Legal
Privacy Policy
How QubitPilot collects, stores and processes your firm's data, including AI processing and the option to use your own cloud storage.
- Last updated
1. Who this policy is about
This Privacy Policy explains how QubitPilot ("QubitPilot", "we", "us", "our") collects, uses, stores and shares information when a law firm, chartered-accountancy practice or other professional services firm ("you", "your firm", "the workspace") and its team members use the QubitPilot application, website and related services (together, the "Service"). It applies to every workspace on QubitPilot, regardless of subscription plan.
QubitPilot is operated by Qubitron Labs, having its registered office at 5th Floor, Gordhan Sky Mall, Office 507, Khatipura Road, Jhotwara, Jaipur, Rajasthan 302012, India ("Company"). If any term in this policy conflicts with the Terms & Conditions, the Terms & Conditions govern the relationship and this policy governs how data is handled.
Two roles are worth separating. For the account and usage information in Section 2, QubitPilot decides why and how it is processed. For the client and matter records your firm puts into its workspace, your firm decides what is collected and why, and QubitPilot processes those records on your firm's behalf to provide the Service — in the terms of the Digital Personal Data Protection Act, 2023, your firm is the Data Fiduciary for that data and QubitPilot its Data Processor. That is why requests about a firm's client data go to the firm first (Section 10).
2. Information we collect
We collect information in three broad categories:
- Account information — the name, email address, phone number and profession (advocate or chartered accountant) of each person who signs up, and the firm/workspace details provided at onboarding (firm name, address, GSTIN, PAN and similar identifiers).
- Practice data you put into the Service — client records, matters/cases, hearing and compliance dates, tasks, notes, documents you upload, WhatsApp conversations you route through the Service, time entries, invoices and payment records, and any other record your firm creates while using QubitPilot.
- Usage and device information — log data, IP address, browser/device type, pages and features used, and diagnostic information generated automatically as you use the Service, together with the small number of cookies described in Section 12.
3. How we use your information
We use the information above to: provide and operate the Service, including the features your plan includes; authenticate you and secure your account; send hearing, task, compliance and billing reminders you have not turned off; process payments and manage your subscription; respond to support requests; detect and prevent abuse, fraud and security incidents; and improve the reliability and usability of the Service. We do not sell your information, and your firm's data is not used to train AI models.
4. Storage of your documents
Documents you upload are stored in one of two places, depending on how your workspace is configured:
- QubitPilot's own file storage — the default. Files are stored on infrastructure we operate or contract with, encrypted at rest, and accessible only to your workspace.
- Your own cloud storage bucket — on plans that offer it, a workspace owner or admin may connect their own Amazon S3, Cloudflare R2 or S3-compatible bucket from Settings. When this is configured, newly uploaded documents are written directly to that bucket instead of QubitPilot's own storage. Your storage credentials are encrypted before we store them and are never shown back to you, or to anyone else, once saved.
Choosing your own storage changes where the file itself sits. It does not change what happens to the file's content once you ask QubitPilot to do something with it — that is covered in the next section, and applies identically whether your documents live in QubitPilot's storage or in a bucket you connected yourself.
5. AI-assisted workflow, search and indexing
Uploaded documents are not only stored passively. Depending on the file and the features in use — and regardless of whether that file lives in QubitPilot's own storage or in a cloud bucket you connected yourself — a document may be:
- parsed so that text can be extracted from it;
- split into smaller passages ("chunks") and indexed so it can be searched;
- converted into numeric representations ("embeddings") held in our database so that relevant passages can be retrieved for search and for AI answers;
- supplied as context to an AI feature when a user asks a question that requires it.
To carry out extraction, embedding, retrieval and AI generation, the relevant content — which can include document text, workspace records and your prompt — is processed by AI and shared with the AI services that power these features, as explained in Section 9. Your storage credentials are never shared with them, and connecting your own bucket does not remove a document from this processing if you use a feature — search, the AI assistant, drafting — that needs it.
What QubitPilot itself keeps. The results of AI features form part of your workspace and are stored in QubitPilot's own database under the same access controls as the rest of your data: assistant conversation history, facts the assistant remembers for your workspace, search indexes and embeddings of your documents, records created or changed through an approved action, and usage and cost logs. Step-by-step logs of assistant and automation runs are kept for 90 days, and the detailed inputs of approval requests are removed 7 days after the request is resolved. None of this is used to train AI models.
People stay in control. By default, actions with real-world consequences — such as creating or changing records or sending messages — wait for approval from a person in your workspace, unless an owner or admin changes your workspace's AI approval settings or allows a specific automation to run without approvals. The WhatsApp assistant only responds to phone numbers your workspace already knows, and client numbers receive read-only answers.
Your professional obligations. Advocates and chartered accountants may owe duties of confidentiality to their clients under the rules of their profession and under the Digital Personal Data Protection Act, 2023. By using the AI features you instruct us to process your workspace data as described in this section and in Section 9. You are responsible for deciding whether that processing is appropriate for a particular client, matter or document, and for obtaining any consent your obligations require.
If you do not want a particular document or record processed this way, do not upload it, or do not use the AI or search features on it. Do not upload content you are not authorised to store or to have processed in this way.
6. Third parties we share information with
We do not sell personal information. We share information with the following categories of service providers, each acting on our instructions and only to the extent needed to provide the Service:
- Payments — Razorpay processes subscription payments and recurring auto-debit mandates. Razorpay receives billing contact details and payment instrument information directly; QubitPilot does not store your card or bank details.
- AI services — the AI that powers the assistant, automations, drafting, search, and document, image and voice understanding receives the content a task needs at the moment that task runs, as described in Section 9.
- Search re-ranking — where re-ranking is enabled for the Service, your search query and the candidate passages are sent to an AI re-ranking service to order the results.
- Web search — when you ask the assistant to search the web or read a web page, the search query or page address is sent to our web search service.
- WhatsApp messaging — if you use the WhatsApp assistant, messages are sent and received through Meta's WhatsApp Business Platform, directly or through an approved WhatsApp business solution provider such as Twilio.
- Calendar sync — if you connect Google Calendar, hearing and task dates are synced with Google under the permissions you grant.
- Push notifications — reminders sent to your phone or browser are delivered through Firebase Cloud Messaging (Google).
- GST, PAN and company verification — GSTIN, PAN and company or director look-ups you ask for are verified through our verification data providers.
- Court data — for firms using court tracking, publicly available case, hearing and order information is retrieved from the eCourts system and other public court data sources.
- Your own cloud storage provider — if you connect your own bucket (Section 4), your document files are stored with that provider (for example Amazon Web Services or Cloudflare) under your own account and their own terms and privacy practices, which we do not control.
- Infrastructure and hosting — the servers, database and email-delivery infrastructure that run the Service.
We may also disclose information where required by law, to enforce our agreements, or to protect the rights, property or safety of QubitPilot, our customers or others.
7. Where your information is processed
QubitPilot is built for Indian practices and its primary infrastructure is operated with that in mind. Some of the third parties listed in Section 6 — including the AI services that power the Service and, if you connect one, your own cloud storage provider — may process or store information on servers located outside India. Where that happens, we require the provider to maintain appropriate safeguards for that information.
8. How long we keep information
We keep your firm's data for as long as your workspace remains active. If a workspace is archived or a subscription lapses, its records are retained in an inactive state for a period to allow reactivation or export, after which they may be permanently deleted in line with our data retention schedule. Logs of AI assistant and automation runs, and the inputs of approval requests, are kept only for the shorter periods set out in Section 5, and the activity log of changes made in your workspace is kept for 12 months. Documents stored in your own connected bucket remain under your control and your provider's own retention settings even after your QubitPilot subscription ends.
9. Data and security
QubitPilot is an AI-assisted service. AI helps run your firm's workflow: the assistant in the app and on WhatsApp, automations your workspace sets up, drafting and summarising, search, reading documents and the voice notes or images sent to the WhatsApp assistant, preparing records for your review, and checking incoming messages for misuse. To do this, your data is processed by AI and shared with the AI services that power these features — only the records a task needs, such as client and matter details, hearing and compliance dates, tasks, notes, invoices, document text and the messages you send, and only at the moment that task runs.
How we protect your data. We restrict access to your firm's data to your own workspace using role-based permissions your firm controls, encrypt storage credentials and sensitive tokens at rest, encrypt traffic to the Service in transit, and keep an activity log of changes made within your workspace. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach affects your workspace, we will inform the workspace owner, and the authorities, as applicable law requires.
10. Your rights
Subject to applicable law, including the Digital Personal Data Protection Act, 2023, you may request access to, correction of, or erasure of your personal information, and you may withdraw consent for a specific processing activity where consent is the basis for it. Because most information in the Service is entered and controlled by your firm — as the party that decides what client and matter data to add — requests relating to your firm's own workspace data should first be directed to your workspace owner or admin. To exercise these rights with QubitPilot directly, contact us using the details in Section 14; we will respond within the time required by law. Where the law provides for it, you may also nominate another person to exercise these rights on your behalf in the event of your death or incapacity, and, if you are not satisfied with how we have handled a grievance, you may complain to the Data Protection Board of India.
11. Children's data
QubitPilot is a professional practice-management tool and is not directed at, or knowingly used by, children. We do not knowingly collect personal information from anyone under 18.
12. Cookies and similar technologies
We use cookies and similar technologies, such as your browser's local storage, to keep you signed in, protect your account and remember your preferences. On our public website we also use analytics cookies to understand how visitors use the site, so that we can improve it. We do not use cookies for advertising within the application. You can manage or delete cookies in your browser settings; blocking essential cookies may stop parts of the Service from working.
13. Changes to this policy
We may update this policy from time to time. If we make a material change, we will notify workspace owners by email or by an in-app notice before the change takes effect. Continued use of the Service after a change takes effect means you accept the updated policy.
14. Contact
Questions about this policy or your data can be sent to info@qubitronlabs.com, or by post to Qubitron Labs, 5th Floor, Gordhan Sky Mall, Office 507, Khatipura Road, Jhotwara, Jaipur, Rajasthan 302012, India.