Last updated: September 19, 2026

This policy describes how QuantumPass handles information for its mobile app, authentication service, browser integration, shared access and recovery features. Independent websites using QuantumPass control their own accounts and have their own privacy policies.

1. Information We Handle

  • Device and account identifiers: enrollment identifiers, public keys, device names, model and operating-system information, push notification tokens and registration metadata.
  • Authentication and access information: connected sites, site-account references and display labels, session times and outcomes, shared-access relationships, permissions and security events.
  • Network and diagnostic information: IP addresses, request timestamps and information needed to investigate errors, operate the service and prevent abuse.
  • Location: the current Android app requests location permission during onboarding. When available, it obtains coordinates, includes location information in session metadata, and sends coordinates to OpenStreetMap's Nominatim service to obtain a city, state and country description. This can include precise location, not only approximate location. Device settings control permission; denying it may prevent onboarding in the current app.
  • Recovery and backup information: recovery credentials and status, helper relationships, and backup material when those features are used. Encrypted material and its associated metadata are still data handled by the service.
  • Contact information: ordinary device enrollment does not require an email address or phone number. Business customers provide contact details for integration and support. If you contact us, we receive the information you choose to send.

A display label or device name may contain personal information if you or another person put it there. Not requiring your civil identity does not mean that device activity is anonymous or cannot be linked across relevant service records.

2. Biometrics and Credentials

The app invokes operating-system biometric authentication. QuantumPass does not receive fingerprint images or face templates from this process. It handles authentication results, cryptographic proofs and information needed to validate requests.

Device authentication keys are managed on the device. The service also handles enrollment, session, offline-access and recovery credentials. We do not describe the entire service as storing no credentials or having no knowledge of account activity.

3. Uses and Recipients

We use information to authenticate requests, recognize enrolled devices, deliver approval notifications, manage sessions and shared access, support recovery, troubleshoot failures and protect against abuse.

QuantumPass uses Google Firebase Cloud Messaging for push delivery and OpenStreetMap Nominatim for location lookup in the current app. These providers process information needed for those functions under their own applicable terms and policies.

Connected websites receive information needed to authenticate and manage their linked accounts. Shared-access participants receive relevant access information and labels. Those websites and participants may retain information independently of QuantumPass.

4. Security

QuantumPass uses encrypted network connections, device-based authentication and access controls. Security controls reduce risk but cannot guarantee protection from every attack or device compromise. This policy does not assert that every database is encrypted with a particular algorithm, that every connection uses one TLS version, or that the service has passed an independent security audit.

5. Retention and Deletion

Account and registration information is kept to provide the associated service. QuantumPass-managed security logs and server backup files follow a 30-day retention policy. Hosting and infrastructure records may be managed separately. Minimal hashed deletion-suppression records and deletion receipts are retained separately to prevent deleted credentials from returning and to confirm the outcome of deletion.

In the updated app, you can delete your account from App Settings > Delete QuantumPass Account using the primary vault device and biometric confirmation. You can also contact our monitored privacy mailbox to request access or deletion without the app. We verify authority before acting. See account and data deletion for steps and access warnings.

Limited records may need to be retained for security, fraud prevention, legal obligations or handling the request. Contact us for applicable scope and retention information. Uninstalling the app or clearing its storage does not itself delete server-side information.

Deleting QuantumPass information does not delete independent website accounts or copies controlled by other people. Arrange an alternative sign-in method with connected websites before deleting your QuantumPass account.

6. Privacy Requests

For privacy questions, access requests, corrections or deletion requests, contact privacy@quantumpass.io.

Do not email passwords, recovery codes, private keys, biometric images or authentication tokens. We may need to verify control of an enrolled device or another appropriate account-ownership method before acting on a request.