Privacy policy
This page exists in French and in English. The French version is the authoritative one.
1. Who is responsible
The data controller is Quavern, SASU, 14 Rue de Menespey, 33185 Le Haillan, France. For any question about this policy or your data, write to hello@quavern.com. Quavern has not appointed a data protection officer; requests are handled directly by the founder.
This policy covers quavern.com, the Marl assistant (chat.quavern.ai, marl.quavern.ai and the Marl Code application), the Marl API (api.quavern.ai), the myQuavern account space (my.quavern.com), Quavsit (quavsit.quavern.com, the api.quavern.net API, departure boards and the feed watch), the Quavern MCP server (mcp.quavern.ai), the Quavblok Minecraft network (mc.quavern.net), and the online services of the QuavernOS operating system: downloads, update checks and optional connected features.
It also covers the blog (blog.quavern.com), the open-source site (oss.quavern.com), which includes the Quavsit Observatory, and the status page (status.quavern.net).
2. What we process
- Account data: e-mail address, display name, hashed password, language, sessions, revocable access tokens, organisation membership, and dated, versioned consent records. If you register a passkey, we store its public key and the name you give it — never a fingerprint, a face or a device PIN, which stay on your device and are never sent to Quavern.
- Telephone number: if you give one, we keep it in international form, the country it belongs to, and a keyed digest that lets the same number be recognised across accounts without being searchable. It has two uses and no others: showing that a person is behind a sign-up or a new device, and, when you choose it, a second factor when you sign in or reset your password. It is never used for marketing, and it is only ever shown back to you masked, as +33 6 •• •• •• 78.
- Marl content: your conversations, the files you attach, optional memory entries the assistant keeps about you, and your settings.
- Usage measures: request counts and token-based usage against your plan's quotas.
- Billing data: billing identity and subscription state, processed by Stripe. Quavern never stores card numbers.
- Support conversations: what you write to Quavern's support, the address you write from, anything you attach, and our replies. If you use the chat on support.quavern.com rather than writing an e-mail, your browser also tells Intercom your IP address, and it keeps an identifier on that host so a conversation survives a page reload.
- If you open the chat from the support page in myQuavern, the conversation is identified: a short-lived signed token tells Intercom your Quavern account identifier and the e-mail address on that account, and nothing else about it, so support can see which account is writing.
- Technical logs: IP addresses, timestamps and error codes, kept for security and operations.
- Fraud-prevention signals: when you create an account or connect a new device, we check the connecting IP address — its network type, approximate location, and whether it is a known abuse source, VPN or anonymising proxy. On higher-risk networks we may ask you to pass a reCAPTCHA challenge or, one rung up, to give a mobile number and enter a six-digit code we send to it. The free card check that did this before was removed in September 2026; opening a free account never requires a card.
- Sign-in notices: when your account is used from a device we have not seen before, we send you a security e-mail. It states the time, the approximate location and network of the connecting address, the address itself, and a short description of the device such as "Chrome on macOS". It includes a map of the approximate area, drawn by Quavern from that location.
- Failed requests: when a request to a Quavern service fails, we record the support code we showed you, the reason behind it, the time, the route that was called, the HTTP status, and your account identifier if you were signed in. That is what lets support explain a failure from the code alone. These records hold no message content, no request or response body, no headers and no address, and they are deleted after seven days.
- Requests about your data: when you ask for access to your data or for its deletion, we record which right you exercised, the day the request reached us and the day we answered it, with your account identifier while the account exists. Nothing else about the request is kept — not what you wrote, not why. We hold that record for three years after the answer, to be able to show the one-month deadline was met, and if the account is deleted in the meantime the identifier goes with it and only the right and the two dates remain. A request we have not yet answered is never deleted.
- Diagnostics: when a Quavern page or application fails, we receive the error and its stack trace, the page path, and your browser and operating system. Conversation content, form contents and request bodies are never attached, and credentials are stripped before the report is sent. Marl Code, which runs on your own machine, sends nothing unless you turn crash reporting on yourself.
- Optional measurement: if, and only if, you accept it, page-load and interaction timings for a sampled share of page loads, together with a trace identifier valid for that page load alone.
- Transactional e-mail: verification and security messages, sent through Mailgun. Delivery events (sent, delivered, bounced) are recorded so that failures can be diagnosed.
- QuavernOS: the installed system sends nothing by default. Downloading images or checking for updates leaves ordinary technical logs; connecting a machine to your myQuavern account, or enabling an optional metrics or assistant feature, is an explicit, revocable choice recorded as a dated consent.
Quavsit and Quavern MCP
- Keys and usage: the Quavsit keys you create and when each was last used; for each key and each day, the units charged and the number of requests and errors; for each calendar month, the units used, the billable units and the estimated overage; your overage setting and spend cap. Quavern MCP uses the same keys and records.
- Departure boards: each board's name, title, stops, lines, hours, theme and language, its link, the time a screen last requested it, and the units it used each day.
- Feed watch: the networks you watch, whether e-mail alerts are on, the webhook address and its signing secret, the time and result of the last webhook delivery, and the alerts opened and resolved. E-mail alerts go to your account address through Mailgun; webhook deliveries go only to the address you set.
- The quavsit.quavern.com application has no sign-in. The searches you make, the stops and lines you open and the journeys you plan are sent to the Quavsit API through Quavern's own server, which also uses your IP address to limit the request rate. Your position is read only when you press the button that asks for it, and is then sent with that request.
- Marl's summary of a stop, a line or the traffic is written only when you press the control that asks for it. The model receives the departure counts and the alert titles Quavsit has already published on the page, and nothing about you: no account, no position, no search history. So that one person cannot generate a summary for every stop on the network, Quavern counts these requests against a keyed digest of your IP address — never the address itself — held in the running service for at most one hour and never written to disk.
Quavblok
- Playing: when you connect to mc.quavern.net, the game proxy asks Mojang's authentication service to confirm your Minecraft account. The game servers store your player name and identifier and your game progress, and their logs record your IP address, your connections, and the chat and commands you type in the game.
- Account link: if you link your Minecraft account, we store its name and identifier with your myQuavern account, together with the player settings you choose. The game servers receive only your player name, the link state and those settings. The /marl command sends your message to Marl and records the usage against the linked account's plan; the message is not saved in your Marl history.
- Anti-cheat: the game servers measure how players move. When a player's movement looks irregular several times in a row, the measurements (speeds, time in the air, height gained without jumping, game mode, connection latency) are sent with the player name to an AI model for assessment. The verdict, its confidence and its explanation are stored with the measurements and the player's name and identifier, and with the myQuavern account if the Minecraft account is linked. Everywhere except the survival world, a player judged with high confidence to be cheating is disconnected.
Status page
status.quavern.net runs on Instatus. If you subscribe to incident updates there, Instatus stores the e-mail or webhook address you give so that it can send them.
3. Why, and on what legal basis
- Providing the services you signed up for, including generating Marl's replies: performance of the contract.
- Billing, accounting and tax records: legal obligation.
- Security, abuse prevention and moderation of prohibited use: legitimate interest.
- Sending a code by SMS when a sign-up comes from a higher-risk network: legitimate interest in preventing automated and fraudulent sign-ups. Keeping that number afterwards as a second factor: consent, given by turning the factor on and withdrawn by turning it off or removing the number.
- Answering you when you write to support: performance of the contract when you have an account, and legitimate interest in answering anyone else who writes.
- Diagnosing errors and crashes so that they can be fixed: legitimate interest.
- Telling you when your account is used from a new device: legitimate interest in the security of your account. These notices cannot be switched off, because a security notice you can be talked out of is not one.
- Optional features such as assistant memory, and any future optional purpose: consent, which you can withdraw at any time.
- Loading maps drawn by Google on quavsit.quavern.com: consent, given by choosing to show the map, which you can change under any map.
- Answering visitors of the sites and applications that need no account, such as quavsit.quavern.com and the status page: legitimate interest in running services open to everyone.
- Assessing how Quavblok players move and disconnecting players judged to be cheating: legitimate interest in fair games for every player.
There is no advertising on Quavern services, no advertising or cross-site tracking, and no sale of personal data. Audience measurement is limited to the optional performance measurement described in section 8, which stays off until you accept it and which you can withdraw at any time.
4. Who receives data
Quavern uses a small number of processors, each limited to what its role requires. Where a service below receives data without acting on Quavern's behalf, its entry says so:
- Hosting: Microsoft Azure (Microsoft Ireland Operations Limited), in the European Union.
- Content delivery: Fastly (Fastly, Inc.), which carries every request to Quavern's websites and APIs, except oss.quavern.com and status.quavern.net, and therefore processes visitors' IP addresses and request details, on servers that include the United States; transfers are governed by the European Commission's Standard Contractual Clauses included in Fastly's data processing terms.
- Hosting of oss.quavern.com and the Quavsit Observatory: GitHub Pages. GitHub (GitHub B.V. in the European Union, GitHub, Inc. in the United States) logs visitors' IP addresses for its own security purposes, under the GitHub Privacy Statement; GitHub states that it complies with the EU-U.S. Data Privacy Framework.
- Status page: Instatus (Instatus, Inc.), which hosts status.quavern.net on servers in the United States and therefore receives visitors' IP addresses, and the addresses of people who subscribe to incident updates.
- Payments: Stripe, for checkout, subscriptions and invoices, and the count of billable Quavsit units, reported as they accrue.
- Transactional e-mail: Mailgun (Sinch Email, Inc.). Mailgun processes the recipient address and the message in the United States; transfers are governed by the European Commission's Standard Contractual Clauses.
- Text messages: Telesign (Telesign Corporation), which sends the codes from the United States. It receives the telephone number — and with it the country that number belongs to — the text of the message, the IP address the request came from, and a code saying which of the four purposes the message serves, the last two so that it can judge whether the request is fraudulent. It receives no name and no e-mail address. Telesign's own privacy notice states that it is a processor for the content of a message and a separate controller for the number it routes. Transfers are governed by the European Commission's Standard Contractual Clauses, which Telesign's data processing agreement incorporates.
- Support conversations and the help centre at support.quavern.com: Intercom, contracted through Intercom R&D Unlimited Company, 124 St Stephen's Green, Dublin 2, D02 C628, Ireland. Quavern's workspace is hosted in the United States by Intercom, Inc., 55 2nd Street, 4th Floor, San Francisco, CA 94105, so what you write to support is transferred there, and so is what your browser sends when you read the help centre. Intercom certifies under the EU-U.S. Data Privacy Framework, and its data processing agreement also applies the European Commission's Standard Contractual Clauses.
- AI inference providers, which process conversation content to generate the reply you asked for, including Quavblok's /marl messages, and Quavblok anti-cheat measurements to assess them. Where such a provider is located in the United States, transfers are governed by the European Commission's Standard Contractual Clauses.
- Abuse-prevention intelligence and geolocation: IP2Location.io, which returns the approximate location, network operator and reputation of an IP address so we can spot automated or fraudulent sign-ups and tell you where a new sign-in came from. It replaced db-ip.com in September 2026.
- Maps: Google Maps Platform, used to draw the map in a sign-in notice. Quavern requests that image from its own servers and attaches it to the e-mail, so Google never learns who received the message or when it was opened.
- Maps on quavsit.quavern.com: Google Maps Platform, loaded by your browser directly from Google, and only after you choose to show the map. Google then receives your IP address and the area shown, and acts as a separate controller under its own Privacy Policy (policies.google.com/privacy).
- Minecraft account checks: Mojang, whose authentication service confirms the Minecraft account of each player who connects to Quavblok. Mojang runs that service for Minecraft itself, not on Quavern's behalf.
- Transport data services: when a Quavsit search or journey needs them, Quavern's servers send the place name, the coordinates or the requested journey to the Base Adresse Nationale or to an operator's journey planner (Île-de-France Mobilités, SNCF, Tisséo), without your IP address or any account detail.
- Error monitoring and optional performance measurement: Sentry (Functional Software, Inc.), used in its European Union region, where the data is stored. Reports carry the error, the page and the technical environment, never conversation content.
- Anti-bot verification: Google reCAPTCHA, shown only on higher-risk sign-ups and sign-ins to tell humans from automated abuse. Its use is subject to Google's Privacy Policy (policies.google.com/privacy) and Terms (policies.google.com/terms).
No other third party receives your data, except where the law requires it.
5. AI processing
Conversation content is processed to produce the reply you requested. Quavern does not use your conversations to train foundation models, and its inference providers are bound by contractual restrictions on how they may use the data they process.
In support, the first answer may come from Fin, Intercom's automated agent, which reads Quavern's published help pages to answer. It says that it is an automated agent, and asking for a person hands the conversation to one.
Assistant memory is optional. When enabled, Marl keeps short, durable facts you can review and delete at any time from your account.
In Quavblok, /marl messages are processed like conversations to produce the reply, and anti-cheat measurements to produce a verdict; neither carries your myQuavern details.
6. How long we keep data
- Account data: for as long as the account exists, then deleted or anonymised.
- Support conversations: kept while they may still be needed to follow up on what you asked, and deleted at your request.
- Telephone number: for as long as your account keeps it. Removing it from myQuavern, and deleting the account, clear the number, its country and its digest.
- Conversations on the Free plan: 30 days, enforced by an automatic daily purge.
- Conversations on paid plans: until you delete them or delete your account.
- Invoicing records: 10 years, as French law requires.
- Technical logs: a short, proportionate period for security and operations.
- Diagnostic and optional measurement records: 90 days, then deleted.
- Quavsit keys and usage records: kept with the account. Revoking a key stops it working; its usage history stays with the account.
- Departure boards and the feed watch, with its alerts: until you delete them from myQuavern.
- Quavblok account link and player settings: until you unlink the Minecraft account from myQuavern.
You can delete your Marl data, or the whole account, directly from myQuavern without asking anyone.
7. Your rights
You have the rights of access, rectification, erasure, portability, restriction and objection, and the right to withdraw consent at any time for processing based on consent. Write to hello@quavern.com; Quavern answers within one month.
If you believe your rights are not respected, you can lodge a complaint with the CNIL, the French supervisory authority, at cnil.fr.
8. Cookies and local storage
Quavern sites use only storage that is strictly necessary: authentication, session refresh, language, theme, and the record of your privacy choice itself. That choice is kept on your device for at most six months, and the notice stays reachable from the bottom of every page that shows it. The blog and oss.quavern.com store only your theme, and show no notice.
There are no advertising or marketing trackers, first-party or third-party, and nothing that follows you across sites. On quavern.com the notice itself offers nothing optional: it only records that you have seen it. The applications — chat.quavern.ai, my.quavern.com and quavsit.quavern.com — offer one optional purpose, from their own notice: performance measurement, which records how quickly pages load and respond so that slow pages can be found and fixed. It is off unless you accept it, accepting and refusing are equally easy, and you can change your mind at any time from the same notice. Refusing it changes nothing about how the service works.
Crash reporting is not part of that choice. When a page fails, the error and its stack trace are reported so the fault can be fixed; this keeps no identifier that outlives the page, and is carried out on the legitimate interest of keeping the service working.
The help centre and the chat live on support.quavern.com, which Intercom serves. Reading or opening a conversation there sets three identifiers on that host: intercom-id-…, which recognises you between visits, intercom-session-…, which lasts a week, and intercom-device-id-…, which guards against abuse for 270 days. The same three are set on my.quavern.com if, and only if, you open the chat from the support page there: that page fetches nothing of Intercom's until you press the control. None of them is set on quavern.com, which loads nothing of Intercom's and nothing third-party at all.
When a reCAPTCHA challenge is shown on a higher-risk sign-up or sign-in, Google may set cookies strictly to run that anti-abuse check; they are not used for advertising or tracking.
On quavsit.quavern.com, maps are drawn by Google Maps Platform and load only after you choose to show them. That choice is kept on your device for at most six months and can be changed under any map.
9. Security
Connections are encrypted in transit. Secret keys stay on the server side. Access tokens are hashed at rest, scoped to an audience, and revocable from your account. Production systems run with restricted privileges and least-access file permissions.
A code sent by SMS can serve as a second factor, but only while the account has neither a passkey nor an authenticator app. SMS is the weakest of the three: a number can be taken over at the operator, and a message can be read on the way. So it is a fallback — adding a passkey or an authenticator app turns the phone back into a contact detail, and an SMS code can never replace, disable or bypass either.
Departure-board links and webhook signing secrets are stored as issued, because they must be shown to you again; issuing a new one from myQuavern makes the old one stop working.
10. Age
Quavern services are intended for people aged 15 or over. Under French law, a person under 15 may only use them with the agreement of a parent or guardian.
11. Changes to this policy
This page is dated and versioned. If the policy changes in a way that matters, the change is announced in the product before it takes effect, and the previous version remains available on request.