the top of this page and publish the new version here. If a change materially affects how we handle your personal data, we will give you notice by email or in the Application before it takes effect. Continuing to use the Application after a change takes effect means you accept the updated policy; if you do not accept it, you can delete your account.
15. Contact us
Questions, requests and complaints about privacy all go to the same place, and we answer them personally:
See also the Terms of Service for the iOS version.