Privacy Policy
QuantumRand API Platform
Last Updated: March 2026
Noel Innovations LLC, doing business as QuantumRand
1. Introduction
Noel Innovations LLC, doing business as QuantumRand ("QuantumRand," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights regarding your personal data when you use quantumrand.dev and the QuantumRand API (collectively, the "Service").
By using the Service, you agree to the collection and use of information as described in this Privacy Policy.
2. Information We Collect
2.1 Account Information
When you create an account we collect:
- Email address
- Password (hashed using bcrypt — never stored in plaintext)
- Account creation timestamp
- Subscription tier
2.2 API Usage Data
When you make API calls we automatically log:
- Endpoint called
- HTTP method and status code
- Response time in milliseconds
- Entropy source (quantum / hybrid / fallback)
- Timestamp of the request
- API key identifier (not the raw key)
This data is retained for 12 months and is visible to you in your audit dashboard.
2.3 Billing Information
Payments are processed by Stripe, Inc. QuantumRand stores only your Stripe customer ID. We do not store payment card numbers, CVVs, or bank account details. Stripe's privacy policy governs how your payment data is handled: stripe.com/privacy.
2.4 Waitlist Information
If you submit an early access waitlist form we collect your name, company name, email address, and estimated transaction volume. This information is used only to contact you about early access.
2.5 Communications
If you contact us by email we retain those communications to respond to your inquiry and improve the Service.
2.6 What We Do NOT Collect
- Entropy values generated for your requests — these are delivered and immediately discarded
- Private keys from /v1/finance/keypair — shown once in response, never stored
- Payload content submitted to /v1/finance/audit-sign — only the hash and signature are stored
- IP addresses — we do not log or store request IP addresses by default
- Browser cookies or tracking pixels on API endpoints
3. How We Use Your Information
| Purpose | Description |
|---|---|
| Provide the Service | Process API requests, authenticate users, enforce rate limits |
| Billing | Process payments, manage subscriptions, send receipts |
| Security | Detect abuse, investigate security incidents, rotate compromised keys |
| Compliance | Maintain audit logs for SOC 2, PCI-DSS, and HIPAA compliance reviews |
| Communication | Send service updates, billing notifications, security alerts |
| Improvement | Analyze aggregate usage patterns to improve the Service |
| Legal | Comply with legal obligations and enforce our Terms of Service |
4. Data Storage and Residency
Data is stored and processed in the United States. If you are located outside the United States, by using the Service you consent to the transfer of your data to the United States.
| Data Type | Location |
|---|---|
| Account & usage data | Google Cloud Firestore — United States (us-central1) |
| API infrastructure | Railway — United States |
| Billing data | Stripe — United States |
| Content delivery & DNS | Cloudflare — United States / global edge |
| Transactional email | Resend — United States |
| Entropy generation | IBM Quantum hardware and/or quantum-circuit simulation — United States |
| Entropy pool | In-memory only — never written to disk |
5. Data Sharing and Third Parties
5.1 Service Providers
We share data with the following third-party service providers strictly to operate the Service:
| Provider | Role |
|---|---|
| Google Cloud (Firestore) | Database — account and usage data storage |
| Railway | API hosting infrastructure |
| Stripe | Payment processing |
| Cloudflare | Content delivery, DNS, and DDoS protection |
| Resend | Transactional email delivery |
| IBM Quantum | Quantum entropy hardware for seed generation (no personal data is sent) |
5.2 Legal Requirements
We may disclose your information if required by law, subpoena, court order, or government request, or if we believe disclosure is necessary to protect the rights, property, or safety of QuantumRand, our users, or the public.
5.3 Business Transfers
If Noel Innovations LLC is acquired, merges with another company, or sells substantially all of its assets, your information may be transferred as part of that transaction. We will notify you via email before your data is transferred and becomes subject to a different privacy policy.
5.4 No Sale of Data
QuantumRand does not sell, rent, or trade your personal information to third parties for their marketing purposes.
6. Security
- API keys are hashed with SHA-256 before storage — raw keys are never retained
- All connections use TLS 1.3 minimum
- Passwords are hashed using bcrypt with appropriate cost factor
- Access to production database is restricted by IAM roles with principle of least privilege
- Security incidents are investigated and affected users notified within 72 hours of confirmation
- No method of transmission or storage is 100% secure. If you discover a security vulnerability please contact security@quantumrand.dev.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Retained while account is active + 90 days after deletion |
| API usage logs | 12 months rolling |
| Billing records | 7 years (tax and legal compliance) |
| Waitlist data | Until you request removal or 24 months, whichever is sooner |
| Support communications | 3 years |
8. Your Rights
8.1 Access and Portability
You may export your account data and API usage logs at any time from your dashboard via the CSV export feature.
8.2 Correction
You may update your account email address from your dashboard. For other corrections contact privacy@quantumrand.dev.
8.3 Deletion
You may request deletion of your account and associated personal data by emailing privacy@quantumrand.dev. We will process deletion requests within 30 days, subject to retention requirements for billing records and legal compliance.
8.4 GDPR Rights (EU Residents)
If you are located in the European Economic Area you have the right to: access your personal data, rectify inaccurate data, erasure (right to be forgotten), restrict processing, data portability, and object to processing. To exercise these rights contact privacy@quantumrand.dev. You also have the right to lodge a complaint with your local data protection authority.
8.5 CCPA Rights (California Residents)
California residents have the right to know what personal information we collect, the right to delete personal information, and the right to opt out of the sale of personal information. QuantumRand does not sell personal information. To exercise your rights contact privacy@quantumrand.dev.
9. Cookies and Tracking
The QuantumRand dashboard uses session cookies strictly necessary for authentication. We do not use advertising cookies, tracking pixels, or third-party analytics. We do not use Google Analytics or similar tracking services on quantumrand.dev.
10. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact privacy@quantumrand.dev and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered account holders at least 30 days before taking effect. The effective date at the top of this document will be updated with each revision.
12. Contact
For privacy questions, data requests, or to exercise your rights:
Noel Innovations LLC DBA QuantumRand
privacy@quantumrand.dev
legal@quantumrand.dev
quantumrand.dev/privacy
New York, NY