Security

How we handle your data

What stays on your device, when our backend is involved, and how to delete your account and data.

Principles

Four design principles

  • Device · cloud

    Where it runs

    Paid plans run simulations on your iPhone, iPad or Mac, with on-device AI where your device supports it. Free plans use our cloud engine. Our backend also handles account sync, the cloud AI features the privacy policy names (such as AI Tutor conversations) and web checkout.

  • NIST FIPS 203

    Post-quantum cryptography

    On the Q-Bio web app, compound inputs are sealed with ML-KEM-768 (NIST FIPS 203) and AES-256-GCM before they are sent. Our other services use standard HTTPS (TLS 1.2 or later). Q-Shield maps your own cryptography to FIPS 203, 204 and 205.

  • GDPR Art. 17

    Right to erasure

    You can delete your account at any time (GDPR Art. 17). Deleting your account removes your sign-in data immediately. Data held by individual apps is removed separately; contact support to confirm. AI Tutor chat history can be cleared in Settings.

  • Labels · no data sale

    Clear labels, no data sales

    Estimates are labeled as estimates, simulations as simulations. We don’t sell personal data, AI Tutor conversations are not used to train models.

Data flow

Where your data goes

There are three stages. The middle one is optional and applies only to the features listed.

  1. 01 · Default

    Your device

    • Simulation on paid plans, and on-device AI where supported
    • Offline learning mode (no data sent)
    • Payments in the app go through Apple
  2. 02 · Only when neededOptional

    Our backend

    • Account sync, and the cloud engine on free plans
    • AI Tutor: OpenAI in the apps, Anthropic on the web
    • HTTPS (TLS 1.2 or later) · one database per app, encrypted at rest (AES-256)
  3. 03 · Your call

    Deletion

    • Delete account and data (GDPR Art. 17)
    • Sign-in data removed immediately; app data separately
    • Request by email: support@swiftquantum.tech
Standards

Standards we are aligned to

“Aligned to” means we design and operate against these frameworks. It is not a third-party certification.

Standards we are aligned to
FrameworkScopeStatus
Privacy regulations
GDPRGeneral Data Protection RegulationEuropean UnionAligned to
CCPACalifornia Consumer Privacy ActCalifornia, USAAligned to
APPIAct on Protection of Personal InformationJapanAligned to
PIPAPersonal Information Protection ActSouth KoreaAligned to
PIPEDAPersonal Information Protection and Electronic Documents ActCanadaAligned to
UK GDPRUK General Data Protection RegulationUnited KingdomAligned to
BDSGFederal Data Protection ActGermanyAligned to
LGPDGeneral Data Protection LawBrazilAligned to
Cryptography
NIST FIPS 203 · ML-KEMKey encapsulation (ML-KEM-768 seals Q-Bio web compound inputs)Aligned to
NIST FIPS 204 · ML-DSALattice-based digital signaturesMapped in Q-Shield
NIST FIPS 205 · SLH-DSAHash-based digital signaturesMapped in Q-Shield
Export control
ECCN 5D002Software with cryptographic capabilitiesSelf-classified
Infrastructure

Hosting, isolation and monitoring

A short summary. The linked pages have the details.

  • Hosting

    Serverless compute and managed databases behind a global edge CDN with firewall and DDoS protection. Data is hosted on AWS in Seoul (ap-northeast-2).

    • Serverless
    • Edge CDN
    • WAF · DDoS
  • Databases & access

    Each app uses its own database on a shared managed database server. Database storage and automated backups are encrypted at rest with AES-256 (AWS KMS). Access to user data is role-based, and container images live in a private registry.

    • TLS 1.2+
    • AES-256 at rest
    • RBAC
  • Monitoring & delivery

    CloudWatch alarms and uptime checks. Deploys are built locally and verified against the origin. Self-serve plans have no SLA or uptime commitment.

    • Monitoring
    • Direct deploy
    • No public SLA
Per product

Limits of each app

These are the same limitation notes shown inside each app.

  • SwiftQuantum

    Free plans run circuits on our cloud engine; paid plans can also simulate on your device.

  • QuantumNative

    The physics is real and tutor answers are checked. Diagrams are not AI-generated.

  • Q-Bridge

    Entanglement views use preset reference patterns, and cost and queue figures are rate-card estimates, not live vendor data.

  • QuantumCareer

    AI-assisted analysis is for reference only. You decide what to send.

  • Q-Shield Sentinel

    Assessment, not certification. Q-Shield assesses your cryptography against the NIST standards; it does not certify compliance.

  • Q-Alpha

    Education, not investment advice. Q-Alpha is for learning; SwiftQuantum is not a registered investment adviser.

  • Q-Logos

    Routes are suggestions from a mathematical model, and income and savings figures are simulated estimates. They do not guarantee time, fuel or earnings.

  • Q-Bio Genesis

    RUO — not a medical device. Research Use Only; do not use it for medical advice or clinical decisions.

  • Where it runs
    Paid plans simulate on your device; free plans use our cloud engine. Cloud AI features are labeled in the app.
  • PQC assessment
    Q-Shield maps your cryptography to NIST FIPS 203, 204 and 205.
  • Labeled estimates
    When a number is an estimate, the app says so.
  • 7 languages
    EN · KO · JA · ZH · ES · FR · DE

Security questions

Are you SOC 2 or ISO 27001 certified?

We don’t claim any third-party certification on this site. What we list are frameworks we align to. If your procurement process needs a security questionnaire answered, contact sales and we’ll answer it directly.

Does my data leave my device?

For the features that need our backend: account sync, the cloud engine on free plans, cloud AI features such as the AI Tutor (OpenAI in the apps, Anthropic on the web, sent without your name or email) and web checkout via Stripe. QuantumCareer cover letters include the name on your profile. On paid plans, simulation runs on the device. We never sell personal data.

How do I delete my account and data?

Email support@swiftquantum.tech (AI Tutor history can also be cleared in the app under Settings → Privacy). This is your right under GDPR Art. 17. Deleting your account removes your sign-in data immediately. Data held by individual apps is removed separately; contact support to confirm.

Where do you actually use post-quantum cryptography?

On the Q-Bio web app, compound inputs are sealed with ML-KEM-768 (NIST FIPS 203) and AES-256-GCM before they are sent. Our other services use standard HTTPS (TLS 1.2 or later). Q-Shield helps you plan your own migration to ML-KEM, ML-DSA and SLH-DSA. It is an assessment tool and does not certify.

Try the apps on your own device

Free to start on iPhone, iPad, Mac and the web. Paid plans from $4.99/mo.

Cancel anytime in your settings.