Quantika - Privacy Policy
Last updated: September 1, 2026 · Versión en español
This policy explains what information Quantika collects through its website, through its software (the Autodesk Revit plugin and the desktop app) and through the budget publishing service at quantikaviewer.com, what we use it for, and how you can exercise your rights.
1. Who we are
Quantika is budget management software for Autodesk Revit. For any question about your data you can write to us at quantikapluggin@gmail.com.
2. What information we collect
a) On this website
The public pages of quantikaviewer.com (home, plans, this policy, the viewer) are static: they ask you for nothing and store nothing of yours. They are served by Cloudflare, which is who hosts the domain. The exception is the customer sign-in —quantikaviewer.com/entrar and the panel it leads to— which is a form where you type your email and which does leave a cookie of ours: it is explained in full in point (e). On the home page we use Google Analytics and Google Ads to measure visits and the performance of our campaigns; these services may use cookies and browsing identifiers in aggregate/anonymous form.
b) In the software (plugin and desktop app)
To issue, activate and validate your license, and to give you support, the software sends to our server:
- Your email address (the one you activate the trial or the license with).
- The name you typed when activating; free trials are recorded as «Trial».
- Your license key.
- A machine identifier: an irreversible SHA-256 hash, computed from your computer name, your Windows user name and the number of processors. It is used only to tie the license to that computer.
- Basic usage data: the software version, the license status (trial, active, expired), its expiry date, the date of the connection, and your computer name.
All of that travels over HTTPS to a Google spreadsheet (Google Sheets, through Google Apps Script). Your license data is also stored locally on your computer, in the application data folder.
Your projects are yours. The software does not send the contents of your models, budgets or files on its own: that data stays on your computer. The only thing that leaves by itself is the list above. The only way a budget reaches our servers is if you publish it on purpose, with the button described in point (d).
c) Payments
Payments are processed through MercadoPago. We do not store and do not see your card details; MercadoPago handles them under its own privacy policy.
d) Budgets you publish on quantikaviewer.com
Quantika has a feature —File → Export interactive budget → Share link— that uploads the budget to this domain and returns an address you can send to your client. It is voluntary and never happens on its own: nothing is uploaded unless you press that button. When you do:
- The budget file as you generated it —the line items, the quantities, the prices and, if you included it, the 3D model— is stored in Cloudflare (R2) object storage, so it can be served when your client opens the link.
- A single row is also stored in a Cloudflare database (D1) with: your license key, the link identifier, how much the file weighs, when it was uploaded, when it expires, and the hash of the code that allows it to be withdrawn. The code itself is stored nowhere: only you have it.
- The name of the project is not stored. It travels in the request, so that we can support you, and it is discarded right there: that database holds no project name and no client name.
- The link lives 60 days. When it expires, an automatic process that runs every day deletes the file. You can withdraw it earlier whenever you want, from Quantika itself, and then the file is deleted and the link stops opening.
- Links are unlisted and not indexed by search engines, and cannot be guessed; but they are not secret: anyone holding the full link can open it.
- We do not read the contents of your budget, we do not use it for anything other than serving it to whoever opens the link, and we do not give it to anyone.
About whoever opens a published budget we store nothing personal: no IP address, no browser, no language, no referrer. What is recorded is which link was opened and when —plus a random mark of the tab, explained in the next paragraph—, so the firm that published it can see in its panel how many times it was opened and the date of the last one. It is the document itself that reports it once it is already on screen, and not the request to the server: that way an automatic preview —the one WhatsApp or Gmail builds as soon as the link is sent— does not count as your client having opened it.
So that reloading the page does not count one reading five times, the page makes up a random mark and keeps it in the tab's storage (sessionStorage): it lives in that tab and clears itself when you close it (some browsers keep it if you restore the session or duplicate the tab). And there is a different mark for each link: if you open two budgets, even in the same tab, there is no way to tell that the same person opened both. That mark is stored next to the link and the date for as long as the link exists, and is deleted with it: it is the third and last thing kept about a visit. It is not a cookie, it does not leave this domain, and it is shown to nobody: in its panel the firm sees the number of visits, never the mark. It is there only so that one same tab counts once per hour on each link. If your browser has storage blocked there is no mark, and then the document reports nothing: that reading is not counted, because we would rather not count than count too much. And what that number says is how many times it was opened, not an auditable measurement: anyone holding the link can push it up.
The budget file is still self-contained. That notice goes out only when this domain served the document over HTTPS: if you save the file and open it from your disk, from your email or from a USB stick, it talks to nobody.
If you are the recipient of a budget and you want it withdrawn, write to us: we withdraw it, or we tell the firm that published it.
e) Customer sign-in (/entrar and your panel)
If you are already a customer you can reach your panel from quantikaviewer.com/entrar, to see your license and the links you published. It is a form where you type your email, and it works like this:
- You type your email and we send you a 6-digit code. That email goes out through Resend, the provider that dispatches our email: it sees your address and the message. Setting a password is optional, and it stays optional forever: whoever does not want one signs in with the code, exactly as on day one.
- While the code is alive (10 minutes) a row is kept in the Cloudflare database (D1) with the hash of your email, the hash of the code —the code itself is stored nowhere— and the license key it belongs to. One line per request is also kept, with the hash of the email and the time: it is the only thing that stops this form from being used to send mail to anyone.
- If you set a password, we do not store it: what stays in D1 is an irreversible PBKDF2 derivation, a random salt that is different for every person, the hash of your email and the dates. Your password cannot be recovered from that, not even by us. And one line per attempt to sign in with it is kept —the hash of the email and the time, nothing else—: it is the only thing that stops someone from trying passwords all day long.
- With the right code —or with your password— a session is opened: a row with your license key, the email you signed in with, when it started and when it expires, and a cookie of ours called qsesion in your browser. That cookie carries only the session identifier: neither your email nor your license travels inside it. The session is renewed on every visit: as long as you keep using your panel it never asks you to sign in again, and it closes by itself after 30 days without you coming back. If you ticked Keep me signed in, that period is one year.
- When you press sign out the session row is deleted, and so is the cookie. An expired code, an expired session, the line of an old request and the line of an old attempt are deleted by the same automatic process that runs every day.
- We keep no statistics of what you do inside the panel, and those pages load neither Google Analytics nor Google Ads.
3. What we do NOT collect
- We do not access, do not read and do not transmit your Revit models or your project files.
- We do not collect your budget data —line items, quantities, prices— unless you publish one on purpose, as explained in point (d).
- We do not store your password. If you set one, what remains is an irreversible derivation and its salt, never the text you typed. We do not collect banking details or personal documents.
- We do not track what you do inside the plugin.
- About whoever opens a published budget we do not collect their IP address, their browser, their location or where they came from.
4. How we use your information
- To issue, activate, renew and validate your license, and to manage the trial period.
- To send you your license key or code and expiry/renewal notices.
- To give you support and to improve the product with usage statistics.
- To serve, while it is valid, the budget you published, to whoever opens its link.
- To show you in your panel how many times each link you published was opened, and the date of the last time.
We do not sell, do not trade and do not share your information with third parties for advertising purposes.
5. Data retention
We keep your license data for as long as your license is active, and for as long as needed to give support and to meet legal obligations.
A published budget is kept until it expires (60 days) or until you withdraw it, whichever comes first; in either case the file is deleted from R2 and the link stops opening right away. The link's row —already without the file— stays 30 more days, so that your panel can still show you that the link existed, how it ended and how many times it was opened; after that it is deleted. A link's visits —which link, when, and the tab's random mark— are deleted together with that row and in the same sweep: when the link stops existing, so does the record that it was opened.
For customer sign-in: the one-time code lives 10 minutes; the line recording that a code was requested, one hour; the line of each attempt to sign in with a password, one hour; the derivation of your password, for as long as you have one set —changing it replaces it—; and the session —the row that holds the email you signed in with— for as long as you keep using it: every visit pushes its expiry 30 days further out (one year if you ticked Keep me signed in), and it is deleted by itself once that period passes without you coming back, or right away if you press sign out.
6. Security
- Everything transmitted travels over HTTPS.
- The machine identifier is stored as an irreversible SHA-256 hash: it cannot be turned back into your computer.
- The code to withdraw a budget is stored hashed. Without that code —which only you have— nobody can withdraw your link, not even someone who knows the address.
- If you set a password, it is stored as a PBKDF2-HMAC-SHA256 derivation with 100,000 iterations and a salt that is different for every person: even if someone took the whole database, they would not have your password.
- The session cookie is HttpOnly, Secure and SameSite=Lax: no page can read it with JavaScript, it never travels outside HTTPS, and it is not sent to other sites. It carries only the session identifier.
- Budget pages are served with noindex, without caching and without a referrer: that way the link does not reach search engines, and it is not leaked to a third party if your client clicks something from that page.
7. Your rights
- To request access, correction or deletion of your data, by writing to us at quantikapluggin@gmail.com.
- To withdraw any budget you published, from Quantika itself or by writing to us.
- To turn off telemetry by disconnecting from the internet: the plugin works fully offline.
8. Cookies
The home page uses Google Analytics and Google Ads cookies. You can disable or delete them from your browser settings.
Customer sign-in uses a cookie of our own, qsesion, and it is what keeps you inside your panel: without it there is no session, so it cannot be turned off and still let you in. It is not an advertising cookie, it does not follow you outside this domain and it is shared with nobody; it is explained in point 2(e) and it is deleted when you press sign out.
The other pages of this domain —this policy, the viewer, and published budgets— do not load Google Analytics or Google Ads, and set no cookie at all. A published budget does not either: the only thing it leaves in your browser is the random tab mark from point 2(d), in sessionStorage, which deletes itself when you close the tab and which no other site can read.
9. Changes to this policy
We may update this policy. Any change will be published on this same page, with its update date, and on its Spanish version.
10. Contact
Quantika · quantikapluggin@gmail.com
Website: quantikaviewer.com
Versión en español: Política de Privacidad.