QUORUM
Committee How it works Features Pricing
Request demo Start free trial
Legal · Privacy

Privacy Policy

How QUORUM collects, uses, and protects information when you use our institutional decision-intelligence platform.

Effective: May 1, 2026 Last updated: May 1, 2026 Version: 1.0
Contents
  1. Scope and applicability
  2. Information we collect
  3. How we use information
  4. Sharing and disclosure
  5. Subprocessors and AI providers
  6. Data retention
  7. Security
  8. Your rights and choices
  9. International transfers
  10. Changes to this policy
  11. Contact us

Scope and applicability

This Privacy Policy describes how QUORUM ("we," "us," or "our") handles personal information and customer data in connection with our software-as-a-service platform, our marketing website, and related services (collectively, the "Service"). It applies to portfolio managers, analysts, compliance staff, and other authorized users of customer organizations that subscribe to QUORUM, as well as visitors to our website.

QUORUM is a business-to-business product. Our customers are professional fund managers and investment firms ("Customers"). When a Customer organization uses QUORUM, the Customer is the controller of its own portfolio, trade, and deliberation data, and QUORUM acts as a processor on its behalf. This policy describes our practices in both capacities.

Note

QUORUM is built for professional and institutional investment workflows. The Service is decision-support infrastructure — not personalized investment advice — and is designed around the documentation, deliberation, and oversight needs of fund managers, family offices, and similar firms.

Information we collect

Account and identity information

When you or your organization signs up, we collect names, work email addresses, professional titles, the name of your organization, and authentication credentials (which are stored as salted hashes — never in plaintext).

Customer content

Through normal use of the Service, you submit information including:

  • Trade theses and proposals — ticker, direction, conviction, investment thesis, and supporting reasoning
  • Portfolio data — positions, sizing, broker uploads, and related context you choose to provide
  • Deliberation records — agent outputs, dissents, overrides, and IC Reports generated by the Service
  • Configuration — risk limits, sector preferences, agent preferences, and other workspace settings

Usage and operational data

We automatically collect log data (IP address, device and browser information, timestamps, requested actions, and error traces), product analytics (which features are used, in what sequence, and with what latency), and infrastructure metrics needed to operate, secure, and improve the Service.

Billing and commercial information

We collect billing contact details, plan tier, and invoicing history. Payment card details are processed and stored by our payment processor (Stripe) under their own security and compliance program; we do not store full card numbers.

Communications

If you contact us by email, request a demo, or correspond with our team, we retain those communications and any information you choose to provide.

How we use information

We use information to:

  • Provide, operate, and maintain the Service, including running deliberations, generating IC Reports, and storing institutional memory
  • Authenticate users, secure accounts, and detect or prevent abuse and fraud
  • Bill Customers, manage subscriptions, and process renewals
  • Improve product quality, debug issues, monitor performance, and develop new features
  • Communicate with Customers about service updates, security advisories, and account matters
  • Comply with legal obligations and respond to lawful requests

We do not use Customer content to train foundation models. Trade theses, portfolio positions, agent deliberations, and IC Reports are not used as training data for any machine learning model — by us, by our AI subprocessors, or by anyone else. See Section 5.

Sharing and disclosure

We share information only in the following limited circumstances:

  • Within your organization. Authorized users in the same Customer workspace can view shared deliberations and IC Reports per the role-based access controls your administrators configure
  • With subprocessors who provide infrastructure, payment processing, AI inference, market data, and analytics on our behalf, under contractual obligations of confidentiality and security (see Section 5)
  • For legal reasons, if we are compelled by valid legal process, regulatory request, or to protect the rights, property, or safety of QUORUM, our Customers, or others
  • In connection with a corporate transaction such as a merger, acquisition, or financing — subject to confidentiality obligations and continuity of this policy's protections

We do not sell personal information. We do not share Customer content with third parties for advertising or marketing purposes.

Subprocessors and AI providers

QUORUM is built on a small set of best-in-class infrastructure providers. Our principal subprocessors include:

  • Anthropic — large-language-model inference for deliberation, synthesis, and IC Report generation. Customer content is processed under Anthropic's commercial terms with zero data retention configured for inference
  • OpenAI — fallback LLM inference under enterprise-grade no-training terms
  • Render / Cloud hosting — application and database hosting in US-region data centers
  • Stripe — payment processing and billing
  • Better Auth (self-hosted) — authentication infrastructure operated by QUORUM in our own database
  • Market data providers — Massive API, Tiingo, Finnhub, and SEC EDGAR for fundamentals, prices, news, and filings. We send tickers and time ranges; we do not transmit Customer portfolio details to these providers

A current list of subprocessors is available upon request to enterprise Customers and is provided in advance of any material change.

Data retention

We retain Customer content for as long as the Customer's account is active and for a reasonable period thereafter to support business continuity, dispute resolution, and legal obligations. IC Reports and deliberation transcripts are designed as long-lived records; Customers who require longer retention to satisfy SEC Rule 204-2 or other regulatory regimes can configure extended retention windows through their workspace settings.

Operational logs are retained for up to 90 days unless a longer period is required for security, audit, or legal purposes. On request, and subject to legal holds, we will delete or return Customer content following termination of a Customer's subscription.

Security

We implement administrative, technical, and physical safeguards designed to protect information against unauthorized access, loss, or alteration, including:

  • TLS 1.2+ encryption for data in transit and AES-256 encryption for data at rest
  • Role-based access controls and the principle of least privilege for all internal access
  • Single sign-on (SSO) and SAML support on Institution and Enterprise+ tiers
  • Secrets management, audit logging, and continuous monitoring of production systems
  • Routine vulnerability scanning, dependency review, and a documented incident-response process

No system is perfectly secure. If you believe your account or data has been compromised, contact us immediately at security@getquorum.ai.

Your rights and choices

Depending on your jurisdiction, you may have rights under applicable privacy laws — including the right to access, correct, delete, or port personal information about you, and the right to object to or restrict certain processing. Where QUORUM acts as a processor on a Customer's behalf, we will direct rights requests to the relevant Customer and assist them in fulfilling those requests.

You may also unsubscribe from non-essential communications at any time using the unsubscribe link in those messages or by contacting privacy@getquorum.ai. Operational and security communications are not subject to opt-out as long as your account is active.

International transfers

QUORUM is operated from the United States, and Customer data is currently processed and stored in US-region infrastructure. If you access the Service from outside the United States, you understand that information will be transferred to and processed in the United States. We are evaluating EU-region inference and storage for future market expansion; until that infrastructure is available, the Service is offered to non-US Customers on the understanding that US data-protection law applies to processing.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify Customers in advance through the Service or by email and update the "Last updated" date at the top of this page. Continued use of the Service after the effective date of an update constitutes acceptance of the revised policy.

Contact us

For questions about this Privacy Policy or about how QUORUM handles information, contact:

  • General privacy inquiries: privacy@getquorum.ai
  • Security disclosures: security@getquorum.ai
  • General contact: hello@getquorum.ai
QUORUM

The AI Investment Committee. Agentic decision intelligence for emerging discretionary fund managers.

Product
Committee How it works Challenge My Thesis Features Pricing
Get started
Request a demo Start free trial
Legal
Privacy Policy Terms of Service Security
© 2026 QUORUM · The AI Investment Committee
QUORUM, Inc.
Request a demo

See QUORUM on your workflow.

A working session: bring a thesis, we'll walk it through QUORUM live.

By submitting, you agree to our Privacy Policy. We'll never sell your data.

One more step.

Your details are in. Pick a time that works for you and we'll meet there.

Pick a time

Calendar not loading? Email us and we'll find a time manually.