← Back

Privacy Policy

Effective Date: 08-10-2026

1. Eligibility

QuoteChecker.ai is offered exclusively to individuals who: (i) are at least 18 years old, and (ii) are located in one of the countries where we offer the Service. If you do not meet both conditions, do not use the Service. Features vary by country — medical bill audits are available only in the United States.

New subscriptions include a 14-day refund window. If you are not satisfied during your first 14 days, email contact@quotechecker.ai and we will refund your first payment in full.

2. Information We Collect

Category Specific Data Purpose
Information you provide • Uploaded quotes (text or files)
• Region selection
• Contractor or company name (optional)
• Tone or delivery preferences
• Account credentials (email, account identifier)
Operate the audit and messaging features and personalize your experience
Information collected automatically (minimized) • IP address and basic device information (browser, operating system)
• Anonymous, cookie-free analytics
Security, abuse prevention, and service diagnostics
Information generated by the service • Audit results and transparency scores
• Per-line metro-benchmark comparisons
Display results and let you save or compare audits
Contact form submissions • Name (optional), email, topic, and message
• Your account identity and email if you are signed in when submitting
• Coarse request metadata (IP, browser, timestamp) appended to the notification
Deliver your message to our support inbox, route replies back to you, and investigate abuse of the form
Consent-based marketing (after a free audit) • Email address, vertical (contractor / auto / solar / medical), and your express consent to receive marketing communications
• Consent, unsubscribe, and deletion-request timestamps
Send the one-off audit copy you requested; send consent-based marketing communications you opted into; honor one-click unsubscribe and deletion
Creator / affiliate program • Applicant name, email, channel URL, requested slug, and consent to the Creator Program Terms
• Application-review outcome and reason
• Payout account identifiers when approved
• Per-commission records (invoice, subscription, plan, amounts, status)
Evaluate applications, provision the creator landing page, attribute referrals, and calculate and pay monthly commissions
Wall of Shame submissions • Quoted price, benchmark price, metro, audit type, category, and an optional one-line comment
• A one-way hash of your IP (never the raw IP) used to deduplicate votes and reports
• Anonymous up/down votes and anonymous reports
Display the community overcharge signal with moderated comments; prevent ballot-stuffing and abuse
Internal operator access (authorized personnel only) • Limited records of access to administrative tools used to operate the Service, retained for security and audit purposes Investigate abuse of administrative tools. This information is not visible to customers or the public.
Your household and its projects (Pro) • The things you tell us you own — a property (address, postal code, description, year built, size), a vehicle (year, make, model, mileage), or a medical lane — and any notes you add to them
• Jobs you create against them: name, category, postal code, and your notes
• Files you upload to a job (photographs, PDFs, floor plans), the text extracted from them, and which page each extracted fact came from
• The scope of work and contractor questions Quotey composes with you, kept as versions so a scope a bid was given against is not overwritten
• Which saved audits you have filed as bids on which job
Keep one durable record of a project so you can leave and return to it, compare bids against the same scope, and let Quotey answer from what you have already given it rather than asking again. You can edit or delete any of it, and deleting an asset unfiles its jobs rather than destroying them.
Your conversations with Quotey (Pro) • The messages you and Quotey exchange, and a rolling summary of older turns
• A record of each action Quotey took on your behalf — which tool, against which job, and a bounded receipt of the outcome
• A record of longer background work (deep research, concept generation): what was requested, its status, and when it finished
Continue a project across sessions, show you what was actually done rather than only what was said, and let you stop or revisit work in progress. Deleting your account deletes all of it.
Browser notifications (Pro, optional) • If you turn them on: the push endpoint your browser issues and the keys needed to encrypt a message to it — a device-issued address, not an identifier we create
• Nothing is sent unless you enable it, and turning it off deletes the record
Tell you when background work you started has finished, so you do not have to keep the page open
Read-only audit share links (Pro) • A randomly generated link associated with a specific saved audit
• Your account identity as the owner, an optional note, an expiration time, a revoked flag, view count, and last-viewed timestamp
• Recipients are not asked for any data — they simply load the link you sent them
Let you send a read-only copy of a saved audit to another person without requiring them to have an account; let you revoke, expire, and review the link's history
Peer-to-peer referrals (Pro) • A personal referral link tied to your account
• A short-lived attribution cookie placed in your friend's browser when they click the link, so the discount can be applied at checkout
• A record of each successful referral (parties, subscription identifiers, reward status), retained until both sides have been rewarded or the attribution window has closed; limited fraud signals retained for up to 90 days to review challenged rewards
Apply your friend's first-month discount, credit your reward after the 14-day refund window closes, prevent self-referrals and abuse, and audit challenged rewards
Security and abuse-prevention state • Rate-limit counters, session and request-validation cookies, and other transient signals used to deter abuse Stop brute-force attempts, prevent duplicate submissions, and deter automated scanners
We do not use marketing pixels, behavioral advertising, or cross-site tracking.

3. How We Use Your Information

We never sell or rent your personal data.

4. Data Storage & Retention

Data TypeStorageRetention Period
Audit results & account detailsEncrypted storage in U.S. regionsUntil you delete them or close your account
Account-deletion record (billing/legal defense packet: email, account & Stripe identifiers, plan, terms-acceptance time, usage counts, and any dispute metadata)Encrypted storage; the linked Stripe customer reference is also retainedRetained up to 540 days after you delete your account to handle chargebacks, fraud, and billing/legal claims, then purged automatically
Medical bill audits (free tier)Processed entirely in memory; never written to our databaseSeconds (purged when the response is sent)
Medical bill audits (Pro tier)Authenticated, user-owned audit. We store only the sanitized result (summary, flagged items, line items, score) in your history — never the raw bill text. While Deep Analysis research runs, the raw bill text is held in restricted, temporary job storage; it never enters our provider cache, provenance preimages, training data, admin displays, or general analyticsSanitized audit results are retained until you delete them. The raw bill text is purged when the research job completes or fails, and in all cases no later than a hard expiration deadline (24 hours after submission) — even if the job never finishes
Clarification messagesGenerated on demand; not stored after deliveryN/A
Uploaded filesProcessed in memory for text extraction; not retained as filesMinutes
Inputs and outputs sent to AI providersU.S.-based AI providersUp to 30 days where the provider retains content solely to detect and prevent abuse
Contact-form submissionsDelivered to our support inbox; the message body is not retained in our own databaseGoverned by our email provider's retention; you may request deletion of any message we retain
Consent-based marketing listEncrypted storageUntil you click the unsubscribe or deletion link in any message we send, or the consent-based marketing series concludes
Creator applicant and commission recordsEncrypted storageRetained while you are an active creator plus 7 years after program exit for tax, clawback, and 1099 purposes (IRS standard). Payment records are also retained by our payment processor.
Wall of Shame published entriesEncrypted storageRetained while the entry is public. Suppressed entries remain stored but hidden for audit; you may request removal through the report link on the entry.
Anonymous vote and report records (Wall of Shame)Encrypted storage; only one-way hashes of identifiers are keptRetained for abuse-pattern analysis; no raw IPs stored
Internal access logEncrypted storage, restricted to authorized personnelUp to 365 days, then eligible for deletion. Shared with law enforcement only in response to a lawful request, or preserved longer as evidence in a security investigation.
Read-only audit share linksEncrypted storage; the link itself is the access credentialUntil you revoke the link or its chosen expiration elapses (default 30 days, maximum 365 days). Revoked or expired records are retained for at least 90 days for audit and abuse investigation, then eligible for deletion. Deleting the underlying audit revokes every link pointing at it.
Rate-limit and security telemetryEncrypted storageRolling windows (minutes to hours); automatically purged
Cookie-banner dismissalYour browser's local storage — never sent to our serversUntil you clear your browser storage

What account deletion does — and doesn't — remove. Deleting your QuoteChecker product account immediately removes your account-linked product data: audits, country and consent preferences, Deep Analysis research jobs and per-axis scores, API keys, webhook configurations and delivery logs, medical case files and authorization records, referral records, and marketing captures. Two categories are retained separately, as shown in the table above — a minimal billing/legal dispute record for up to 540 days, and, if you participate in the Creator Program, creator applicant and commission records for tax and payout obligations. De-identified benchmark statistics that no longer identify you may also remain.

Back-ups are encrypted at rest and destroyed on a rolling schedule.

We do not retain uploaded PDFs or images. Files are processed in memory to extract text, then erased. No copies are written to durable storage and uploaded files are never used to train any model.

Where AI providers retain inputs or outputs to detect and prevent abuse, that data is excluded from model training and is purged automatically after the retention window. If a provider's retention policy changes materially, we will update this Policy and notify you where feasible.

5. Service Providers

We engage vetted, U.S.-focused providers in the following categories to operate the Service:

Each provider accesses personal information solely to perform the service it provides to us and is bound by written terms requiring it to meet or exceed our security and confidentiality standards. We will provide a current list of subprocessors upon request and will give advance notice of material changes where feasible.

Enterprise customers may request a data processing addendum (DPA) subject to legal review.

6. Use of AI

QuoteChecker.ai submits your text to trusted AI engines to generate analyses and summaries. We configure these requests so the provider does not keep your request as retained response state; providers may nonetheless retain inputs and outputs for up to 30 days solely to detect and prevent abuse, as required by their safeguards.

Any retained model outputs are excluded from training and are automatically purged after the retention window. We do not allow AI partners to use your content to improve their models.

Deep Analysis (Pro). When you turn the Deep Analysis toggle ON for a Pro audit, we run additional vertical-specific research and score the result with an independent model panel. The research is performed by the AI through a web-search-and-extract pipeline — we do not connect to or sell your data to any third-party data broker, and every fact we surface carries the source we read it from. When Deep Analysis is OFF, no research job is created and no enrichment is produced. The same applies whether you paste a quote or upload a file.

Outputs are informative; confirm them before relying on them.

6a. Billing-Advocacy Model

QuoteChecker is flat-fee billing advocacy ($10/month). We help you understand a quote or bill and, for medical bills, draft documents you send yourself (for example, a financial-assistance application or an overcharge appeal). We do not negotiate on your behalf, we do not act as your agent, and we never take a percentage of any savings, assistance, or correction — you keep 100% of it. We are not a debt-settlement, debt-adjustment, or debt-relief service.

7. Your Rights & Controls

At any time, you may:

  1. Access the data stored in your account
  2. Export audits in a portable format
  3. Delete your QuoteChecker product account, which erases your associated product data — including individual audits, or your whole account, from Settings. A minimal billing/legal dispute record is retained for up to 540 days (see §4), and Creator Program financial records are governed separately (see §4).

Self-service controls are under Settings. For additional requests, contact support. We aim to acknowledge privacy requests within two U.S. business days and complete them promptly, subject to verifying your identity and legal requirements.

8. Your California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act of 2018 (as amended by the California Privacy Rights Act of 2020) gives you specific rights regarding personal information we collect. This section describes those rights and how to exercise them; the categories and purposes referenced below correspond to §§2 and 3 above.

Categories of personal information we have collected in the preceding 12 months

Sources and purposes

We collect personal information directly from you (account sign-up, quote submissions, contact-form messages, creator-program applications, Wall of Shame entries) and automatically through your interactions with the Service (IP address, browser metadata, rate-limit counters). We use each category solely for the business purposes described in §3: delivering audits, securing the platform, processing payments, supporting you, and investigating abuse of administrative tools. We do not use personal information for marketing or targeted advertising.

“Sale” and “Sharing” disclosure

We do not sell or share personal information as those terms are defined by the CCPA / CPRA. Specifically:

Because we do not sell or share, we do not need to honor Global Privacy Control signals as an opt-out — there is nothing to opt out of — but we respect them as a signal of privacy preference and will not change that posture without updating this section.

Your CCPA rights

As a California resident, you may request that we:

  1. Disclose the specific pieces and categories of personal information we have collected about you, the sources, the business purposes, and the categories of third parties with whom we shared it (the “right to know”).
  2. Correct inaccurate personal information we maintain about you.
  3. Delete personal information we hold about you, subject to the exceptions in Cal. Civ. Code § 1798.105(d) (e.g., completing a transaction, detecting security incidents, complying with a legal obligation such as 7-year 1099 retention for Creator Program payouts).
  4. Port your data in a portable, readily usable format. Our audit-history export (Settings → Export) covers the largest data set; additional categories are available by request.
  5. Limit use of sensitive personal information — not applicable to us, because we do not collect any. See the categories list above.
  6. Opt out of sale or sharing — not applicable to us, as stated above. This section serves as our “Do Not Sell or Share My Personal Information” notice in lieu of a dedicated link.
  7. Be free from retaliation for exercising any of these rights. We will not deny service, charge different prices, or provide a different level of quality because you exercised a CCPA right.

How to exercise your rights

Email contact@quotechecker.ai with the subject line “CCPA request” and describe which right you are exercising. To prevent impersonation, we will verify your identity before fulfilling any non-trivial request — typically by confirming control of the email address on your QuoteChecker account. We will respond within 45 days (extendable once by 45 additional days with notice, per Cal. Civ. Code § 1798.130(a)(2)).

Authorized agents acting on your behalf must provide (a) your written permission, signed by you, and (b) proof of the agent’s identity. We may still require you to verify your identity directly with us before we act.

“Shine the Light” (Cal. Civ. Code § 1798.83)

California residents who have an account with us may request once per calendar year information about any personal information we shared with third parties for those third parties’ own direct-marketing purposes. We did not share personal information for third-party direct-marketing purposes in the preceding calendar year, and we have no intention of doing so. Send any “Shine the Light” request to the address above.

Notice of financial incentive

We do not offer financial incentives or price differences in exchange for personal information.

8a. EU & UK Users (GDPR / UK GDPR)

If you are in the European Economic Area or the United Kingdom, we process your personal data as a controller under the EU General Data Protection Regulation (GDPR) or UK GDPR. Our lawful bases are: performance of a contract (Art. 6(1)(b) — delivering the audits, account features, and subscriptions you request) and legitimate interests (Art. 6(1)(f) — securing the platform, preventing fraud and abuse, and maintaining minimal cookie-free analytics); we rely on consent (Art. 6(1)(a)) only for optional communications such as the post-audit email course, and you may withdraw it at any time via the unsubscribe link in any message. We do not sell personal data, we do not profile you for marketing, and free audits are processed ephemerally as described in §4. Your personal data is processed on infrastructure in the United States; those international transfers rest on the European Commission's Standard Contractual Clauses (and the UK Addendum / International Data Transfer Agreement, as applicable) in our contracts with service providers.

You have the right to:

Exercise any of these rights by emailing contact@quotechecker.ai; we will verify your identity and respond within one month.

8b. Canada (PIPEDA)

If you are in Canada, we handle your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and its fair-information principles: we collect only what the Service needs, use it only for the purposes described in §§2–3, and obtain your consent for anything beyond them (the email course is strictly opt-in). Your personal information is processed and stored in the United States and, while there, is subject to U.S. law; we bind our providers to contractual safeguards comparable to the protections described in this Policy. You may access and correct your personal information, withdraw consent (subject to legal or contractual restrictions), and challenge our compliance by contacting contact@quotechecker.ai; if you are unsatisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada.

8c. Australia (Privacy Act 1988)

If you are in Australia, we aim to handle your personal information consistently with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). Consistent with APP 8 (cross-border disclosure): by using the Service you should know that your personal information is disclosed to overseas recipients — our infrastructure and service providers are located in the United States — and we take reasonable steps, through the contractual and security safeguards described in this Policy, to ensure those recipients handle it in a manner consistent with the APPs. We do not sell personal information or use it for direct marketing. You may request access to and correction of your personal information (self-service under Settings, or by email), and you may complain to us at contact@quotechecker.ai; if we do not resolve your complaint, you may escalate it to the Office of the Australian Information Commissioner (OAIC).

8d. India (Digital Personal Data Protection Act, 2023)

If you are in India, we process your digital personal data as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act). The Act and its 2025 Rules are being brought into force in phases, with the main Data-Principal-rights and Data-Fiduciary-obligation provisions expected to become operative around 2027; we already apply the protections described here rather than waiting for each provision's effective date. We process your data only for the purposes described in this Policy: with your consent (given when you create an account, submit a quote, or opt into the email course) or for legitimate uses recognised by the Act, such as processing you voluntarily initiate. Your data is processed on infrastructure in the United States under the contractual safeguards described in §5. As a Data Principal you may: access a summary of the personal data we process about you; request correction and erasure (full account deletion is self-service under Settings); withdraw consent as easily as you gave it — one click on any email we send unsubscribes or deletes you from that list; nominate another individual to exercise these rights on your behalf; and raise grievances with us at contact@quotechecker.ai, which we will address promptly. If you remain unsatisfied, you may approach the Data Protection Board of India.

8e. New Zealand (Privacy Act 2020)

If you are in New Zealand, we handle your personal information consistently with the Information Privacy Principles (IPPs) in the Privacy Act 2020: we collect it directly from you, only for the purposes described in §§2–3, and we do not use or disclose it for anything else. Consistent with IPP 12 (disclosure outside New Zealand): your personal information is processed on infrastructure in the United States, and we take reasonable steps — the contractual and security safeguards described in this Policy — to ensure it is subject to comparable privacy protections while there. You may request access to and correction of your personal information (self-service under Settings, or by email to contact@quotechecker.ai), and if you believe we have interfered with your privacy you may complain to us first and then to the Office of the Privacy Commissioner (OPC).

9. Security Measures

We apply commercially reasonable administrative, technical, and organizational safeguards to protect personal information from unauthorized access, disclosure, alteration, or destruction. These safeguards include:

No system can guarantee absolute security. We continue to strengthen our safeguards as the Service evolves.

Security researchers may report potential issues to contact@quotechecker.ai; we commit to timely review and coordinated updates. We are not currently SOC 2 or ISO 27001 certified. We follow aligned controls and will share details with enterprise customers upon request, subject to legal review.

10. Changes to This Policy

Material changes will be posted with an updated effective date. Where required or feasible, we will also notify you through the service or via email. Continued use after the effective date constitutes acceptance of the revised Policy.

11. What Changed

August 2026 (2.5): added country sections for the EU & UK (GDPR / UK GDPR, §8a), Canada (PIPEDA, §8b), Australia (Privacy Act 1988, §8c), India (DPDP Act 2023, §8d), and New Zealand (Privacy Act 2020, §8e); documented cross-border transfer safeguards (Standard Contractual Clauses with the UK Addendum) and named the supervisory authorities you can escalate to. Added the per-vertical data-contribution controls: anonymized price-comparison contributions are off unless you opt in for medical audits, on-with-an-off-switch for trades, and controllable per category from Pro Settings → Data contribution. Pro became a place your projects live rather than a series of one-off audits, and §2 now says so: added disclosure of your household and its projects — the property, vehicle, or medical lane you record, the jobs you create against them, the files you upload and the text extracted from them, the scope and contractor questions Quotey composes with you, and which saved audits you file as bids — and of your conversations with Quotey, including the record of each action it takes on your behalf and of longer background work. Added browser notifications as an optional, off-by-default record, and named browser push delivery in §5. All of it is covered by the export and deletion controls in §7: deleting your account deletes every one of these records, and deleting an asset unfiles its jobs rather than destroying them.

We will note material updates to this Policy in this section after they are made. Enterprise commitments may be offered upon request rather than guaranteed by default.

12. Contact

The data controller responsible for the personal information described in this Policy is QuoteChecker.ai LLC, based in Boise, Idaho, USA. For questions or data requests, email: contact@quotechecker.ai


QuoteChecker.ai provides informational insights only and does not constitute legal or contracting advice. Consult a qualified professional before making binding decisions.