Skip to main content
Back to home

Privacy Policy

Last updated: September 2, 2026

Scope and our roles

Quad Labs Technologies LLC, 1021 E Lincolnway, 10208, Cheyenne, WY 82001, United States operates the Service under the Annot8 name and is the controller for the independent purposes described below. Quad Labs publishes its company information at quad-labs.com. Contact privacy@annot8.app for privacy matters and legal@annot8.app for formal notices.

This Privacy Policy explains how Quad Labs Technologies LLC (operating as "Annot8," "we," "us," or "our") handles personal data through annot8.app, our dashboard, documentation, public feedback pages, and related services (the "Service").

Annot8 is the controller of account, website, support, security, and billing-related personal data. When an Annot8 customer installs our widget or uses the Service to collect feedback, forms, analytics, recordings, or live-chat messages from its own visitors, that customer normally determines why the data is processed and acts as controller; Annot8 acts as its processor or service provider. Those visitors should also read the customer's privacy notice and direct requests about customer-controlled data to that customer.

This policy does not replace a customer's privacy notice and does not apply to third-party websites or services that a customer connects to Annot8.

Personal data we process

2.1Account and workspace data

  • Name, email address, profile image, authentication identifiers, sign-in provider, and account timestamps
  • Workspace and project names, roles, memberships, invitations, settings, allowed domains, notification preferences, and support requests
  • Billing customer, subscription, order, seat, payment-status, and transaction metadata; payment-card details are handled by our merchant of record and are not stored by Annot8

2.2Customer content and visitor data

  • Annotations, comments, replies, feature requests, questionnaire answers, ratings, live-chat messages, names and email addresses submitted by visitors
  • Screenshots, attachments, voice notes, screen recordings, spoken narration, transcripts, and AI-generated classifications or replies
  • Page path and minimized page URL, page title and external referrer, DOM selector, element text or attributes, click/reproduction steps, and annotation coordinates
  • Browser and device details such as user agent, viewport, language, timezone, color scheme, console errors, failed network request metadata, performance measurements, and Annot8-owned storage-key names

Recordings and free-text fields may incidentally contain personal or sensitive information. Customers and users must avoid capturing passwords, authentication tokens, payment data, health data, or other sensitive information unless they have a lawful, necessary reason and appropriate safeguards.

2.3Consent-gated Analytics

On annot8.app, optional Google Analytics and PostHog measurement starts only after the visitor allows Analytics. It covers minimized page URLs, UTM campaign values, external referrer hostname, intentional product-funnel milestones, web-vitals measurements, and pseudonymous browser or opaque account/workspace/project identifiers needed to connect those steps. We disable advertising signals, PostHog autocapture, and session replay, and do not send form contents, feedback text, email addresses, or full query strings. Customer widget Analytics is separately disabled for new projects and starts only when the customer enables it and its site explicitly signals analytics consent. When active, widget Analytics processes the categories described in the Cookie & Storage Notice. Annot8 does not use these systems for targeted advertising.

2.4Technical and source data

Our hosting, authentication, database, email, and security providers may process IP addresses, request headers, device/browser information, timestamps, diagnostic logs, and cookie identifiers needed to deliver and secure the Service. We also receive data from a customer's selected integrations and from Google or GitHub when a user chooses federated sign-in.

Why we process personal data

  • Contract: create and secure accounts; provide workspaces, feedback, chat, recording, AI, integrations, support, billing, and data export/deletion features; and communicate service notices.
  • Legitimate interests: prevent fraud and abuse, maintain reliability, diagnose faults, improve product usability, support customers, and establish or defend legal claims, balanced against individual rights.
  • Consent: run non-essential analytics or storage technologies, send optional marketing, or process information where consent is the required basis. Consent can be withdrawn without affecting earlier lawful processing.
  • Legal obligations: retain tax and transaction records, respond to lawful requests, protect rights and safety, and comply with data protection, consumer, and accounting requirements.
  • Customer instructions: process customer-controlled widget, feedback, chat, analytics, and integration data under our agreement with the customer.

How we disclose data

We do not sell personal data or share it for cross-context behavioral advertising. We disclose data only as needed to provide the Service, follow customer instructions, or meet legal obligations, including:

  • Authorized members and administrators of the relevant workspace
  • Clerk (identity and authentication), Convex (database, functions, and storage), Vercel (hosting, delivery, AI Gateway, Workflow, and Sandbox), Polar (merchant of record and billing), Resend (transactional email), OpenAI (AI processing through Vercel AI Gateway), and—only after Analytics consent and when configured—Google Analytics and PostHog (acquisition and product measurement)
  • Customer-selected integrations, which may include Slack, Linear, Jira, Asana, Discord, Microsoft Teams, Trello, GitHub, GitLab, email recipients, or customer-provided webhooks
  • Professional advisers, auditors, insurers, authorities, courts, or counterparties where reasonably necessary and legally permitted
  • A buyer, investor, or successor in a merger, financing, reorganization, or asset transfer, subject to appropriate confidentiality and notice where required

Providers may use subprocessors under their own published terms. See the maintained Subprocessors list and request an execution copy of the Data Processing Addendum at privacy@annot8.app.

AI processing

When an AI feature is used, relevant prompts, comments, screenshots, recordings, or chat context are routed through Vercel AI Gateway to OpenAI to generate classifications, summaries, transcripts, suggestions, replies, or proposed code fixes. AI output can be inaccurate and should be reviewed by a person before it is relied on. Annot8 labels AI chat replies and transcripts in the product. We do not use customer content to train our own general-purpose model and request no-prompt-training routing from AI Gateway.

Retention

  • Account and workspace records are kept while the relevant account or customer relationship is active and are deleted or anonymized when the account/workspace is deleted, subject to the exceptions below.
  • Shared workspace content may remain under the workspace customer's control after an individual member deletes an account; the member's account identity is anonymized in those shared records.
  • Consent-based Analytics events and sessions are deleted after no more than 13 months.
  • Origin-validation widget session tokens expire after two hours and expired records are routinely removed.
  • Billing, tax, fraud-prevention, security, dispute, and legal records are retained for the period required or permitted by applicable law and then deleted or anonymized.
  • Backups and provider logs may persist for a limited rolling period before secure deletion. We may retain de-identified statistics that can no longer reasonably identify a person.

International transfers

Annot8 and our providers may process data in countries outside the person's country, including the United States. Where a restricted transfer requires safeguards, the relevant parties use an applicable adequacy decision, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, or another legally recognized mechanism, together with supplementary measures where appropriate. Contact us for information relevant to your transfer.

Security

We use safeguards appropriate to the Service, including encryption in transit, managed authentication, role- and workspace-based access checks, domain allowlists, short-lived origin-validated widget sessions, restricted webhook verification, dependency monitoring, and data minimization. No system is completely secure. Customers are responsible for configuring workspace roles, allowed domains, integrations, and consent controls appropriately and for keeping credentials confidential. Report a suspected vulnerability or incident to security@annot8.app.

Cookies and local storage

We use cookies and browser storage for authentication, security, preferences, widget operation, live chat, and—only after the required signal—Analytics. Details, purposes, durations, and control instructions are in our Cookie & Storage Notice.

Your privacy rights

Depending on location and context, a person may have rights to know or access personal data, correct it, delete it, restrict or object to processing, receive portable data, withdraw consent, opt out of certain uses, appeal a denied request, and not be discriminated against for exercising a right. EEA and UK residents may complain to their local supervisory authority. California and other eligible US residents may use an authorized agent where the law permits.

Signed-in users can download account data or delete their account from Account & privacy. Requests can also be sent to privacy@annot8.app. We may verify identity and authority before acting. For data submitted to a customer's widget or workspace, contact that customer first; we will assist the customer as its processor. Appeals may be sent to the same address with the subject “Privacy appeal.”

Children

The Service is designed for business users and is not directed to children. A person must be at least 18 to create an Annot8 account. Customers must not knowingly use the widget or public forms to collect personal data from children under 16—or under the higher age required locally—without first obtaining Annot8's written approval and implementing all required notices, age assurance, and parental consent. Contact privacy@annot8.app if you believe a child submitted data through our own Service.

Changes and contact

We may update this policy to reflect product, provider, or legal changes. We will post the revised date and provide additional notice when required. Questions, requests, or complaints may be sent to privacy@annot8.app. Security reports may be sent to security@annot8.app. Controller identity: Quad Labs Technologies LLC, 1021 E Lincolnway, 10208, Cheyenne, WY 82001, United States.