Quell
ProductCompareBlogFree toolsPricing
Request early access
ProductCompareBlogFree toolsPricing

Privacy Policy

Last updated: 8 July 2026

This policy explains what data Quell collects, why, and your rights over it. It forms part of our Terms of Service.

1. Who we are

Quell is a trading name of Rain Ventures Limited, a company registered in England and Wales (company number 16041437, VAT registration number GB 492 9409 50). Registered office: 71–75 Shelton Street, Covent Garden, London WC2H 9JQ. For privacy matters, Rain Ventures Limited ("we", "us") is the data controller for your account and your processor for the end-user feedback you capture through the widget. We are registered with the UK Information Commissioner's Office (ICO), registration number ZC011688. Data-protection enquiries: [email protected].

2. What we collect

  • Account data — your name, email address, and a securely hashed password (we never store passwords in plain text).
  • Feedback content — the feedback your users submit and the context the widget captures on your behalf: screenshots, console logs, network activity, page URLs and titles, and basic browser/device metadata.
  • Usage and audit logs — timestamped records of account and feature activity (logins, seats, API-key use, issues created, tickets resolved) used to operate, secure, and support the Service, and to administer billing and refunds.
  • IP address and device/browser information (user-agent) — collected at account login, registration, and when you accept our Terms and initiate a billing checkout. We collect this to prevent fraud and to preserve evidence for billing-dispute (chargeback) resolution, in our legitimate interest under GDPR Recital 47. This is scoped to the paying account holder's authenticated sessions only; your end users submitting feedback through the widget are not subject to this collection.
  • Payment data — handled by our payment processor, Stripe. We do not receive or store your card details.
  • Product analytics — first-party, server-side usage events (for example, activation steps and feature adoption signals) collected to understand and improve the Service. We use PostHog (EU region) for this processing. No cookies, no session replay, and no feedback content is included. See section 9 (Cookies) and section 5 (Sub-processors).

3. How we use it

We use this data to provide and secure the Service, authenticate users, deliver transactional email (such as verification and password-reset messages), administer billing and refunds, provide support, and improve the product. We do not sell your data, and we do not meter or tax your AI usage.

4. Legal bases (UK GDPR)

Under the UK GDPR and the Data Protection Act 2018 (and the EU GDPR where you are in the EU), we rely on: performance of our contract with you (to provide the Service); our legitimate interests (to secure and improve the Service, prevent fraud, and preserve billing-dispute evidence — consistent with GDPR Recital 47, which expressly recognises fraud prevention as a legitimate interest); your consent where required (for example for any non-essential cookies); and compliance with legal obligations.

5. Sharing and subprocessors

We share data only with the providers needed to run the Service, each under appropriate data-protection terms:

  • Stripe — payments processing.
  • Hetzner — application hosting (Germany, EU).
  • Supabase — managed cloud database (EU region). Used for cloud-hosted accounts.
  • Resend — transactional email delivery.
  • Cloudflare — DNS, network security, and email routing.
  • Purelymail — support and operational email hosting.
  • PostHog (EU Cloud) — first-party product analytics. No session replay, no advertising use, no feedback content.

We may also disclose data where required by law. We provide 30 days' notice of material sub-processor changes to account holders.

6. Where your data is stored

Cloud data is hosted in the European Union. Application servers run in Germany (Hetzner); cloud database storage is provided by Supabase in the EU. Where any provider processes data outside the EU/UK, it does so under appropriate safeguards such as Standard Contractual Clauses.

7. Retention

We retain account and Customer Data for as long as your account is active. After you delete your account, we delete or anonymise associated personal data within 30 days, except where we must retain limited records to meet legal obligations.

Fraud-prevention and billing-dispute evidence (IP addresses and device/browser information recorded at login and billing events) is retained for up to 18 months, which covers card-scheme chargeback windows. After that window, IP and user-agent data is automatically stripped from session records and the associated audit log entries are deleted.

8. Your rights

Subject to applicable law, you may request access to, correction or deletion of, or a copy of your personal data, and you may object to or restrict certain processing. To exercise these rights, email [email protected].

Right to erasure and fraud-prevention evidence. Where we hold IP address or device/browser information as fraud-prevention or billing-dispute evidence, we may lawfully retain it under our legitimate interest (GDPR Art. 17(3)(b)) for the bounded 18-month window described in section 7, even if you request erasure. This exemption is narrow: it covers only that evidence, for that period. At the end of the window the data is automatically purged. We will always tell you what we are retaining and why.

If you are in the UK or EU and have concerns we have not resolved, you may complain to your local supervisory authority (in the UK, the Information Commissioner's Office).

9. Cookies and analytics

We use only the cookies strictly necessary to run the Service — a session cookie to keep you signed in and a CSRF token cookie for security — which are exempt from consent under the Privacy and Electronic Communications Regulations 2003 (PECR). We do not use third-party advertising or cross-site tracking cookies; if we ever introduce non-essential cookies, we will ask for your consent first.

We collect first-party product analytics using PostHog (EU Cloud). These are server-side events only — no tracking pixels, no client-side cookies, no session replay, and no advertising use. Events record product interactions (for example, completing onboarding steps) in our legitimate interest to understand how the product is used and improve it. PostHog is listed in our sub-processor list above and operates under a Data Processing Agreement.

10. Security

We protect data with measures including encryption in transit (TLS), scrypt password hashing, scoped API keys with fine-grained permissions, a trust-aware model for feedback, and EU-based hosting. No system is perfectly secure, but we work to protect your data and to disclose incidents as required.

11. Children

Quell is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16.

12. Changes and contact

We may update this Privacy Policy and will post changes here. Questions or requests: [email protected].

QuellQuell

Feedback infrastructure for teams that ship with AI agents. Bring your own AI. No token tax.

Ask AI about Quell
ProductWidgetInboxQueueAgents
ResourcesBlogCompareQuell vs UserbackFree tools
MorePricingFAQStatus
© 2026 Quell
TermsPrivacyRefunds
capture · route · act

Quell is a trading name of Rain Ventures Limited, registered in England & Wales (company no. 16041437, VAT no. GB 492 9409 50).