Privacy Policy
Last Updated: May 8, 2026
This Privacy Policy explains how MQuantum (operating as SwiftQuantum, "we", "us") collects, uses, discloses, and protects information when you use any application or service in the SwiftQuantum ecosystem ("Services"). The Services covered include SwiftQuantum, QuantumNative, Q-Bridge, QuantumCareer, Q-Alpha, Q-Shield, Q-Logos, Q-Bio Genesis, the SwiftQuantum website, the QuantumNative EDU website, and the SwiftQuantum Legal API.
By using the Services, you agree to the collection and use of information in accordance with this policy.
0. Geographic Scope and Targeted Audiences
This Privacy Policy applies worldwide to users of the Services with the following important clarification regarding language coverage:
-
Chinese-language (中文 / zh) content in our Services and on this site is intended for the global Chinese-speaking diaspora — including Chinese Americans, Singaporeans, Taiwanese, Hong Kong residents, and Malaysians. The Services are not distributed in mainland China or in Russia, and SwiftQuantum applications are not published on any mainland-China or Russia app stores. We do not represent compliance with mainland-China or Russian legal regimes.
-
The Services are operated from the Republic of Korea by MQuantum (registration 309-96-05114) under Korean Personal Information Protection Act (PIPA) primary jurisdiction. Where you reside in another jurisdiction with applicable data-protection law, additional rights apply (see Section 9 below).
1. Information We Collect
1.1 Information You Provide
When you create an account or use the Services, you may provide:
- Account credentials: email address, username, password (stored hashed; never in plaintext), display name, and optional profile picture.
- Profile and preference information: learning preferences, skill level, interests, and language selection.
- Subscription and payment information: handled by Apple App Store, Google Play, or Stripe — we receive transaction confirmation but do not receive or store payment card numbers, bank account numbers, or full billing details.
- Communications: messages you send to support, feedback, bug reports.
- App-specific content:
- SwiftQuantum / QuantumNative: quantum circuits, simulation outputs, saved experiments, AI Tutor chat history (auto-deleted after 90 days).
- Q-Bridge: hardware-execution submissions to third-party quantum backends (anonymized before forwarding).
- QuantumCareer: resume / portfolio details, job-search history, skill certifications. Career data is not shared with employers without your explicit "apply" action.
- Q-Alpha: financial-risk model parameters, portfolio configurations, quantum-random-number-generator (QRNG) seeds. We do not receive your bank account or brokerage credentials.
- Q-Shield: organization profile, algorithm selections, compliance parameters. No real security-infrastructure data is collected; Q-Shield is a planning and assessment tool.
- Q-Logos: GPS coordinates, route data, vehicle status, delivery metrics — collected only while the app is foregrounded for an active route, revocable in device settings.
- Q-Bio Genesis: compound parameters, in-silico toxicity scores. The platform is Research Use Only (RUO); no patient data and no clinical decision support.
1.2 Information We Collect Automatically
- Device information: device type, operating system version, app version, screen size, language and region settings, unique device identifiers (IDFA / Advertising ID only with your consent on platforms that require it).
- IP address: for security, abuse prevention, and rough geolocation (country / region only). Not used for advertising.
- Usage data: which features you use, session duration, course progress, quiz scores, time spent — aggregated and anonymized after 30 days.
- Diagnostic data: crash reports, error logs, app performance metrics. Crash reports do not include the contents of your circuits or chats.
1.2.1 AI Service Provider and Data Processing
The AI Tutor and related AI-assisted features use Anthropic PBC's Claude model. When you send an AI chat message:
- The message and a recent context window are transmitted to Anthropic under Standard Contractual Clauses (SCCs).
- Anthropic stores message content for a maximum of 90 days for abuse-monitoring purposes, after which it is deleted.
- The default setting is opt-out of model training; your conversations are not used to train Claude unless you explicitly opt in.
- AI chat history visible in your account is auto-deleted after 90 days.
1.3 Information We Do NOT Collect
- Bank account numbers, full credit card numbers, brokerage credentials, national ID / SSN-equivalent numbers — never collected.
- Real-world facial recognition data — never collected.
- Patient health records or clinical diagnostic data (Q-Bio is RUO).
- Children under 13 information without verified parental consent — see Section 8.
2. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve the Services;
- Authenticate accounts and prevent abuse, fraud, and security incidents;
- Process subscriptions and refunds via Apple, Google, or Stripe;
- Send you transactional and security emails (you cannot opt out of security-critical notices);
- Send you product updates and educational content (you can opt out at any time);
- Conduct internal research and analytics on aggregated, anonymized data;
- Comply with legal obligations and respond to lawful requests.
We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.
3. Data Sharing and Disclosure
We share information only as follows:
- Service providers under written Data Processing Agreements:
Amazon Web Services (AWS, hosting in
ap-northeast-2/ Seoul, with EU regional copies ineu-west-1andeu-central-1where feasible), Anthropic PBC (AI), Apple (App Store payments and analytics), Google (Play Store payments), Stripe (web subscription payments), email providers, error-monitoring providers. - Quantum hardware partners (Q-Bridge only): IBM Quantum, IonQ, Rigetti Computing, and other backends you explicitly choose. Submissions are anonymized — no account email, name, or device identifier is forwarded.
- Legal compliance: in response to a valid subpoena, court order, or other lawful government request, with notice to you where legally permitted.
- Business transfers: in the event of a merger, acquisition, or asset sale, your information may transfer to the successor entity, which must honor this Privacy Policy or provide 30 days' advance notice.
4. Data Security
We protect your information with:
- HTTPS / TLS 1.2+ in transit;
- AES-256 encryption at rest in AWS;
- Argon2id password hashing;
- JWT-based session tokens with short rotation windows;
- Quarterly security reviews and continuous vulnerability scanning;
- Migration to NIST Post-Quantum Cryptography (ML-KEM-768 / ML-DSA / SLH-DSA) ongoing — Q-Shield, Q-Alpha, and Q-Bridge backends targeted for full PQC by end of 2026 to align with NSA CNSA 2.0 timelines.
No system is perfectly secure. If you discover a vulnerability, please
contact security@swiftquantum.tech (we will not pursue legal action
against good-faith researchers who follow responsible-disclosure norms).
5. Data Retention
| Category | Retention |
|---|---|
| AI Tutor chat history | 90 days, then auto-deleted |
| Anthropic-side AI message logs | up to 90 days, then deleted by Anthropic |
| Account data after deletion | 30 days, then permanently erased |
| Aggregated, anonymized analytics | up to 2 years |
| Crash and error logs | up to 90 days |
| Backups | up to 35 days, encrypted |
| Tax / billing records | as required by Korean tax law (5 years) |
6. Your Rights and Choices
You may, at any time:
- Access your data: visit Settings → Privacy → Export Data.
- Correct inaccurate data: via in-app profile editor.
- Delete your account: Settings → Account → Delete (30-day irreversible erasure window with cancellation option).
- Port your data: receive a JSON export of your circuits, progress, and chat history.
- Opt out of marketing emails: footer of every marketing email, or Settings → Notifications.
- Restrict processing for specific purposes: contact privacy@swiftquantum.tech.
- Withdraw consent for processing where consent is the legal basis.
We respond to all rights requests within 30 days (or 45 days where permitted by CCPA), with one 30-day extension where the request is complex.
7. Children's Privacy (COPPA)
The Services are not intended for children under 13. For users under 13:
- We do not knowingly collect personal information without verified parental consent.
- Parental consent is verified by a credit-card-on-file confirmation charge (refunded immediately) or by signed parental-consent form.
- If we learn we have collected a child's information without parental consent, we delete it and the account immediately.
- Parents may review, modify, or request deletion of their child's data
by contacting
privacy@swiftquantum.tech.
QuantumNative EDU additionally requires that users 13 and older agree to its Terms of Service, with school-administered installations using parental delegation forms.
8. International Data Transfers
The Services are operated from the Republic of Korea. When you use them from outside Korea, your information is transferred to and processed in Korea. We rely on:
- Korea — EU adequacy decision under GDPR Article 45, adopted by the European Commission on 17 December 2021 and currently in effect. The decision is reviewed every four years, with the first review period shortened to three years; transfers from the EEA to commercial operators in Korea may proceed without additional transfer tools.
- Standard Contractual Clauses (SCCs) for transfers to Anthropic PBC, AWS US regions, Apple, Google, and Stripe;
- Data Processing Agreements (DPAs) with all named service providers.
Where feasible, EEA-resident user data is preferentially stored in
eu-west-1 (Ireland) or eu-central-1 (Frankfurt) AWS regions.
9. Region-Specific Rights
9.1 European Economic Area (GDPR), United Kingdom (UK GDPR), Switzerland
You may file a complaint with your local Data Protection Authority. Our designated representative for EEA inquiries is reachable at privacy@swiftquantum.tech.
9.2 California (CCPA / CPRA)
We do not sell or share personal information for cross-context behavioral advertising. You have the right to know, delete, correct, and limit use of sensitive personal information. We do not discriminate against users who exercise these rights. Authorized agents may submit requests on your behalf with written authorization.
9.3 Republic of Korea (PIPA)
The Korean Personal Information Protection Act ("PIPA") amendment was passed by the National Assembly on 12 February 2026 and officially promulgated on 10 March 2026. Most provisions take effect on 11 September 2026; the regime described below applies prospectively from that date.
Key changes you should know about:
- The administrative-fine cap increases from 3% to up to 10% of total revenue, but only in specific high-severity circumstances: (a) repeated violations involving willful misconduct or gross negligence within a three-year period, (b) violations affecting ten million or more data subjects, or (c) failure to comply with a corrective order issued by the Personal Information Protection Commission (PIPC). Lower-severity violations remain subject to the prior penalty bands.
- The business owner or legal representative is now explicitly designated as the ultimate person responsible for processing and protecting personal information.
- Where a violation is not caused by intent or gross negligence, the PIPC must reduce penalties for organizations that demonstrate verified investment in privacy (dedicated budget, personnel, equipment, and systems).
- ISMS-P (Personal Information & Information Security Management System) certification, previously voluntary, becomes mandatory for qualifying private entities from 1 July 2027.
We treat Korean users' data under PIPA's mandatory / optional consent distinction. We do not collect Korean Resident Registration Numbers (주민등록번호) under any circumstance.
9.4 Japan (APPI)
The most recent amendment bill to Japan's Act on the Protection of Personal Information ("APPI") was approved by the Japanese Cabinet on 7 April 2026 and submitted to the Diet. As of the "Last Updated" date of this Privacy Policy, the bill is pending Diet enactment; once enacted and promulgated, the amendments come into force within two years.
Anticipated changes once the amendment takes effect include:
- A new consent exemption for statistical processing, including AI-model training, allowing businesses to use publicly available sensitive personal data and to share personal data with third parties for such purposes, subject to transparency and contractual safeguards.
- New protections for children's data, including parental consent for users under 16 and enhanced child rights to request deletion or suspension of data use.
- New protections for biometric data.
- An administrative fine system under the Personal Information Protection Commission (PPC).
- A risk-based notification regime: businesses may be exempt from individual notification where the PPC designates a breach as low-risk, provided alternative safeguards are taken.
Cross-border transfers to Japan-based partners (including quantum hardware partners where Q-Bridge routes a circuit submission to Japan) are made under SCCs with explicit Japanese-language disclosures available on request to privacy@swiftquantum.tech.
9.5 Canada (PIPEDA, Quebec Law 25)
Quebec users may request French-language communications. Our designated Privacy Officer is Park Eun Min, contactable at privacy@swiftquantum.tech.
9.6 Germany (BDSG)
We operate without a physical presence in Germany; for inquiries please contact privacy@swiftquantum.tech. Data minimization and storage limitation principles are applied across the platform.
9.7 Brazil (LGPD), Australia (Privacy Act 1988)
LGPD: our Data Protection Officer is contactable at the privacy email. Australia: complaints may be lodged with the Office of the Australian Information Commissioner (OAIC) after first attempting resolution with us.
9.8 Other Jurisdictions
We aim to comply with applicable data-protection laws in every
jurisdiction where the Services are available. The Compliance page
(/compliance) lists our regulation tracking across the eight primary
jurisdictions.
10. Quantum Hardware Disclosure
When you use Q-Bridge to submit a circuit to a third-party quantum backend (IBM Quantum, IonQ, Rigetti, or others you select):
- Submissions are subject to the applicable hardware provider's terms and privacy policy.
- Hardware availability is not guaranteed; queues, calibration windows, and outages may delay or prevent execution.
- Results may be affected by quantum noise and decoherence; shot-by-shot variance is inherent and not a defect.
- Hardware-execution credits are non-refundable once consumed.
11. Changes to This Policy
We will notify you of material changes by:
- In-app notification at next launch;
- Email to your registered address (for non-trivial changes);
- Updating the "Last Updated" date at the top of this page.
For material changes affecting privacy rights, we provide 30 days' advance notice before the change takes effect.
12. Contact
| Purpose | Contact |
|---|---|
| General privacy inquiries | privacy@swiftquantum.tech |
| Data subject rights requests | privacy@swiftquantum.tech |
| Security disclosures | security@swiftquantum.tech |
| Legal / formal notices | legal@swiftquantum.tech |
| Customer support | support@swiftquantum.tech |
| Phone (Korea, business hours KST) | +82 10-5369-1420 |
| Postal | MQuantum, 39 Goryeodae-ro 10-gil, #206, Seongbuk-gu, Seoul, Republic of Korea |
Operating Entity: MQuantum (엠퀀텀) Sole proprietor, Republic of Korea Business Registration No. 309-96-05114 Representative: Park Eun Min (박은민) — IEEE Member, Designated Privacy Officer
This policy is the canonical English version. Translations are provided for convenience; in case of conflict, the English version controls unless local law mandates otherwise (notably PIPA in Korea, where the Korean version controls).