Skip to content
qikfox

Legal

qikfox Privacy Policy

Last Updated: August 27, 2026. Effective: September 1, 2026.

This Privacy Policy explains what information qikfox Cybersecurity Systems, Inc. ("qikfox," "we," "us," or "our") collects when you use the qikfox Smart Browser, the qikfox Wallet and qikPay, Subscription Plans, Credits, and related features, websites, and storefronts (collectively, the "Service"), how we use it, and the choices you have. Capitalized terms not defined here have the meaning given in the qikfox Smart Browser Terms of Use at https://qikfox.com/terms-of-use (the "Terms"). This Privacy Policy is incorporated into the Terms.

Our Commitments

  • We do not sell your personal information. Not to advertisers, data brokers, or anyone else.
  • We do not share your personal information with third parties for their own use. The only organizations that ever process your data are trusted partners who provide services to us, and they may use it only to provide those services.
  • We do not show ads, and we do not build advertising profiles. We do not engage in cross-context behavioral advertising or "sharing" as defined by California law.
  • We do not store your browsing history. What you browse stays on your device.
  • We do not collect usage analytics that identify you. The only usage signal the browser sends is an anonymized cohort heartbeat that cannot be tied back to you.
  • We cannot connect who you are to what you do. Your billing identity (the email or phone number used to buy a Subscription) and your browsing identity (your DID and Handle) are kept separate, and we do not correlate them.
  • We avoid storing consumer information on our servers. What must exist server-side is limited to billing records and the uncorrelated ledger described below.
  • We cannot read your encrypted content. Smart Stacks and Onqik are end-to-end encrypted with keys only you hold.
  • We do not write personal data to any blockchain.

The rest of this policy gives the detail behind these commitments.

1. Information That Stays on Your Device

The following information is created and stored only on your device, inside your browser profile. It is never transmitted to qikfox, and qikfox has no copy of it. Uninstalling the Software, clearing browser data, or resetting your device deletes it permanently.

  • Browsing history, bookmarks, open tabs, saved passwords, form data, and site settings
  • Data Island content (see Section 3.9)
  • Notes Application content (see Section 3.10)
  • Onqik messages (see Section 3.8)
  • BYOLLM credentials, stored in an encrypted local keystore (see Section 3.9)
  • Your Wallet private keys, Recovery Phrase, PIN, and the encryption keys for Smart Stacks and Onqik (see Section 3.5)
  • Downloaded antivirus definitions and local scan results (see Section 3.11)

Because we hold none of this, we cannot recover it for you if it is lost.

2. Information We Collect

2.1 Information you provide

Wallet registration and subscription validation. qikfox deliberately keeps your billing identity and your browsing identity separate.

When you register a Wallet, your decentralized identifier (DID) and Handle are generated on your device and anchored in a Hyperledger-based distributed ledger. No personal data is written to that ledger. Your browser profile, Wallet, Credits, and all personalizations relate only to your DID and Handle, and personalization happens entirely on your device.

Separately, you verify an email address or phone number. We use the verified contact method only to validate purchases and Subscriptions: it lets us confirm that a customer has bought a Plan, send verification codes, order confirmations, and required notices, and process refund requests. We do not correlate your email address or phone number with your Handle or DID, and we do not retain any record linking them. Proof that you control the contact method used at checkout happens on your device at the moment a purchase is activated. The result is that we can tell that a customer holds a Subscription, but we cannot trace that Subscription back to a specific browser instance, Handle, or any browsing activity.

Your Handle is visible to other users who search for it or receive a share, invite, or Credit transfer from you. It does not reveal your email address, phone number, or personal identity.

Checkout. When you buy a Plan or Add-On Credits through a qikfox Storefront, you provide your first and last name, phone number, email address, billing and shipping address, ZIP code, city, state, and country. We retain this information as part of your order and invoice record.

Payment card details. Your card number, expiry date, and CVV are entered into and processed by our Payment Processor. qikfox does not receive or store full card numbers. We receive a payment confirmation, the last four digits of the card, the card type, and the transaction identifier.

Support requests. When you contact support, we retain your message, your contact details, your order number if provided, and the information support staff record to resolve the request (browser version, screen heading, error or support reference, flow stage, and masked subscription or transaction references). Support staff are instructed never to record Wallet secrets, payment details, or full personal identifiers.

Managed Services. If you request Managed Services for a device, we may ask you to prove ownership or control of that device. We retain the proof you provide only as long as needed to verify eligibility. If support connects to your device remotely with your consent, the session is not recorded, and we do not copy files from your device.

Verified Reviews. If you submit a qikfox Verified Review of a website, the review and your universal handle are published. The review stops at the handle and cannot be traced back to your email address, phone number, or identity. See Section 3.13.

2.2 Information processed by the Service on your behalf

qikPay ledger. qikPay records your Credit balance, Plan Credit grants and expirations, Top-Ups, Add-On Credit redemptions, Credit deductions for metered operations (the Credit amount and operation type, not the content of the operation), Credit transfers between users (sender Handle, recipient Handle, amount, timestamp, and any note the sender adds), shared balance access and limits, Subscription status, Licenses, Device Limits, and Member invitations. Owners can see Credit consumption by their Members under shared access. Recipients of a Credit transfer see the sender's Handle and note.

qikPay keeps these records in two uncorrelated sets: billing records (order, invoice, and Subscription validation, tied to the contact method used at checkout) and ledger records (Credits, transfers, and entitlement use, tied to DIDs and Handles). We do not maintain a link between the two.

Subscription and entitlement records. We record which Plan you hold, its billing cycle, renewal date, activation status, and which devices and Members are associated with it, so that we can deliver what you bought and enforce License counts and Device Limits.

Verification codes. When we send a 6-digit code to your email or phone for registration, recovery, migration, or identity linking, we record that a code was sent and whether it was verified. Codes expire within minutes.

2.3 Information collected automatically

Anonymized cohort heartbeat. The browser periodically sends a signal indicating that an installation is active. The signal contains a cohort identifier derived as a hash of the month and year the browser was installed, session length, platform, and browser version. It contains no account identifier, device identifier, or IP address retained by us, and is stripped of metadata and aggregated with signals from many other installations. This tells us how many users from a monthly cohort are active without telling us who they are.

Update servers. When the browser checks for or downloads updates, our component servers record aggregated counts of platform, version, and update completion. No user-specific information is collected.

Feature lookups. Some features query qikfox servers in order to work (for example, Active-Link Protection, proxyLLM requests, and Wallet operations). Those requests necessarily reach our servers from your IP address. We do not use IP addresses to build a profile of you, and we do not retain them beyond what is required to return the response, secure the Service against abuse, and meet legal obligations.

We do not use crash reporters, third-party analytics SDKs, or advertising identifiers in the Software.

3. Feature-by-Feature Details

3.1 Browsing, Ad and Privacy Blocker

Your browsing history is stored only on your device. The Ad and Privacy Blocker applies filter rules on your device. Rule list updates are downloaded from qikfox servers in the same way as other updates and do not report which sites you visited.

3.2 Active-Link Protection and Safe Browsing

Active-Link Protection uses a proprietary qikfox Safe Browsing API to protect against websites, downloads, extensions, and phone numbers known to be fraudulent or malicious. Lookups are performed against threat lists using hashed or partial identifiers where possible, and qikfox does not store a record of the pages you visited or the lookups made from your installation.

On iOS, the Software also uses Google Safe Browsing, which Apple proxies through Apple's own servers; see Apple's Safari privacy disclosure. If you prefer not to use Google Safe Browsing on iOS, open "qikfox Shields & Privacy" in Settings and disable "Block Dangerous Sites." On Android, only the proprietary qikfox Safe Browsing API is used.

3.3 qikfox Search

When you use qikfox Search, your searches are proxied through our anonymized relays. We do not set cookies, fingerprint your searches, or allow any website to track you through qikfox Search. Websites that receive a search cannot relate it to you or to your other activity.

3.4 Location

If a website asks for your location, the browser asks you first. If you allow it, the website receives an approximation of your location based on your IP address. qikfox does not store your IP address or location for this purpose. The website you visited may store what it receives, under its own privacy policy.

3.5 Wallet and qikPay

Your Wallet identity is a decentralized identifier (DID), anchored in a Hyperledger-based distributed ledger to which no personal data is written. The private keys, Recovery Phrase, and PIN that control it are generated and stored only on your device. qikfox stores the public identifier and your Handle. The email address or phone number you verify is kept in our billing records for Subscription validation and is not linked to your DID or Handle, as described in Section 2.1. We do not store your Recovery Phrase and cannot reset your PIN. Wallet migration re-verifies your contact method and keeps your identity and credentials; it does not use your Recovery Phrase and does not create a new wallet or Handle.

qikPay stores the ledger and entitlement records described in Section 2.2. No fiat currency or cryptocurrency is held.

3.6 IPFS

IPFS is a peer-to-peer network qikfox does not control. When you retrieve content by its content address, your request may be visible to the peers or gateways that serve it. If you enable node functionality, other peers may see your node's network address and the content your node serves. Content you publish to IPFS is public, may be copied and pinned by others, and cannot be reliably deleted. qikfox does not log which IPFS content you retrieve.

3.7 Smart Stacks

Data stored or created in Smart Stacks is end-to-end encrypted on your device before upload, using keys held only by you. The encrypted data is stored with a cloud storage partner selected by qikfox. Neither qikfox nor the storage provider can decrypt it. Only you, and the specific people you share an item with, can read it. qikfox stores the amount of storage you are using so that it can enforce your allocation. qikfox reserves the right to change cloud storage providers; encrypted data remains unreadable to any provider.

When you share or publish an item, you make it decryptable by the recipients you choose. Content you make publicly discoverable can be viewed by anyone, and qikfox may act on public or shared content in response to reports or legal requests as described in the Terms.

3.8 Onqik Decentralized Email

Onqik messages are end-to-end encrypted on your device using a Double Ratchet protocol and are delivered peer-to-peer through a DIDComm relay service that runs on your device. Messages are stored only on your device and on the recipient's device. qikfox cannot read message content and does not hold copies. Any infrastructure qikfox operates to help peers locate one another does not have access to message content. Because messages are encrypted and stored only on user devices, qikfox cannot produce message content in response to legal process.

3.9 AI Assistant, proxyLLM, BYOLLM, and Data Island

proxyLLM Service. When you use the AI Assistant with the proxyLLM Service, your prompt, any page content or Data Island content needed to answer it, and the model's response pass through qikfox relays to a large language model. The model is currently operated by a partner on our behalf; qikfox strips account identifiers before forwarding the request, so the provider receives the request anonymously and cannot associate it with you. qikfox does not retain your prompts or the responses after the response is returned, does not use them to train or improve any model, and our agreement with the partner prohibits the partner from retaining them or using them for its own purposes, including training. qikfox reserves the right to replace the third-party model with its own. qikPay records only the Credit amount deducted and the operation type, never the content.

BYOLLM. When you connect your own model, your prompts go directly from your device to the provider you configured, under that provider's privacy policy. qikfox never sees this traffic. Your API keys are stored on your device in an encrypted keystore and are not transmitted to qikfox.

Data Island. Data Island content is stored only on your device and is never synced to qikfox. When you ask the AI Assistant to store or retrieve Data Island content, the relevant content is sent to the model (proxyLLM or your BYOLLM provider) as part of that request only, and is not retained after the response.

Accuracy. AI summaries and answers may be inaccurate, misleading, or false. Do not submit sensitive or private information you would not want processed by a language model, and use caution with anything related to health, finance, or personal safety.

3.10 Notes Application

Notes are stored only on your device. qikfox holds no copy. Generation requests made through the AI Assistant are handled as described in Section 3.9. If you choose to publish or share a note through Smart Stacks, Section 3.7 applies to the shared copy.

3.11 Antivirus and Managed Services

The Antivirus component downloads virus definitions, which qikfox licenses from third-party security vendors, to your device and scans locally. It includes a file scanner and, on Windows, may include an on-access scanner. If a file is identified as potentially malicious, a cryptographic hash of the file (not the file itself) may be sent to our antivirus definition partner for classification. Anonymized threat information, containing no identifiable information, may also be transmitted to that partner. Scan results stay on your device.

Managed Services data handling is described in Section 2.1.

3.12 qiktalk

qiktalk is a private video and audio conferencing tool built on qikfox's own WebRTC implementation (STUN/TURN/ICE). What you say or type is not logged or saved. We process only your IP address and the meeting URL, and only to connect the call; this session information is not retained after the call ends. Chat messages are cached on your device for the duration of the meeting and may pass through a qikfox relay server but are never stored by us.

qikfox does not authenticate qiktalk participants and will never contact you through a qiktalk call. Do not share confidential information with anyone on qiktalk, Onqik, or any other channel unless you are certain who you are talking to.

3.13 qikfox Verified Reviews

Verified Reviews are public. When you submit a review, we publish the review text and your universal handle, and nothing else. A universal handle is like a domain name and does not reveal your personal identity unless you choose to associate it. Because we do not correlate handles with email addresses or phone numbers, a review cannot be traced back to you through qikfox. Do not post false or misleading information or content that defames anyone, and remember that anything you write in the review itself is public. qikfox may remove reviews.

3.14 Updates and Cohort Analytics

See Sections 2.3 and 7. Updates push only binaries and components. Cohort analytics describe general use of the browser (cohort, session length, platform, version) and cannot be combined in any way to identify you.

3.15 Nightly, Dev, and Beta Versions

Nightly, Dev, and Beta versions are experimental previews used to find and fix errors before release. They are unfinished and untested, and their behavior may not be fully described by this policy. Beta features may collect additional diagnostic information, which we describe in the release notes for that version.

4. How We Use Information

We use the information described above only to:

  • Register, recover, and migrate your Wallet and verify that you control the linked email or phone number
  • Deliver the Plans, Credits, storage, and features you purchase, and enforce Plan Credit allocations, License counts, Device Limits, and Credit expiration rules
  • Process payments through our Payment Processor and issue invoices
  • Operate Credit transfers, shared balance access, and shared Subscriptions between users at your direction
  • Provide support and Managed Services
  • Send transactional messages: verification codes, order confirmations, invoices, renewal and price change notices, and notices required by the Terms or by law
  • Keep the Service secure, detect fraud, refund abuse, chargeback abuse, and violations of the Terms
  • Measure how many installations from each monthly cohort are active, in aggregate
  • Comply with legal obligations and enforce our rights

We do not use your information for advertising, profiling, or automated decisions that have legal or similarly significant effects on you.

5. Who We Disclose Information To

We do not sell personal information and do not share it with third parties for their own purposes. Personal information is disclosed only in the following circumstances.

Partners who provide services to us. These organizations process data solely on our behalf and on our instructions, and our agreements with them prohibit any other use:

  • Payment partner: card details entered at checkout, billing name and address, transaction amount
  • E-commerce platform underlying the Qikware store: order and customer information for purchases made there
  • Email and SMS delivery providers: your email address or phone number, for verification codes and transactional messages
  • Cloud storage partner: your end-to-end encrypted Smart Stacks data, which it cannot decrypt
  • Language model partner: anonymized proxyLLM requests with account identifiers removed
  • Antivirus definition partner: file hashes and anonymized threat information
  • On iOS only, Google Safe Browsing via Apple's proxy, as described in Section 3.2

At your direction. When you share an item, publish content, send Credits, share your balance, invite a Member, or post a Verified Review, the recipients see what you chose to send them, including your Handle.

Legal requirements. We may disclose the limited information we hold if required by valid legal process, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of qikfox, our users, or the public. What we hold consists of billing records on one side and Handle and ledger records on the other, and the two are not correlated. We cannot disclose what we do not have: browsing history, end-to-end encrypted content, local notes, Data Island content, or Onqik message content, and we cannot link a Handle to a name, email address, or phone number.

Corporate transactions. If qikfox is involved in a merger, acquisition, or sale of assets, information may be transferred to the successor, who will be bound by this policy for information collected under it. We will notify you before your information becomes subject to a different privacy policy.

6. Data Retention

  • Verified contact method (billing records) and Handle (ledger records), held separately and uncorrelated: for as long as your Account is active, plus 30 days after closure to allow recovery of mistaken closures
  • Order, invoice, and qikPay ledger records: 7 years after the transaction, as required by tax and accounting law
  • Subscription and entitlement records: for the life of the Subscription, plus the same 7-year period for billing-related records
  • Support records: 2 years after the request is closed
  • Managed Services proof of ownership: until eligibility is verified, then deleted
  • Verification code records: 30 days
  • Encrypted Smart Stacks data: for the life of the Subscription, then 30 days for download, then deleted
  • Cohort heartbeat and update statistics: retained only in aggregated form, indefinitely
  • qiktalk session information: not retained after the call ends
  • proxyLLM prompts and responses: not retained after the response is returned

Data we do not hold (Section 1) has no retention period because it never leaves your device.

7. Security

qikfox uses encryption in transit for all communication between the Software and our servers, end-to-end encryption for Smart Stacks and Onqik, an encrypted local keystore for BYOLLM credentials, and access controls that limit staff access to the minimal data we hold. Automatic updates deliver security fixes. No method of transmission or storage is completely secure, and the security of information stored on your device depends on your device, your PIN, and your Recovery Phrase. qikfox support will never ask for your PIN, Recovery Phrase, or payment card details.

8. Your Rights and Choices

8.1 Choices within the Service

  • Use BYOLLM instead of the proxyLLM Service if you prefer that no AI request pass through qikfox
  • Disable IPFS node functionality in Settings
  • Adjust or disable Ad and Privacy Blocker rules per site
  • On iOS, disable Google Safe Browsing under "qikfox Shields & Privacy"
  • Decline location requests from websites
  • Control Smart Stacks sharing settings for each item, and revoke Member and shared balance access in the Wallet

8.2 California residents

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, you have the right to know what personal information we collect, use, and disclose; to request deletion; to request correction; to opt out of sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights. Because qikfox does not sell or share personal information and uses sensitive personal information only to provide the Service you request, there is nothing to opt out of or limit, but you may still submit any request.

The categories of personal information we collect are identifiers (email, phone, and order number on the billing side; Handle and DID public identifier on the ledger side, not correlated with each other), customer records (name, billing and shipping address, payment confirmation), commercial information (purchases, Credits, transfers, Subscriptions), internet activity limited to the anonymized cohort heartbeat and feature lookups described in Section 2.3, and the content of support communications. We collect them from you directly and from your use of the Service. We use them for the purposes in Section 4 and disclose them only as described in Section 5. We have not sold or shared personal information in the preceding 12 months.

To exercise your rights, email privacy@qikfox.com from the email address used at purchase, or contact us at the address in Section 13. For billing records, we will verify your identity by confirming control of the email address or phone number used at checkout. Because we do not correlate Handles or DIDs with contact information, we usually cannot verifiably associate ledger-side records with a specific person; where we cannot verify that information relates to you, applicable law does not require us to produce, correct, or delete it, and attempting to do so could compromise the privacy protections described in Section 2.1. You may designate an authorized agent by providing written authorization. We will respond within 45 days, extendable once by a further 45 days where reasonably necessary.

8.3 Other United States residents

Residents of states with comprehensive privacy laws have similar rights to access, delete, correct, and port their personal information, and to opt out of sale, targeted advertising, and certain profiling. qikfox does not engage in any of those opt-out activities. Submit requests as described in Section 8.2. If we deny a request, you may appeal by replying to our response, and we will respond to the appeal within 45 days.

8.4 European Economic Area, United Kingdom, and Switzerland

Where these laws apply, qikfox is the controller of the personal information described in this policy. Our legal bases are: performance of our contract with you (Wallet registration, purchases, delivery of the Service, support); our legitimate interests in securing the Service, preventing fraud, and understanding aggregate usage through anonymized cohort analytics; compliance with legal obligations (tax and accounting records, legal process); and your consent where you choose to share, publish, or transfer information to others. You have the right to access, rectify, erase, restrict, and port your personal information, to object to processing based on legitimate interests, to withdraw consent, and to lodge a complaint with your supervisory authority. Contact privacy@qikfox.com to exercise these rights.

9. International Transfers

qikfox is located in the United States, and the information we hold is processed there. Where we transfer personal information from the EEA, UK, or Switzerland, we rely on standard contractual clauses approved by the relevant authorities or other lawful transfer mechanisms.

10. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Under the Terms, a parent or legal guardian who is at least 18 may permit a minor in their care to use an Account under supervision; in that case the parent or guardian is the Account holder and the contact information we hold is theirs. If you believe a child under 13 has provided personal information to us, contact privacy@qikfox.com and we will delete it.

11. Websites and Storefronts

Our websites (including qikfox.com and offers.qikfox.com) and the Qikware store use only the cookies strictly necessary to operate the site, keep your cart, and complete checkout. We do not use advertising cookies, third-party tracking pixels, or cross-site tracking. The Qikware store runs on an e-commerce platform operated by a partner that processes order data on our behalf.

12. Changes to This Policy

We may update this Privacy Policy. If we make a material change, we will notify you at least 30 days before it takes effect by email, by an in-product notice, or by posting the updated policy at https://qikfox.com/privacy with a new Last Updated date. We will not begin using your information in a materially different way without giving you that notice.

13. Contact Us

qikfox Cybersecurity Systems, Inc.
Attn: Privacy
55 E 3rd Ave
San Mateo, CA 94401
Privacy: privacy@qikfox.com
Support: support@qikfox.com

Related qikfox pages

Questions about your privacy?

Email privacy@qikfox.com and we will answer, or use the contact page for anything else.