Privacy Policy
Quorum · Last updated 2026-06-06
This policy explains how Quorum ("Quorum", "we") handles data in connection with the
Quorum connector for AI assistants (the "Service"). The Service gives an AI agent
deterministic, privacy-safe ground truth about real-world consumer behavior — always as
aggregate, k-anonymous cohorts, never individuals.
What the Service returns
- Aggregate cohorts only. Household counts, distributions, cross-shop affinities,
and lifts. We never return an individual person, household record, or personally identifying
information (PII).
- K-anonymity. Any cohort smaller than our minimum cell size (currently 50
households) is suppressed, not estimated.
- No raw identifiers to external callers. Household identifiers exposed to
non-Quorum callers are HMAC-hashed; raw identifiers never leave our environment.
- Honest coverage. Results disclose a deterministic-sample basis and a coverage
multiplier — we never claim to "see everyone." Anything we cannot measure is returned as
null, not guessed.
What we process
- Your queries. Brand, category, advertiser, or domain names you ask about, used
to compute the requested aggregate insight.
- Device IDs you voluntarily provide (e.g., to profile a list): pseudonymous
mobile advertising IDs are matched to aggregate household cohorts and used only to compute the
response. We do not return which input mapped to which household, and we do not build a
profile of you from them.
- Usage metadata. We meter calls and volume for operations and billing
(call counts, units, latency) — not personal data.
Where the data comes from
Insights are derived from advertising-impression and web-analytics logs and an
opt-in identity graph that resolves devices to households. Audience activation, when
used, occurs only via hashed / data-cleanroom matching — never by exposing identities.
What we do not do
- We do not sell personal information.
- We do not return PII or individual-level records through the Service.
- We do not write to or modify your systems — the Service is read-only with respect to your data.
- The Service is not directed to children.
Security
The Service queries our data warehouse through a least-privilege, read-only role, and data in
transit is encrypted (HTTPS/TLS).
Your choices
You control what you send the Service. For questions, data requests, or opt-out inquiries related
to the identity graph, contact us below.
Changes
We may update this policy; material changes will be reflected by the "Last updated" date.
Contact
Quorum — privacy@quorum.inc
Draft pending counsel review.