Privacy Policy

Last updated:

Quorum is a private, invite-only tool used by members of a single corporate board to coordinate meetings and manage shared board documents.

Data we access

When you sign in with Google, Quorum requests:

  • Your Google Calendar (https://www.googleapis.com/auth/calendar) to query your free/busy times and create meeting events with you and other attendees.
  • Per-file Google Drive access (https://www.googleapis.com/auth/drive.file) to create and manage the folder and documents for each scheduled meeting. Quorum CANNOT access other files in your Drive.
  • Your Google account email, name, and profile picture.

How we use your data

  • Calendar data is used only to rank candidate meeting times and to create confirmed meeting events. We never send your calendar data to third parties.
  • Drive data is limited to the folder structure and documents Quorum creates for each meeting.
  • Your email, name, and profile picture are shown in-app so other board members can identify you.

How we store your data

  • Your Google OAuth refresh token is encrypted at rest using AES-256-GCM with a server-side key. Access to this table is restricted to our backend service and is not readable by any end user.
  • Your profile, meeting records, and availability preferences are stored in our managed Postgres database (Supabase). Row-level security policies scope reads to authenticated board members only.

How we share your data

We do NOT sell or share your Google user data with any third party. The only external services that receive data on your behalf are:

  • Google (to create Calendar events and Drive folders you initiate).
  • Resend (transactional email delivery for meeting notifications).

Data retention and deletion

  • Your data is retained for as long as you are an active board member.
  • When your membership is deactivated or you request deletion, your profile and stored Google credentials are deleted within 30 days. Calendar events and Drive documents you authored remain in YOUR Google account and are NOT deleted by us.
  • You can revoke Quorum's access to your Google account at any time via myaccount.google.com/permissions.

Contact

Questions? Email brandynthibault@gmail.com.