Privacy Policy
This Privacy Policy explains how TheQuantAI ("we", "us") collects, uses, shares, and protects personal data when you use TheQuantCloud, QuantStudio (studio.thequantcloud.com), the QuantSDK, our API (api.thequantcloud.com), and our websites (collectively, the "Services"). It is written to meet India's Digital Personal Data Protection Act, 2023 (DPDP), the EU/UK General Data Protection Regulation (GDPR), and the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA).
1. Who we are & how to contact us
TheQuantAI is based in Bengaluru, India. For any privacy request — including access, correction, or deletion — contact our privacy team at privacy@thequantai.in. Indian users may address grievances to the same contact, which serves as our grievance channel under the DPDP Act.
2. What we collect
- Account data — the email address (and any name) you provide when you create an account, and authentication metadata managed by our auth provider.
- Circuits you create — quantum circuits and related code you save or submit for execution are stored so we can run them and show your history.
- Run telemetry & results — job metadata (chosen backend, timing, status), circuit characteristics (e.g. qubit count, gate count, depth), and execution results.
- Analytics events — product-usage events, described in §4. In QuantStudio these are collected only with your consent.
- Technical logs — IP address, user agent, and request logs kept for security and reliability.
3. Why we use your data (purposes)
- Provide the Services — authenticate you, run your circuits, return results, and maintain your history.
- Product analytics — understand feature usage to improve the product (consent-based in Studio).
- Machine-learning training — we use submitted circuits and their run telemetry to train and improve QuantRouter, our backend-routing model. We state this plainly so you can make an informed choice. Where required, training data is pseudonymised (account identifiers removed) before use.
- Security & reliability — detect abuse, debug, and keep the platform available.
4. Legal bases (GDPR)
- Performance of a contract — providing the Services you request.
- Consent — product analytics in QuantStudio; you may withdraw consent at any time (see §7).
- Legitimate interests — security, abuse prevention, and improving our routing model, balanced against your rights.
5. Service providers & third parties
We share data only with processors that help us run the Services, under appropriate agreements:
- Supabase — database, authentication, and storage of accounts, circuits, and results.
- Railway — hosting for our API.
- Vercel — hosting and privacy-friendly analytics for QuantStudio.
- Cloudflare — CDN and cookieless Web Analytics on our marketing websites (aggregate traffic only; no cross-site tracking).
- Google Fonts — serves web fonts; your IP is visible to Google when fonts load.
- PostHog (EU region) — product analytics in QuantStudio; runs only with your consent, and session replay is disabled.
We do not sell your personal data, and we do not "share" it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA.
6. Retention
We keep account data and your workspace files (folders, circuits, notes, and other saved files) until you delete them or close your account. Technical logs are kept for a limited rolling period for security and debugging. Pseudonymised data used to train QuantRouter may be retained after account deletion because it is no longer linked to you.
Deleted workspace files. When you delete a file or folder in QuantStudio it is moved to a Trash, where you can restore it. Items in the Trash are permanently deleted 30 days after deletion (or sooner if you empty the Trash). After that they cannot be recovered.
Run telemetry survives file deletion. When you run a circuit, we record pseudonymised execution telemetry (for example, circuit characteristics and backend-routing decisions) to operate and improve QuantRouter. This telemetry is retained even after you delete the file the run came from, because it is not stored as part of that file and is not linked to you as an identified individual.
7. Your rights
Depending on where you live, you have some or all of the following rights. To exercise any of them, email privacy@thequantai.in.
- GDPR (EU/UK) — access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent at any time without affecting prior processing.
- DPDP (India) — access, correction, erasure, grievance redressal, and nomination.
- CCPA/CPRA (California) — the right to know, to delete, to correct, and to opt out of sale/sharing. We do not sell or share personal data, so no opt-out is necessary, but you may still exercise the other rights.
8. Deleting your data
You can delete individual workspace files and folders yourself in QuantStudio at any time; deleted items sit in the Trash for 30 days (restorable) before they are permanently removed, and you can empty the Trash to remove them immediately. To delete your whole account, email privacy@thequantai.in from your account address. We will remove your profile, your workspace files, and associated logs, and confirm within a reasonable period. As noted in section 6, pseudonymised run telemetry that is no longer linked to you may be retained. A self-service account-deletion option is planned for the future.
9. International transfers
We operate from India and use providers that may process data in other countries. Where personal data is transferred internationally, we rely on appropriate safeguards (such as standard contractual clauses) as required by applicable law.
10. Children
The Services are not directed to children. You must be at least 18, or the age of digital consent in your jurisdiction, to create an account.
11. Changes to this policy
We may update this policy as the Services evolve. We will revise the "Last updated" date above and, for material changes, provide a more prominent notice.