Privacy Policy - QVI
Effective date: 22/09/2026
1. About QVI
QVI (Quality Virtual Instruments) builds intelligent audio software — including QV1 and Neyora — and free browser tools that process files on your device. When you create an account you can save your waitlist place and manage it from any device.
This notice describes only the data the current website actually collects and processes, as implemented in the application code and database. It is not a list of services we might add later.
2. Data we collect
We collect personal data when you create an account, sign in, join a product waitlist, or send a message. Some technical data is read automatically to run those features.
Data you provide
- Sign-up form: full name, gender, country, date of birth, phone number, email, password, and password confirmation.
- Required consent to this Privacy Policy and the Terms of Use, and an optional marketing checkbox (off by default) to receive updates and offers about QVI services by email.
- Sign-in form: email and password only.
- Account page: you may correct the same profile fields (name, gender, country, date of birth, phone).
- Product waitlist: email address and product name (QV1 or Neyora), plus your account id if you are signed in.
- Contact form: name, email, and message. Submitting opens your own mail app (mailto) and does not insert a row in our database.
Data collected automatically
- A country code from the hosting request header (x-vercel-ip-country, or an equivalent country header) via /api/geo, used only to pre-fill the country field on sign-up. We do not store IP addresses in the profiles or waitlist_signups tables.
- Browser language (navigator.language) to choose Arabic or English and to suggest a default country (Egypt when the interface is Arabic).
- Authentication session cookies after you sign in, issued through Supabase Auth.
- On-device local storage: interface language (qvi-locale), theme (qvi-theme), recent color-picker swatches (qvi-recent-colors), the last Neyora demo prompt (qvi-neyora-last-prompt), and a local waitlist email copy (qvi-waitlist-*) if the server is unreachable.
What we do not collect through free tools
Images, audio, video, PDFs, and text you process in the free tools stay in the browser. There is no upload API for those files. We do not use GPS or precise location. The current application dependencies do not include analytics or messaging SDKs such as Google Analytics, Mixpanel, Sentry, or OneSignal.
3. How we use your data and why
- Create and secure your account, and sign you in.
- Save your profile and waitlist place so you can manage them from any device.
- Check that you meet the minimum age of 13 using the date of birth you enter.
- Send the account confirmation email through the authentication provider.
- Reply if you contact us.
- If you ticked the marketing box: send updates and offers about QVI services by email.
- Operate and protect the service (session handling and basic abuse prevention needed for the site to work).
4. Legal bases (Egyptian Law No. 151 of 2020)
We process personal data in line with the Egyptian Personal Data Protection Law (Law No. 151 of 2020), on the following bases:
- Consent: the required privacy/terms checkbox, and the separate optional marketing checkbox.
- Performance of a service (contract): creating the account, storing the profile, and letting you save and manage your waitlist place from any device.
- Legitimate interest: keeping authentication secure, pre-filling country so the form is usable, and operating hosting for the website. That interest is limited to what the code actually does.
5. Sharing data
We share data only with the processors wired into this codebase. We do not sell personal data.
- Supabase: email/password authentication and the PostgreSQL tables public.profiles and public.waitlist_signups, plus auth user metadata. Row Level Security lets an authenticated user read and update only their own profile. Waitlist emails cannot be read with the public anon key.
- Hosting platform: serves the site and supplies the country-code header used by /api/geo. Like any web host, it may retain technical request logs (such as IP and user agent) under its own operations. Those logs are not written into our application tables.
- unpkg.com: when you use in-browser audio conversion or trimming, the page downloads the FFmpeg engine (JavaScript/WASM) from unpkg. Your media files are not uploaded to unpkg or to our servers.
We do not integrate advertising networks, analytics pixels, or crash-reporting services in the current package.json or application code.
6. How long we keep data
- Account, profile, and authentication records: for as long as the account exists. The site does not currently include an in-app delete-account button; you may request deletion by emailing the privacy address below.
- Waitlist rows: until you ask us to remove them or we no longer need them for the product waitlist.
- Browser local storage: until you clear site data in your browser.
- Hosting logs: not given a separate retention period in our code; they follow the hosting provider’s operations.
7. Your rights
Subject to Egyptian Law No. 151 of 2020, you may exercise the following:
- Access: the account page displays your profile after you sign in.
- Rectification: you can edit name, gender, country, date of birth, and phone on the account page.
- Erasure: request deletion of your account, profile, and waitlist email via the privacy address. We will action that request because the product has no self-serve delete flow yet.
- Withdraw marketing consent: email the same address. Marketing consent is stored as marketing_consent on your profile; the account page does not yet include a later toggle.
- Withdraw the privacy/terms consent: that consent is required to create an account, so withdrawing it means we should close the account upon request.
8. Data security
- Passwords are sent to Supabase Auth and are not stored in plaintext in public.profiles. The authentication provider stores them hashed.
- The production site and API calls use HTTPS.
- The sign-up form requires a password of at least 6 characters.
- Database access for profiles is limited by Row Level Security (select/insert/update of the user’s own row only).
9. Cookies
We use cookies and similar storage only as implemented below. The current code does not set third-party advertising cookies.
- Essential session cookies from Supabase Auth after sign-in, so the site can recognize you on later visits.
- localStorage keys on this device: qvi-locale, qvi-theme, qvi-recent-colors, qvi-neyora-last-prompt, and qvi-waitlist-* as described above. These stay in your browser and are not sent to our database except when you submit a waitlist email to the server.
10. Children’s privacy
You must be at least 13 years old to create an account. The date-of-birth field rejects younger ages in the form (MIN_ACCOUNT_AGE = 13). We do not knowingly allow accounts for children under 13.
11. Marketing consent
- The second checkbox on sign-up is optional and off by default. Its label asks whether you would like to receive updates and offers about QVI services by email.
- If you tick it, we store marketing_consent = true in your profile and in authentication metadata, and we may email you about QVI services.
- If you leave it unticked, we store marketing_consent = false and do not use that flag to send marketing email.
- You can withdraw this consent later by writing to the privacy address. Withdrawing marketing consent does not delete your account.
12. Changes to this policy
We may update this policy when the product changes. The effective date at the top of this page is generated when the page is viewed. Material changes will be reflected in this text; continued use after an update means you accept the revised policy for further use of the site.
13. Contact us
For privacy requests (access, correction, deletion, or withdrawing marketing consent), email privacy@qvi.app. Contact.
