Privacy Policy
Last updated: June 30, 2026 · Effective: June 30, 2026
QRF (“QRF”, “we”, “us”, “our”) is operated by Delvir Limited Liability Co., a Wyoming limited liability company in the United States. This Privacy Policy explains what information the QRF mobile application and the qrforce.app website collect, how we use and share it, and the choices and rights you have. By using QRF, you agree to this Policy.
1. Information We Collect
QRF is designed to collect as little as possible. We do not require you to provide your email address, phone number, or real identity to use the core service. We collect:
| Data | Why |
|---|---|
| Anonymous device identifier. A random UUID generated on your device at first launch. | To maintain your group membership and route alerts to your device. It is not linked to your real-world identity. |
| Display name (optional). The name you choose to show your group. | So members can recognize who is summoning them. You may use any name or a nickname. |
| Profile photo (optional). Only if you add one. | Shown to members of groups you share. Stored via our image provider. |
| Push notification token. Your Apple Push Notification service (APNs) token, with your permission. | To deliver “you’re needed” alerts to your device. |
| Group & membership data. The groups you create or join, their names, and invite codes. | To keep your crew connected and let you summon them. |
| Activation events. When you summon a group or person — who summoned whom, in which group, and when — until dismissed. | To show the recipient who needs them, even if the push didn’t arrive. |
| Optional sign-in identifier. If QRF offers Sign in with Apple or Google and you choose to use it, we receive a unique authentication identifier from that provider. | To secure and restore your profile. With Sign in with Apple you may hide your email via Apple’s private relay. |
| Basic technical logs. IP address and request metadata, kept transiently for security and abuse prevention. | To operate the service, enforce rate limits, and prevent abuse. Not used to build advertising profiles. |
2. What We Don’t Collect
We do not collect your precise location, your phone’s contacts, your browsing history, biometric data, or health/financial data. We do not use third-party advertising or analytics SDKs that track you across apps and websites, and we do not sell or rent your personal information.
3. How We Use Information
- Deliver activation alerts to the members of your groups.
- Maintain your groups, memberships, invite codes, and roster.
- Show recipients who summoned them.
- Operate, secure, and troubleshoot the service, including rate limiting and abuse prevention.
- Process subscriptions (handled by Apple — see §6).
- Comply with law and enforce our Terms.
4. Legal Bases for Processing (EEA/UK)
If you are in the European Economic Area or the United Kingdom, we process your information on the basis of: performance of a contract (to provide QRF features you request); legitimate interests (to keep the service secure and prevent abuse); consent (e.g., enabling push notifications, which you can withdraw in iOS Settings); and legal obligation where applicable.
5. How Information Is Shared
- With members of your groups. Your display name, profile photo (if any), and the fact that you summoned or were summoned are visible to people in groups you share. Only share a group or invite code with people you trust.
- With service providers who process data on our behalf under contract (§6).
- For legal reasons — to comply with law, lawful requests, or to protect the rights, safety, and property of users, the public, or Delvir Limited Liability Co.
- In a business transfer — if we are involved in a merger, acquisition, or sale of assets, your information may transfer subject to this Policy.
We never sell your personal information and we do not share it for cross-context behavioral advertising.
6. Service Providers
We rely on a small set of reputable providers, each acting as our processor:
- Apple — push delivery (APNs), the App Store, in-app subscriptions, and (if used) Sign in with Apple. Apple processes payments; we never receive your card details.
- Google Firebase — optional authentication and storage of profile photos.
- Neon — our managed PostgreSQL database (United States).
- Vercel — application and website hosting.
Each provider’s use of data is governed by its own privacy terms.
7. Where Your Data Is Stored
Your account record (anonymous ID, display name, push token, group memberships, and pending activations) is stored in our managed PostgreSQL database hosted by Neon in the United States, and our application is hosted on Vercel. Profile photos, if you add one, are stored by our image provider. Data is encrypted in transit using TLS.
8. Security
We protect your information with industry-standard measures: encryption in transit (HTTPS/TLS), restricted database access, rate limiting, input validation, and least-privilege credentials kept server-side and never embedded in the app. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security, but we work to protect your information and to limit what we hold to the minimum needed.
9. Data Retention & Deletion
We keep your information for as long as your profile exists. Pending activation entries are removed when dismissed. You can delete your data at any time:
- In the app: open your profile (top-right icon) → Delete account. This removes your user record and group memberships from our servers.
- By email: contact team@delvir.co and we will delete your data.
We may retain limited records where required for legal, security, or fraud-prevention purposes, and transient logs expire on a rolling basis.
10. Your Rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, email team@delvir.co. We will respond as required by applicable law. You will not be discriminated against for exercising your rights. You may also disable notifications at any time in iOS Settings.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use it (described above), the right to delete it, the right to correct it, and the right to opt out of “sale” or “sharing.” We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we do not process it for cross-context behavioral advertising. To make a request, contact team@delvir.co.
12. Children
QRF is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact team@delvir.co and we will delete it.
13. International Data Transfers
We are based in the United States and process data there. If you access QRF from outside the United States, you understand your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your country. Where required, we rely on appropriate safeguards for such transfers.
14. Changes to This Policy
We may update this Policy from time to time. We will revise the “Last updated” date above and, for material changes, provide additional notice where appropriate. Your continued use of QRF after an update means you accept the revised Policy.
15. Contact Us
Delvir Limited Liability Co.
Wyoming, United States
Email: team@delvir.co