Privacy Policy
Last updated: July 5, 2026
Quero ("we", "us", "our") is operated by Elias Lindblad, based in Sweden. This policy explains what data we collect, why, and how we handle it.
What Quero does
Quero lets you query APIs across multiple values (markets, languages, IDs) and merge the results into a single table. It offers two run modes — Browser mode and Server mode — which affect how your data is handled.
Browser mode vs. Server mode
Browser mode: API requests go directly from your browser to the target API. No request data, response data, API keys, or credentials pass through Quero's servers. We never see or store your query results.
Server mode: API requests are proxied through our infrastructure (Cloudflare Workers). Request URLs and headers are forwarded to the target API on your behalf. Response data passes through our servers but is not stored — it is streamed to your browser and discarded.
What data we collect
Account data: Your email address and display name, used to authenticate you and manage your account. Stored in our database (Cloudflare D1, EU region).
Connector configurations: The API URL patterns, header templates, and settings you save. Stored in our database so you and your team can reuse them. These may contain URL patterns but should not contain credentials — use your browser's native headers for authentication in Browser mode.
Usage data: Basic analytics (page views, feature usage) collected via Cloudflare Web Analytics, which is cookieless and does not track individual users across sites.
AI wizard conversations: When you use the AI setup wizard, your API URL and the AI's follow-up questions and your answers are processed to generate a connector configuration. The conversation content is sent to our AI provider for processing and is not stored after the configuration is created.
What we do not collect
- API response data (in Browser mode, we never see it; in Server mode, it is streamed and discarded)
- Passwords (authentication is handled via magic links)
- Payment information (no payments during beta)
Sub-processors
We use the following third-party services to operate Quero:
| Service | Purpose | Data processed | Location |
|---|---|---|---|
| Cloudflare (Pages, Workers, D1) | Hosting, compute, database | Account data, connector configs | EU |
| Resend | Transactional email (magic links) | Email address | EU region |
| Cloudflare Workers AI | AI wizard for connector setup | API URLs, wizard conversation | EU |
Data retention
Your account data and saved connector configurations are retained as long as your account is active. If you delete your account, all associated data is removed from our database within 30 days.
Your rights under GDPR
As an EU resident, you have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and all associated data
- Export your data in a portable format
- Object to or restrict certain processing
To exercise any of these rights, email elias@lindblad.dev. We will respond within 30 days.
Data security
All data is transmitted over HTTPS. Account data is stored in Cloudflare D1 with encryption at rest. Authentication uses secure, time-limited magic links — no passwords are stored.
Changes to this policy
We may update this policy as the product evolves. Material changes will be communicated via email. The "Last updated" date at the top reflects the most recent revision.
Contact
For any privacy-related questions or requests: