security privacy

Where your data is stored

EU-hosted. Encrypted credentials. Per-organisation isolation.

Primary storage

  • Database, authentication and files: Supabase, in the EU (Stockholm, Sweden). Your data is isolated per organisation with row-level security; other accounts cannot see it.
  • Application servers: Vercel, in the EU (Frankfurt, Germany).
  • Background jobs (research, writing, publishing, exports): Railway, in the EU (Amsterdam, Netherlands).
  • Files (uploaded images, data exports): same Supabase project, with signed URLs that expire.

Connector credentials

Your CMS credentials (WordPress, Shopify, Webflow, Wix, Ghost, HubSpot, Sanity and Framer) and Google Search Console tokens are encrypted at rest with AES-256-GCM. Each value gets its own random nonce and authentication tag, so a tampered record fails to decrypt instead of decrypting to garbage. The master key lives only in the server environment, is versioned, and has a documented rotation procedure that re-encrypts every stored value with the new key.

Credentials are decrypted only on the server, when Quibo talks to your CMS. They are never returned to the browser, never written to logs or error reports, and never included in data exports.

What leaves the EU

Some processing happens through providers in the US under Standard Contractual Clauses (SCCs):

  • AI generation (Anthropic, with OpenRouter as an LLM gateway): prompts, brand profile, article drafts.
  • Web research and keyword data (Exa, DataForSEO, Firecrawl): keywords and the pages we read for you.
  • Image generation (fal.ai): image prompts.
  • Job orchestration (Inngest): job metadata and step payloads while a job runs.
  • Transactional email (Resend): your email address and the messages we send you.
  • Payments (Stripe) and, for AppSumo customers, license activation (AppSumo).
  • Search Console (Google): only for sites you connect.

The full list, with regions and safeguards, is on the security page. Error monitoring (Sentry), rate limiting (Upstash) and cookieless analytics (Litlyx) stay in the EU.

What we never do

  • Sell or share your data with advertisers.
  • Train any model on your content.
  • Read your content for any purpose other than running the service.

Data minimisation

We collect only what we need:

  • Email and (optional) full name at signup
  • Site credentials at connection
  • Keywords, articles, and brand profiles you create
  • Audit log entries (login, write actions, deletions), with IP address and user agent scrubbed after 30 days

Anything else is opt-in. See the Privacy Policy for the full breakdown.

Retention

  • Articles: unpublished drafts (ready, failed, abandoned) are deleted 14 days after generation. Published articles keep a slim row for as long as your account exists (title, slug, URL, keyword, social and meta copy, Search Console stats, provenance and the approval trail); their body, FAQ and structured data are removed 30 days after publishing, because the live copy lives on your CMS. Framer sites are the exception: Quibo is the source of their feed, so their articles stay complete.
  • Audit log: IP address and user agent for 30 days; anonymised entries for three years, then deleted by a daily job.
  • Data exports: the signed download link lasts 24 hours (a fresh link can be issued from Settings, Privacy & data); the export file itself is deleted 7 days after it is ready and the request then shows as expired. It is also removed when the organization is deleted.
  • Everything else: until you delete it, or until your account is deleted (see How to delete your account).