Home/Legal

Privacy Policy

Last updated October 1, 2026

This Privacy Policy explains how Magentic Studio ("we", "us", or "our") collects, uses, and protects personal data when you use Qoren, our managed agent hosting platform at qoren.sh. We act as the data controller for the personal data described here.

Where you use Qoren to process personal data through your agents, you are the controller of that data and we act as your processor, as described under Data processed on your behalf below.

1. Information we collect

We collect the following categories of information:

  • Account information: your name, email address, password or authentication identifiers, and organization details.
  • Billing information: subscription plan, transaction history, and billing details. Card and payment data are handled by our payment processor, Polar, and we do not store full card numbers.
  • Agent configuration and secrets: the agent settings, prompts, files, and credentials you store so your agents can run. We treat stored secrets as confidential.
  • Usage and operational data: logs, activity, model and resource usage, diagnostics, and metrics generated as your agents run and as you use the dashboard.
  • Device and analytics data: IP address, browser and device information, and product analytics events collected to understand and improve the service.
  • Communications: messages you send us, including support requests and waitlist sign-ups.
  • Demo requests: the answers you give on our demo page (your name, email, company, what you want your agents to do and how you want to get started), and the details of any call you book, including its time and whether a session was paid.
  • Site assistant chats: when you use the Ask Qoren assistant on our website, the messages you send and the replies you receive, the page you started from, a random visitor ID stored in your browser, your approximate country, and a hashed form of your IP address that changes every day, so we never store the address itself. If you ask to be contacted, the email, name and note you give are stored as a demo request.

2. How we use information

We use the information we collect to:

  • Provide, operate, and maintain Qoren and your agents.
  • Process payments and manage subscriptions.
  • Monitor, secure, and troubleshoot the service and prevent abuse.
  • Communicate with you about your account, changes, and support.
  • Understand usage and improve features and reliability.
  • Comply with legal obligations and enforce our Terms.

3. Legal bases for processing

Where the GDPR applies, we rely on the following legal bases:

  • Performance of a contract, to provide the service you sign up for.
  • Our legitimate interests, such as securing the service, preventing abuse, and improving the product, balanced against your rights.
  • Legal obligation, for example to meet accounting and tax requirements.
  • Consent, where required, for example for certain analytics or marketing. You can withdraw consent at any time.

4. How we share information

We do not sell your personal data. We share it only as needed to run the service:

  • Service providers (subprocessors) that host infrastructure, process payments, send email, and provide analytics, under contracts that require appropriate protection.
  • Model providers and runtimes you connect or use, which receive the inputs your agents send them in order to return outputs.
  • AI providers for the site assistant: your assistant chats are sent to OpenRouter and the model providers it routes them to so they can be answered. On free models, those providers may use the chats to improve their models, which is why the assistant asks you not to share personal data.
  • Legal and safety reasons, where disclosure is required by law or necessary to protect rights, safety, or the integrity of the service.
  • Business transfers, if we are involved in a merger, acquisition, or sale of assets, subject to this Policy.

5. Subprocessors

We use a limited set of subprocessors to operate Qoren, which currently include cloud infrastructure providers that host agent environments, Polar for payment processing, PostHog and Google Analytics for product analytics, Reddit for advertising measurement, an email provider for transactional and waitlist email, Cal.com (its EU instance, cal.eu) for scheduling demo calls and setup sessions, together with the payment provider connected to it for paid sessions, Cloudflare Turnstile to check that site assistant conversations come from a real browser, and OpenRouter together with the model providers it routes to (for example Qwen, DeepSeek and Z.ai models) to answer site assistant chats. Free models' providers may use those chats to improve their models. We may update this list as the service evolves.

6. Data retention

We keep personal data for as long as your account is active and as needed to provide the service, and afterward only as required to meet legal, accounting, security, or dispute-resolution needs. You can delete agents and content from the dashboard, and we delete or anonymize data within a reasonable period once it is no longer needed. Site assistant chats, with their visitor ID and IP hash, are deleted automatically after 30 days; a contact request made through the assistant is kept as a demo request, with a short excerpt of the chat that led to it.

7. Security

We use technical and organizational measures designed to protect personal data, including isolation between agent environments, access controls, and encryption in transit. No system is completely secure, so we cannot guarantee absolute security. Use least-privilege credentials for your agents and rotate secrets you no longer need.

8. International transfers

We are based in Portugal and may process data in countries outside your own, including through subprocessors. Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

9. Your rights

Depending on your location, you may have the right to access, correct, delete, or export your personal data, to restrict or object to certain processing, and to withdraw consent. To exercise these rights, contact us at hello@qoren.sh. If you are in the European Economic Area, you also have the right to lodge a complaint with a supervisory authority; in Portugal this is the Comissao Nacional de Protecao de Dados (CNPD).

10. Cookies and analytics

We use cookies and similar technologies for authentication, to remember preferences, and for product analytics through PostHog and Google Analytics. On our website we also use the Reddit pixel to measure whether our Reddit ads lead to visits, sign-ups, and purchases; Reddit receives the page visited and, when you submit a form or sign up, your email address in hashed form. Google Analytics and the Reddit pixel only set cookies after you accept them in our cookie banner, and you can change that choice at any time through the Cookie settings link in the site footer. You can control cookies through your browser settings, though some features may not work without them.

11. Data processed on your behalf

When your agents process personal data that belongs to your end users, you are the controller and we act as your processor. We process that data according to your instructions and the service configuration, and you are responsible for having a lawful basis and appropriate notices for that processing. Contact us if you require a data processing agreement.

12. Children

Qoren is not intended for anyone under 18, and we do not knowingly collect personal data from children.

13. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated version here and revise the date below, and for material changes we will provide additional notice where appropriate.

14. Contact

For privacy questions or requests, contact us at hello@qoren.sh.