Privacy policy
Last updated 9 October 2026
What we collect, why we need it, and your rights.
Who is responsible
QuarryPasswords is operated by Adstralia LDA (NIPC 518542807), trading as Specscreen, at Rua da Tecnologia K-Épsilon, nº1 9560-421, Lagoa, Açores, Portugal. We are the data controller. Contact: support@specscreen.com.
Data and purposes
- Sharing and requests: encrypted contents, identifiers, labels, requested services, recipient details, status, times and approximate country. We use these to deliver shares, requests and history under our contract with you. Shared contents are encrypted in your browser; we do not receive their decryption keys. Labels and request metadata are not encrypted.
- Accounts: email, optional username, password hash and encrypted vault keys, to provide your account under our contract. Login and vault passwords are not stored in readable form.
- Security: IP addresses, browser and connection information, approximate location, session identifiers and login activity. Our legitimate interest is preventing abuse and protecting accounts. Raw IP addresses are not stored with shares, history or sessions.
- Payments: customer and transaction identifiers, amounts, currency, status and subscription dates, to provide purchased access under our contract and meet tax and accounting obligations. Stripe collects payment and billing details; we do not receive full payment card numbers or security codes.
Data comes from you, your browser, payment providers and users who send you requests. We process contact details supplied by another user in our legitimate interest in delivering their request. Guest sharing requires no account. Email and authentication details are required for accounts; payment details are required for purchases. Without them, those features are unavailable.
Retention
- Shares: contents deleted on retrieval, failed-attempt lockout or expiry (maximum 30 days). Metadata and history remain until 90 days after scheduled expiry.
- Requests: seven days to respond, then seven days to retrieve the response. Contents are deleted on retrieval, applicable cancellation or lockout, vault reset or expiry. History remains until 90 days after the later request or response expiry.
- Accounts and vaults: until account deletion; unverified accounts expire after 48 hours. Sessions last seven days or until logout; device recognition lasts 180 days from last login.
- Authentication: expired verification and recovery records are removed during cleanup. Temporary security records are removed when no longer needed to prevent abuse. Queued emails are deleted after delivery or expiry.
- Billing: account-linked records until account deletion; payment-event receipts for 90 days. Financial records held by Stripe remain for applicable legal and accounting retention periods.
Expired records are removed by scheduled cleanup; outages or backlogs can delay deletion. Deleted data may remain in recovery backups for up to 30 days. Account deletion removes linked shares, requests and history, but not copies saved by recipients or your details in another user’s request history before its expiry.
We store purchase confirmations, accepted Terms and consent, and withdrawal/refund records while your account exists. Stripe retains payment records under its own retention rules.
Who receives data
Link holders can retrieve shared contents, subject to any passphrase or account restriction; request responses are available to the requester. Addressed requests show the recipient the sender’s email, username and request label. We may disclose records when legally required.
- Cloudflare hosts the service and processes technical data. Its Turnstile login checks use IP, browser and connection signals to block bots; Cloudflare also uses these as an independent controller to improve bot detection.
- Resend receives your email and authentication, security and purchase messages for delivery, never shared credentials.
- Stripe receives your email and account identifier to process payments, alongside billing details you provide directly.
These providers may process data outside the EEA, including in the US. Their transfer agreements provide safeguards, including EU Standard Contractual Clauses where required: Cloudflare, Resend and Stripe.
Cookies
We use essential authentication and security cookies:
- __Host-quarry_session: sign-in, seven days; removed on logout.
- __Host-quarry_challenge: email verification, up to ten minutes.
- __Host-quarry_device: device alerts, 180 days, renewed on login.
You can delete them in your browser; this may sign you out or trigger a device alert. We use no advertising or analytics cookies. Stripe’s hosted payment pages use their own cookies.
Your rights
You may request access, correction, erasure, restriction or portability of your personal data, and object to processing based on legitimate interests, where applicable. Contact support@specscreen.com. You can also complain to Portugal’s CNPD or your local supervisory authority. Legal retention obligations may limit erasure. We do not make automated decisions with legal or similarly significant effects on you.