Your work is yours

Privacy, without the fog.

Quester holds work that may be unpublished, sensitive, and years in the making. This policy explains what we collect, why we collect it, who helps us process it, and the choices you have.

Last updated: August 29, 2026

The boundaries we build around your work.

Your research is not training data.

We do not use your sources, notes, questions, models, or prompts to train Quester or general-purpose AI models.

We do not sell your data.

We do not sell personal information or use it for targeted advertising.

Analytics never receives research content.

PostHog receives reviewed event names, internal IDs, counts, and coarse categories.

Your workspace has controls.

You can export projects, turn off AI per project, opt out of product analytics, and request account deletion.

1. Scope, definitions, and our role

This policy applies to Quester's marketing website at www.quester.tech, the Quester application at app.quester.tech, and related support and services. In this policy, personal data means information that identifies or can reasonably be linked to a person. Research Content means the projects, files, sources, notes, questions, models, messages, and other material placed in a Quester workspace.

The individual operating the Service as a California sole proprietorship under the trade name Quester is the controller of information used for our own purposes, including account administration, billing, service security, support, and the limited product analytics described below. You can contact the operator at support@quester.tech.

When a university or other organization provides your workspace

If an organization has contracted with Quester and controls your workspace, that organization is generally the controller of Research Content and related workspace activity, and Quester processes that data on its behalf. The organization's agreement with Quester (including any data processing addendum) governs if it conflicts with this policy. Privacy questions about an organization-managed workspace may need to be directed to that organization.

2. Information we collect and where it comes from

We collect information you provide, information created through your use of Quester, information provided by a workspace administrator or service provider, and selected public scholarly metadata.

Category Examples and sources
Account and profile Name, email, authentication identifiers, verification status, avatar, locale, citation preferences, and an optional ORCID link; provided by you, an inviting administrator, or our identity provider.
Workspace and membership Workspace name and type, projects, membership, invitations, role, permissions, settings, and plan; provided by members and workspace administrators.
Research Content Uploaded documents, extracted text and metadata, sources, notes, questions, models, connections, searches, Advisor conversations, journal entries, feedback, and generated outputs; provided or created by you and your collaborators.
Activity and usage Sign-ins, resource creation or modification timestamps, feature interactions, imports, exports, AI usage and cost records, response times, failures, and workspace audit events; created when you use the service.
Device and network IP address, request time, browser or device details, response codes, session and security events, and diagnostic logs; provided by your browser and our infrastructure.
Billing and communications Plan, seat count, billing identifiers and transaction status from Stripe; plus messages and attachments you send to support or sales. Quester does not receive your full card number.
Scholarly metadata Public source, author, institution, venue, citation, and open-access metadata from services such as Crossref, Open Library, and OpenAlex, matched using an identifier or search you provide.

Third-party personal data in your research

You and the customer responsible for a workspace decide what Research Content to place in Quester. If it contains information about research participants, collaborators, or other people, you are responsible for having an appropriate legal basis and for using the minimum identifying information needed.

Quester is a research workspace, not a repository for regulated raw data. Do not upload protected health information, student education records, government identifiers, financial-account credentials, or similarly regulated or highly sensitive personal data unless Quester and your organization have agreed in writing to the required safeguards.

3. How we use information and our legal bases

We use information only for the purposes described here:

  • Provide the service: create accounts and workspaces; store, synchronize, search, analyze, and export Research Content; process citations and files; and deliver requested AI features.
  • Administer the relationship: authenticate users, manage memberships, support requests, subscriptions, payments, previews, and usage limits, and send service communications.
  • Secure and maintain Quester: enforce permissions, diagnose failures, prevent abuse and fraud, protect accounts, back up data, and maintain reliability.
  • Improve the product: understand adoption and failure points using the bounded analytics described below, develop features, and evaluate service quality.
  • Meet legal obligations: keep required business records, respond to lawful requests, resolve disputes, and enforce our agreements.

For people in the EEA, United Kingdom, or other places that require a legal basis, we rely on performance of a contract to provide the service; our legitimate interests in operating, securing, supporting, and improving Quester; compliance with legal obligations; and consent where we specifically request it. Our legitimate interests do not override your rights, and you may object to processing based on those interests.

What we do not do

We do not sell personal data, share it for cross-context behavioral advertising, serve targeted advertising, or use Research Content to market to you. We do not make solely automated decisions that produce legal or similarly significant effects about users. We may create aggregate or de-identified statistics that cannot reasonably identify you and use them to operate and improve Quester.

4. Bounded product analytics

The authenticated Quester application uses PostHog, hosted in its United States region, to answer specific product questions such as whether an import succeeded, where onboarding stalls, or whether an Advisor response was useful. The redesigned marketing website does not currently run behavioral analytics.

What an analytics event may contain

A stable internal account ID; workspace and project IDs; a reviewed route or event name; counts; coarse duration or failure categories; and broad context such as plan, personal/shared workspace, role class, and locale.

What it may never contain

Names, email addresses, organization names, raw URLs or referrers, filenames, source titles, DOI or ISBN values, search text, prompts, responses, notes, questions, uploaded documents, or other research content.

PostHog autocapture, session replay, exception capture, performance capture, surveys, and experiments are disabled. Analytics uses memory-only browser state, does not create a persistent analytics cookie or browser identifier, does not create PostHog person profiles, and respects your browser's Do Not Track signal. We restrict event properties through a reviewed allowlist before they leave the application.

Product analytics is enabled by default for authenticated accounts. You can disable it at any time under Settings → Profile → Product analytics. The preference is saved to your account so it follows you across devices. When it is disabled, Quester does not send product events to PostHog.

Operational activity is separate

Turning off PostHog does not turn off records Quester needs to provide and secure the service, for example: sign-ins, permission changes, resource timestamps, billing usage, or workspace audit and activity history. These service records are collected separately from PostHog. When PostHog is enabled, only the allowlisted product-event fields above are eligible to leave Quester through that analytics pipeline.

5. AI processing and Research Content

Quester uses commercial API services, currently including Google Gemini, for document metadata extraction, semantic embeddings, and generative features such as the Advisor. AI processing may begin when you upload a document or ask Quester to analyze, generate, or advise. Depending on the task, the provider may receive a prompt, document text, or relevant excerpts from sources, notes, questions, models, and prior Advisor context.

We send the context needed for the requested task and use business/API offerings under terms that do not permit submitted Research Content to train the provider's general-purpose models. Quester does not use Research Content to train models of its own. We store AI outputs, embeddings, usage records, and selected conversation context when needed to provide workspace features and continuity.

A workspace manager can turn AI processing off for a project under Project settings → Advisor. Turning it off stops new AI processing for that project and leaves its structured, non-AI workspace available; it does not automatically remove content or outputs already stored. AI output may be inaccurate and should be reviewed rather than treated as an authoritative decision.

6. When we disclose information

We disclose information only as needed for the purposes in this policy. The recipients may include:

  • Infrastructure providers for application hosting, databases, backups, and document storage, currently including Render and Cloudflare R2 or compatible S3 storage.
  • WorkOS for identity, authentication, organization membership, and session management.
  • Stripe for subscriptions, checkout, payments, fraud prevention, and billing records.
  • Google Gemini and other approved AI providers for the limited AI processing described above.
  • PostHog for the optional, bounded product analytics described above.
  • Scholarly data and discovery services, such as Crossref, Open Library, OpenAlex, and Firecrawl, when a feature needs to resolve a DOI or ISBN, match an author, enrich a source, or perform a scholarly search. The identifier, name, or search terms needed for that request may be sent to the relevant service.
  • Professional advisers and authorities when reasonably necessary to obtain legal, security, accounting, or insurance services, comply with law, or protect users, Quester, or others.

Our service providers process data under contracts and data-protection terms appropriate to their role. The list can change as Quester evolves; a replacement provider will be used only for a purpose consistent with this policy.

Business transfers

If Quester is involved in a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets, information may be disclosed during diligence and transferred as part of that transaction, subject to confidentiality protections and applicable notice requirements.

7. Collaboration and workspace visibility

Quester is collaborative. Research Content is visible to members who have permission to access the relevant workspace, department, or project. Depending on their role, workspace owners and administrators may invite or remove members, assign permissions, view member and project activity, manage billing, transfer projects, export content, or delete workspace resources. Your organization's own policies govern how it uses data it can access through an organization-managed workspace.

If you leave or delete your Quester account, Research Content in a shared workspace may remain available to that workspace. A sole owner must transfer any shared workspace that other members will retain before deleting the account. Workspaces with no remaining members are deactivated with the account and then handled under our retention and deletion process.

8. Cookies and data stored in your browser

Quester uses first-party cookies for authentication, security, workspace routing, and interface state. We do not currently use advertising cookies. The application also uses local or session storage for practical features such as theme and layout preferences, the last active workspace, recent search shortcuts, onboarding state, and short-lived handoffs between screens.

To protect work in progress, Quester may keep an unsaved note draft in that browser's local storage until the note is saved or the draft is cleared. This browser-local data is not PostHog analytics and is not available on another device. Clearing site data in your browser can remove it and may sign you out or reset interface preferences.

9. Retention, deletion, and security

How long we keep information

We keep account information and Research Content while the relevant account or workspace is active and for as long as needed to provide the service. The retention period for a particular record depends on what it is, why we hold it, whether a workspace owner has asked us to delete it, and whether law or a dispute requires us to preserve it.

  • Deleted projects and accounts may remain recoverable for a limited operational period before permanent deletion workflows and backup rotation complete.
  • Content in a retained shared workspace remains with that workspace after an individual member leaves.
  • Billing, transaction, security, audit, and legal records may be kept longer when needed for tax, fraud prevention, dispute resolution, safety, or legal obligations.
  • De-identified or aggregate data may be retained when it can no longer reasonably be linked to a person.

When information is no longer needed under these criteria, we delete it or de-identify it. You may contact us for more information about the retention criteria for a specific category of data.

International processing

Quester and its providers primarily process data in the United States. If you access the service from another country, your data may be transferred to the United States and other countries where our providers operate. Where required, we use recognized transfer safeguards, which may include adequacy decisions, contractual protections, or a provider's approved transfer mechanism. You may contact us for information about the safeguards relevant to your data.

How we protect information

We maintain technical and organizational safeguards designed for the nature of the data Quester holds. These include encrypted network transport, provider encryption at rest, tenant-scoped authorization, role-based access controls, protected authentication sessions, backups, logging, and deletion workflows. Access by Quester personnel and service providers is limited according to role and need. No system can guarantee absolute security, so please use a strong sign-in method, protect your device, and tell us promptly if you believe your account has been compromised.

10. Your choices and privacy rights

Depending on where you live, you may have the right to:

  • know whether and how we process your personal data;
  • access and receive a portable copy of personal data we hold about you;
  • correct inaccurate account information;
  • request deletion of personal data, subject to applicable exceptions;
  • object to or restrict certain processing;
  • withdraw consent where processing relies on consent;
  • appeal our response where local law provides that right; and
  • complain to your local data-protection authority.

You can turn off product analytics under Settings → Profile → Product analytics, export a project from its settings, manage profile data in account settings, turn off AI in project settings, and start account deletion from account settings. You may also email support@quester.tech. We may need to verify your identity or authority before fulfilling a request. Where permitted, an authorized agent may submit a request for you. We will not discriminate against you for exercising a privacy right.

Organization-managed accounts

For personal data controlled by a university or other customer, please contact that organization first. We will assist it with requests as required by our agreement and applicable law. Deleting an individual account does not delete content the organization or other members are entitled to retain in a shared workspace.

Children

Quester is designed for adult and higher-education researchers, not children. We do not knowingly collect personal data from children under 13. A person below the age at which they can consent to online services in their jurisdiction may use Quester only with any required authorization from a parent, guardian, or educational institution. Contact us if you believe a child provided personal data improperly.

11. California and other U.S. state disclosures

Where a comprehensive U.S. state privacy law applies, the categories described in Section 2 may correspond to identifiers; customer records; commercial information; internet or electronic-network activity; approximate location inferred from an IP address; professional or education-related information; user-provided content that may include sensitive information; and inferences such as product or Advisor preferences. We collect these categories from the sources and for the purposes described in Sections 2 and 3.

We disclose these categories for business purposes to the recipients described in Section 6 as relevant to the service each recipient provides. We do not sell personal information or share it for cross-context behavioral advertising, and we do not have actual knowledge that we sell or share the personal information of anyone under 16. We do not use sensitive personal information to infer characteristics about you outside the purpose for which you provided it.

12. Changes and contact

We may update this policy as Quester or applicable law changes. We will revise the date above and provide additional notice, such as in the application or by email, when a change materially affects your rights or how we use personal data. We will request consent when applicable law requires it before applying a materially different use to data already collected.

Questions, privacy requests, or security concerns can be sent to support@quester.tech. Quester is operated from California, United States. If you are not satisfied with our response, you may contact the data-protection or privacy regulator where you live.