Quotain Privacy Policy

Last updated: May 29, 2026

California Notice at Collection / State Privacy Rights Notice: See the State Privacy Rights Notice section below for important information about your rights under applicable state privacy laws.

Eden AI, Inc., a Delaware corporation doing business as Quotain ("Quotain," "we," "us," or "our") provides a business-to-business sales-roleplay software-as-a-service platform. Sales representatives use Quotain to practice live sales conversations against AI buyer personas, in text or voice, and receive automated scorecards. This Privacy Policy describes how Quotain collects, uses, and shares information through our marketing website at https://quotain.com and our product at https://app.quotain.com (collectively, the "Service").

By accessing the Service, you accept this Privacy Policy and our Terms of Use, and you consent to our collection, storage, use, and disclosure of your information as described here.

1. Information We Collect

1.1 Information you and your organization provide.

When you or your organization uses the Service, we collect and process the following categories of information (collectively, "Customer Data"):

  • Account data: your name, work email address, organization name, role, password hash, (if you register a passkey) the public-key credential used for passwordless sign-in, and (if you sign in with an identity provider) the OAuth identity returned by Google, Microsoft, or another configured provider.
  • Roleplay transcripts: the text of each roleplay conversation, including speaker turns, between you and the AI buyer.
  • Voice recordings: the audio of each voice roleplay, stored in Cloudflare R2.
  • Facial-expression signals: if you choose to turn your camera on during a voice roleplay, your webcam video is analyzed entirely within your browser to derive a timeline of expression and engagement signals — for example, estimated attentiveness, confusion, or emotional tone, each scored from 0 to 1. The raw video and the underlying facial-geometry measurements are processed on your device in real time; they are never transmitted to or stored by Quotain. Only the derived numeric signals are saved, tied to that roleplay session, and shared with the foundation-model provider that produces the delivery feedback on your scorecard. Using your camera is optional: if you keep your camera off or decline the camera permission, no facial-expression signals are collected. We do not use these signals to identify or authenticate you, and we never use them to make decisions that produce legal or similarly significant effects.
  • Scorecards and performance metrics: the rubric scores, written feedback, and derived metrics that Quotain produces from each roleplay.
  • Buyer personas: the product descriptions, ideal-customer-profile descriptions, and persona attributes that representatives or admins provide so the AI buyer can simulate the right conversation.
  • Uploaded files: PDFs, documents, and other files you upload to the in-product knowledge library.
  • OAuth-connected integration data: when you connect a third-party tool such as Notion, Salesforce, or Gong, the access tokens we hold and the data those tools return when Quotain uses the integration on your behalf. Integration-derived content may be processed to provide requested features and may be retained where it is imported, saved, included in generated outputs, included in chat history, or otherwise used as part of the Service.
  • Support communications: any messages you send us at [email protected] or through other support channels.

1.2 Information collected automatically.

When you interact with the Service, we and our service providers automatically log:

  • Telemetry: Langfuse traces of LLM calls (prompts, tool inputs and outputs, model identifiers, latencies); Sentry error reports (stack traces, breadcrumbs); and PostHog product-analytics events (page views, feature usage, anonymous and authenticated user identifiers).
  • Application logs: HTTP request logs, including IP address, user agent, request path, timing, and outcome.
  • Device and browser data: browser type and version, operating system, device type, screen resolution, and language settings.
  • Cookies and similar technologies: see our Cookie Notice for details.

1.3 Information about others.

Some features let you bring information about other people into the Service. When you connect a third-party tool (such as Notion, Salesforce, or Gong) or upload files to the knowledge library, the data we process on your behalf may include personal information about third parties — for example, your prospects, customers, or colleagues. You and your organization are responsible for having the rights and permissions needed to provide that information to us. We process it on your organization's behalf, as a service provider, solely to provide the Service, and we do not use it for our own independent purposes.

1.4 Children.

The Service is intended for use by sales professionals and is not directed to anyone under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us at [email protected].

2. How We Use Information

We use Customer Data and the automatic telemetry described above for the following purposes, and only for these purposes:

  • Operating the Service: hosting roleplays, generating buyer personas, producing scorecards — including, where you enable your camera, the delivery feedback derived from the in-browser facial-expression signals described in Section 1.1 — authenticating users, and delivering the features your organization has subscribed to.
  • Debugging and incident response: investigating errors, security incidents, and reports from customers, including by reviewing the relevant traces and logs.
  • Aggregated and de-identified analytics: producing statistics about how the Service is used and otherwise operating and improving the Service, in each case using data that cannot reasonably be used to identify a customer or individual. We never publish customer-identifiable performance metrics, scorecards, transcripts, or recordings, and we never identify a customer or individual in marketing, case studies, blog posts, demos, pitch decks, or fundraising materials without that customer's prior written consent.
  • Service communications: sending you transactional messages, security alerts, and administrative notices about the Service.
  • Legal and compliance: complying with applicable laws, lawful requests, and legal process; protecting our or others' rights, safety, and property; and preventing fraud, abuse, and security incidents.

No sale or unauthorized sharing. We do not sell, rent, lease, or share Customer Data with third parties for their own marketing, advertising, or commercial purposes.

Foundation-model training. We do not direct or authorize our model providers to use Customer Data to train foundation models.

Targeted advertising and profiling. We do not process Customer Data for targeted advertising, and we do not use Customer Data to make automated decisions that produce legal or similarly significant effects about you.

3. How We Share Information

We share Customer Data only with the following categories of recipients, and only to the extent necessary for the purposes listed in Section 2:

  • Service providers (subprocessors): cloud infrastructure (Vercel, Neon, Cloudflare R2), foundation-model providers (such as OpenAI and Anthropic, accessed via the Vercel AI Gateway), voice and real-time providers (Deepgram, ElevenLabs, LiveKit), observability (Langfuse, Sentry, PostHog), and email delivery (Resend). A current list of subprocessors is maintained at /trust/subprocessors. These providers may process Customer Data only on our documented instructions and under written contracts that require appropriate confidentiality and security safeguards.
  • Your organization: administrators and other authorized members of the organization you belong to within the Service may see your roleplay activity, transcripts, recordings, and scorecards in accordance with the access controls you and your organization configure.
  • Legal and safety: law enforcement, regulators, courts, and other authorities when we have a good-faith belief that disclosure is required by law or is necessary to protect rights, safety, or property.
  • Business transfers: a successor entity in connection with a merger, acquisition, financing, reorganization, or sale of assets. Any successor will be bound by commitments at least as protective as those in this Privacy Policy.
  • Professional advisors: our auditors, lawyers, accountants, and insurers, in the ordinary course of their services to us and under duties of confidentiality.

4. Retention

We retain Customer Data for as long as needed to provide the Service, maintain security, comply with legal obligations, resolve disputes, and enforce our agreements.

Roleplay transcripts, scorecards, recordings, uploaded materials, and related workspace content are retained while the customer account or workspace remains active, unless deleted earlier by the customer or as part of an offboarding request.

Facial-expression signals are retained with their associated roleplay session. Raw webcam video and facial-geometry measurements are not stored.

OAuth tokens for connected integrations are retained until the customer disconnects the integration or revokes access at the source provider.

Content retrieved from connected integrations may be processed by Quotain to provide requested features, including by being provided to AI models in context. Quotain does not write to connected integration systems unless the customer authorizes that action. Integration-derived content may be retained where it is imported, saved, included in generated outputs, included in chat history, or otherwise used as part of the Service.

Operational logs, analytics data, observability traces, security records, and backups are retained for limited periods based on their purpose, our provider settings, and applicable legal or security needs. We periodically review and update these retention practices.

4.1 Biometric data: retention and destruction.

This subsection is our written retention schedule and destruction policy for biometric data, published as required by applicable biometric privacy laws, including the Illinois Biometric Information Privacy Act (BIPA). When you choose to enable your camera during a voice roleplay, the facial-expression feature transiently computes facial-geometry measurements within your browser to derive the numeric expression and engagement signals described in Section 1.1.

We do not transmit or store the raw webcam video or the underlying facial-geometry measurements. That biometric data is processed in real time on your device and is permanently destroyed as soon as the analysis that produces each derived signal is complete. We retain only the derived numeric signals, tied to their roleplay session, until you delete that session or close your account. In no event will we retain biometric data, or signals derived from it, longer than the purpose for which it was collected requires, and in any case no later than three (3) years after your last interaction with the Service.

We do not sell, lease, trade, or otherwise profit from biometric data, and we do not disclose it to any third party except as needed to provide the facial-expression feature you have requested — namely, sharing the derived numeric signals with the foundation-model provider that generates your delivery feedback — and only with your consent.

5. Security

We implement technical and organizational measures designed to protect Customer Data, including encryption in transit (TLS) and at rest, access controls, least-privilege production access, application-layer authentication, and routine vulnerability monitoring. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

6. International Transfers

Quotain is headquartered in the United States and processes Customer Data in the United States. Our service providers may process Customer Data in other countries. Where required by applicable law, we rely on standard contractual clauses or other lawful transfer mechanisms with our service providers.

7. Your Rights and Choices

Access, export, correction, and deletion. You may request a copy of your personal information, ask us to correct inaccurate information, or ask us to delete your personal information by emailing [email protected]. We aim to respond within thirty (30) days of receiving a verified request, subject to extensions permitted by applicable law. If your organization is the controller of the relevant Customer Data, we may refer your request to your organization's administrator.

Communications. You can unsubscribe from marketing emails using the link in the email. We will continue to send service-related messages (security alerts, billing notices, and similar).

Cookies and analytics. See our Cookie Notice for choices about cookies and similar technologies.

Deleting content and closing your account. You can delete certain content, such as voice recordings, directly in the product. To close your account and delete the associated Customer Data, email [email protected]; we target a 30-day response, subject to any information we are required to retain to meet legal obligations.

Do Not Track and opt-out preference signals. Some browsers send "Do Not Track" (DNT) or Global Privacy Control (GPC) signals. There is no common industry standard for responding to DNT, and we do not respond to it. Because we do not sell or share personal information (see Section 8), opt-out preference signals such as GPC have no sale or sharing to act on; where applicable law requires, we honor them as opt-out requests.

8. State Privacy Rights Notice

This section applies to residents of U.S. states with applicable privacy laws (the "State Privacy Laws"), including California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, Utah, and others as the laws evolve.

8.1 Your rights.

Depending on your state of residence, you may have the right to:

  • Request information about the categories of personal information we collect, the sources of that information, the purposes for which we use it, and the categories of third parties with whom we share it.
  • Request access to a copy of the personal information we have collected about you.
  • Request correction of inaccurate personal information we hold about you.
  • Request deletion of personal information we have collected from you.
  • Appeal our denial of a request submitted under these rights.

8.2 No sale, sharing, or targeted advertising.

We do not sell personal information within the meaning of the State Privacy Laws. We do not share personal information for cross-context behavioral advertising. We do not process personal information for targeted advertising purposes. We do not use personal information to engage in profiling that results in legal or similarly significant effects.

8.3 Sensitive personal information.

We do not collect Social Security, driver's license, or financial-account numbers, account credentials, precise geolocation, or information revealing racial or ethnic origin, religious beliefs, health, sex life, sexual orientation, or union membership.

If you choose to enable your camera during a voice roleplay, Quotain analyzes your webcam video within your browser to derive expression and engagement signals, as described in Section 1.1. This processing happens on your device; we do not retain the raw video or the underlying facial-geometry measurements, and we use the derived signals only to give you coaching feedback on your own delivery. We never use them to identify or authenticate you, and never to make decisions that produce legal or similarly significant effects. To the extent any State Privacy Law treats these signals as sensitive or biometric personal information, we process them solely at your direction to provide the feature you have requested, and we limit our use of this information to performing the Service as permitted under those laws.

Your right to limit. You may decline this processing at any time by leaving your camera off, and you may ask us to stop processing or to delete the derived signals we have stored by emailing [email protected]. We do not use sensitive or biometric personal information to infer characteristics about you for our own purposes, or for any purpose other than providing the coaching feedback you have requested.

8.4 Nondiscrimination.

You are entitled to exercise the rights described above free from unlawful discrimination.

8.5 Exercising your rights.

To exercise any of the rights above, email [email protected]. We may need to verify your identity (or that of your authorized agent) before fulfilling your request, and we may require additional information for verification. If your request is denied, you may appeal by replying to our response with the word "Appeal" in the subject line.

8.6 Additional notices.

California Shine the Light. California residents may request information about disclosures of personal information to third parties for their direct marketing purposes. We do not make such disclosures.

Nevada. Nevada residents may request that we not sell their personal information. We do not sell personal information, but you may direct any inquiry to [email protected].

8.7 Categories of personal information we collect, disclose, and sell or share.

The following describes our practices during the preceding 12 months (or since we began offering the Service, if shorter). We collect the categories of personal information below from the sources described in Section 1, for the business and commercial purposes described in Section 2, and we disclose each category only to the categories of recipients described in Section 3. Categories are listed by reference to the statutory categories in the California Consumer Privacy Act (Cal. Civ. Code § 1798.140).

Category (CCPA § 1798.140)Personal information in this categorySold or shared?
Identifiers (A)Name, work email, organization name, account and identity-provider (OAuth) identifiers, passkey credential identifier, and IP address.No
Customer records (B)Name, account name, and the role or title associated with your account.No
Commercial information (D)Records about your organization's subscription to and use of the Service.No
Biometric information (E)Facial-expression and engagement signals derived in your browser from your webcam when you choose to enable your camera. We do not store the raw video or the underlying facial-geometry measurements. May be sensitive personal information — see Section 8.3.No
Internet or other electronic network activity (F)Telemetry (Langfuse traces, PostHog events), application logs, and device and browser data.No
Geolocation data (G)Approximate location inferred from your IP address.No
Audio, electronic, visual, or similar information (H)Voice recordings of your roleplays and the webcam-derived signals described above.No
Professional or employment-related information (I)Your role, your roleplay activity, and the scores and feedback produced from it.No
Inferences (K)Scorecards, performance metrics, and the expression and engagement signals inferred from facial analysis.No

We do not collect protected classification characteristics (category C), education information (category J), or government-issued identification, financial-account, or payment-card numbers. We have not sold or "shared" — as those terms are defined under the State Privacy Laws, including sharing for cross-context behavioral advertising — any category of personal information, and we do not do so.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date above and, where appropriate, by sending you an email or posting a notice through the Service. Continued use of the Service after the updated Privacy Policy becomes effective constitutes your acceptance of the changes.

10. Contact Us

If you have questions about this Privacy Policy or our practices, or if you would like to exercise a privacy right, please contact us at [email protected].