01Who we are and what this policy covers
We are the controller for the personal data described here. This policy covers the QRouter website, console, and API.
This Privacy Policy explains how [[LEGAL_ENTITY_NAME]], [[ENTITY_TYPE_AND_JURISDICTION]], of [[COMPANY_ADDRESS]] (we, us, QRouter) collects, uses, shares, and protects personal data when you use the QRouter website, the console, the HTTP API, and related services (the Service).
For the personal data described in this policy we act as the data controller under the EU and UK General Data Protection Regulation. Our use of the Service is governed separately by the Terms of Service.
- Privacy contact: [[PRIVACY_EMAIL]]
- Data protection contact: [[DPO_CONTACT]]
- EU / UK representative (Article 27 GDPR, where applicable): [[EU_UK_REPRESENTATIVE]]
02The short version
- You sign in with Google or GitHub. We never see or store a password.
- We collect the account, workspace, billing, and usage data needed to run circuits and charge for them accurately.
- Circuits you submit are transmitted to the quantum compute provider that runs them. That is inherent to the product — see how circuits reach compute providers.
- Card details go to Stripe, not to us. We store only Stripe's customer identifier and our own credit ledger.
- We set only the cookies needed to keep you signed in. There is no analytics, advertising, or cross-site tracking, so there is no cookie banner.
- We do not sell personal data, and we do not share it for cross-context behavioural advertising.
- You can purge circuit source, results, and stored artifacts yourself through the API, and you can ask us to erase your account data.
03Personal data we collect
Most of this comes directly from you or is generated as you use the Service. We do not buy personal data from data brokers and we do not enrich your profile from third-party sources.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account and profile | Email address, display name, and the account identifier from your sign-in provider; optional company or project name; your interface preferences; whether onboarding and billing setup are complete. | Google or GitHub at sign-in; the onboarding form |
| Workspace and membership | Workspace name and identifier, who created it, and each member's role (owner, admin, developer, billing, or member). | Created automatically at signup; workspace administrators |
| Waitlist application | Name, email address, LinkedIn profile URL, job title, self-declared quantum experience level, how you heard about us, and the status of your application. | The waitlist form |
| Contact enquiries | Name, email address, phone number, and the content of your message. | The public contact form |
| Support reports | Your account identifier and email, the category, subject, and body of the report, its status, and our internal notes on it. | The in-console report form |
| Billing | The customer identifier issued by our payment processor, whether a payment method is saved, your credit balance, and a ledger of every purchase, reservation, charge, release, refund, and adjustment with the associated payment identifier. We never receive or store your full card number. | Generated as you buy and consume credits; Stripe |
| API credentials | For each API key: its label, a short non-secret prefix, environment, scopes, creation and last-used timestamps, and expiry or revocation time. The key itself is stored only as an irreversible SHA-256 hash. | Created by workspace administrators |
| Usage and technical | Job timestamps and status transitions, routing decisions and rejection reasons, request identifiers, per-key request counters used for rate limiting, and the server and platform logs our hosting and database providers generate, which include IP address and user agent. | Generated automatically as you use the Service |
| Integrations | If you connect GitHub: the app installation identifier and the connected account login and type. For each project: repository name and URL, branches, and the circuit path. If you configure webhooks: the destination URL and delivery history. | You, when you enable the integration |
| Assistant conversations | The messages you send to the console assistant, the model replies and reasoning summaries, thread titles, and per-workspace message and token counters. | You, when you use the assistant |
| Access administration | Email addresses recorded on the pilot access list and the administrator list, and who added them. | Our administrators |
We do not intentionally collect special category data (such as health, biometric, or political data). Please do not put such data into circuit names, support messages, or the console assistant.
04Your circuits, results, and artifacts
Circuit source, transpiled programs, execution results, job parameters, and connected repository content are your content rather than data about you, but they are held under your account and are covered by this policy. We treat them as confidential to your workspace.
We store, for each submission:
- the OpenQASM source and a hash of it;
- the analysis, the routing decision and its trace, the quote, and the chosen backend;
- encrypted copies of the source, the transpiled program, and the result as stored artifacts; and
- the request and response exchanged with the compute provider, kept as a diagnostic record of the attempt.
If a circuit contains personal data — for example in a comment, a job name, or embedded input data — that data is processed as part of running the job and is transmitted to the compute provider along with the circuit. Please avoid putting personal data into circuits.
05Circuits are transmitted to the compute provider that runs them
This is the most important disclosure in this policy. QRouter routes work to hardware operated by other companies. Running a circuit means sending it to one of them.
When a job is dispatched, we transmit the transpiled circuit, the shot count, and the associated job identifiers to the selected compute provider. The provider executes the program on its own infrastructure, under its own terms and privacy practices, and returns a result which we normalize and store for you.
Which provider receives your circuit depends on the routing decision for that job, on the constraints and target you set, and on which backends are available. The console and the API show the selected backend before execution when you request a quote, and the job record preserves it afterwards. If you need a specific provider — or need to avoid one — pin the target rather than relying on automatic routing.
Compute providers act as independent controllers of the data they receive, not as our processors. We cannot control how long a provider retains a submitted program, whether it is reviewed by provider staff, or which jurisdictions it is processed in. Review the terms of any provider you route to before submitting sensitive or proprietary circuits.
The current provider list is under who we share data with. Simulator-only routing keeps the workload within our own infrastructure and the infrastructure provider that hosts it.
06Why we use your data, and our legal bases
Where the EU or UK GDPR applies, we rely on the following legal bases under Article 6. Where it does not apply, the purposes are the same.
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and secure your account and workspace | Account, profile, workspace and membership data | Article 6(1)(b) — performance of a contract |
| Analyze, price, route, execute, and return your workloads | Circuits, job parameters, results, API credentials, usage data | Article 6(1)(b) — performance of a contract |
| Take payment, meter credits, and keep the ledger | Billing data, ledger entries, payment identifiers | Article 6(1)(b) — contract; Article 6(1)(c) — legal obligation for accounting and tax records |
| Review waitlist applications and grant pilot access | Waitlist application data, access list entries | Article 6(1)(b) — steps at your request before a contract; Article 6(1)(f) — legitimate interest in selecting suitable pilot participants |
| Answer your enquiries and provide support | Contact form data, support reports, account data | Article 6(1)(b) — contract; Article 6(1)(f) — responding to your enquiry |
| Send operational messages about your account, jobs, and billing | Email address, job and billing events | Article 6(1)(b) — performance of a contract |
| Prevent abuse, enforce quotas and rate limits, and secure the Service | Usage counters, request identifiers, logs, API key metadata | Article 6(1)(f) — legitimate interest in a secure, available service |
| Debug failures and improve routing, pricing, and reliability | Job records, provider request and response diagnostics, aggregated metrics | Article 6(1)(f) — legitimate interest in maintaining and improving the Service |
| Comply with law, including export control and sanctions screening | Account and workspace data, usage records | Article 6(1)(c) — legal obligation; Article 6(1)(f) — legitimate interest |
| Establish, exercise, or defend legal claims | Whatever is relevant to the claim | Article 6(1)(f) — legitimate interest |
We do not currently run a marketing mailing list. If we start sending marketing email, we will rely on your consent under Article 6(1)(a) where required and every message will have a one-click unsubscribe. You can object to any processing based on legitimate interests — seeyour rights.
07Who we share data with
We do not sell personal data. We share it with the service providers below, who process it on our behalf or, in the case of compute providers and identity providers, as independent controllers for the part they operate. Which of them is engaged depends on how your job is routed and which integrations you enable.
| Provider | Role | What it receives |
|---|---|---|
| Supabase | Database, authentication, and file storage | Substantially all account, workspace, job, billing-ledger, assistant, waitlist, and support data, plus encrypted artifacts when object storage is not configured |
| Vercel | Application hosting and content delivery | Request metadata and server logs, including IP address and user agent, and any data in transit through the application |
| Stripe | Payment processing | Your card details entered into Stripe's payment form, the customer record associated with your workspace, and purchase amounts and identifiers |
| Google sign-in, and the Gemini API behind the console assistant | For sign-in: your email and basic profile. For the assistant: the text of your requests and the workspace context attached to them | |
| GitHub | GitHub sign-in and repository access through our GitHub App | For sign-in: your email and basic profile. For repositories: the installation and repository selections you grant, in order to read the files you point us at |
| Amazon Web Services | Amazon Braket execution — including the IonQ, IQM, and Rigetti processors offered through it — and result storage | Transpiled circuits, shot counts, job identifiers, and execution results |
| IBM Quantum | Execution on IBM quantum hardware | Transpiled circuits, shot counts, job identifiers, and execution results |
| IonQ | Execution on IonQ hardware when addressed directly | Transpiled circuits, shot counts, job identifiers, and execution results |
| Vultr | Simulator capacity, encrypted artifact object storage, and AI inference for the routing advisor | Circuits and shot counts sent for simulation, encrypted artifact objects, and advisor request text where that provider is used |
| OpenRouter | Fallback AI inference for the routing advisor | Advisor request text, where the primary inference provider is unavailable |
We also share personal data with professional advisers where necessary, with authorities where we are legally required to, and with an acquirer if we are involved in a merger, acquisition, or sale of assets — in which case we will tell you before your data becomes subject to a different policy.
If you configure a webhook endpoint, job events including execution results are delivered to the URL you supply. Data sent there leaves our control and is your responsibility.
Where a provider acts as our processor, we put a data processing agreement in place. The status of those agreements and of the international transfer safeguards is: [[DPA_AND_TRANSFER_STATUS]].
08International transfers
The providers listed under who we share data with operate globally, and several are established in the United States. Using the Service therefore involves transferring personal data outside the European Economic Area and the United Kingdom. Individual quantum backends are located in specific regions — for example the Braket devices we route to sit in United States and European regions — so a job may be executed in a country different from the one you are in.
Our primary data hosting regions are: [[DATA_HOSTING_REGIONS]].
Where we transfer personal data out of the EEA or the UK, we rely on an adequacy decision where one covers the recipient, and otherwise on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by the technical measures under how we protect your data. You can ask us for details of the safeguards applying to a specific transfer by writing to [[PRIVACY_EMAIL]].
09How long we keep data, and how to delete it
You can purge circuit source, results, and stored artifacts yourself through the API. Account closure is currently handled by request.
We keep personal data only as long as we need it for the purposes set out under why we use your data.
| Data | Retention |
|---|---|
| Account, profile, workspace, and membership | For as long as the account exists, then erased on closure |
| Circuit source, transpiled programs, results, and artifacts | Until you release or delete the circuit, or the account is closed. Otherwise: [[RETENTION_PERIOD]] |
| Job records, routing decisions, events, and provider diagnostics | Job and routing history remain as the execution and billing audit trail after a release. Provider attempt rows and event payloads for that circuit's jobs are cleared with the release: [[RETENTION_PERIOD]] |
| Webhook delivery records and payloads | Delivery history may remain; payloads for jobs of a released or deleted circuit are cleared with that operation. Otherwise: [[RETENTION_PERIOD]] |
| Billing ledger and payment records | For the period required by applicable tax and accounting law, typically six to ten years from the transaction |
| Assistant conversation threads | Until the thread or the workspace is deleted: [[RETENTION_PERIOD]] |
| Assistant usage counters | Automatically deleted two days after the usage window |
| API rate-limit counters | Automatically deleted ten minutes after the window closes |
| Waitlist applications | Until the application is decided, then: [[RETENTION_PERIOD]] |
| Contact enquiries and support reports | [[RETENTION_PERIOD]] |
| Server and platform logs | For the retention period of the hosting and database providers listed under who we share data with |
Deleting data yourself
- Release a circuit —
POST /api/v2/circuits/{id}/releaseerases the stored source, results, provider attempt diagnostics, job-event and webhook-delivery payloads, and encrypted artifacts for that circuit and its executions, once every job has reached a final state. Job, quote, and billing records remain as the audit trail. - Delete a circuit —
DELETE /api/v2/circuits/{id}does the same scrub and then removes the circuit record. - Revoke an API key or remove a webhook endpoint from the console at any time.
- Disconnect billing from the console to remove saved payment methods, or uninstall the GitHub App to end repository access.
Releasing or deleting a circuit through the API clears circuit content in the database and removes the related encrypted artifact objects. Age-based SQL retention uses the same database scrub; encrypted objects in object storage are removed on the API release and delete paths, so do not treat a SQL-only scheduled purge as a complete artifact wipe.
Closing your account
There is no self-service account deletion in the console today. To close your account and have the associated personal data erased, email [[PRIVACY_EMAIL]] from the address on the account. We will confirm your identity, erase or anonymize your personal data, and retain only what we are legally required to keep — principally billing and tax records — for the period stated above.
Deleted data may persist in encrypted backups for a limited period before those backups expire on their normal cycle.
10How we protect your data
These are the measures actually implemented in the Service today. They are a description of our controls, not a warranty of absolute security.
- No passwords. Sign-in is delegated to Google or GitHub, so we never handle or store a password.
- API keys are stored as hashes. Only an irreversible SHA-256 hash and a short non-secret prefix are kept. The key itself is shown once and cannot be recovered from our systems.
- Sensitive values are encrypted at rest. Circuit source, transpiled programs, and results written to object storage are encrypted with AES-256-GCM before upload, as are provider credentials and webhook signing secrets.
- Tenant isolation is enforced in the database. Row-level security is enabled on the tables holding customer data, and access is checked against workspace membership on every query. Artifact storage is private and scoped to the owning workspace.
- Privileged operations are server-only. The database routines that move credits and dispatch jobs cannot be called by a browser or an API client; access to infrastructure credentials is restricted to server-side code.
- Encryption in transit. All traffic to the Service and to the providers listed under who we share data with uses TLS.
- Abuse controls. API requests are rate limited per key, the console assistant is quota limited per workspace, and console access is restricted to an approval list during the pilot.
- Restricted administration. Administrative views are limited to a named list of administrator accounts held in the database.
No system is completely secure. If you believe your account or a key has been compromised, revoke the key and contact [[SECURITY_EMAIL]] immediately.
11Your rights
If you are in the European Economic Area, the United Kingdom, or another region with comparable law, you have the rights below. We honour these requests for everyone, wherever you are, unless the law prevents it.
- Access — get confirmation of whether we process your personal data and a copy of it.
- Rectification — have inaccurate data corrected and incomplete data completed.
- Erasure — have your personal data deleted where we no longer have grounds to keep it.
- Restriction — have us pause processing while a dispute about accuracy or legitimacy is resolved.
- Portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another controller where technically feasible.
- Objection — object to processing based on our legitimate interests, on grounds relating to your situation.
- Withdraw consent — where we rely on consent, withdraw it at any time, without affecting processing already carried out.
- Complain — lodge a complaint with your local supervisory authority. We would appreciate the chance to address it first.
To exercise any of these, email [[PRIVACY_EMAIL]] from the address on your account, or use the contact form. We may ask for information to confirm your identity. We respond within one month, and will tell you if we need up to two further months because the request is complex. Exercising these rights is free unless a request is manifestly unfounded or excessive.
12United States privacy rights
This section applies to residents of California and of other US states with comprehensive privacy laws.
In the past twelve months we have collected the following categories of personal information under the California Consumer Privacy Act as amended by the CPRA: identifiers (name, email, account identifier, IP address); commercial information (credit purchases and consumption); internet or network activity (API and console usage, logs); professional or employment-related information (job title and experience level, if you applied to the waitlist); and inferences drawn only for routing and reliability purposes. The sources, purposes, and recipients are described under personal data we collect, why we use your data, and who we share data with.
We do not sell personal information, and we do not share personal information for cross-context behavioural advertising. We have not done so in the preceding twelve months, including for consumers we know to be under 16. We do not use or disclose sensitive personal information for purposes beyond those permitted without an opt-out, so no "Limit the Use of My Sensitive Personal Information" link is required.
You have the right to know what we collect and why, to request deletion, to request correction, to opt out of sale or sharing (which does not occur), and not to be discriminated against for exercising these rights. Submit a request to [[PRIVACY_EMAIL]]. An authorized agent may submit on your behalf with proof of authorization; we will still verify your identity directly.
13Cookies and local storage
We set only the cookies needed to keep you signed in. There is no analytics, advertising, or cross-site tracking on this site, and therefore no cookie banner.
Authentication cookies (strictly necessary). When you sign in, our authentication provider sets session cookies that identify your session and hold the tokens that keep you signed in. Our server refreshes them as you browse. Without them you cannot use the console. They are removed when you sign out or when the session expires.
Theme preference (local storage, not a cookie). Your light or dark appearance choice is saved in your browser under qrouter-theme. It stays on your device and is never sent to our servers.
Payment fraud prevention (third party). When the Stripe payment form is displayed during billing setup, Stripe sets its own cookies to detect fraudulent activity. These are set by Stripe under its own privacy policy and are necessary for the payment function you requested.
What we do not use. No analytics, product-analytics, session-recording, advertising, retargeting, or social media tracking technologies are loaded on this site. No third-party tracking pixels are embedded.
You can block or delete cookies through your browser settings, but blocking the authentication cookies will prevent you from signing in. If we ever introduce non-essential cookies, we will ask for your consent first and update this section.
14Automated processing and AI
Routing. The QCI Engine automatically selects a backend for your workload by applying your constraints and scoring eligible candidates on projected quality, queue time, cost, and reliability. This decision is based on the properties of the circuit and the parameters you set, not on personal data about you, and it does not produce legal or similarly significant effects on you within the meaning of Article 22 GDPR. Every decision keeps a trace you can inspect, and you can override it by pinning a target.
Assistant and routing advisor. These features send the text you enter, plus the workspace context attached to the request, to a third-party language model provider — Google, and where configured Vultr or OpenRouter — which processes it and returns a response. Conversations are stored so threads persist, and usage is metered per workspace.
We do not use your conversations or your circuits to train our own models. Whether a given model provider retains submitted input or uses it to improve its own models depends on the plan and terms in effect between us and that provider; our current position is: [[AI_PROVIDER_TRAINING_TERMS]].
Please do not enter credentials, personal data about other people, or content you are not permitted to disclose into the assistant.
15Children’s privacy
The Service is a developer and research tool intended for people aged 18 and over. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact [[PRIVACY_EMAIL]] and we will delete it.
16If something goes wrong
We maintain procedures for handling suspected personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to you, we will notify you directly without undue delay, describing what happened, the likely consequences, and the steps we are taking.
17Changes to this policy
We update this policy as the Service changes or as the law requires. The current version is always at this page, with the last-updated date at the top. For changes that materially affect how we use your personal data, we will give notice by email to the address on your account, by an in-console notice, or both, before the change takes effect. Please review it periodically.
18How to contact us
[[LEGAL_ENTITY_NAME]], [[COMPANY_ADDRESS]].
- Privacy requests and questions about this policy: [[PRIVACY_EMAIL]]
- Data protection contact: [[DPO_CONTACT]]
- EU / UK representative: [[EU_UK_REPRESENTATIVE]]
- Security reports: [[SECURITY_EMAIL]]
- General support: [[SUPPORT_EMAIL]] or the contact form
If you are in the EEA or the UK and you are not satisfied with our response, you may complain to your national data protection authority.
Questions about this document?