Privacy Policy
Plain English summary: We collect the minimum data needed to run the service. We don't sell your data. We use Stripe for payments (they handle card data, not us). Wallet addresses you paste are public blockchain data — we never ask for private keys.
1. Who We Are
Quantum Exposure Index ("QEI", "we", "us", "our") operates the website at qeindex.xyz. This Privacy Policy explains what personal data we collect, how we use it, and your rights regarding that data.
Questions? Contact us at privacy@qeindex.xyz.
2. Data We Collect
| Data Type | What It Is | How We Get It |
|---|---|---|
| Email address | Used for alerts, subscription management, and updates | You provide it via signup or notification opt-in |
| X (Twitter) profile | Display name, username, profile photo URL — used to personalize your experience | X OAuth when you connect your account (optional) |
| Blockchain addresses | Public wallet addresses used to calculate quantum exposure scores | You paste them into the Wallet Scanner |
| Usage data | AI search count, feature usage, session data | Automatically collected while you use the Service |
| Referral data | Referral link clicks and conversions tied to your account | Generated when you share your referral link |
| Device / browser info | Browser type, viewport, approximate location (country level) | Standard server logs and analytics |
We do not collect: private keys, seed phrases, passwords, payment card numbers, government IDs, or any biometric data.
3. How We Use Your Data
- To provide the Service — account personalization, AI search limits, subscription enforcement, wallet scanning
- To communicate with you — Q-Day alerts, product updates, and newsletters you've opted into
- To manage subscriptions — Stripe uses your email to manage billing; we store subscription status in our database
- To improve QEI — anonymous aggregate usage data helps us understand which features are valuable
- To prevent abuse — IP-based rate limiting to protect the Service from excessive automated use
We do not use your data for automated profiling, targeted advertising, or sale to data brokers.
4. Third-Party Services
QEI integrates with the following third parties. Each has its own privacy policy governing data they receive:
| Service | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing and subscription management | Email, subscription plan. Card data goes directly to Stripe — never to QEI. |
| Supabase | Database and authentication backend | Email, X profile data, usage counters, cached AI scores |
| Anthropic (Claude) | AI-powered quantum risk assessments | Your search query (entity name). No personal identifiers sent. |
| X (Twitter) OAuth | Optional account connection | We receive your public X profile. X's policy governs their side. |
| CoinGecko | Live cryptocurrency price data | No personal data sent — public API calls only |
| Vercel | Hosting and serverless functions | Standard server access logs including IP addresses |
5. Cookies and Local Storage
QEI uses browser localStorage (not traditional cookies) to store:
- Cached AI search results (to reduce API calls and speed up repeat searches)
- Your watchlist of bookmarked entities
- Tour completion status
- Theme and display preferences
- Daily AI search usage counter
This data stays in your browser. It is not transmitted to our servers unless you explicitly trigger a sync action. You can clear localStorage at any time through your browser settings.
We may use standard server-side session cookies for authentication. These are essential for the Service to function and are not used for tracking or advertising.
6. Data Retention
- Account data — retained while your account is active. Deleted within 30 days of account deletion request.
- Email addresses — retained until you unsubscribe or request deletion.
- AI score cache — cached results expire after 14 days and are regenerated on next request.
- Server logs — retained for up to 90 days for security and debugging purposes.
7. Your Rights
Depending on where you live, you may have the following rights regarding your personal data:
- Access — request a copy of data we hold about you
- Correction — request correction of inaccurate data
- Deletion — request deletion of your account and associated data
- Portability — request your data in a portable format
- Opt-out — unsubscribe from marketing emails at any time via the unsubscribe link in any email, or by contacting us
- Withdraw consent — disconnect your X account at any time from your profile panel
To unsubscribe from QEI emails directly: qeindex.xyz/api/unsubscribe?email=YOUR_EMAIL (replace YOUR_EMAIL with your address). You can also use the unsubscribe link in the footer of any QEI email.
To exercise any other rights, email privacy@qeindex.xyz. We will respond within 30 days.
EU/EEA residents (GDPR): Your legal basis for processing is legitimate interest (operating the Service) and consent (optional X connection and email opt-in). You have the right to lodge a complaint with your local data protection authority.
California residents (CCPA): We do not sell personal information. You have the right to know what personal information we collect and to request deletion.
8. Data Security
We use industry-standard security measures including TLS encryption in transit, access-controlled databases, and API key management through environment variables. No method of transmission over the internet is 100% secure. We cannot guarantee absolute security but we take it seriously.
In the event of a data breach that affects your personal data, we will notify affected users in accordance with applicable law.
9. Children's Privacy
QEI is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us at privacy@qeindex.xyz and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email or in-app notification. The effective date at the top of this page will always reflect the most recent version.
11. Contact Us
Privacy questions, data requests, or concerns: