the boring, necessary part

Privacy policy

quzora holds the most personal things two people own. Here is exactly what happens to them.

effective 20 September 2026 · quzora.com

the short version

  • No ads, no trackers, no analytics. There is not a single third-party tracking script in quzora.
  • We never sell or share your story, and we never use it to train anything.
  • Your story is visible only to the two people in it.
  • Google Photos is import-only: we only ever receive the photos you pick, and we can never write anything back or browse your library.
  • Email support@quzora.com and we will send you a copy of everything, or delete all of it.

1Who we are

quzora is a small, independent product built and run by one person, an individual developer based in India. There is no company behind it, no investors, and no advertising business that needs your data. For anything in this policy, write to support@quzora.com — a person reads it.

2What we collect

Three things, and nothing else.

Your account
When you sign in with Google, we receive your name, your email address and an account identifier from our sign-in provider. We never see or store a password.
What the two of you put in
Your names and nicknames, the dates that matter to you, your memories and the words you write about them, notes, letters, bucket-list wishes, photo captions, and the photos, videos and audio you upload. This is the whole point of the app, and it is yours.
The little that keeps it running
Our host keeps short-lived server logs (IP address, request path, timestamp) to keep the service up and to stop abuse. We do not build profiles from them and we do not have an analytics system of any kind.

3Photos you bring from Google Photos

This is the part people most want to be sure about, so it gets its own clause. If you use the “Google Photos” button:

  • quzora requests exactly one permission — photospicker.mediaitems.readonly — and nothing else.
  • That permission does not let us browse, search or list your library. It lets us receive only the specific items you hand over inside Google’s own picker, in that one session.
  • We copy those files into your quzora story, along with the date each photo was taken, so it hangs on the wall under the right day. From then on they are ordinary quzora photos and this policy covers them like any other.
  • We never write anything back to Google Photos. We cannot create, edit, delete or organise anything in your library, and we never will.
  • Your Google access token is held in a short-lived cookie in your own browser for about an hour and is never written to our database. We do not ask for or keep a refresh token, so our access ends when that hour does.
  • You can revoke quzora’s access at any time at myaccount.google.com/permissions. Photos already copied into your story stay in your story until you delete them.

quzora’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4What we use it for

The complete list:

  • Showing your story to the two of you, and keeping it safe between visits.
  • Sending the reminder emails you set up — anniversaries, birthdays, the day you adopted the plant.
  • Nightly backups, so a bad day for a database is not a bad day for your memories.
  • Answering you when you write to support.
  • Keeping the service up and stopping abuse.

We do not sell your data. We do not share it for anyone else’s marketing. We do not profile you, we do not advertise to you, and we do not use your memories, letters or photos to train machine-learning models — ours or anybody else’s.

5Who can see your story

Only the two people in it. A story is joined with an invite from the person who created it; nobody else can reach it. Your photos and videos are kept in a private bucket and are served to your browser through short-lived signed links, never a public URL.

We will be straight with you about the limit of that promise: running the service means we hold the database and the storage, so an operator technically could look. We do not, as a matter of practice. We look at your content only if you ask us to — for example, when you report something broken and want us to go and see.

6The companies that help run it

quzora is one person, so a handful of services carry the heavy parts. Each one receives only what it needs to do its job, and none of them get your story for their own purposes.

Fly.io
Runs the application server. Singapore region.
Neon
The Postgres database — your words, dates and captions. Singapore region.
Cloudflare R2
Stores your photos, videos and audio, and the nightly database backups. Private buckets.
WorkOS
Handles Google sign-in, so quzora never touches your Google password.
Google
Only if you choose to import photos — the Picker API described above, and Google sign-in through WorkOS.
Resend
Delivers the reminder emails. It sees the email address and the reminder text.

7Cookies, and the lack of them

quzora sets no advertising or analytics cookies, because it has no advertising or analytics.

wos-session
Keeps you signed in. Sealed and http-only, so no script can read it. Cleared when you sign out.
gphotos-token, gphotos-state, gphotos-pick
Set only while you are importing from Google Photos, and only for as long as that takes — minutes, or about an hour for the access token.
Your browser’s own storage
Three small preferences stay on your device and never reach us: your theme, whether you are reading or editing, and how wide you dragged the memory panel.

8Where it lives, and for how long

Your story is stored in Singapore. It stays until you delete it — this is a keepsake, not a feed, so nothing expires on its own.

Backups are taken nightly and kept for 30 days, with one snapshot a month kept longer so a mistake found late can still be undone. When you delete something it goes from the live service immediately, and ages out of the backups on that schedule.

9Your say over all of it

  • Delete any photo, memory, note, letter or wish yourself, inside the app, whenever you like.
  • Ask for a copy of everything you have put in, and we will send it to you. Write to support@quzora.com.
  • Ask us to delete the whole story and the account behind it. Write to support@quzora.com and we will do it within 30 days — in practice, within a few days.
  • Withdraw Google Photos access at myaccount.google.com/permissions.
  • Correct anything wrong — most of it you can simply edit in the app.

Depending on where you live, the law may already give you these rights by name — India’s Digital Personal Data Protection Act, the GDPR in the EU and UK, and similar laws elsewhere. We do not ask which country you are in before honouring a request; write to us and we will do it.

10Keeping it safe

Everything travels over HTTPS. Sign-in cookies are sealed and http-only. Media sits in private storage reachable only through short-lived signed links. Each couple’s data is separated at the database level, and every request is checked against the story it belongs to.

No service can promise perfect security, and we will not pretend otherwise. If something ever goes wrong that affects your data, we will tell you what happened, in plain words, quickly.

11Children

quzora is for adults. You must be 18 or older to use it, and we do not knowingly collect anything from anyone under 18.

12Changes to this policy

If this policy changes, the date at the top changes with it. For anything that materially affects your data, we will email you rather than quietly editing the page.

13Getting hold of us

support@quzora.com — for privacy questions, a copy of your data, deletion, or anything else. One person reads that inbox, and it is the same person who wrote this page.