Pathquill
How it worksLimits
Request a pilotSign in
PATHQUILL / PRIVACY POLICY

Privacy policy

Pathquill is built on payload minimization: we prove that website enquiries arrive at their destination without retaining visitor lead data, message bodies, or mailbox contents.

1. Overview and architecture

Pathquill is an automated enquiry delivery verification service designed for web and marketing agencies. It is not a CRM, form builder, or email marketing platform. Pathquill only generates and monitors clearly labelled synthetic test submissions carrying unguessable tokens (pq-run-…). We do not collect, intercept, or monitor submissions from real website visitors.

2. Information we collect and process

We process only the minimum operational metadata necessary to run delivery checks and administer operator accounts:

  • Operator accounts: Name, email address, and authentication session tokens for authorized agency administrators.
  • Monitored journey configuration: Authorized target form URLs, form submission actions, HTTP methods, and descriptive inbox labels.
  • Delivery check evidence: Generated run tokens (pq-run-…), start and completion timestamps, HTTP status codes (e.g. 200, 503), delivery outcome (PASSED, FAILED, UNSUPPORTED), and failure diagnostic stage codes.
  • Inbound webhook events: The matched run token, provider source identifier (e.g. provider:webhook), and arrival timestamp.

3. Information we explicitly do not collect or store

Pathquill enforces payload minimization at the Worker architecture level:

  • Zero form response bodies: Monitored form submission responses are processed in memory and discarded. We do not store form response bodies in our database.
  • Zero webhook payload content: Inbound webhook requests discard all arbitrary payload data; database storage for webhook content is strictly empty ({}).
  • Zero email body retention: When using Cloudflare Email Routing (inbound@pathquill.app), the email handler parses only the pq-run-… token. Sender address, recipient, subject, headers, and message text are immediately discarded.
  • No mailbox scraping: We never request OAuth access to read, sync, or search customer Gmail, Google Workspace, or Microsoft 365 mailboxes.

4. Data retention and erasure

Check evidence is retained for a customer-approved retention window (default 30 days) and automatically pruned nightly by Cloudflare Cron triggers. Agency administrators can also preview and permanently delete all tenant data at any time via the Customer Data dashboard or via POST /api/admin/customer-data/erase.

5. Infrastructure and subprocessors

Pathquill is deployed entirely on Cloudflare Workers and Cloudflare D1. All communications use TLS 1.3 encryption in transit, and data in D1 is encrypted at rest. Our sole infrastructure subprocessor is Cloudflare, Inc.

6. Contact and inquiries

For privacy questions, access requests, or custom data retention agreements, contact us at pilots@pathquill.app.

PathquillProve the enquiry arrived.
How it worksLimitsSecurityPrivacyTermspilots@pathquill.app