1. Scope
This pre-release policy describes the website as it works today and the data practices Quorum’s private pilot is designed to use when the relevant app services are enabled. Quorum is the product name used for this project and is operated by the owner of lukerykta.io. Before any public release, this policy and the store privacy disclosures must be checked again against the app’s actual production behavior.
2. Information Quorum handles
- Account and identity data. Authentication identifiers from Apple or Google, session records, and the display name you use in Quorum. A provider may supply an email claim to the authentication service, but Quorum does not use email as an app password or copy it into your Quorum product profile.
- Club and reading data. Club membership, the active book and physical edition, exact-page progress events, and the timestamps needed to keep current reading state.
- Notes. The note text you choose to publish, its kind, author, accepted page, and publication time. A friend who has not reached that page receives only the limited locked-card information needed to show that a note is waiting, not its text.
- Support messages. The address and content you send to the support inbox, plus the information needed to respond.
- Limited technical data. App environment, build or release version, and privacy-filtered error details when monitoring is enabled. Quorum’s monitoring policy excludes note text, exact reading locations, credentials, authentication URLs, and invite tokens.
3. How information is used
Quorum uses information only to:
- authenticate an invited reader and maintain their session;
- provide the private club, exact-page progress, note, and unlock loop;
- protect club boundaries and investigate security or reliability issues;
- answer support, privacy, and deletion requests; and
- meet legal obligations that apply to the service.
Quorum does not sell reading data, use note content for advertising, or run targeted advertising.
4. Service providers and disclosure
Quorum relies on a small set of providers to operate: Supabase for the application backend and authentication, Apple and Google for sign-in when those options are enabled, Expo/EAS for app builds and delivery, and Cloudflare for the public website and planned support-email routing. They process only the information needed for their role under their own terms and Quorum’s configuration.
Information may also be disclosed when required by law, to protect a person’s safety or the service, or as part of a future service transfer where this policy continues to apply. Quorum is not a public data broker and does not disclose club content for marketing.
5. The public website
This website uses no advertising pixels, analytics service, remote font, account form, or tracking cookie. Its hosting provider may process ordinary network records such as IP address, user agent, requested path, and time to deliver and protect the site. The website does not receive your in-app club, progress, or note data.
6. Retention and deletion
Quorum keeps account and reading data only while it is needed to operate the pilot, maintain the shared club record, protect the service, or meet legal obligations. Published progress is append-only so current state can be derived honestly; it is not used as a public score.
The reviewed V0 deletion path is designed to remove the requesting person’s local draft and publication keys, authored V0 notes, membership, profile, and authentication account without deleting another member’s data or the shared read. See Account deletion for the current request path. A limited content-free record may be kept where necessary to document or secure the deletion process.
7. Security and your choices
Quorum uses access controls, separate environments, least-privilege credentials, encrypted transport, and server-side spoiler boundaries. No system can promise perfect security. If you think your account or an invitation has been exposed, contact support promptly and do not include passwords, tokens, or note text in the message.
You may ask about, correct, or delete your information by emailing support@lukerykta.io. Apple and Google account information can also be managed through those providers.
8. Changes and contact
Material changes will be posted here with a new effective date. Questions about this policy can be sent to support@lukerykta.io.