Skip to content

Privacy

Last updated August 20, 2026

This page describes what Quantalog collects on the sites that embed our tracker, what we collect from you as a customer, and what happens when you connect a third-party account or ask our AI assistant a question. It is written to be read, not to be survived.

What the tracker collects

When someone visits a site running our script, we receive the page path, the referrer, the screen size, any UTM parameters in the query string, and the HTTP request itself. From the request we derive the device type, operating system, browser and country.

What the tracker does not collect

  • No cookies are set, and the tracker writes nothing to localStorage. (This website — not the tracker — stores one flag to remember that you closed the newsletter dialog, so it is not shown again. It identifies nobody and is never sent anywhere.)
  • No cross-site identifier is created, so no browsing profile exists.
  • No raw IP address is stored. It is hashed on receipt and discarded.
  • No form input, keystrokes, session recordings or mouse movement.

How visitors are counted

A visitor is a SHA-256 hash of the IP address, the user agent, the site key and a salt that rotates every day. Because the salt changes daily, the same person visiting tomorrow appears as a new visitor, and the same person on two different sites produces two unrelated hashes. The hash cannot be reversed into an identity.

Data we hold about you as a customer

Your name, your email address, a bcrypt hash of your password, and the workspaces and sites you create. If you subscribe to a paid plan, payment is handled by our payment processor (Razorpay) and we never see your card details.

Connecting a social account

If you connect LinkedIn (or another network we add support for) to schedule posts, we store the access token that connection grants, the account's name and profile picture, and a record of what was published through it — never anything else from that account, and never anything the network itself doesn't hand us. The token is encrypted at rest and is used only to publish the posts you compose and schedule yourself. We never post anything you didn't write, and disconnecting the account deletes the stored token immediately.

Orbit, our AI assistant

Questions you ask Orbit are sent to a third-party AI model to generate an answer. Orbit currently runs on Meta's Llama models hosted by Cloudflare Workers AI. If more than one model is available, the one that answers is chosen automatically — you can express a preference in the chat window, but we cannot guarantee it in advance, because Orbit falls through to another model when one is busy.

Conversations you have with Orbit while signed in are saved to your workspace so you can return to them, and so we can see which questions our documentation fails to answer. They are visible to members of that workspace, and you can delete any conversation from the chat window. Conversations with the assistant on this public website are not saved at all — they exist only in your browser and are gone when you close the tab. We do not use anything you ask Orbit to train a model of our own.

Retention and deletion

Event data is retained according to your plan — 30 days on Hobby, 2 years on Pro. You can export or permanently delete a site's data at any time from the dashboard, and deleting your account removes everything associated with it, including any connected social accounts.

Sub-processors

Data is stored in MongoDB Atlas and served from Vercel and Cloudflare. Images you upload (for scheduled posts or elsewhere in the product) are stored with Cloudinary. Payments are processed by Razorpay. We do not sell data, share it with advertising networks, or use it to train anything.

Contact

Questions about any of this go to daorbit2k25@gmail.com.