Who is responsible
Quince AI is the data controller.
Organisationsnummer 559481-4799
Övre Hallegatan 50, 417 09 Göteborg, Västra Götaland, Sweden
info@quince-ai.com
What we collect, and only when you send it
We collect nothing about you until you choose to send it. Every place on this site where that happens is listed here.
The contact form
When you submit the form on the contact page we receive your name, email address, message, and the page you came from. That last field tells us which part of the site prompted you to write; it is a path like /services.html, never an identifier for you.
The submission is sent to a serverless function we operate, which stores it in our lead database and notifies us by email. If that function is unreachable, the site offers to open a pre-filled draft in your own mail client instead — you choose whether to send it, and nothing is stored on our side unless you do.
The self-check and the requirements brief
The sovereignty self-check and the requirements check work without any details about you. Only if you choose to send us your result do we receive your email address, your answers, and the optional context you picked, such as sector and timeframe. It reaches the same lead database.
The field-guide download
The gated download on Real Value vs. Hype asks for your email address, and optionally your name and company. It reaches the same lead database.
The work-note subscription
The signup at the foot of our articles asks for your email address only, and stores it with the article you signed up from, your language, and the timestamps of your request and your confirmation. Nothing is sent to you until you click the confirmation link we email you — signing someone else up does nothing. Every email we then send carries a working one-click unsubscribe.
Job applications
The form on the careers page asks for your name, email address, and optionally a phone number, a link you choose to share, a message, and a CV. Applications go into their own store, separate from the lead database, and the CV file sits in a private bucket in the same EU region — it is never publicly reachable, and only signed-in team members can open it, through links that expire in minutes.
Why we are allowed to hold it
The enquiry forms rest on Article 6(1)(b) GDPR — steps taken at your request before entering a contract — and, where you are writing on behalf of an organisation, our legitimate interest under Article 6(1)(f) in responding to a business enquiry. The same Article 6(1)(b) covers a job application: you sent it asking us to consider you. The work-note subscription rests on your consent (Article 6(1)(a)), given by the confirmation click and withdrawable at any time with the unsubscribe link. We do not use your details for automated decision-making or profiling, and we do not sell, rent, or share them for advertising.
If you contacted us about a project, we may follow up on that enquiry with a few scheduled emails — started by a person on our team, never automatically. This rests on the same legitimate interest in answering your enquiry; every such email carries a working opt-out link, and one click stops all email from us, follow-ups included.
How long we keep it
We keep an enquiry until we have replied and the conversation has run its course, and for a reasonable period afterwards in case you come back to it. If nothing comes of it, we delete it. You can ask us to delete it at any time and we will do so — deleting a lead is a one-click action in our own tooling, not a support ticket.
A subscription is kept until you unsubscribe. When you do, we keep only your bare email address on an internal do-not-email list, so that no future mailing can reach you by mistake; ask us at info@quince-ai.com and we erase that too.
A job application, including the CV, is kept through the recruitment and for at most two years afterwards — the window in which Swedish discrimination law lets a candidate challenge a hiring decision, which is the one reason we do not delete it the day the process ends. Ask us and we delete it sooner; deleting an application removes the CV file with it.
Where it is stored, and who else touches it
These are every third party involved in running this site. There are no others.
- Supabase — hosts our database and the serverless functions that receive form submissions. Our project runs in the EU (Stockholm, eu-north-1) region. Access to the table is locked down: the public site cannot read it, and only signed-in team members can.
- Resend — delivers our email: the notification that tells us a new enquiry has arrived, and the work-note emails you subscribe to. It processes the message content and your address in order to deliver them.
- Google Analytics — measures how the site is used. It sets cookies and is the one item on this list that only runs with your permission inside the EU/EEA. See the analytics section below for exactly when it loads and how to turn it off.
- Google Fonts — serves the three typefaces this site uses. Your browser requests them from Google's servers, which means Google receives your IP address when you load a page here. This is the one third-party request the site makes on every visit, and we are naming it rather than leaving you to find it in the network tab. We intend to self-host these fonts and remove the dependency.
Analytics
There are two separate things measuring traffic here, and they behave very differently. The first always runs and cannot identify you. The second only runs if you allow it.
Our own measurement — always on, no cookies
We count page views with our own first-party analytics. There are no cookies and no localStorage identifiers involved, and nothing in it can follow you to another site.
For each page view our server derives a hash that rotates every day from your IP address and browser user-agent, then stores only that hash. Neither your IP address nor your user-agent is ever written down. Because the hash changes daily, it cannot be used to follow you from one day to the next.
We also record a two-letter country code. This is resolved on our own server against a local lookup database — your IP address is not sent to any geolocation service. If the lookup finds nothing, we store nothing.
Raw events are deleted after 90 days. Only aggregate daily totals survive, and those contain nothing about any individual.
The beacon honours Global Privacy Control. If your browser sends that signal, we do not count you at all.
Optional analytics cookies — off unless you allow them
We also use a third-party analytics product to understand how the site is used. Unlike the above, it does set cookies in your browser and sends data to a provider outside the EU. Today that product is Google Analytics. We name it rather than writing "our partners"; if we add or replace tools, this list changes with them.
Inside the EU and EEA it does not load at all unless you press Accept on the banner. Press Decline and it is never loaded.
Outside the EU and EEA it loads by default, because the consent requirement is a European one. We would rather say that plainly than let you assume otherwise — if you are reading this from outside Europe and would prefer it off, use the button below.
Your choice is remembered in your browser's own local storage, not in a cookie, and it is never sent to us.
Cleared. The banner will ask again on your next page load.
Your rights
Under GDPR you may ask us for a copy of what we hold about you, correct it, delete it, restrict or object to how we use it, or receive it in a portable format. Write to info@quince-ai.com and we will respond within one month.
If you think we have handled your data badly, you can complain to the Swedish authority, Integritetsskyddsmyndigheten (IMY) — imy.se.
Changes
If we change how any of this works, we change this page in the same commit. It is version-controlled alongside the site itself.
Last updated .