Checkable facts about Questro account access, public and private event links, processors, AI Captions audio, payments, and how to report a security issue.
This page lists processors, what is stored or streamed, and how a visitor can verify those facts. It is not a certificate wall. questro.live is served over HTTPS and sends Strict-Transport-Security. Public share tokens and Personal Access Tokens are stored as SHA-256 hashes, not as the secret string. Owner APIs require a Firebase ID token, and unverified email is rejected unless the account carries a legacy exemption. Payments never put a full card number on Questro servers. Security reports go to support@questro.live, which is also listed in https://questro.live/.well-known/security.txt.
Questro does not sell personal information. Firebase / Google Cloud handles identity, Firestore event data, file storage, and the AI Captions speech proxy. Vercel hosts the website, serverless APIs, and performance monitoring. Alibaba Cloud DashScope performs speech recognition and live translation. Lemon Squeezy processes subscriptions, Event Pass purchases, the customer portal, cancellations, and refunds. Sentry receives application error reports; session replay runs only after an error, with on-screen text masked and media blocked. Google Analytics and Google Ads run only after cookie consent. Each processor publishes its own documentation: Firebase privacy, the Vercel Trust Center, DashScope documentation, Lemon Squeezy privacy, Sentry security, and the Google privacy policy. Those pages describe the processors, not a Questro certificate.
Questro is operated as a remote team and the service is governed by the laws of Singapore. The website and serverless APIs run on Vercel. Accounts, projects, uploads, and public-view mirrors are stored with Firebase / Google Cloud. AI Captions audio is streamed through a Google Cloud WebSocket proxy in asia-southeast1 (Singapore) to Alibaba DashScope for recognition and translation. Information may still move across borders because those processors operate in more than one region.
Questro stores account details, event and project records (timers, Q&A questions, teleprompter scripts, images, and AI Captions context), caption and translation text, billing records from Lemon Squeezy such as plan type and renewal timing, and limited technical logs. Microphone audio for AI Captions is streamed live for recognition; Questro is not a recording or transcript archive product. Questro does not store full payment card numbers, passwords in recoverable form, or the secret string of a public share token or Personal Access Token after creation.
Display and audience links are public-facing. Control, moderator, operator, and owner links should stay with the event team. Timer and Q&A can regenerate tokens. Interpreter operator links expire and rotate. Webhook deliveries are signed with HMAC-SHA256. AI Captions uses browser microphone access when an operator starts captioning; captions still need rehearsal and human review for high-stakes sessions. Payments are processed by Lemon Squeezy. Card details are handled by the payment provider; Questro does not store full card numbers.
Questro does not currently publish an independent information-security certificate. If a certificate is issued, this page will show the standard, the certificate number, the validity dates, and a link to the issuing body's verification page. Enterprise questionnaires can be sent to support@questro.live. Report a suspected vulnerability to the same mailbox with enough detail to reproduce it, and do not test against a live event other people are relying on. The mailbox is published in /.well-known/security.txt.