Privacy policy
About this policy
This policy covers the Qwrki app at app.qwrki.com. The Qwrki website at qwrki.com has its own policy.
The app is operated by Qwrki Pty Ltd, 74 Thorburn St, Nimbin NSW 2480, Australia. Questions about this policy go to [email protected].
Information the app holds
An organisation that uses Qwrki owns its workspace. Its members enter and manage records such as customers, cases, projects, invoices and files. Qwrki stores those records to run the app for that organisation and shows them to that organisation's members, according to the roles its admins assign, and to the people the organisation shares them with, such as its portal contacts and visitors to its public forms and surveys.
To sign you in, Qwrki keeps your email address and your password, stored only as a one-way hash, and sets a sign-in cookie in your browser.
When a member opens a page in the app, Qwrki records the page's path, the referring page, the device type, the country and the campaign value, with a daily pseudonymous visitor value, so the organisation's admins can see how the app is used.
Google user data
When you connect a Google account, Qwrki asks Google for the permissions below and nothing else.
| Permission | Connected by | What Qwrki reads | Why |
|---|---|---|---|
| openid | An admin, for the organisation | The Google account's identifier. | So a later reconnection can only use the same Google account. |
| analytics.readonly | An admin, for the organisation | Report totals for the Google Analytics property the admin picks: sessions, users, conversions and sessions by channel. | To show the organisation its own website figures on its dashboards. |
| webmasters.readonly | An admin, for the organisation | Search Console totals for the site the admin picks: clicks, impressions and click-through rate, also split by search query, page, device and country. | To show the organisation how its site appears in Google Search. |
| adwords | An admin, for the organisation | Performance reports for the Google Ads account the admin picks: cost, clicks, impressions and conversions. Google offers no read-only Ads permission; Qwrki only reads reports and never changes a campaign. | To show the organisation its advertising figures beside its other figures. |
| openid, email | A member, for themselves | The identifier and email address of the member's own Google account. | To show which account is connected and to refuse a different account on reconnection. |
Qwrki's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
Google's policy: https://developers.google.com/terms/api-services-user-data-policy
How Qwrki uses Google user data
Qwrki does not access Gmail or Google Drive. If this changes, this policy will say so first.
Qwrki uses Google user data only to provide the features described in the table above, which the person connecting the account can see in the app.
Who can see it
Figures from an organisation's Google Analytics, Search Console and Google Ads connection are shown to members of that organisation. Only its admins and owners can connect, update or disconnect that connection.
AI features
An organisation's admins can give one of its AI Employees access to a connected Google Analytics, Search Console or Google Ads account. The figures Qwrki stored from that account are then included in requests to Qwrki's AI model provider to draft that Employee's work. Qwrki sends those requests with the provider's logging of prompts turned off.
Qwrki does not use Google user data to train or improve AI or machine learning models.
Storage, retention and deletion
Text already copied into a case stays in Qwrki as part of that case.
Report figures from Google Analytics, Search Console and Google Ads are deleted automatically 400 days after the period they cover, while the organisation is active. Figures of a suspended organisation are kept until it is active again. Copies in exports, saved reports, report emails, drafts and notifications are not automatically deleted.
Google access tokens are stored encrypted with AES-256-GCM.
Every page from the app carries a header telling browsers to keep using HTTPS. Stored report figures belong to one organisation: the figures table enforces row-level security, and every request that reads those figures runs with that organisation set as the tenant. Qwrki only shows those figures to members of the organisation they belong to, in the app and in emails they receive.
When a Google connection is disconnected, or when a member's own Google connection is disconnected because that member is removed from an organisation, Qwrki overwrites its stored token so it can no longer be used and discards its cached access token. After an organisation's Google Analytics, Search Console or Google Ads connection is disconnected, Qwrki's background job deletes the report figures Qwrki stored from that connection and the figure files exported from it, normally within two hours. Copies already in the organisation's own work keep what they contain: drafts an AI Employee wrote, saved reports already run, notifications in Qwrki, alert messages already posted to a chat tool, and emails already sent or waiting to send.
When you disconnect Google in Qwrki, Qwrki can no longer use the access. Google keeps listing Qwrki until you remove it in your Google Account, under Security, Third-party apps and services. Removing it there ends every Qwrki connection that Google account holds, in every organisation.
What Qwrki never does with Google user data
Qwrki does not sell Google user data, does not use it for advertising, and does not transfer it to data brokers or information resellers.
People at Qwrki do not read Google user data, except with your explicit permission for specific data, when needed for security purposes such as investigating abuse, to comply with applicable law, or when it has been aggregated and anonymised for internal operations.
Your Google Account permissions page: https://myaccount.google.com/permissions
Services Qwrki uses
Qwrki uses service providers for AI features, bot protection, sending email and billing. The app, its database and its file storage are hosted on servers in the United States.
Changes to this policy
When this policy changes, this page shows the new text and the date it was updated.
The outside services that may receive company data are listed on our subprocessors page.