A checkable record of how Questro handles data

Checkable facts about Questro account access, public and private event links, processors, AI Captions audio, payments, and how to report a security issue.

How to verify

This page lists processors, what is stored or streamed, and how a visitor can verify those facts. It is not a certificate wall. questro.live is served over HTTPS and sends Strict-Transport-Security. Public share tokens and Personal Access Tokens are stored as SHA-256 hashes, not as the secret string. Owner APIs require a Firebase ID token, and unverified email is rejected unless the account carries a legacy exemption. Payments never put a full card number on Questro servers. Security reports go to support@questro.live, which is also listed in https://questro.live/.well-known/security.txt.

Processors

Questro does not sell personal information. Firebase / Google Cloud handles identity, Firestore event data, file storage, and the AI Captions speech proxy. Vercel hosts the website, serverless APIs, and performance monitoring. Alibaba Cloud DashScope performs speech recognition and live translation. Lemon Squeezy processes subscriptions, Event Pass purchases, the customer portal, cancellations, and refunds. Sentry receives application error reports; session replay runs only after an error, with on-screen text masked and media blocked. Google Analytics and Google Ads run only after cookie consent. Each processor publishes its own documentation: Firebase privacy, the Vercel Trust Center, DashScope documentation, Lemon Squeezy privacy, Sentry security, and the Google privacy policy. Those pages describe the processors, not a Questro certificate.

Where processing happens

Questro is operated as a remote team and the service is governed by the laws of Singapore. The website and serverless APIs run on Vercel. Accounts, projects, uploads, and public-view mirrors are stored with Firebase / Google Cloud. AI Captions audio is streamed through a Google Cloud WebSocket proxy in asia-southeast1 (Singapore) to Alibaba DashScope for recognition and translation. Information may still move across borders because those processors operate in more than one region.

What is stored, streamed, or not kept

Questro stores account details, event and project records (timers, Q&A questions, teleprompter scripts, images, and AI Captions context), caption and translation text, billing records from Lemon Squeezy such as plan type and renewal timing, and limited technical logs. Microphone audio for AI Captions is streamed live for recognition; Questro is not a recording or transcript archive product. Questro does not store full payment card numbers, passwords in recoverable form, or the secret string of a public share token or Personal Access Token after creation.

Accounts, links, captions, and payments

Display and audience links are public-facing. Control, moderator, operator, and owner links should stay with the event team. Timer and Q&A can regenerate tokens. Interpreter operator links expire and rotate. Webhook deliveries are signed with HMAC-SHA256. AI Captions uses browser microphone access when an operator starts captioning; captions still need rehearsal and human review for high-stakes sessions. Payments are processed by Lemon Squeezy. Card details are handled by the payment provider; Questro does not store full card numbers.

Independent audits and security contact

Questro does not currently publish an independent information-security certificate. If a certificate is issued, this page will show the standard, the certificate number, the validity dates, and a link to the issuing body's verification page. Enterprise questionnaires can be sent to support@questro.live. Report a suspected vulnerability to the same mailbox with enough detail to reproduce it, and do not test against a live event other people are relying on. The mailbox is published in /.well-known/security.txt.

Key details

Common questions

Does Questro currently publish an independent security certificate?
No. This page is the public record of how Questro handles data. If a certificate is issued, this page will link the certificate number and a verification URL from the issuing body.
Who processes AI Captions audio?
Live microphone audio is streamed through a Google Cloud proxy in asia-southeast1 to Alibaba DashScope for speech recognition and translation. Captions and translations can be stored as event data. Questro does not sell that audio.
Does Questro store full card numbers?
No. Payments are processed by Lemon Squeezy. Card details are handled by the payment provider; Questro does not store full card numbers.
How are public event links protected?
Display and audience links are meant for public screens. Control, moderator, operator, and owner links should stay with the event team. Share tokens are stored as SHA-256 hashes. Timer and Q&A can regenerate tokens, which invalidates the current links.
How do I report a security issue?
Email support@questro.live with enough detail to reproduce the issue, and do not test against a live event other people are relying on. The same mailbox is listed in /.well-known/security.txt.
Where is Questro data processed?
Questro is governed by the laws of Singapore. The website and APIs run on Vercel. Event data is stored with Firebase / Google Cloud. Live speech traffic goes through a proxy in Google Cloud asia-southeast1 to Alibaba DashScope.

https://questro.live/security