Truth-first privacy notice

What CoQuest stores today

This page describes the current application behavior. It does not claim certifications, storage regions, retention periods, or deletion guarantees that have not been verified for the deployed environment.

Reviewed July 29, 2026

Data categories

Account identity

Clerk authenticates the account. CoQuest stores the verified email, display name, and product settings needed to associate application data with that account.

Product data

Tracked keywords, discovered public posts, lead workflow state, CRM configuration, and measured product activity are stored in PostgreSQL.

Billing state

Stripe handles payment details. CoQuest stores Stripe identifiers, subscription state, checkout attempts, webhook processing records, and its own credit ledger.

Optional providers

When configured, social-data and AI providers receive only the request data needed for the selected feature. Their availability depends on deployment configuration.

Deletion requests are pending work

The Settings area contains the real account-deletion request control. A submitted request means the request is pending; it is not a promise that every application, identity-provider, billing, backup, and log record was immediately purged.

Completion must be handled by the backend workflow and confirmed separately. Until that end-to-end workflow is deployed and verified, CoQuest must not describe deletion as instant or automatic.

Open account settings

Current privacy safeguards

  • Server operations re-check the authenticated account and tenant ownership.
  • API responses use bounded data-transfer objects instead of complete database rows.
  • The core logger redacts common identity, credential, and free-text fields.
  • Payment-card details are not stored in the CoQuest application database.