Privacy Policy
1. What we collect
- Account / sign-in data: your email address, submitted to receive a one-time sign-in link, and a session identifier.
- Content you submit: the text, claims, documents, or cryptographic-inventory details you enter into the agent to be analysed, and the reports generated from them.
- Usage records: which analyses you run and when (for quota and audit purposes).
- Technical logs: IP address, request path, status, timing, and a correlation ID, retained for security, abuse-prevention, and debugging.
We do not collect payment-card data on our systems. We do not knowingly collect data from children.
2. How we use it & our legal bases (GDPR Art. 6)
- To provide the service — run analyses, store your reports, and route them through the reviewer workflow. Legal basis: performance of a contract.
- To secure the service — rate-limiting, abuse detection, and incident investigation. Legal basis: legitimate interests in protecting the service.
- To communicate with you about a request or engagement you initiated. Legal basis: contract / legitimate interests.
We do not sell or "share" (as defined under CCPA/CPRA) your personal data, and we do not use the content you submit to train our own models. Our AI processor does not train on submitted content under its API terms.
3. Cookies, analytics & fonts
We do not set advertising or third-party analytics cookies. The product uses only a
first-party session token (held in your browser's sessionStorage) needed to keep you
signed in. Web fonts are self-hosted on our own domain and served same-origin; we do
not load fonts from a third-party content-delivery network, so no third party receives
your IP address or request metadata when fonts load.
Do Not Track: Because we do not set cross-site tracking cookies or engage in cross-site behavioural advertising, our website does not change its behaviour in response to a browser Do Not Track (DNT) signal. We will update this disclosure if our practices change.
4. Service providers (subprocessors)
We rely on the following processors. Each receives only the data needed to perform its function:
| Provider | Purpose | Data |
|---|---|---|
| Vercel | Website + application hosting, edge/CDN, request logging | Technical logs, request content in transit |
| Supabase | Managed Postgres database | Account email, reports, usage + audit records |
| Anthropic | Optional AI enrichment of analysis (only when live-AI mode is enabled) | The material you submit for that analysis |
| Sentry (optional) | Error tracking, when enabled | Technical error context (no report content; PII scrubbing on) |
5. International transfers
Quantum Nexus Technologies Ltd is organised in the Cayman Islands; our processors operate infrastructure in the United States and other regions. Where personal data of EEA/UK individuals is transferred across borders, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) as the transfer mechanism, and process only what is necessary to deliver the service.
6. Retention
We retain account data and reports for as long as your account is active and for up to three (3) years after account closure or last activity, whichever is later, unless you request earlier deletion (see §7) or applicable law requires a different retention period. Technical/access logs are retained for up to 90 days for security and debugging, after which they are deleted or aggregated. Content you submit for analysis is retained as part of the associated report record; account deletion will result in deletion of associated reports subject to limited legal-hold exceptions (e.g., where retention is required by applicable law or to resolve an open dispute).
6a. Automated decision-making
Veriqa's scoring engine applies a transparent rule-based heuristic to the text you submit. The scores and verdicts it produces are decision-support tools provided for your review; they do not constitute a legally or similarly significant automated decision within the meaning of GDPR Article 22 or equivalent law. Every customer-facing report is held in draft and must pass through a human reviewer workflow gate before it is delivered — a human approves the report before release. You are not subject to a decision based solely on automated processing that produces legal effects concerning you.
7. Your rights
Depending on your jurisdiction (including under the GDPR/UK GDPR and CCPA/CPRA), you may have rights to access, correct, delete, or port your personal data; to object to or restrict certain processing; and to opt out of any "sale" or "sharing" of personal information (we do not sell or share). You also have the right not to receive discriminatory treatment for exercising these rights. To exercise any right, contact us at hello@quantum-nexus.dev; we may need to verify your identity, and we respond within the timeframe required by applicable law (generally 30 days under the GDPR; 45 days under the CCPA). EEA/UK users may also lodge a complaint with their local data-protection supervisory authority.
8. Security
Connections are encrypted in transit (TLS), and database connections require TLS. Sign-in links are one-time and are not written to our application logs; access to customer-facing reports is gated by authentication and a reviewer workflow. No method of transmission or storage is perfectly secure; we cannot guarantee absolute security.
8a. Law enforcement & legal process
We will disclose personal data to law enforcement, regulators, or other third parties only when we are required to do so by applicable law, a valid court order, or other binding legal process; when necessary to protect the rights, property, or safety of Quantum Nexus, our users, or the public; or when we believe in good faith that disclosure is required to respond to a claim that content on the site infringes third-party rights. Where legally permitted and practically feasible, we will attempt to notify affected users prior to disclosure.
9. Changes
We may update this policy from time to time. We will notify registered users of material changes by email (to the address on your account) or by posting a prominent notice on the site before the change takes effect. Non-material clarifications will be reflected only by updating the "last updated" date above. Continued use of the service after a material change takes effect constitutes your acceptance of the revised policy.
10. Contact
Quantum Nexus Technologies Ltd — hello@quantum-nexus.dev