Privacy Policy
Effective: 2026-08-29
1. What we collect
- Account: email, display name, and local password (stored only as a salted hash). If you use Google sign-in, we also store Google's stable account identifier and verified email, but not Google sign-in tokens;
- Usage: API call counts (aggregated by key, endpoint, date), sign-in times, registration IP (anti-abuse);
- Website analytics (enabled by default; opt out anytime): page visits, interaction events, acquisition channel, device and browser type, and coarse location reported by Google Analytics; we do not send account email, API keys, or form contents to Google Analytics;
- Referrals: when an account registers through a personal referral link, we record the referring and referred accounts and the registration and email-verification states;
- Payment: handled by Stripe; we store only order and access-period status plus a customer id — we never touch or store card numbers.
2. How we use it
- Operating the service: quotas, rate limits, billing;
- Transactional email only (password reset, expiry reminders) — no marketing mail;
- Abuse prevention: detecting bulk registration and anomalous traffic.
3. Cookies
With analytics enabled, we also measure account creation, email verification, API key creation, a successful console connection test and confirmed initial purchases when you return to the console. Purchase events use an opaque transaction reference and plan name, not your email, API key or payment details. Browser analytics can miss events and is not our billing ledger.
We use a necessary session cookie (httponly, Secure). Referral IDs are passed explicitly from personal referral links to registration requests; no referral-attribution cookie is used. Google Analytics is enabled by default and may set _ga analytics cookies. You can disable it anytime through “Analytics settings” in the footer; your choice is stored in browser local storage. We disable Google advertising signals and ad personalization.
4. Third parties
- Stripe (payments, PCI-DSS compliant);
- Alibaba Cloud (servers, database, email delivery).
- Google Analytics (website traffic analysis enabled by default; you can opt out anytime).
- Google Identity Services (identity verification only when you choose Google sign-in).
Beyond what these services require to operate, we never sell or share your personal data.
5. Security & retention
- HTTPS everywhere; API keys stored as SHA-256 hashes only, plaintext shown once at creation;
- Account data is deleted within 30 days of account closure, except records we must retain by law.
6. Your rights
Export or delete your account data, or correct your email, anytime — write to support@quantcoda.com; we respond within 7 business days.
7. Contact
support@quantcoda.com