Privacy Policy

Last updated 8 August 2026

Quorum records class attendance, coursework and exams for universities. This page explains what we collect, why, who we share it with, and how long we keep it.

Two kinds of people

Quorum holds data about two groups, and their relationship to us is different.

  • Instructors hold an account with us. They chose to sign up, and we are the data controller for their account details.
  • Students do not hold an account. Their details are entered by their instructor or captured when they check in to a class. For that data the university or instructor decides what is collected and why — we process it on their instructions, as a data processor.

If you are a student with a question about your attendance record, your instructor or university is the right place to start. We can only act on their instructions, but you can always contact us at support@quorumqr.app and we will help you reach the right person.

What we collect from instructors

  • Your name, email address and — if you give it — your university.
  • A password, stored only as a hash we cannot reverse. If you sign in with Google we never receive a password at all.
  • Your subscription status, plan and billing history.
  • Feedback you send us, including any files you attach.
  • Server logs of requests to the service, which include IP addresses.

What we collect about students

Some of this exists specifically to make attendance trustworthy. We have described it plainly rather than as “security data”, because students are entitled to know what a QR check-in actually records.

  • The student ID and name your instructor enters or imports.
  • A record of each check-in: which session, when, and whether it counted as present or late.
  • A device identifier and browser fingerprint, used to detect one phone checking in for several students. This is how proxy attendance is caught.
  • Approximate location at check-in, but only when the instructor has set a geofence for that session, and only to compare against it. We do not track location at any other time and do not keep a location history.
  • For online exams: answers, marks, and a record of moments the exam tab lost focus, which instructors use to review integrity.

Location is supplied by the student's browser and can be refused or altered. We treat it as a deterrent rather than proof, and instructors should too.

What we never collect

  • Card numbers. Payments happen on Stripe's own pages and card details never reach our servers.
  • Student passwords, because students do not have accounts with us.
  • Anything from a student's device beyond what is listed above — we do not read contacts, photos, or other apps.

Why we are allowed to hold it

  • To provide the service you asked for — performing our contract with you.
  • To detect proxy attendance and exam misconduct, which is the legitimate interest of the institution running the class.
  • To take payment and meet our accounting obligations.
  • To send account emails such as confirmations and password resets. These are not marketing and cannot be switched off while you hold an account.

Who else sees it

We do not sell data and do not use it for advertising. We share it only with the services that make Quorum work:

ServicePurposeData
SupabaseDatabase, authentication and file storageAll account and attendance data
VercelApplication hostingRequests to the service, including IP addresses in server logs
StripeCard payments and subscription billingBilling contact details and payment records. Card numbers are entered on Stripe's own pages and never reach our servers
ResendTransactional emailEmail addresses and the contents of account emails we send you
GoogleOptional sign-inYour name, email address and profile picture, only if you choose to sign in with Google

Within Quorum, instructors see the students in their own groups and nobody else's. Teaching assistants invited to a group see that group. A small number of our staff can access accounts to provide support; every such action is recorded in an audit log.

Where it is stored

Our database and email sending are hosted in the European Union. The application itself runs on a global network, so a request may be handled near you before reaching that database.

How long we keep it

  • Account and teaching data: for as long as you hold an account. Letting a paid plan lapse does not delete anything — you keep your data on the Free plan's limits.
  • Attendance and coursework records: until the instructor deletes them or closes the account, since these are academic records the institution may need to retain.
  • Billing records: kept as long as tax and accounting rules require, even after an account closes.
  • Rate-limiting counters and server logs: short-lived, and not used to build a profile of anyone.

Your rights

Depending on where you live, you may have the right to see a copy of your data, correct it, delete it, or object to how it is used. You can change your name, university and email from your account settings at any time.

For anything else, write to support@quorumqr.app. If your request concerns a student record, we will usually need to refer it to the instructor or university responsible for it — we will tell you when that happens rather than leaving the request unanswered.

Children

Quorum is sold to universities and is not intended for children. We do not knowingly create accounts for anyone under 16.

Changes

If we change this policy in a way that materially affects you, we will tell you in the app before it takes effect rather than quietly editing this page.

Questions about this page? support@quorumqr.app