Privacy

Last updated 15 September 2026

Who operates Quokka

Quokka is operated by Growth Insights Limited, a company incorporated in Hong Kong. Our address is Unit 1603, 16/F, The L. Plaza, 367–375 Queen's Road Central, Sheung Wan, Hong Kong. Contact info@askquokka.com about privacy, account administration or the service.

Your business decides which work accounts and records to connect and why. For that workspace data, your business is the controller and we process it on its instructions under our data processing terms. We separately determine how to use account, support, security and billing information to operate Quokka and meet our own obligations. Where data protection law uses the term, we are the controller for those purposes.

Information we collect and use

Information may come from you, your workspace administrators and colleagues, connected Google services, CRM exports, and people corresponding with those accounts. Company websites you provide may be read to understand what your business sells. This policy also covers people whose information appears in those sources without having a Quokka account.

  • Accounts and access: name, email address, Google identity identifier, company, role, invitations, language, time zone and display preferences. Password sign-in stores a password hash. These records create accounts, authenticate users, enforce workspace access and remember your settings.
  • Connected sources: Google account identifiers, granted permissions, encrypted access and refresh tokens, connection status, sync bookmarks and errors. These let us access authorized sources and keep connections working.
  • Work correspondence: email headers, sender and recipient addresses, dates, subjects and selected message bodies, including meeting notes or transcripts received by email. We do not record calls.
  • Calendar events: event information is retrieved before filtering. Retained external meetings include identifiers, titles, times, external invitees and RSVP outcomes, with links to relevant deals. Internal-only and recognized personal events are filtered out of retained meeting records.
  • Google Drive activity: Quokka retrieves activity metadata and retains daily counts of the connected user's own edits, creations, comments and sharing changes. It does not retain Drive file names, paths, file contents or collaborator identities.
  • Workspace records: uploaded CRM rows and import history, contacts, companies, deal fields, notes, corrections, source references, promises, signals, meeting summaries and saved forecasts. These build and maintain your pipeline. Live CRM connectors are not currently available.
  • Assistance and replies: chat inputs and answers, conversation titles, translated quotes, generated drafts, edits, recipients, approved sent copies and delivery receipts. These support assistance and show what was sent.
  • Security and operations: session records, IP addresses and browser information supplied during sign-in, login attempts, request and error logs, audit events, sync counts, job status and model usage/cost records. These help secure, operate and troubleshoot the service.
  • Support and any future billing: messages you send us and, if you expressly start a paid plan, customer/subscription identifiers, plan, seat count and payment status. Payment details entered into hosted checkout are handled by Stripe.

Google permissions and filtering

Google sign-in requests identity information through openid, email and profile. Connecting work sources is a separate authorization using the permissions below.

Sender and subject rules exclude recognized personal, medical, financial, job-related and irrelevant mail before fetching new message bodies. The rules can make mistakes. A conversation first accepted may later be excluded; its source messages are then blocked from ordinary retrieval for viewing and AI processing. Exclusion does not erase every previously stored record or derived output. Information already copied into profiles, custom fields or other records without a complete source link may remain visible or be used in later assistance until separately reviewed or erased. Contact us to review inappropriate retained information. Only connect accounts you are authorized to process.

  • gmail.readonly: list conversations and read headers, then fetch selected message bodies. Bodies are needed to identify sales facts and support them with source evidence.
  • gmail.send: send a reviewed reply from the connected mailbox only when its owner explicitly approves it. Managers and administrators cannot approve sending from another person's mailbox.
  • calendar.events.readonly: read events in the connected account's primary calendar for meeting context. Older connections may retain the broader calendar.readonly permission; the application still uses them only for this event-reading feature.
  • drive.activity.readonly: read activity metadata and reduce the connected user's own Drive actions to daily counts. Quokka does not request Drive file-content access and does not retain target names or collaborator identities.

AI processing

Selected content is transferred from your connected sources to Quokka and AI service providers. Depending on the feature, this includes message text, source quotes, your questions and recent chat history, deal facts, company profiles and relevant team or pipeline context. We use AI to extract facts, answer questions, assist with requested updates, translate quotes, prepare company profiles and summaries, and draft replies. AI output can be wrong; review its source and any action before relying on it.

We do not use customer content to train AI models or permit our AI service providers to do so. We use privacy settings to limit their retention of content. This does not mean every operational record is deleted or that Quokka erases the workspace information it stores. Our data processing terms explain these providers' functions; current provider identities and details are available from info@askquokka.com before connection or on request.

Who can see workspace information

Workspace permissions and reporting lines determine access. Managers can see deals, results, source receipts and full work correspondence linked to deals owned by people in their reporting subtree; administrators can see the company workspace. Other users see their own records. Your business must explain this access to connected employees and have authority to process the correspondence. Only the connected mailbox owner may approve its outgoing replies.

Quokka does not provide an hours-worked or response-speed productivity score and does not turn Drive activity into a people ranking. It does retain privacy-minimised work-state counts and access records. Filtering reduces personal content; it cannot guarantee that authorized workspace users will never encounter personal information in an accepted message.

Vercel hosts the application, Supabase provides the database, and AI service providers process selected content for the features described above. Their roles are explained in the data processing terms. Stripe handles payments when you choose a paid plan. We may also disclose information where necessary to meet legal obligations or protect the service, subject to the stricter Google-data limits below.

Cookies and technical records

Quokka uses a necessary sign-in cookie, normally valid for up to 30 days, and short-lived cookies of up to ten minutes to secure Google authorization. Sign-out and access revocation can end a session sooner. Blocking these cookies can prevent sign-in or connection. We do not use advertising cookies, pixels or third-party analytics scripts. Necessary hosting/security logs and product activity records are separate from advertising tracking. Google and any hosted payment service apply their own policies on their pages.

Security and retention

Message bodies, chat bodies and cached quote translations use application encryption tied to a person's key. OAuth tokens are also encrypted. Derived facts, contact details, metadata, chat titles, drafts and frozen sent copies are stored separately and are not protected by that same message-body key. Access controls and database protections apply to those records. Our Security page describes the controls and their limits.

Workspace records are retained for the customer's use of the service and its requested business records. When a workspace closes, retention is reviewed against the customer's return or erasure instructions, applicable legal obligations and any necessary dispute or security records. Closure, cancellation and disconnection do not automatically delete the workspace. We agree the handling of retained records with the customer rather than promise an automatic deletion date that the service does not enforce.

Account and support records are retained as needed to administer the relationship and resolve requests. Security, audit and operational records are retained according to their troubleshooting, abuse prevention, accountability and legal needs. Sign-in attempt records are scheduled for removal once older than 24 hours; session expiry ends access and does not mean every historical session record is immediately deleted. Payment records, if any, may need to be kept for accounting and legal obligations.

Backups follow the provider's configured retention. We do not state a universal backup lifetime. Erasure must address separately retained records and backups as well as live data. Our restore procedure requires retained erasure instructions to be reapplied before a restored database is opened for use.

Disconnecting, leaving and erasing

Disconnecting Google stops further syncing; you can also revoke Quokka through your Google Account's connected-app controls. Removing a user revokes their Quokka access. Neither action automatically deletes the work records already kept for the business. Contact your workspace administrator or us to request export, correction or erasure.

Removing a person's live encryption key makes their associated encrypted content unreadable in the live database. It does not by itself erase drafts, sent copies, facts, contacts, metadata, audit records or older backups. Those need separate handling. We explain what can be returned or erased and any records that must remain; your original email in Google is not deleted by a Quokka erasure request.

Locations, legal grounds and your rights

The operator is in Hong Kong and our service providers may process data in other countries. Processing locations and any legally required transfer safeguards must be confirmed for the customer's use. These pages do not themselves execute standard contractual clauses or represent that a particular transfer agreement has been completed. Contact us for the applicable arrangements before connecting data subject to a specific location or transfer requirement.

Where applicable law requires a legal basis, our own account and service administration relies on performing the relevant agreement, our legitimate interests in operating and securing a business service, legal obligations, or consent where required. Your business is responsible for identifying the lawful basis for its workspace data. Google authorization does not by itself establish the legal basis for processing employee or correspondent information.

Depending on applicable law, you may request access, correction, erasure, restriction or portability, object to processing, withdraw consent for future processing, and complain to the relevant privacy regulator. Withdrawal does not affect prior lawful processing. These rights can have exceptions. This includes people named in customer correspondence, not only Quokka users. Contact the business responsible for the workspace or email us; we may verify your identity and route the request to that business. For our own processing, contact us directly. You may also contact the Hong Kong Privacy Commissioner or, where applicable, your local data protection authority.

Changes

We update this page when our practices change and identify its revision date. We will notify affected customers of material changes through the service or their account contact, and obtain additional consent where required before a new use.

Limited Use of Google data

Quokka’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google data for the visible workspace features described here, not advertising, data brokerage, credit decisions or training general-purpose AI models. We do not sell it.

Transfers are limited to providing those features with authorization, necessary security purposes, legal obligations, or a business transfer with the explicit prior consent required by Google. Our personnel may access specific content only with documented permission, where needed to investigate security issues, or where the law requires it. These limits also apply to people and processors acting for us.

Contact and related terms

Contact Growth Insights Limited at info@askquokka.com. Read our data processing terms, security information and terms of service.