Your documents, photos, extracted dates, reminders, family member names, and household data are stored in an encrypted vault on your device. They are never transmitted to MQL Capture. We cannot read, access, recover, or disclose them — we do not have them. We use no analytics, advertising, or tracking technologies in the app.
| Data | Purpose | Who handles it |
|---|---|---|
| Payment details (name, email, card) | Subscription billing | Stripe, our payment processor. Card numbers never touch us; we receive only a customer reference and subscription status. |
| Standard web server logs (IP address, request time) | Serving and securing the site | Netlify, our hosting provider. |
| Support email you send us | Answering you | MQL Capture (support@mqlcapture.com). |
Cloud sync: if you enable it, one end-to-end-encrypted file is stored in a cloud account you own (Google Drive or Microsoft OneDrive). Only ciphertext leaves your device; the decryption passphrase never does. That storage is governed by your provider's privacy policy, and sign-in tokens are kept encrypted on your device. AI enhancement: if you add your own Anthropic API key, captured document text/images are sent to Anthropic under your key and their privacy terms; this is off by default.
Because your data lives on your devices and in your own cloud account, you delete it yourself: "Erase all data" in Settings wipes the device vault, and deleting the sync file from your cloud account removes the synced copy. Billing records are retained by Stripe and by us as required for tax and accounting law. To cancel billing, use Settings → Manage subscription; to ask us about any data we hold (essentially billing records), email support@mqlcapture.com.
The Service is for adults (18+). Parents may add family members, including children, to their own household records — that information stays in the family's own vault like everything else. We do not knowingly collect personal information from children.
Vault contents are encrypted on-device with AES-256-GCM using a key derived from your passphrase (PBKDF2, 310,000 iterations). We cannot reset your passphrase — this is a deliberate security property, and it means you are responsible for remembering it and keeping backups.
Depending on where you live, you may have rights to access, correct, or delete personal information. For vault data, you can exercise these directly in the app (export, edit, erase) because only you hold it. For billing data, contact us at support@mqlcapture.com and we will work with you and Stripe to honor applicable rights. We do not sell or share personal information for advertising.
If our practices change, we will update this page with a new effective date. Because the architecture is local-first, material changes (such as ever introducing server-side processing) would be prominently disclosed in the app before you opt in.
MQL Capture LLC · support@mqlcapture.com