Quero

Privacy Policy

Last updated: July 5, 2026

Quero ("we", "us", "our") is operated by Elias Lindblad, based in Sweden. This policy explains what data we collect, why, and how we handle it.

What Quero does

Quero lets you query APIs across multiple values (markets, languages, IDs) and merge the results into a single table. It offers two run modes — Browser mode and Server mode — which affect how your data is handled.

Browser mode vs. Server mode

Browser mode: API requests go directly from your browser to the target API. No request data, response data, API keys, or credentials pass through Quero's servers. We never see or store your query results.

Server mode: API requests are proxied through our infrastructure (Cloudflare Workers). Request URLs and headers are forwarded to the target API on your behalf. Response data passes through our servers but is not stored — it is streamed to your browser and discarded.

What data we collect

Account data: Your email address and display name, used to authenticate you and manage your account. Stored in our database (Cloudflare D1, EU region).

Connector configurations: The API URL patterns, header templates, and settings you save. Stored in our database so you and your team can reuse them. These may contain URL patterns but should not contain credentials — use your browser's native headers for authentication in Browser mode.

Usage data: Basic analytics (page views, feature usage) collected via Cloudflare Web Analytics, which is cookieless and does not track individual users across sites.

AI wizard conversations: When you use the AI setup wizard, your API URL and the AI's follow-up questions and your answers are processed to generate a connector configuration. The conversation content is sent to our AI provider for processing and is not stored after the configuration is created.

What we do not collect

  • API response data (in Browser mode, we never see it; in Server mode, it is streamed and discarded)
  • Passwords (authentication is handled via magic links)
  • Payment information (no payments during beta)

Cookies

We use only strictly necessary cookies:

  • Session cookie — identifies your login session. Required for the service to function.
  • Cloudflare security cookies (__cf_bm, cf_clearance) — bot protection and security, set automatically by Cloudflare.

We do not use advertising, tracking, or analytics cookies. No cookie consent banner is required because all cookies are strictly necessary under GDPR. See our Cookie Policy for details.

Sub-processors

We use the following third-party services to operate Quero:

ServicePurposeData processedLocation
Cloudflare (Pages, Workers, D1)Hosting, compute, databaseAccount data, connector configsEU
ResendTransactional email (magic links)Email addressEU region
Cloudflare Workers AIAI wizard for connector setupAPI URLs, wizard conversationEU

Data retention

Your account data and saved connector configurations are retained as long as your account is active. If you delete your account, all associated data is removed from our database within 30 days.

Your rights under GDPR

As an EU resident, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your account and all associated data
  • Export your data in a portable format
  • Object to or restrict certain processing

To exercise any of these rights, email elias@lindblad.dev. We will respond within 30 days.

Data security

All data is transmitted over HTTPS. Account data is stored in Cloudflare D1 with encryption at rest. Authentication uses secure, time-limited magic links — no passwords are stored.

Changes to this policy

We may update this policy as the product evolves. Material changes will be communicated via email. The "Last updated" date at the top reflects the most recent revision.

Contact

For any privacy-related questions or requests:

Elias Lindblad

elias@lindblad.dev

Sweden