Privacy Policy — Quido AI App

Last updated: 30 June 2026 Version: 1.0

This Privacy Policy describes how Quido S.r.l. (hereinafter "Quido", "we", or the "Controller") processes the personal data of users of the Quido AI mobile application for iOS and Android (the "App"). The App is a professional company & financial intelligence tool and is an auxiliary tool of the main Quido platform (app.quido.ai), of which it offers a mobile version of certain features.

Access to the App is not open. It is restricted to client companies that have entered into a contract with Quido (typically organizations operating in the financial sector) and whose organization has been enabled to use the App. Accounts are created and provided by Quido: no self-registration by the user is available. After authentication, a user whose organization is not enabled is blocked and invited to contact Quido.


1. Data Controller

  • Controller: Quido S.r.l.
  • Registered office: Via Giovanni Marradi 1, 20123 Milan (MI), Italy
  • VAT no.: 13490770966
  • Privacy contact: francesco@quido.ai

For any request regarding the processing of your data or the exercise of your rights under applicable law, you may write to the contact address above.


2. What data we collect

2.1 Account and identity data

Accounts are provisioned by Quido on behalf of the client company; the user does not register independently. To access the App you must authenticate through our identity provider Auth0 (Okta). During authentication we process:

  • first and last name;
  • e-mail address;
  • profile picture (if available);
  • the organization identifier (org_id) the user belongs to;
  • technical account identifiers and authentication tokens.

Access and refresh tokens are stored exclusively in the operating system's secure store (iOS Keychain / Android Keystore) and are never stored in clear text by the App.

At login we check whether the user's organization is enabled to use the App. If not, access is blocked: the only data processed in that case is the organization identifier, solely for the purpose of the enablement check.

Providing account data is necessary to use the App: without it you cannot authenticate or access its features.

2.2 User-generated content

While using the App, the user may send the following to our services:

  • search queries about companies and people (search history is stored server-side);
  • favorites (saved lists and items);
  • projects, deals, notes and activities (CRM-type data created by the user);
  • chat messages sent to the "Quido Agent" AI assistant (free text; conversations and message history are stored server-side and, to generate responses, are processed by an external artificial-intelligence provider — see §5);
  • uploaded documents added to the organization's knowledge base;
  • any images attached to searches or messages.

2.3 Voice data (microphone and speech recognition)

If the user uses voice dictation, the App accesses the microphone and uses the device's speech recognition service (Apple Speech Recognition on iOS, Google Speech Recognizer on Android) to convert speech to text. The transcribed text becomes search or chat input. The conversion may involve sending the audio to Apple's or Google's servers according to their respective policies.

2.4 Diagnostics and crash data (Sentry)

To ensure the App's stability and quality we use Sentry for error and crash monitoring. When an error occurs we collect:

  • crash and error reports, stack traces and application logs;
  • technical data about the device and runtime environment, and the IP address from which the report was generated;
  • App version and in-use OTA update metadata (updateId, channel, runtime version).

Before sending, we strip sensitive headers (authorization tokens, cookies) from the reports. Only events of "error" level or higher are sent to Sentry.

2.5 Local on-device preferences

The following non-personal preferences are stored on the device only (not transmitted to our servers): selected language, light/dark theme, and onboarding completion status.

2.6 Technical and operational data

For every call to our backend services we transmit the authentication token and the minimal technical data needed to operate (App version, device locale). We receive over-the-air software updates through Expo Application Services (EAS).

We do not collect: geolocation data, address book/contacts, calendar, advertising data or advertising tracking identifiers. The App does not integrate any third-party analytics or advertising SDK and does not sell personal data.


3. Why we process data and legal bases

PurposeData involvedLegal basis (GDPR)
Authentication and account managementIdentity, tokensPerformance of a contract (Art. 6(1)(b))
Providing the App's features (searches, favorites, CRM, AI chat, documents)User-generated contentPerformance of a contract (Art. 6(1)(b))
Voice dictationAudio/microphone, transcriptionConsent (Art. 6(1)(a)), revocable via system permissions
Stability, security and improvement of the AppDiagnostics and crashesLegitimate interest (Art. 6(1)(f))
Legal complianceData as requiredLegal obligation (Art. 6(1)(c))

4. Device permissions

The App requests the following permissions, only when needed and subject to the user's authorization:

  • Microphone — to dictate searches and messages by voice.
  • Speech recognition (iOS) — to convert speech to text.
  • Photo library — to attach images to searches and messages.
  • Files and documents — to select and upload documents to the organization's knowledge base.

Permissions can be revoked at any time from the operating system settings; some features may be unavailable without them.


5. Parties we share data with (processors)

To provide the service we rely on the following providers, which process data on our behalf as processors:

ProviderPurposeTransfer note
Auth0 (Okta)Authentication and identity managementTenant in the European Union
SentryCrash and error monitoringPossible transfer outside the EU with appropriate safeguards
Expo / EAS (Expo Application Services)OTA software update distributionPossible transfer outside the EU with appropriate safeguards
Apple / GoogleOperating-system speech recognitionSubject to the respective providers' policies
OpenAIProcessing of messages sent to the "Quido Agent" AI assistant (GPT models)Transfer outside the EU (USA) under Standard Contractual Clauses
Quido servers and servicesProcessing of the App's featuresController's infrastructure

We do not share personal data with third parties for marketing purposes and we do not sell it to data brokers.


6. International transfers

Some providers may process data outside the European Economic Area. In such cases transfers are carried out in compliance with the GDPR, on the basis of Standard Contractual Clauses or other appropriate safeguards provided for by applicable law.


7. Data retention

We retain personal data for as long as necessary for the purposes for which it was collected and, in particular:

  • account data and user content: for the entire duration of the contractual relationship between Quido and the client company (typically annual, subject to renewal) and, thereafter, for the time needed to comply with legal obligations or to establish, exercise or defend a legal claim. Upon termination of the contract, the organization's enablement is revoked and the related data is deleted or anonymized within the periods indicated above;
  • diagnostics and crashes: up to 90 days from collection;
  • local preferences: for as long as the App remains installed or until the App's data is cleared.

At the end of the retention periods, data is deleted or anonymized.


8. Your rights

Within the limits set by applicable law, the user has the right to:

  • access their data and obtain a copy of it;
  • request its rectification or update;
  • request its erasure;
  • request restriction of, or object to, the processing;
  • obtain data portability;
  • withdraw consent at any time (e.g. device permissions), without affecting prior processing;
  • lodge a complaint with the supervisory authority (in Italy, the Garante per la protezione dei dati personali).

To exercise your rights you may write to francesco@quido.ai. Since the account is provided by Quido to the client company and access is managed at the organization level, some requests may be handled in coordination with the user's company, which may in turn act as controller or joint controller with respect to its own users' data.


9. Security

We adopt appropriate technical and organizational measures to protect the data, including: encrypted transmission (HTTPS/TLS), token-based authentication with expiry and renewal, storage of tokens in the operating system's secure store, removal of sensitive headers from diagnostic reports, and organization-level access control.


10. Automated decision-making and AI features

The App provides an artificial-intelligence assistant ("Quido Agent") that processes the user's requests to provide answers and analysis. To generate responses, messages are transmitted to OpenAI (GPT models), which processes them as a processor on our behalf. Data sent through the API is not used by OpenAI to train its models.

This feature is informational in nature and does not involve automated decision-making that produces legal effects or similarly significantly affects the user within the meaning of Art. 22 GDPR. Assessments and decisions remain with the user.


11. Children

The App is a professional tool not intended for children under 16 and we do not knowingly collect their data. Should we become aware of any processing of a child's data, we will delete it.


12. Changes to this Policy

We may update this Policy from time to time. In the event of material changes we will provide appropriate notice through the App or our channels. The "Last updated" date at the top of this document indicates the version in force.


13. Contact

For any questions about this Policy or the processing of personal data:

  • Quido S.r.l. — Via Giovanni Marradi 1, 20123 Milan (MI), Italy
  • E-mail: francesco@quido.ai