Privacy Policy

Privacy Policy

Last updated: April 28, 2026

How Qarote collects, uses, and protects your data. In short: we read RabbitMQ management and metrics data to detect and explain incidents — we never access or store your message payloads unless you explicitly enable payload capture for tracing.

Section 01

Information We Collect

1.1 Account Information

When you create an account with Qarote, we collect:

  • Email address
  • First and last name
  • Password (encrypted)
  • Company information (optional)

1.2 Usage Data

We automatically collect information about how you use our service:

  • RabbitMQ server connection details (host, port, credentials)
  • Queue monitoring metrics (queue depths, message rates, consumer counts — message payloads are never accessed or stored)
  • Application performance metrics
  • Error logs and debugging information
  • Feature usage patterns

1.3 Technical Information

We collect technical information about your device and browser:

  • IP address
  • Browser type and version
  • Operating system
  • Device information
  • Cookies and similar tracking technologies
Section 02

AI Features and Broker Context

When you use AI Explain (root-cause analysis), Qarote sends relevant broker context — such as the affected queue, metrics, topology, and recent configuration changes — to a language-model provider to generate an explanation. We do not send your message payloads. You choose the provider, and this choice determines where the data goes:

  • Managed — processed by our model provider (Anthropic) using Qarote's account.
  • Bring your own key — processed by your own Anthropic or OpenAI account, under that provider's terms.
  • Local (Ollama) — processed entirely on your own infrastructure; no broker context leaves your network.

Self-hosted deployments that require strict data residency can keep all AI processing in-network with the local provider.

Section 03

Agent Access (MCP)

You may connect AI agents to Qarote over the Model Context Protocol using scoped API keys. Keys are shown once and stored only as a hash. Depending on the scope you grant, an agent can read monitoring data, request diagnoses, and — where you enable it — perform management actions on your brokers. Actions taken via an agent are logged for audit. You are responsible for the scopes you grant and for the agents you authorize.

Section 04

How We Use Your Information

We use the information we collect to:

  • Provide and maintain our RabbitMQ monitoring service
  • Process payments and manage your subscription
  • Send you important service updates and notifications
  • Provide customer support
  • Improve our service and develop new features
  • Ensure security and prevent fraud
  • Comply with legal obligations
Section 05

Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

3.1 Service Providers

We may share information with trusted third-party service providers who assist us in operating our service:

  • Payment processors (Stripe)
  • Email service providers
  • Analytics services
  • Cloud hosting providers

3.2 Legal Requirements

We may disclose your information if required by law or to:

  • Comply with legal processes
  • Protect our rights and property
  • Prevent fraud or security issues
  • Protect the safety of our users
Section 06

Data Security

We implement appropriate security measures to protect your personal information:

  • Encryption of data in transit and at rest
  • Regular security audits and assessments
  • Access controls and authentication
  • Secure data centers and infrastructure
  • Employee training on data protection

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

Section 07

Data Retention

We retain your personal information for as long as necessary to provide our service and fulfill the purposes outlined in this privacy policy. Specifically:

Account informationUntil you delete your account
Queue monitoring metrics (depths, rates, consumer counts)30 days, automatically purged
Message trace events (metadata)7 days, automatically purged
Usage dataUp to 2 years for analytics purposes
Payment informationAs required by law and payment processors
Support communicationsUp to 3 years
Section 08

Your Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access: Request a copy of your personal information
  • Correction: Request correction of inaccurate information
  • Deletion: Request deletion of your personal information
  • Portability: Request transfer of your data to another service
  • Objection: Object to certain processing activities
  • Restriction: Request limitation of processing

To exercise these rights, please contact us at security@qarote.io

Section 09

Cookies and Tracking

We use cookies and similar technologies to enhance your experience:

  • Essential cookies: Required for basic functionality
  • Analytics cookies: Help us understand usage patterns
  • Preference cookies: Remember your settings
  • Marketing cookies: Used for targeted advertising (with consent)

You can control cookie settings through your browser preferences.

Tracking technologies we use

  • PostHog — product analytics and session replay. Records interactions on the page (clicks, navigation, form inputs) and may capture anonymized recordings of your session to help us improve the product. Hosted by PostHog Inc. Cookies and local storage keys: ph_*.
  • Google Tag Manager — loads marketing and analytics tags. Downstream cookies depend on the tags configured and may include _ga, _gid.
  • TawkTo — live chat widget for support requests. Drops tawk_* cookies and connects to embed.tawk.to.

None of these technologies load until you accept them in the consent banner shown on your first visit. You can change your decision at any time via the "Cookie preferences" link in the page footer.

Section 10

International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers, including:

  • Standard contractual clauses
  • Adequacy decisions
  • Certification schemes
  • Binding corporate rules
Section 11

Children's Privacy

Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you become aware that a child has provided us with personal information, please contact us immediately.

Section 12

Changes to This Privacy Policy

We may update this privacy policy from time to time. We will notify you of any material changes by:

  • Posting the updated policy on our website
  • Sending you an email notification
  • Displaying a notice in our application

Your continued use of our service after any changes constitutes acceptance of the updated policy.

Section 13

Contact Us

If you have any questions about this privacy policy or our data practices, please contact us:

  • Email: support@qarote.io
  • Address: 229 rue Saint-Honoré, 75001, Paris, France

Questions? Email support@qarote.io · 229 rue Saint-Honoré, 75001 Paris, France

See also our Terms of Service.