QuixiCloud Privacy Policy
Last Updated: July 10, 2026
Effective Date: May 1, 2026
Our Privacy Principles
At QuixiCloud, we believe that privacy is a fundamental human right. We built our architecture from the ground up to protect your data. Before getting into the legal details, here are our core principles:
- Your files belong to you.
- We never sell your personal information.
- We minimize data collection.
- We encrypt data before storage.
- We secure data during transmission.
- We limit employee access.
- We comply with applicable legal obligations while protecting user privacy.
- We continuously improve our security practices.
1. Introduction
This Privacy Policy explains how QuixiCloud Data Storage Private Limited ("QuixiCloud," "we," "us," or "our") collects, uses, and protects your personal data when you use our web platform, mobile applications, APIs, and associated services (collectively, the "Service").
This policy should be read in conjunction with our Terms and Conditions, Security Policy, and Cookie Policy. By using QuixiCloud, you consent to the data practices described in this document.
2. Information We Collect
To operate the Service reliably, we must collect certain limited data points. We only collect what is strictly necessary to provide and maintain your account:
- Account Information: Name, email address, and authentication credentials (securely hashed).
- Billing Information: Invoicing details, tax identifiers, and payment status (note: actual credit card processing is handled by compliant third-party payment gateways; we do not store full card numbers).
- Device Information: Operating system, app versions, and basic hardware identifiers used solely to manage your active synchronization sessions.
- Login History: Timestamps, IP addresses, and successful/failed authentication attempts to prevent account takeover and fraud.
- Storage Metadata: File sizes, storage quota usage, directory structures, and file modification timestamps to facilitate multi-device synchronization.
- WebDAV Connections: Connection logs strictly for troubleshooting and rate-limiting WebDAV endpoints.
- API Usage: Request volumes and error rates to prevent abuse and enforce Fair Usage limits.
- Support Tickets & Abuse Reports: Correspondence when you contact us for technical support or report violations.
3. Information We DON'T Collect
We are a cloud storage provider, not a data broker. We want to be unequivocally clear about what we do not do:
- We do not sell personal data.
- We do not use advertising trackers on our storage platforms.
- We do not build advertising profiles based on your behavior.
- We do not scan customer files for advertising, marketing, or profiling purposes.
4. File Encryption
QuixiCloud's security architecture is designed so that your stored data remains completely unreadable to unauthorized parties.
Where supported, files are encrypted by the client before upload. For storage policies using Upload Replay, QuixiCloud performs secure streaming encryption before storing encrypted data. Ultimately, our underlying storage providers receive and host encrypted data only.
5. Storage Architecture
QuixiCloud operates a globally distributed, high-availability architecture designed for maximum data integrity:
- Main Infrastructure: Located in secure data centers in India.
- Regional Storage & Replication: Data is actively replicated across multiple geographic zones to prevent data loss in the event of hardware failure.
- Disaster Recovery: We maintain isolated disaster recovery arrays.
- Encryption Integrity: At every layer of our storage architecture, the data remains encrypted. Even if physical hard drives are compromised, the raw data is entirely unreadable.
6. Administrator Access
Administrative access to QuixiCloud infrastructure is strictly limited to authorized personnel for infrastructure management, billing, account administration, security operations, and compliance with applicable law. Administrative actions are logged and subject to rigorous internal controls. Administrators do not have access to your encryption keys and cannot decrypt your files.
7. Security Measures
We employ industry-leading standards to protect the limited personal data we hold and the encrypted files you store:
- TLS (Transport Layer Security): Securing all data in transit.
- AES-256 Encryption: The global standard for data encryption at rest.
- Master Key & Key Rotation: Advanced cryptographic management for internal systems.
- MFA (Multi-Factor Authentication): Available and highly recommended for all users.
- Audit Logs: Continuous monitoring of infrastructure access.
- Rate Limiting & DDoS Protection: Safeguarding our network against malicious traffic.
- Disaster Recovery: Ensuring service continuity.
8. Data Retention & Lifecycle
We adhere to a strict, transparent data retention lifecycle:
- Active Storage: Your data remains active and accessible while your account is in good standing.
- 7-Day Grace Period: Upon expiration or non-renewal of a subscription, your account enters a 7-day grace period.
- Disaster Recovery Backup: If an account is not renewed, active primary storage is deleted. Encrypted disaster recovery backups may persist for up to 30 days purely for infrastructural integrity. (Note: These backups are not recoverable to expired accounts).
- Permanent Deletion: After the 30-day period, all traces of the account's encrypted files are permanently and irretrievably purged from our systems.
9. Cookies
We use essential cookies strictly to manage user sessions and platform security. We do not use third-party tracking cookies for targeted advertising. For detailed information, please review our Cookie Policy.
10. Children's Privacy
QuixiCloud services are strictly limited to individuals who are 18 years of age or older (or the age of legal majority in their jurisdiction). We do not knowingly collect personal data from minors. If we discover that an account has been created by a minor, the account and all associated data will be immediately deleted.
11. International Transfers
QuixiCloud operates globally utilizing infrastructure in India, Singapore, Europe, and the US. By using the Service, you acknowledge that your encrypted data and limited account metadata may be transferred to and processed in these regions. We ensure that all international transfers comply with applicable data protection laws through Standard Contractual Clauses (SCCs) and equivalent legal frameworks.
12. User Rights
Regardless of where you live, QuixiCloud respects your data rights, aligning with both the GDPR (Europe) and the India DPDPA. You have the right to:
- Access the personal metadata we hold about you.
- Request the deletion of your account and all associated data.
- Export your account data.
- Correct inaccurate billing or profile information.
To exercise these rights, please contact our Privacy Officer.
13. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy, please reach out to the appropriate department:
- Privacy Officer / DPO: privacy@quixicloud.com
- Technical Support: support@quixicloud.com
- Security Team: security@quixicloud.com
- Abuse Reporting: abuse@quixicloud.com
QuixiCloud Data Storage Private Limited
10159, Sharada Colony, West of Chord Road 1st Stage,
Basaveshwar Nagar, Bengaluru, Karnataka 560079
INDIA