This policy explains how Quantenius ("we", "our", or "us") handles personal information when you use the Quantenius website, create an account, purchase a subscription, or contact support.
1. Information we handle
Account and authentication information. We receive your email address, internal user identifier, account timestamps, authentication status, and related security records. Supabase Auth receives and manages authentication credentials. Quantenius does not receive or store your plain-text password.
Your email address and password are mandatory if you choose to create an account: the email is used to identify, confirm, and recover the account, and the password secures access. If you do not provide them, we cannot create an account for you. An account is not required to use features described on the site as available without signing in.
Billing and subscription information. Stripe and its Sold through Link service process Managed Payments purchases and may collect your name, billing address, country or region, payment-method details, and information needed for tax, fraud prevention, transaction processing, transaction support, and subscription management. Quantenius stores identifiers and records needed to operate and reconcile subscriptions, including Stripe customer, subscription, invoice, payment, and refund identifiers; plan and status; paid amount and currency; lifecycle events; and the Terms version, acceptance evidence, and corresponding Stripe lifecycle-event time. We do not receive or store complete card numbers, bank-account credentials, or card security codes.
Product and acquisition events. Unless your browser sends a Do Not Track signal, we may record a random session identifier, event name, page path, referring hostname, campaign parameters, and event time. These are pseudonymous event records; reports may be aggregated. Our product-event table does not store your IP address or browser user-agent, although infrastructure providers such as Cloudflare may independently process request metadata for security, delivery, abuse prevention, and rate limiting.
Practice progress and preferences. Solved, attempted, and saved questions, game statistics, display preferences, and similar progress are stored in your current browser using local storage. Creating an account does not currently synchronize this progress between devices. Supabase authentication may also use browser storage to keep you signed in.
Support communications. If you contact us, we process your email address, message, attachments, and the information needed to investigate and answer your request. Do not send passwords, authentication codes, complete payment-card numbers, or card security codes.
2. How we use information
- Provide, secure, and maintain accounts, subscriptions, gated content, and games.
- Send transactional messages such as account confirmation, password recovery, and important account or billing notices.
- Prevent fraud, automated scraping, abuse, and unauthorized access.
- Operate customer support, investigate billing issues, and meet record-keeping obligations.
- Understand product use and improve practice flows using pseudonymous or aggregated reporting.
- Comply with applicable law and enforce our terms.
Where applicable law requires a legal basis, we rely as appropriate on performance of a contract, legitimate interests in operating and protecting the service, compliance with legal obligations, and consent where required.
3. Service providers and international processing
We use service providers including Supabase for authentication and database hosting; Stripe and Sold through Link for Managed Payments, subscription management, transaction support, and payment-related messages; Cloudflare for hosting, delivery, and security; Resend for transactional authentication email; and Namecheap Private Email for the support mailbox.
These providers may process information in Hong Kong or other jurisdictions where they or their subcontractors operate. Those jurisdictions may have privacy laws different from those where you live. We use provider terms and other safeguards required by applicable law. Providers may also act under their own legal obligations for activities such as payment processing, fraud prevention, and compliance.
We do not sell or rent personal information for advertising, and we do not currently use advertising cookies or send a marketing newsletter. If you choose to provide your email through an optional newsletter subscription feature, we may store the email address, signup source, consent time, and subscription status for that purpose. Before sending marketing messages, we will obtain or confirm consent where required by applicable law and provide a way to unsubscribe.
4. Browser storage and security cookies
We use local storage for practice progress, preferences, and authentication-session persistence, and session storage for a random analytics session identifier. Cloudflare may set cookies or similar storage needed for security verification, such as a bot challenge. Product-event collection is disabled when the browser sends a Do Not Track signal.
5. Retention
We retain information for as long as reasonably needed to provide the service, maintain security and audit records, resolve disputes, enforce agreements, and meet legal, tax, accounting, and payment obligations. Retention differs by data category and service provider. After a verified deletion request, we delete or de-identify information that is no longer required, subject to legal obligations, fraud-prevention needs, backups, and provider retention cycles.
Browser-stored progress can be removed through your browser settings. Clearing browser storage may also sign you out and permanently remove locally saved progress.
6. Your choices and rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, or a copy of personal information, or to object to or restrict certain processing. You may also withdraw consent where processing relies on consent. To make an access or correction request, contact the Data Protection Contact, Quantenius at support@quantenius.com. We may need to verify your identity before acting, and some records may need to be retained as permitted or required by law.
7. Security
We use HTTPS, access controls, credential separation, multi-factor authentication for provider administration, and other safeguards appropriate to the service. No online service is completely secure. Use a strong, unique password and notify us promptly if you suspect unauthorized account access.
8. Age requirement
Quantenius is not intended for children under 16. Do not create an account or submit personal information if you are under 16. If you believe a child has provided information contrary to this policy, contact us.
9. Changes and contact
We may update this policy to reflect changes to the service or legal requirements. We will update the version or effective date and provide additional notice when required. Questions and privacy requests can be sent to support@quantenius.com.