Back to QuickReports
EN
Deutsch
English

QuickReports Privacy Policy

Last updated: July 2026

1. Controller and scope

JUSA Engineering UG (haftungsbeschränkt)
Münzerstraße 6
74080 Heilbronn
Germany
Managing Director: Julian Sascha Wilken
Email: kontakt@jusa.io
Phone: +49 1523 7286173

This policy applies to the QuickReports apps, QuickReports web access, and the related account, billing, synchronisation, AI, and export features. The general Privacy Policy applies to the public JUSA website.

2. Roles for individuals and organisations

QuickReports can be purchased and used by individuals and organisations. We are generally the controller for account, contract, billing, security, and usage data. Where a customer uses QuickReports in a professional or organisational context and reports, photos, files, voice recordings, or other customer-provided content contains personal data, the customer generally determines the purposes of that processing and we process the content on its documented instructions. Customers and users remain responsible for the required rights and permissions for content they provide.

3. Data we process

  • Account and organisation: email address, internal account and user IDs, authentication status, organisations, workspaces, roles, invitations, and permissions.
  • Report and project data: reports, forms and templates, notes, photos, PDFs and other files, voice recordings and transcripts, annotations, pins, captions, and export settings.
  • Synchronisation and operations: device IDs, changes, synchronisation and deletion status, timestamps, technical error and security data, and the IP address used to access the server.
  • Contract and billing: plan, entitlements, storage and AI usage, transactions, invoice and subscription state, and payment references supplied by Stripe. We do not receive complete card details.
  • Support: the content of your request and, only where required and authorised for handling it, technical information or affected product data.

4. Local-Only mode and device permissions

In Local-Only mode, reports and related files generally remain on the device being used. PowerSync and persistent storage of report and file data in Supabase are not used for that workspace. Local data may, however, be included in device or operating-system backups if you have enabled them.

Camera, photo or file access, and microphone access are used only for a capture, selection, or editing action that you start and remain subject to operating-system permissions. Required data is also processed online from Local-Only mode when you start an AI, transcription, or export feature. Moving data to a synchronised workspace requires an express product confirmation.

5. Synchronised mode

In synchronised mode, account, workspace, permission, report, and file data is stored within the European Union. PowerSync synchronises the data available to each user between the cloud and their devices.

6. Online AI, transcription, and exports

Text improvement, title generation, transcription, and transcript improvement run only at your request. The required text, audio, or transcript is sent to Microsoft Azure OpenAI Service and processed within the European Union.

Microsoft automatically checks content for potential abuse. Flagged content may be temporarily stored within the European Union for human review.

To create DOCX or PDF files, the selected report content and layout settings are processed online. Temporary export files are stored only to make the download available.

7. Billing through Stripe

If you purchase a subscription, additional storage, or AI credits, or open the billing portal, we send the necessary account, plan, and transaction data to Stripe Payments Europe, Limited, Ireland. Stripe processes contact and billing data, payment instrument data, IP address, device information, and fraud-prevention data. Stripe may act as an independent controller for certain legal, regulatory, and security purposes. For more information, see Stripe's Privacy Policy.

8. Purposes and legal bases

  • Providing the account, synchronisation, storage, collaboration, export, AI, and billing features: Article 6(1)(b) GDPR where you are the contracting party, otherwise Article 6(1)(f) GDPR to perform our contract with your business.
  • Authentication, abuse prevention, error analysis, service security, and enforcement of roles, quotas, and deletion states: Article 6(1)(f) GDPR. Our legitimate interest is operating the product securely and reliably.
  • Invoicing and tax or commercial-law records: Article 6(1)(c) GDPR.
  • Where we process customer content as a processor, purposes and legal bases are determined by the respective customer's documented instructions and responsibility.

9. Recipients and infrastructure

  • Supabase: authentication and storage of account, report, and file data.
  • PowerSync / Journey Mobile, Inc. DBA PowerSync: synchronisation of authorised data between the cloud and devices.
  • Fly.io: operation of the QuickReports online services.
  • Microsoft Azure: processing of deliberately initiated AI and transcription requests.
  • Stripe Payments Europe, Limited, Ireland: checkout, subscriptions, invoices, billing portal, payments, and fraud prevention.

The listed services process central QuickReports data within the European Union. We have entered into data processing agreements under Article 28 GDPR with our processors.

Where affiliates or subprocessors process data in third countries, Articles 44 et seq. GDPR apply. Transfers rely in particular on adequacy decisions, including the EU-US Data Privacy Framework, or on the EU Standard Contractual Clauses with supplementary safeguards. More information is available from Supabase, PowerSync, Fly.io, Microsoft, and Stripe.

10. Retention and deletion

  • Local-Only data remains on your device until you remove it in the app or operating system, or by uninstalling the app and deleting its data.
  • Canceling a subscription does not immediately delete the account. Paid or trial access continues until Stripe's authoritative period end. We then retain synchronised product data for a 30-day recovery period. During that period you can resubscribe to restore access or download your data from the account page. When it ends, automated deletion of product data, cloud files, and the sign-in identity begins.
  • An explicit account-deletion request locks access immediately and has a seven-day undo period before permanent deletion begins. Canceling a subscription and deleting an account are separate actions.
  • Minimal deletion markers needed to prevent old or offline clients from restoring deleted records remain for at least 90 days. They do not contain report content.
  • Replaced or deleted source files are deleted 30 days after no active reference remains. Temporary export downloads expire after 24 hours.
  • We retain contract, invoice, security, consent, and abuse-prevention records for as long as required for legal obligations, performance of the contract, or the establishment, exercise, and defence of legal claims. Statutory retention duties remain unaffected.

Deleted data may remain in encrypted backups and with processors until the end of their applicable backup and deletion cycles. We also assess whether third-party rights or statutory retention duties prevent deletion when responding to a request.

11. Your rights

Subject to the GDPR, you have rights including access, rectification, erasure, restriction of processing, data portability, and objection. You may withdraw consent at any time with effect for the future. Where processing relies on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation.

If your request concerns content processed under the responsibility of your employer or another QuickReports customer, please contact that customer first. We will assist the customer in responding. You may also lodge a complaint with a data protection supervisory authority, in particular the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg.

12. Privacy requests and changes

Signed-in users can download an account-level access and portability copy or request account deletion directly from the account page. The download contains authentication, settings, membership, and privacy-history data. Local-Only data is not included because it is not held by JUSA. Organization-workspace content and billing are provided through the organization responsible for that processing.

For rectification, restriction, objection, organization-related, representative, or other exceptional requests, contact kontakt@jusa.io. We may request appropriate proof of identity to prevent unauthorised disclosure.

We update this policy when QuickReports, the providers we use, or legal requirements materially change. The current version is available on this page.