Qwrki

Privacy policy

Updated 29 September 2026

About this policy

This policy covers the Qwrki app at app.qwrki.com. The Qwrki website at qwrki.com has its own policy.

The app is operated by Qwrki Pty Ltd, 74 Thorburn St, Nimbin NSW 2480, Australia. Questions about this policy go to [email protected].

Information the app holds

An organisation that uses Qwrki owns its workspace. Its members enter and manage records such as customers, cases, projects, invoices and files. Qwrki stores those records to run the app for that organisation and shows them to that organisation's members, according to the roles its admins assign, and to the people the organisation shares them with, such as its portal contacts and visitors to its public forms and surveys.

To sign you in, Qwrki keeps your email address and your password, stored only as a one-way hash, and sets a sign-in cookie in your browser.

When a member opens a page in the app, Qwrki records the page's path, the referring page, the device type, the country and the campaign value, with a daily pseudonymous visitor value, so the organisation's admins can see how the app is used.

Google user data

When you connect a Google account, Qwrki asks Google for the permissions below and nothing else.

Google permissions Qwrki can request
PermissionConnected byWhat Qwrki readsWhy
openidAn admin, for the organisationThe Google account's identifier.So a later reconnection can only use the same Google account.
analytics.readonlyAn admin, for the organisationReport totals for the Google Analytics property the admin picks: sessions, users, conversions and sessions by channel.To show the organisation its own website figures on its dashboards.
webmasters.readonlyAn admin, for the organisationSearch Console totals for the site the admin picks: clicks, impressions and click-through rate, also split by search query, page, device and country.To show the organisation how its site appears in Google Search.
adwordsAn admin, for the organisationPerformance reports for the Google Ads account the admin picks: cost, clicks, impressions and conversions. Google offers no read-only Ads permission; Qwrki only reads reports and never changes a campaign.To show the organisation its advertising figures beside its other figures.
openid, emailA member, for themselvesThe identifier and email address of the member's own Google account.To show which account is connected and to refuse a different account on reconnection.

Qwrki's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.

Google's policy: https://developers.google.com/terms/api-services-user-data-policy

How Qwrki uses Google user data

Qwrki does not access Gmail or Google Drive. If this changes, this policy will say so first.

Qwrki uses Google user data only to provide the features described in the table above, which the person connecting the account can see in the app.

Who can see it

Figures from an organisation's Google Analytics, Search Console and Google Ads connection are shown to members of that organisation. Only its admins and owners can connect, update or disconnect that connection.

AI features

An organisation's admins can give one of its AI Employees access to a connected Google Analytics, Search Console or Google Ads account. The figures Qwrki stored from that account are then included in requests to Qwrki's AI model provider to draft that Employee's work. Qwrki sends those requests with the provider's logging of prompts turned off.

Qwrki does not use Google user data to train or improve AI or machine learning models.

Storage, retention and deletion

Text already copied into a case stays in Qwrki as part of that case.

Report figures from Google Analytics, Search Console and Google Ads are deleted automatically 400 days after the period they cover, while the organisation is active. Figures of a suspended organisation are kept until it is active again. Copies in exports, saved reports, report emails, drafts and notifications are not automatically deleted.

Google access tokens are stored encrypted with AES-256-GCM.

Every page from the app carries a header telling browsers to keep using HTTPS. Stored report figures belong to one organisation: the figures table enforces row-level security, and every request that reads those figures runs with that organisation set as the tenant. Qwrki only shows those figures to members of the organisation they belong to, in the app and in emails they receive.

When a Google connection is disconnected, or when a member's own Google connection is disconnected because that member is removed from an organisation, Qwrki overwrites its stored token so it can no longer be used and discards its cached access token. After an organisation's Google Analytics, Search Console or Google Ads connection is disconnected, Qwrki's background job deletes the report figures Qwrki stored from that connection and the figure files exported from it, normally within two hours. Copies already in the organisation's own work keep what they contain: drafts an AI Employee wrote, saved reports already run, notifications in Qwrki, alert messages already posted to a chat tool, and emails already sent or waiting to send.

When you disconnect Google in Qwrki, Qwrki can no longer use the access. Google keeps listing Qwrki until you remove it in your Google Account, under Security, Third-party apps and services. Removing it there ends every Qwrki connection that Google account holds, in every organisation.

What Qwrki never does with Google user data

Qwrki does not sell Google user data, does not use it for advertising, and does not transfer it to data brokers or information resellers.

People at Qwrki do not read Google user data, except with your explicit permission for specific data, when needed for security purposes such as investigating abuse, to comply with applicable law, or when it has been aggregated and anonymised for internal operations.

Your Google Account permissions page: https://myaccount.google.com/permissions

Services Qwrki uses

Qwrki uses service providers for AI features, bot protection, sending email and billing. The app, its database and its file storage are hosted on servers in the United States.

Changes to this policy

When this policy changes, this page shows the new text and the date it was updated.

The outside services that may receive company data are listed on our subprocessors page.