Last updated: August 11, 2026 · QuQi is operated by OhMySaaS, LLC · Questions? legal@quqi.io
This policy explains what QuQi collects, why, and what you can do about it. It covers quqi.io, the QuQi application, and the WhatsApp and Telegram assistants operated under the QuQi name.
QuQi is operated by OhMySaaS, LLC, 1111B S Governors Ave, Suite 43066, Dover, DE 19904, United States. For data protection purposes OhMySaaS, LLC is the controller of the personal data described here.
Questions, requests, or complaints: privacy@quqi.io.
Your name, email address, and a hashed password. If you sign in through a third-party provider, we receive your name, email, and provider account identifier. We never receive your password from that provider.
Domains you add, and everything our crawler records about them: page URLs, titles, meta descriptions, headings, status codes, link structure, and the SEO issues we detect. You may also store brand details, target audiences, competitors, and content settings.
When you connect WordPress, Shopify, a webhook endpoint, or Google Search Console, we store the credentials or tokens required. These are encrypted at rest and are never displayed back to you or included in exports.
If you link WhatsApp or Telegram, we store the identifier for that channel — your phone number in international format, or your Telegram chat ID — along with the display name or username the platform supplies. We store the content of messages exchanged with the assistant so conversations have continuity.
IP address, browser type, pages visited, and timestamps, recorded in server logs for security and diagnostics.
What we do not collect. We do not ask for payment card numbers, government identifiers, or special-category data (health, biometrics, political or religious views). Please do not send these to the assistant.
We do not sell personal data, and we do not use your content for advertising.
| Purpose | Basis |
|---|---|
| Delivering the service you signed up for | Performance of a contract |
| Security, abuse prevention, diagnostics | Legitimate interests |
| Linking a WhatsApp or Telegram account | Consent (withdrawable at any time) |
| Marketing email | Consent |
| Retaining records where law requires | Legal obligation |
QuQi uses third-party AI models to generate audits, articles, and chat replies. To do that, we send the relevant context — your prompt, brand settings, and site data such as detected issues or page titles — to our model provider, currently OpenAI.
Our provider processes this to return a response. Under our API terms, submissions are not used to train their models. We do not control how a model reasons, and outputs may be inaccurate — review anything you intend to publish.
Linking a messaging account is optional and entirely under your control.
Our crawler fetches pages from domains you add, identifying itself in the user agent and respecting configured limits. Crawled content is stored as project data for your account only.
You must have the right to crawl any domain you add. If a page contains personal data, that data enters our systems as part of the crawl record — please avoid crawling pages that expose personal data unnecessarily.
We share personal data only with providers that process it on our behalf under contract:
| Provider | Purpose | Location |
|---|---|---|
| OpenAI | AI model inference for chat, audits, and articles | United States |
| DigitalOcean | Application hosting and crawler infrastructure | United States |
| Meta Platforms | WhatsApp message delivery | United States |
| Telegram Messenger | Telegram message delivery | United Arab Emirates |
| Search Console data, where you connect it | United States | |
| Serper | Search results used for article research | United States |
| ScrapingBee | Page retrieval during research, where enabled | European Union |
We may also disclose data where legally compelled, to protect our rights or the safety of others, or to a successor in a merger or acquisition — in which case this policy continues to apply until you are notified otherwise.
After account deletion we remove or anonymise personal data within 30 days, except where retention is legally required. Backups age out on their own cycle, within 90 days.
We encrypt traffic with TLS, encrypt integration credentials at rest, hash passwords, and sign every inbound webhook so forged requests are rejected before they are read. Access to production data is limited to personnel who need it.
No system is perfectly secure. If a breach affects your personal data, we will notify you and any required regulator without undue delay.
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time.
If you are in California, you additionally have the right to know what we collect, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA.
Exercise any of these by emailing privacy@quqi.io. We respond within 30 days. EEA and UK residents may also complain to their local supervisory authority.
We operate from the United States, so using QuQi involves transferring your data there. Where we move personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum.
QuQi is for business use and is not directed to anyone under 16. We do not knowingly collect their data; if you believe a child has provided us data, contact us and we will delete it.
We may update this policy. The date at the top always reflects the current version, and we will notify you by email or in-app before any material change takes effect.
OhMySaaS, LLC
1111B S Governors Ave, Suite 43066
Dover, DE 19904, United States
privacy@quqi.io