Data we collect
We collect account data such as name, work email, hashed password or Google sign-in identifier, organization and team details, and billing information. Stripe processes payments; QBR Studio never sees or stores full card numbers.
- Connected tools — When you connect ConnectWise, Autotask, HaloPSA, or NinjaOne, or import CSV, we read the clients, tickets, SLA metrics, assets, and warranty dates needed to build reports.
- Read-only access — Integrations do not write back to connected systems, and connection credentials are encrypted at rest.
How we use and share data
We use data to generate reports and client pages, deliver them by email, operate scheduling, provide support, process billing, and secure the service. We do not sell your data or your clients' data, and do not use it to train public AI models.
- Executive summaries are generated from report figures by a third-party LLM provider under a zero-retention arrangement that does not train on the text.
- Data is shared only with subprocessors needed for payment, email delivery, summary generation, hosting, or when disclosure is required by law.
Published report links
Published reports and client pages are reachable by anyone with the unguessable share link. They are excluded from search indexing and can be unpublished, but should be treated as public to anyone who receives the link.
Retention, deletion, and your rights
Data is kept while the account is active. Users can delete individual clients and reports and request full account deletion; data is removed within 30 days except for records retained for legal or accounting reasons. Depending on location, users may also request access, correction, export, or deletion.
Security and changes
Passwords are hashed, integration credentials are encrypted at rest, and access is restricted to what the service needs. Material policy changes update the effective date and significant changes are communicated to account owners by email.
Keep recommendations reviewed and evidence explicit
QBR Studio computes service metrics and drafts client-facing summaries from connected data. Your MSP reviews the evidence, chooses every recommendation, and approves the final report before a client sees it.
What MSP teams usually ask
Does QBR Studio sell customer or client data?
No. QBR Studio does not sell your data or your clients' data and does not use it to train public AI models.
Can QBR Studio write back to my PSA or RMM?
No. ConnectWise, Autotask, HaloPSA, and NinjaOne integrations are read-only. Connection credentials are encrypted at rest.
How do I request an export or deletion?
Email support@qbrstudio.com to request access, correction, export, or deletion. Full account deletion is completed within 30 days except for records that must be retained for legal or accounting reasons.