Privacy Policy

Last updated: August 30, 2026

This Privacy Policy is issued by Minders Technology Inc, doing business as Qurio ("Qurio", "we", "us", or "our"). It describes how Qurio collects, uses, discloses, and protects information when you use our services.

1. Introduction

At Qurio, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using Qurio, you agree to the collection and use of information in accordance with this policy.

2. Google User Data — Digital Secretary

When you connect a Google account to Qurio's Digital Secretary feature, Qurio requests two OAuth scopes from Google in a single consent flow:

  • https://www.googleapis.com/auth/gmail.modify
  • https://www.googleapis.com/auth/calendar.events

The sections below describe exactly what data each scope grants, how we use it, and how we protect it. The Limited Use, retention, and revocation terms at the end of this section apply to both scopes.

Gmail Integration

What we access:

  • Message metadata: sender, recipient, subject, date, and Authentication-Results headers, for the purpose of evaluating your configured inbox rules.
  • Message content (bodies and snippets) to determine whether a rule matches, to generate a suggestion, or to extract structured data (such as lead details) that you have configured Digital Secretary to capture.
  • Gmail labels (read and modify), so Digital Secretary can apply the labels and archive actions your rules specify.

What we do NOT access:

  • Sent-mail composition. We do not request gmail.send or gmail.compose and cannot send email on your behalf.
  • Other Google services beyond those listed in this section (Drive, Contacts, Photos, etc.).

Calendar Integration

What we access:

  • Events on your primary calendar, including their titles, dates, times, and locations. Used to surface today's schedule in the Secretary Inbox.
  • Ability to create new events on your primary calendar. Used when you click "Schedule follow-up" on a lead email in the Email Manager.

What we do NOT access:

  • Other calendars beyond your primary calendar.
  • Calendar sharing permissions or the calendar list itself (we do not request calendar.acls or full calendar).
  • Attendee availability, Meet links, or resource bookings.
  • Read or write access to any calendar Qurio did not create the event on. Qurio only reads events on your primary calendar and only creates events you have explicitly asked us to schedule.

How we store and protect Google user data

  • OAuth access and refresh tokens are encrypted at rest using AES-256-GCM with a per-environment key.
  • Gmail message metadata processed by Digital Secretary is stored in our database and retained for 30 days for rule evaluation history, after which it is automatically purged.
  • Full Gmail message bodies are processed in memory and not persisted beyond the duration of the rule evaluation, except where you explicitly instruct Digital Secretary to store a suggestion or extracted data.
  • Calendar event data is fetched on demand for display and is not stored in Qurio's database beyond the request that reads it. When you schedule a follow-up event, the event is created directly on your Google Calendar via Google's API and Qurio stores no local copy of the event once creation succeeds.
  • Access to Google user data within Qurio is limited to the individual user who connected the account and, where applicable, sub-account team members authorized within that user's HighLevel location.

Limited Use disclosure

Qurio's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, and applying equally to both the Gmail and Calendar scopes described above:

  • We do not transfer Google user data to third parties except as necessary to provide or improve the Digital Secretary feature, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
  • We do not use or transfer Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
  • We do not allow humans to read Google user data unless we have obtained your affirmative consent to view specific messages or events, are doing so for security purposes (e.g., investigating abuse), are complying with applicable law, or the data has been aggregated and anonymized for internal operational reporting.
  • We do not use Google user data to develop, improve, or train generalized or general-purpose AI or machine learning models. Where Digital Secretary uses AI to categorize or summarize messages, the AI provider (Anthropic) is contractually prohibited from retaining or training on customer data.

Revoking access and deleting your data

  • You can disconnect your Google account at any time from Digital Secretary → Email Accounts → Disconnect. This immediately revokes Qurio's OAuth tokens and stops any further Gmail and Calendar access. Because Gmail and Calendar share a single OAuth grant, disconnecting removes both.
  • You may also revoke Qurio's access directly at https://myaccount.google.com/permissions.
  • To request deletion of previously-processed Google user data from Qurio's systems, email privacy@qurio.com. We will complete the deletion within 30 days.

Contact

Questions about our handling of Google user data: privacy@qurio.com. Security concerns: security@qurio.com.

3. Information We Collect

Personal Information

When you register for an account, we collect:

  • Name and contact information (email, phone number)
  • Business information (company name, address)
  • Billing and payment information
  • Profile information and preferences

Usage Data

We automatically collect certain information about your device and how you interact with our Service:

  • IP address and browser type
  • Operating system and device information
  • Pages visited and features used
  • Time and date of visits
  • Referring website addresses

SMS and Phone Number Data

If you opt in to receive SMS communications from Qurio, we collect and store your mobile phone number and records of SMS messages sent and received (including timestamps and delivery status). This data is used solely to deliver transactional notifications, appointment reminders, support responses, and document alerts. We do not share your phone number or SMS data with third parties for marketing purposes.

Customer Data

As part of our CRM and marketing services, you may upload information about your customers and contacts. You are responsible for ensuring you have the right to collect and process this information.

4. How We Use Your Information

We use the collected information to:

  • Provide, operate, and maintain our Service
  • Process your transactions and manage your account
  • Send you technical notices and support messages
  • Respond to your comments and questions
  • Analyze usage patterns to improve our Service
  • Detect and prevent fraud and abuse
  • Comply with legal obligations
  • Send marketing communications via email (with your consent). SMS is used strictly for transactional messages and is never used for marketing.
  • Send transactional SMS messages such as document-ready notifications, appointment reminders, and support responses (with your opt-in consent)

5. Data Sharing and Disclosure

We do not sell your personal information. We may share your information with:

  • Service Providers: Third-party companies that help us operate our Service (payment processors, hosting providers, analytics services)
  • Legal Requirements: When required by law, court order, or government request
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • With Your Consent: When you explicitly authorize us to share your information

We do not sell, share, or rent your phone number or SMS consent data to third parties for marketing purposes.

6. Data Security

We implement appropriate technical and organizational measures to protect your information, including:

  • Encryption of data in transit and at rest
  • Regular security assessments and updates
  • Access controls and authentication requirements
  • Employee training on data protection

However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

7. Data Retention

We retain your information for as long as your account is active or as needed to provide you services. We will retain and use your information as necessary to:

  • Comply with legal obligations
  • Resolve disputes
  • Enforce our agreements

Upon account cancellation, we retain your data for 30 days before permanent deletion.

8. Your Rights and Choices

You have the right to:

  • Access: Request a copy of your personal information
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your personal information
  • Portability: Receive your data in a structured, machine-readable format
  • Opt-out: Unsubscribe from marketing communications
  • Object: Object to processing of your information in certain circumstances

To exercise these rights, please contact us at support@qurio.com.

9. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our Service and hold certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent.

10. Third-Party Links

Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.

11. Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us immediately.

12. International Data Transfers

Your information may be transferred to and maintained on servers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ. We take steps to ensure your information is treated securely and in accordance with this Privacy Policy.

13. SMS Communications

If you opt in to receive SMS messages from Qurio, we use your mobile phone number to send transactional messages including document-ready notifications, appointment reminders, and responses to support requests. Your consent to receive SMS is not required as a condition of using the Service.

Message frequency varies based on your activity and requests. Message and data rates may apply. You may opt out at any time by replying STOP to any message. Reply HELP for assistance or contact us at support@qurio.com.

We do not sell, rent, or share your phone number or SMS opt-in data with third parties or affiliates for their own marketing purposes. SMS data collected is retained only for as long as necessary to provide the SMS service and fulfill legal obligations. Supported carriers are not liable for delayed or undelivered messages.

14. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.

15. Contact Us

If you have any questions about this Privacy Policy, please contact us:

Email: support@qurio.com