Quantiles Privacy Policy

Last updated June 30, 2026

Quantiles (“Quantiles,” “we,” “our,” or “us”) recognizes the importance of protecting your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you interact with our website, platform, applications, and online services that reference this Privacy Policy (collectively, the “Services”).

If you interact with Quantiles open source projects hosted on GitHub, GitHub may also collect and process information under its own privacy policies. This Privacy Policy applies to information Quantiles collects through our websites, hosted Services, accounts, communications, and any open source project interactions that we receive or control.

Our Services are intended for use only in the United States. We do not offer or market the Services to individuals located outside the United States, including in the European Economic Area (EEA) or United Kingdom.

By accessing or using the Services, you acknowledge that you have read and understand this Privacy Policy.

1. Information we collect

We collect information that identifies, relates to, or is reasonably capable of being associated with an individual or organization.

1.1 Information you provide

We may collect personal information directly from you when you interact with the Services, including when you:

Categories of data you may provide include:

Contributions, issues, comments, pull requests, profile information, and other activity you submit to public open source repositories may be publicly visible and may be processed by GitHub and other third parties according to their own terms and privacy policies.

Users are solely responsible for ensuring they have the lawful right to upload prompts, datasets, model outputs, logs, evaluation artifacts, or any content to the Services. Quantiles is not responsible for any data uploaded in violation of applicable laws, agreements, or third-party rights.

Important: Do not upload or transmit sensitive or regulated data, including PHI, unless you are authorized to do so and any required agreement, such as a HIPAA Business Associate Agreement (BAA), is in place. Quantiles is not responsible for PHI submitted outside a BAA.

1.2 Information collected automatically

When you access or use the Services, we may automatically collect:

1.3 Information from third parties

We may receive information from:

2. How we use information

We use information for the following purposes:

2.1 Service delivery

2.2 Research, development, and analytics

We do not use customer prompts, datasets, model outputs, traces, or evaluation artifacts in Quantiles-controlled systems to train general-purpose AI models unless you direct us to do so or agree otherwise.

2.3 Compliance and legal purposes

2.4 Communications

2.5 With your consent

For any additional purpose disclosed to you at the time of collection.

3. How we share information

We may share personal information as follows:

3.1 With service providers

With third-party vendors performing services on our behalf, including:

Service providers are contractually required to protect the information and use it only for the services provided.

3.2 With affiliates

We may share data with our wholly or majority-owned affiliates to support operations consistent with this Privacy Policy.

3.3 Legal compliance and protection

We may disclose information to:

3.4 Business transfers

If Quantiles undergoes a merger, acquisition, financing, asset sale, or bankruptcy, information may be transferred to the successor. The recipient must process the data consistent with this Privacy Policy.

3.5 Aggregated or de-identified data

We may share anonymized, aggregated, or de-identified data for:

This information does not personally identify individuals.

4. Cookies and tracking technologies

We use cookies, pixels, and similar technologies to:

You can manage cookie preferences in your browser settings. Disabling cookies may affect site functionality.

We do not respond to “Do Not Track” signals at this time. Third parties may collect information through our Services consistent with their own privacy policies.

5. Third-party content and links

The Services may contain links or integrations operated by third parties. We are not responsible for their privacy practices. Review their policies before interacting with them.

6. Sensitive, Regulated, and Evaluation Data

6.1 Customer responsibility for evaluation data

Quantiles is a general AI evaluation platform. Your evaluation workflows may involve private prompts, datasets, model responses, traces, annotations, metrics, and other artifacts that can reveal information about your users, products, models, business logic, or regulated operations. You are responsible for deciding what data is appropriate to submit to the Services and for ensuring that you have the rights, permissions, notices, consents, and agreements needed to process that data.

6.2 PHI and HIPAA

Quantiles may act as a Business Associate under HIPAA only when providing services to HIPAA-covered entities or their Business Associates under a valid BAA.

Users must not upload or transmit PHI unless a BAA is executed. Quantiles is not responsible for PHI provided outside a BAA.

6.3 Synthetic and test data

Synthetic, test, or generated evaluation data:

6.4 Safeguards

We maintain administrative, technical, and physical safeguards designed to protect personal information, customer evaluation data, and regulated data where applicable.

7. California Privacy Rights (CCPA/CPRA)

We collect personal information as described in this Privacy Policy. The categories of information collected and purposes for collection are outlined in Sections 1 and 2 of this Privacy Policy, which serve as our Notice at Collection. We do not sell or share personal information as those terms are defined under CCPA/CPRA. If you are a California resident, you may exercise the rights described below.

7.1 Categories of information collected

In the last 12 months, we may have collected:

7.2 Your rights

To exercise these rights, email security@quantiles.io.

Identity verification may be required.

8. Data retention

We retain information only as long as necessary to:

We retain personal information for the periods described below unless a longer retention period is required or permitted by law.

We securely delete or de-identify data once retention periods expire unless law requires otherwise.

Public open source contributions may remain visible in public repositories, forks, clones, archives, or third-party systems even if you ask us to delete information from Quantiles-controlled systems.

9. Data security

We employ administrative, technical, and physical security measures, including:

However, no system is completely secure. We cannot guarantee absolute security of data transmitted or stored.

9.1 Breach notification

In the event of a breach affecting personal information, we will provide notifications as required by applicable U.S. law.

10. Children's privacy

The Services are intended for users who are at least 18 years old. We do not knowingly collect personal information from children under 13 years of age. If we become aware that we have collected personal information from a child under 13, we will take reasonable steps to delete that information.

11. Your choices

You may:

12. U.S. Only

Our Services are intended for users located in the United States. We do not purposefully collect or process data from individuals located outside the U.S.

13. Changes to this privacy policy

We may update this Privacy Policy from time to time. Changes become effective upon posting. We encourage you to review this Privacy Policy periodically.

14. Contact information

If you have questions about this Privacy Policy or our practices, contact us at:

Email: security@quantiles.io

Subject Line: Privacy Inquiry – Quantiles