Privacy Policy
Querio Privacy Policy
Last Updated: March 24, 2026 Effective Date: March 24, 2026
About Querio and This Policy
Querio Ltd., is a Delaware corporation and the parent company of the Querio group. Querio Ltd is our UK operating subsidiary. In this Policy, "Querio," "we," "us," and "our" refer to these entities together, and any reference to a specific entity is called out where it matters (for example, the controller of your personal data — see Section 8).
Querio provides software and services that help teams explore and analyze data (the "Services"). This Privacy Policy explains how we collect, use, share, and protect information about you when you use our websites, including any subdomains, and the Services (together, the "Websites"). If you do not agree with this Policy, please do not use the Websites or Services.
If your organization has a separate agreement with Querio (a "Customer Agreement"), that agreement governs our processing of data in your organization's workspace. In that case, your organization controls its workspace and may set rules for how you and other users use the Services. Questions about your organization's settings should be directed to your organization.
1 — Information We Collect
We collect the following categories of information:
Account and Profile Information. Name, email address, organization, role or title, and any information you add to your profile. If you sign up via a third-party identity provider (e.g., Google), we receive identifiers such as your name and email consistent with your settings with that provider. For paid plans, payment details are processed by our payment provider and are not stored by Querio.
Usage and Device Information. When you use the Websites or Services, we automatically collect log data (e.g., IP address, browser type, device identifiers, pages viewed, referring and exit pages, and timestamps) and use cookies and similar technologies as described in Section 9. We use PostHog for product and website analytics.
Customer Data. Content you or your organization submit to or process through the Services (e.g., data source connections, queries, dashboards, prompts, and inputs and outputs generated by AI features). We process Customer Data on behalf of the Customer under the Customer Agreement.
Support and Communications. Information you provide in support tickets, surveys, or other communications with us.
2 — How We Use Information
We use information for the following purposes:
Provide and maintain the Services. Account creation, authentication, customer support, and operating and securing the Services.
Communicate with you. Service-related notices, onboarding, product updates, security alerts, and administrative messages. Some communications are fundamental to the Services and you may not be able to opt out.
Improve and develop. Troubleshoot, debug, analyze trends and usage, and develop new features and integrations.
Marketing. Send newsletters and promotional communications. You can unsubscribe at any time.
Safety and compliance. Detect and prevent fraud, abuse, or security incidents; comply with legal obligations; enforce our terms; and protect our rights.
We rely on a combination of consent (where required), performance of a contract, legitimate interests (to deliver and improve the Services and to market to business users), and legal obligations as our legal bases, as applicable.
3 — AI Functionality
Some features use artificial intelligence, including large language models ("LLMs") provided by vetted third-party providers.
Inputs and Outputs. Prompts, schema descriptions, and contextual information you provide ("Inputs") and results generated by the AI features ("Outputs") are treated as Customer Data where submitted within a Customer workspace.
How data is processed. To generate Outputs, we transmit relevant Inputs — which may include prompts, schema and metadata, and content or query results from your connected data sources — to our LLM providers. Our LLM providers process this data solely to return a response to the applicable request. Under our agreements with these providers:
they do not use Customer Data or Inputs to train or improve their models; and
they do not retain this data beyond the limited period necessary to process the request, and in many cases retain none.
Querio does not use Customer Data to train any models. Querio does not currently operate its own foundation models. If we introduce first-party models in the future, we will update this Policy and will not train them on Customer Data without appropriate notice and, where required, consent.
Caution. Outputs may contain inaccuracies and should not be used as a substitute for professional medical, clinical, legal, or financial judgment. Customers in regulated industries are solely responsible for validating Outputs before use in any decision-making context.
4 — Healthcare and Sensitive Data
The Services are general-purpose data tools and are not, by default, a HIPAA-compliant offering. You should not submit protected health information ("PHI") as defined under HIPAA, or other sensitive personal data subject to heightened legal protection, to the Services unless Querio has entered into a Business Associate Agreement ("BAA") or an equivalent data protection agreement with your organization covering that use.
Where a BAA or equivalent agreement is in place, Querio will process such data in accordance with that agreement and applicable law. Customers are responsible for determining whether their intended use of the Services is appropriate for the categories of data they submit and for obtaining any necessary consents or authorizations. To discuss a BAA or a regulated-industry deployment, contact us at hello@querio.ai.
5 — How We Share Your Personal Data
We share information in the following circumstances:
Service Providers (Sub-processors). With vendors that host, support, analyze, bill, message, or otherwise help us operate the Services (e.g., cloud hosting, storage and backup, analytics, crash reporting, email, payment processing, customer support tools, and AI/LLM infrastructure). These providers may access personal data only to perform services for us and are bound by contractual confidentiality and security obligations. A current list of our sub-processors is available at here.
Affiliates. With our affiliates and subsidiaries for purposes consistent with this Policy.
Third-Party Services Enabled by You. If you choose to connect or enable integrations, the third party may receive information per its own terms and privacy policy.
Compliance and Safety. To comply with law or legal process; protect the rights, property, or safety of Querio, our users, or the public; and detect, prevent, or address fraud, security, or technical issues.
Business Transfers. In connection with a merger, acquisition, financing, or sale of assets.
With Consent. When you direct us to share or consent to sharing (e.g., testimonials, case studies).
6 — Data Retention
We retain personal data for as long as necessary to provide the Services and for other legitimate purposes such as complying with legal obligations, resolving disputes, and enforcing agreements. Retention periods vary by category:
Account and profile information is retained for the life of the account and for a limited period after closure (up to 90 days) unless a longer period is required by law.
Usage, log, and analytics data is retained on a rolling basis (generally up to 24 months) and may be kept in aggregated or de-identified form thereafter.
Customer Data is retained per the Customer Agreement and is deleted or returned within 30 days of account termination upon request.
Support and communications are retained as long as needed to handle the matter and for a reasonable period afterward.
Backups are purged on a rolling cycle in the ordinary course.
Payment card data is processed and stored by our payment processor (e.g., Stripe) in accordance with its policies; we do not store full card numbers or CVV.
7 — International Transfers
We may process and store information in the United States, the United Kingdom, and other countries where we or our service providers operate. Where required, we use appropriate safeguards for cross-border transfers, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum (or IDTA), and, if applicable, participation in recognized data-transfer frameworks. Additional details, including our sub-processors, are available here.
8 — Your Rights
Your rights depend on your location and the applicable law. Subject to exceptions, you may have the right to access, correct, delete, restrict, or object to processing, and to port your data, as well as the right to withdraw consent where processing is based on consent. You also may have the right to lodge a complaint with a supervisory authority. We will respond to requests consistent with applicable law.
Residents of the EEA, UK, and Switzerland. Querio Ltd is the controller for personal data we collect outside of a Customer workspace. Within a Customer workspace, Querio acts as a processor to the Customer. If you are in the UK, you may lodge a complaint with the Information Commissioner's Office (ICO); if you are in the EEA, you may complain to your local data protection authority.
California Residents. If you are a California resident, you have rights under the California Consumer Privacy Act (as amended by the CPRA), including the rights to know and access, delete, correct, and to opt out of certain sharing or targeted advertising as defined by law. We do not sell personal information for money. We use PostHog for first-party product and website analytics, not for cross-context behavioral advertising, and we do not share personal information with third parties for such advertising. Where required, we honor Global Privacy Control (GPC) signals as a request to opt out of any "sale" or "sharing" as defined under California law. We will not discriminate against you for exercising your rights.
To exercise any rights, please contact us at hello@querio.ai. We may request information to verify your identity and residency, and we will respond within the timeframes required by law.
9 — Cookies and Similar Technologies
We and our service providers use cookies, pixels, and similar technologies to operate and improve the Websites, remember preferences, analyze how the Services are used (via PostHog), and provide and measure marketing. You can control cookies through your browser settings. If you disable certain cookies, some features may not function properly.
We honor Global Privacy Control (GPC) signals where required by applicable law. The Services do not respond to browser "Do Not Track" (DNT) signals, which are separate from GPC and not standardized.
10 — Security
We maintain administrative, technical, and physical safeguards designed to protect personal data. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
11 — Google API Data
Querio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Where you connect a Google data source, we access and process data from that source only to provide the features you request. To generate AI Outputs, relevant data may be transmitted to our LLM sub-processors solely to return a response; these providers do not use it to train their models and do not retain it beyond what is necessary to process the request. We do not transfer Google user data for advertising or to train generalized AI or machine-learning models.
12 — Children's Privacy
The Services are intended for business use and are not directed to children. We do not knowingly collect personal data from children under 16 (or under 13 where that is the applicable threshold). If you believe a child has provided us with personal data, please contact us at hello@querio.ai and we will take appropriate steps to delete it.
13 — Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will provide notice (e.g., by in-product message or email) prior to the change becoming effective. Your continued use of the Services after the effective date constitutes acceptance of the revised Policy.
14 — Contact
Have questions or concerns about privacy? Contact us at hello@querio.ai, or by mail:
Querio Ltd. (United States) 2505 South Rainbow Ranch Road, Wimberley, Texas 78676
Querio LTD (United Kingdom) Suite 102 Pill Box, 115 Coventry Rd, London E2 6GG
