Privacy Policy
QuarterMaster (“we”, “us”) is an inventory and buildability platform for hardware teams, available at quarter-master.co and as iOS and Android apps. This policy describes what we collect, why, and the choices you have. It applies to the web console, the mobile apps, and the public API.
What we collect
- Account data — your name, work email address, and a hashed password (or your Google sign-in identity if you use it). We never store plaintext passwords.
- Workspace data — the inventory, parts, BOMs, purchase orders, supplier records, work instructions, and files (including photos and CAD attachments) that you and your team put into your organization. You own this data.
- Activity records — an append-only audit trail of actions taken in your organization (who did what, when, from which surface). This is a core product feature: inventory corrections are traceable, never silently rewritten.
- Technical data — standard server logs (IP address, user agent, timestamps) kept for security and debugging.
What we don’t do
- We don't sell your data or share it with data brokers.
- We don't run third-party advertising or cross-app tracking SDKs in our apps.
- We don't use your workspace data to train AI models, and our AI providers are contractually restricted from doing so.
Device permissions (mobile apps)
- Camera — used to scan QM labels and photograph parts you choose to add to inventory. Photos are uploaded only when you attach them.
- Face ID / biometrics — used to confirm sensitive actions like purchase-order approval. Biometric matching happens entirely on your device via the operating system; we only receive a success or failure signal and never see biometric data.
- Photo library — read only when you pick an existing photo to attach.
- Microphone — used only while you talk to the QuarterMaster assistant by voice.
AI features
Some features (the assistant, document intake, supplier research) send the content you provide — such as a photo, a BOM spreadsheet, or a chat message — to our AI provider (Anthropic) to generate drafts and suggestions. AI output is always a draft: a human on your team confirms before anything is written to your inventory ledger. Our AI providers process this data to serve the request and do not train on it.
Who processes your data
We use a small set of subprocessors to run the service: Google Cloud Platform (hosting and storage, United States), Anthropic (AI processing), and Postmark (transactional email). If you connect an integration such as QuickBooks, data flows to that provider only after you authorize it.
Retention and deletion
Workspace data is retained while your organization is active. Organization owners can delete their organization from the web console; audit-trail retention is configurable per organization. You can delete your account at any time — from the mobile app (profile → Delete account) or by emailing support@quarter-master.co. Account deletion revokes every session and API key, removes you from your organizations, anonymizes your personal information immediately, and schedules the remaining records for purge. If you are the sole owner of an organization, transfer ownership or delete that organization first.
Security
All traffic is encrypted in transit (TLS). Data is stored on Google Cloud infrastructure with encryption at rest. Access to production systems is limited and logged. QuarterMaster is not an ITAR-compliant environment — do not store ITAR-controlled technical data in the service.
Children
QuarterMaster is a business tool and is not directed to children under 16. We do not knowingly collect personal information from children.
Changes and contact
We’ll post any material changes to this policy here and update the date above. Questions or data requests: support@quarter-master.co.