Privacy

Last updated 18 September 2026

Quirow is archival software for institutions. It is used by library and archives staff to describe collections and publish them. This page explains what it collects, why, and where that data lives.

Quirow runs no analytics, loads no advertising or tracking scripts, and sells no data to anyone. There is no tag manager, no advertising pixel, and no third-party script on any page of this site or the application.

Who this covers

There are two kinds of people in the system, treated differently:

  • Account holders — staff at a subscribing institution who sign in to catalog and publish.
  • Visitors — anyone reading a published archival site or this marketing site. Visitors do not have accounts and are not asked to identify themselves.

What is collected from account holders

  • Account details. An email address, and a password (stored only as a hash, never in readable form) or a Google account identifier if signing in with Google. A display name and the institution the account belongs to.
  • Attribution. Records carry who created and last updated them, so an institution can see who changed what.
  • Content you enter. Archival descriptions, authority records, uploaded files, and the pages built from them. This is institutional material, not personal data about you, although archival material can of course describe people.

Signing in with Google shares only your email address, name, and profile picture. Quirow does not request, receive, or store access to your Gmail, Drive, contacts, calendar, or any other Google service.

What is collected from visitors

Nothing that identifies you. No account, no cookie, and no tracking script is set for an anonymous visitor to a published site or to this one. Our hosting provider keeps standard server logs, which include IP addresses, for operating and securing the service.

Cookies

The only cookies Quirow sets are the session cookies that keep an account holder signed in. They are strictly necessary for authentication and are not used to profile anyone. Signing out clears the session. There are no advertising or analytics cookies to consent to, because there is no advertising or analytics.

Where the data lives

Quirow is hosted infrastructure and relies on a small number of providers, each of which processes data only to run the service:

  • Supabase — the database and authentication, hosted in the United States.
  • Cloudflare R2 — storage for uploaded files. Each institution’s files are held in a separate bucket, and access to them is granted through short-lived signed links rather than public URLs.
  • Vercel — application hosting and delivery.
  • Google — only if an account holder chooses to sign in with a Google account.

Data is stored in the United States. If you are in a jurisdiction with data-transfer requirements, raise it before adopting the service so it can be addressed honestly rather than retrospectively.

Who can see what

Institutional separation is enforced in the database, not by application code remembering to filter: an account holder at one institution cannot read another institution’s records, and a published site shows only what has been deliberately marked as published. Draft material is not visible to the public.

As the operator, I can access institutional data where necessary to run, support, or repair the service. I do not browse it otherwise, and I do not use it to train anything.

How long it is kept

Institutional content is kept for as long as the institution has an account, because that is the point — this is a system of record. Deleting a digital object removes the stored file as well as the database row. On request, an institution’s data can be exported or deleted.

Your rights

You can ask what personal data is held about you, ask for it to be corrected or deleted, or ask for a copy. Email the address below and you will get a real answer from a person — there is only one of us.

Institutional content belongs to the institution, so requests about archival records are handled with the institution that holds them.

Changes

Quirow is in active development, and this page will change as the software does. The date at the top is the last revision. Material changes affecting account holders will be communicated directly, not posted quietly.

Contact

Questions about any of this: hello@quirow.com.