Privacy Policy
Quorum Privacy Policy
This Privacy Policy explains how Pampas Systems, Inc. (“Quorum,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects information when you use the Quorum mobile application, websites, accounts, health-data features, the Axiom assistant, and related services (the “Services”). It is incorporated by reference into the Quorum User Agreement; accepting the User Agreement constitutes acceptance of this Policy. Quorum is a consumer health and wellness information service. It is not a healthcare provider, and the information you share with us is generally not protected by HIPAA. The protections that apply are the ones described here and required by applicable law.
1. Who we are and how to contact us
The controller of your information is Pampas Systems, Inc., a company based in the United States. You can reach us at hello@quorum.care with any privacy question or request.
2. Information we collect
2.1 Health and fitness data you authorize (Apple Health / HealthKit)
With the permissions you grant, Quorum reads health and fitness data from Apple Health (HealthKit). Depending on what your devices record and what you authorize, this can include, for example: heart rate, resting heart rate, and heart-rate variability; sleep stages and timing; steps, distance, and workouts; cardio fitness (VO₂max); blood pressure; respiratory measures; body measurements such as weight, body-fat percentage, and waist circumference; nutrition entries; mobility and walking measures; and audio-exposure levels. Quorum may import multiple years of history for the categories you authorize.
This is sensitive health information. We collect it only after you grant HealthKit permission, and only the categories you authorize.
2.2 Information you provide during onboarding (optional)
If you choose to answer optional onboarding questions, we collect an age range, sex assigned at birth, a self-reported activity level, and your reasons for using Quorum. These are optional and self-reported; you may skip them. We use them to tailor context and dashboard focus. We do not treat self-reported answers as measured clinical data, and an answer of “intersex” or “prefer not to say” is not converted into any default value.
2.3 Account and authentication data
To create and secure an account we collect your email address and name, and authentication data for the method you use — a one-time email code, a passkey (WebAuthn credential), or Sign in with Apple (including the email address Apple provides, which may be a private relay address).
2.4 Legal-acceptance records
When you accept the User Agreement, we record a receipt: your account identifier, the document identifier, version, effective date, and a content fingerprint (SHA-256) of the exact document you accepted, the confirmations you gave, the platform, app version, locale, and a timestamp. These receipts are kept as a record of consent.
2.5 Usage, analytics, and device data
We collect first-party product-analytics events (for example, which screens and flows you use) to understand and improve the Services, and technical data such as app version, device and operating-system information, IP address, error reports, and diagnostic logs. Our marketing website uses Google Analytics; the Quorum app’s product analytics are collected and stored by us.
3. How we use information
We use information to:
- provide the Services — import and organize the data you authorize, and calculate trends, baselines, summaries, and wellness-oriented observations;
- power the Axiom assistant, which generates AI-assisted explanations and conversations about your data (see Section 4);
- personalize context and dashboard focus using your optional onboarding answers;
- authenticate you, secure accounts, and prevent abuse and fraud;
- operate, maintain, debug, and improve the Services, including product analytics;
- communicate with you about the Services and respond to support requests; and
- comply with law and enforce our agreements.
We do not use HealthKit data for advertising, marketing, or unrelated data mining, and we do not sell your personal information or share it for cross-context behavioral advertising.
4. The Axiom assistant and AI processing
Axiom answers questions about your health data. To generate a response, relevant information from your account — including health-related data and computed findings — is sent to our AI service provider, OpenAI, which processes it to produce the response and returns it to us. OpenAI acts as a service provider under API terms that do not permit it to use your data to train its models.
Axiom renders precomputed, source-grounded findings and does not independently diagnose. Outputs can still be incomplete or wrong and are not medical advice. You control whether to use Axiom; asking Axiom a question is what sends the relevant data to the AI provider.
5. How information is stored and secured
We host the Services on Google Cloud Platform in the United States. Account and health data are stored in a managed database on a private network, and older data may be archived to cloud storage. Data is encrypted in transit and at rest, access is restricted, and cross-account isolation is enforced. No system is perfectly secure, and we cannot guarantee absolute security.
6. How we disclose information
We disclose information only as follows:
- Service providers. We use vendors that process information on our behalf under contract: OpenAI (Axiom AI responses), Google Cloud (hosting, storage, and infrastructure), Apple (Sign in with Apple and push notifications), Google Workspace (transactional email), and Sentry (error monitoring). Our marketing website also uses Google Analytics.
- At your direction. When you ask us to share or export information.
- Legal and safety. When required by law or legal process, or to protect the rights, safety, or security of users, the public, or Quorum.
- Business transfers. In a merger, financing, acquisition, or sale of assets, subject to this Policy and applicable law.
We do not disclose HealthKit data to third parties for advertising or for their own independent purposes, and we do not sell it.
7. Data retention and deletion
We keep information for as long as your account is active and as needed to provide the Services, then for a limited period afterward for backups, security, dispute resolution, and legal obligations.
You can delete your account in the app or by contacting hello@quorum.care. Deleting your account deletes your health samples, findings, onboarding answers, and related records from our active systems. Residual copies may persist in routine backups for a limited period, and legal-acceptance receipts may be retained as a record of consent as permitted by law.
8. Your choices and rights
- HealthKit permissions. You choose which categories to authorize and can revoke access at any time in Apple’s Health settings. Revoking limits features and does not by itself delete data already provided to Quorum.
- Optional onboarding. You may skip these questions or update your answers.
- Access, correction, deletion, and portability. You can request a copy, correction, or deletion of your information, and you can delete your account.
- Withdraw consent. You can stop using the Services and delete your account at any time.
Depending on where you live, you may have additional rights under state or national privacy laws, including rights to know, access, correct, and delete personal information, and to non-discrimination for exercising those rights. We honor verified requests as required by the law that applies to you; contact hello@quorum.care to make a request.
9. Sensitive data and legal bases
Health data is sensitive personal information and, in some places, “consumer health data.” We process it based on your consent — your HealthKit authorization and your acceptance of the User Agreement — and as necessary to provide the Services you request, secure the Services, and comply with law. We do not use sensitive health data for advertising or sell it.
10. Breach notification
If a breach of security affects your information, we will notify you and any regulators as required by applicable law, including the FTC Health Breach Notification Rule where it applies and state breach-notification laws.
11. Children
The Services are for adults. You must be at least 18 to use Quorum, and we do not knowingly collect information from anyone under 18. If we learn we have, we will delete it.
12. International users and data transfers
We operate the Services from the United States, and information is processed and stored in the United States. If you use the Services from outside the United States, you understand that your information is transferred to and processed in the United States.
13. Changes to this Policy
We may update this Policy to reflect changes in the Services, law, or our practices. The version and effective date identify the Policy in force. If a change is material, we will provide notice and, where required, ask you to accept again.
14. Contact
Questions or requests about your privacy may be sent to:
Pampas Systems, Inc.
Email: hello@quorum.care
© 2025–2026 Pampas Systems, Inc. All rights reserved. Quorum is a wellness and informational product and is not a medical device.