How we handle your data
What stays on your device, when our backend is involved, and how to delete your account and data.
Four design principles
- Device · cloud
Where it runs
Paid plans run simulations on your iPhone, iPad or Mac, with on-device AI where your device supports it. Free plans use our cloud engine. Our backend also handles account sync, the cloud AI features the privacy policy names (such as AI Tutor conversations) and web checkout.
- NIST FIPS 203
Post-quantum cryptography
On the Q-Bio web app, compound inputs are sealed with ML-KEM-768 (NIST FIPS 203) and AES-256-GCM before they are sent. Our other services use standard HTTPS (TLS 1.2 or later). Q-Shield maps your own cryptography to FIPS 203, 204 and 205.
- GDPR Art. 17
Right to erasure
You can delete your account at any time (GDPR Art. 17). Deleting your account removes your sign-in data immediately. Data held by individual apps is removed separately; contact support to confirm. AI Tutor chat history can be cleared in Settings.
- Labels · no data sale
Clear labels, no data sales
Estimates are labeled as estimates, simulations as simulations. We don’t sell personal data, AI Tutor conversations are not used to train models.
Where your data goes
There are three stages. The middle one is optional and applies only to the features listed.
- 01 · Default
Your device
- Simulation on paid plans, and on-device AI where supported
- Offline learning mode (no data sent)
- Payments in the app go through Apple
- 02 · Only when neededOptional
Our backend
- Account sync, and the cloud engine on free plans
- AI Tutor: OpenAI in the apps, Anthropic on the web
- HTTPS (TLS 1.2 or later) · one database per app, encrypted at rest (AES-256)
- 03 · Your call
Deletion
- Delete account and data (GDPR Art. 17)
- Sign-in data removed immediately; app data separately
- Request by email: support@swiftquantum.tech
Standards we are aligned to
“Aligned to” means we design and operate against these frameworks. It is not a third-party certification.
| Framework | Scope | Status |
|---|---|---|
| Privacy regulations | ||
| GDPRGeneral Data Protection Regulation | European Union | Aligned to |
| CCPACalifornia Consumer Privacy Act | California, USA | Aligned to |
| APPIAct on Protection of Personal Information | Japan | Aligned to |
| PIPAPersonal Information Protection Act | South Korea | Aligned to |
| PIPEDAPersonal Information Protection and Electronic Documents Act | Canada | Aligned to |
| UK GDPRUK General Data Protection Regulation | United Kingdom | Aligned to |
| BDSGFederal Data Protection Act | Germany | Aligned to |
| LGPDGeneral Data Protection Law | Brazil | Aligned to |
| Cryptography | ||
| NIST FIPS 203 · ML-KEM | Key encapsulation (ML-KEM-768 seals Q-Bio web compound inputs) | Aligned to |
| NIST FIPS 204 · ML-DSA | Lattice-based digital signatures | Mapped in Q-Shield |
| NIST FIPS 205 · SLH-DSA | Hash-based digital signatures | Mapped in Q-Shield |
| Export control | ||
| ECCN 5D002 | Software with cryptographic capabilities | Self-classified |
Hosting, isolation and monitoring
A short summary. The linked pages have the details.
Hosting
Serverless compute and managed databases behind a global edge CDN with firewall and DDoS protection. Data is hosted on AWS in Seoul (ap-northeast-2).
- Serverless
- Edge CDN
- WAF · DDoS
Databases & access
Each app uses its own database on a shared managed database server. Database storage and automated backups are encrypted at rest with AES-256 (AWS KMS). Access to user data is role-based, and container images live in a private registry.
- TLS 1.2+
- AES-256 at rest
- RBAC
Monitoring & delivery
CloudWatch alarms and uptime checks. Deploys are built locally and verified against the origin. Self-serve plans have no SLA or uptime commitment.
- Monitoring
- Direct deploy
- No public SLA
Limits of each app
These are the same limitation notes shown inside each app.

SwiftQuantum
Free plans run circuits on our cloud engine; paid plans can also simulate on your device.

QuantumNative
The physics is real and tutor answers are checked. Diagrams are not AI-generated.

Q-Bridge
Entanglement views use preset reference patterns, and cost and queue figures are rate-card estimates, not live vendor data.

QuantumCareer
AI-assisted analysis is for reference only. You decide what to send.

Q-Shield Sentinel
Assessment, not certification. Q-Shield assesses your cryptography against the NIST standards; it does not certify compliance.

Q-Alpha
Education, not investment advice. Q-Alpha is for learning; SwiftQuantum is not a registered investment adviser.

Q-Logos
Routes are suggestions from a mathematical model, and income and savings figures are simulated estimates. They do not guarantee time, fuel or earnings.

Q-Bio Genesis
RUO — not a medical device. Research Use Only; do not use it for medical advice or clinical decisions.
- Where it runsPaid plans simulate on your device; free plans use our cloud engine. Cloud AI features are labeled in the app.
- PQC assessmentQ-Shield maps your cryptography to NIST FIPS 203, 204 and 205.
- Labeled estimatesWhen a number is an estimate, the app says so.
- 7 languagesEN · KO · JA · ZH · ES · FR · DE
Security questions
Are you SOC 2 or ISO 27001 certified?
We don’t claim any third-party certification on this site. What we list are frameworks we align to. If your procurement process needs a security questionnaire answered, contact sales and we’ll answer it directly.
Does my data leave my device?
For the features that need our backend: account sync, the cloud engine on free plans, cloud AI features such as the AI Tutor (OpenAI in the apps, Anthropic on the web, sent without your name or email) and web checkout via Stripe. QuantumCareer cover letters include the name on your profile. On paid plans, simulation runs on the device. We never sell personal data.
How do I delete my account and data?
Email support@swiftquantum.tech (AI Tutor history can also be cleared in the app under Settings → Privacy). This is your right under GDPR Art. 17. Deleting your account removes your sign-in data immediately. Data held by individual apps is removed separately; contact support to confirm.
Where do you actually use post-quantum cryptography?
On the Q-Bio web app, compound inputs are sealed with ML-KEM-768 (NIST FIPS 203) and AES-256-GCM before they are sent. Our other services use standard HTTPS (TLS 1.2 or later). Q-Shield helps you plan your own migration to ML-KEM, ML-DSA and SLH-DSA. It is an assessment tool and does not certify.
Try the apps on your own device
Free to start on iPhone, iPad, Mac and the web. Paid plans from $4.99/mo.
Cancel anytime in your settings.