Privacy

Last updated 11 August 2026

The short version

Quokka reads work email, calendar entries and call transcripts for the people your company connects, and uses them to rebuild your sales pipeline. It does not read personal mail. It does not sell anything to anyone. If you ask us to erase somebody, we destroy the key their data is locked with, and it becomes permanently unreadable.

Who is responsible for what

Your company decides what Quokka reads and who is connected. In data protection terms your company is the controller and Quokka is the processor: we handle the data on your instructions and for no other purpose.

What we read

  • Work email from connected accounts
  • Calendar entries: title, time, who was invited, who joined
  • Call transcripts, where a transcript tool is connected. We never record calls ourselves.
  • Your CRM, read-only, if you connect one

What we never read

Personal, medical, financial and job-related messages are excluded from the sender and the subject line alone, before the message is opened. Their contents are never stored and never sent to any model.

What we store

  • Message contents, encrypted with a key belonging to that one person
  • Facts drawn from those messages, each linked to the message that proves it
  • A log of every read, answer and action taken in the product
  • Your name, work email address, and which company you belong to

Artificial intelligence

Message text is sent to Anthropic’s API to extract facts from it. Roughly eight in ten messages are discarded by ordinary code first and never reach it. Your data is not used to train anyone’s models. Quarantined personal mail is never sent.

Who else sees it

Inside your company: a manager can see deals and results by owner. Nobody can see hours worked, response times, activity counts, or the contents of a personal message. The product does not record them.

Outside your company: our hosting and database providers, and Anthropic for the extraction step described above. Nobody else. We do not sell data, and there are no advertising or analytics trackers on this site or in the product.

How long we keep it

For as long as your company is a customer, and 30 days after that, after which keys are destroyed. Sign-in attempt records are deleted after 24 hours.

Somebody leaving

Your administrator can remove a person’s access at any time. They can no longer sign in and nothing new is read from their accounts. Work correspondence they already sent about your deals stays readable to your team, because it is your company’s record and whoever inherits those deals needs it.

Erasing somebody

A separate and deliberate step, for a genuine erasure request. We destroy their key. Their messages become permanently unreadable, in the live database and in every backup, for everyone including us. What survives is the audit log and a fingerprint of each message: enough to prove a record existed, not enough to read it. Your administrator is shown, before confirming, that this also removes your own history of those deals.

Your rights

If you are in the UK or the EU you have the right to see what we hold about you, correct it, or have it erased. Ask your company’s administrator, or email us and we will route it to them.

Contact

info@askquokka.com