Privacy policy
Last updated: September 4, 2026
Quantum General Intelligence Inc. ("QGI", "we", "us") operates the website qgi.studio and the QGI Studio application, including the Finance Studio vertical at fin.qgi.studio ("Studio"). This policy explains what personal data we collect, why, and what rights you have. It supplements the QGI privacy policy at qgi.dev/privacy-policy. Where the two differ, this policy governs Studio.
1. Who we are
Quantum General Intelligence Inc. is headquartered in San Diego, California, United States. We are the data controller for the personal data described in this policy. Contact us through qgi.dev/contact.
2. Data we collect on this website
- Server logs. IP address, user agent, requested page, referrer, and timestamp, retained for up to 30 days for security and operations.
- Contact requests. This site does not host forms. Enterprise and demo requests are submitted on qgi.dev and are covered by the QGI privacy policy.
- Cookies. This website sets no advertising or tracking cookies. If we add analytics, it will be cookieless or disclosed here.
3. Data we process in Studio
What Studio processes depends on what you place in a project, which tools are enabled for it, and which MCP servers, connectors and skills you add.
- Account data. Name, email address, tenant, role, plan, credit balance and billing status, used to provide and bill the service. In platform mode, signing in requires your email to be on the app's access list.
- Project content. Prompts, files, and artifacts inside a project, and data returned by tools you run. Content is processed to perform the runs you request. Runs execute on the engine and model you select; content needed for a run is sent to that engine's model provider for processing. We do not use project content to train models.
- Run and audit data. Run ids, transcripts, tool calls, timings, workflow run history, approvals and version history. These are stored with the project so you and your team can review the work, and form the audit trail described on this site.
- Diagnostics and telemetry. Run status, process and host health, and error reports that admins see in the console. These do not include project content beyond what is needed to diagnose a failure.
4. Why we process data
- To provide Studio and perform the runs and workflows you ask for (performance of a contract).
- To secure the service, isolate tenants and users, prevent abuse, and keep it reliable (legitimate interest).
- To bill and communicate about your account (performance of a contract, legal obligation).
- To respond to requests you send us (consent or legitimate interest).
We do not sell personal data. We do not use project content to train models.
5. Engines, tools, MCP servers and connectors
Engines and their model providers are configured per tenant by an admin. When a run executes on an engine, the prompt and the project content it needs are sent to that engine's provider under the provider's terms.
Collection tools in Finance Studio query third-party public data sources (for example FRED, the CFPB HMDA API and FHFA) and the lending and disclosure services connected to your tenant. When you add an MCP server or a connector (for example Gmail, Google Sheets, GitHub, Slack or Notion), Studio accesses that service on your behalf within the scope you grant. Those services process your data under their own terms and privacy policies. You can remove a server, skill or connector at any time from Library or Integrations, and revoke access from the third-party service.
We use service providers for hosting, authentication, email delivery, payment processing, and support. They process data only on our instructions and under contract.
6. Data retention
- Account data: for the life of the account and up to 12 months after closure, unless a longer period is required by law.
- Project content, artifacts, versions and run history: for as long as the project exists in your workspace. Deleting a project removes its content from the host.
- Audit and telemetry data: up to 90 days, or longer where an Enterprise agreement requires it.
- Website logs: up to 30 days.
Enterprise agreements can set different retention and residency terms, and those terms take precedence.
7. International transfers
QGI is based in the United States. If you use Studio from outside the United States, your data may be processed in the United States and, for engine runs, in the regions used by the engine's model provider. Where required, we rely on standard contractual clauses or an equivalent safeguard. Enterprise deployments with private executors keep run execution in the environment you choose.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to restrict or object to processing, and to withdraw consent. Residents of the European Economic Area and the United Kingdom have rights under the GDPR and UK GDPR. California residents have rights under the CCPA and CPRA, including the right to know, delete, and opt out of sale (we do not sell data). To exercise a right, contact us at qgi.dev/contact. You may also lodge a complaint with your local supervisory authority.
9. Security
We use encryption in transit, bearer authentication on every API route, tenant and role checks, per-user OS isolation for run execution, access controls, and logging to protect data. No system is perfectly secure. If we learn of a breach affecting your personal data, we will notify you and any required authority as the law requires.
10. Children
Studio is a business product and is not directed at children under 16. We do not knowingly collect personal data from children.
11. Changes
We will post changes to this policy on this page and update the date at the top. Material changes to how Studio handles project content will also be announced in the application.
12. Contact
Quantum General Intelligence Inc., San Diego, California, United States. qgi.dev/contact. The application runs at fin.qgi.studio.