Privacy Policy
Last updated August 17, 2026
1. Introduction and Scope
This Privacy Policy explains how InQuantum, Inc (“Company,” “we,” “our,” or “us”) collects, uses, discloses, and protects personal information when you visit inquantum.ai, use PlanckAI, interact with our APIs or software, communicate with us, or otherwise use our related services (collectively, the “Service”).
Please read this policy together with our Terms of Service. This policy also explains our use of cookies, local storage, and similar technologies. If you do not agree with this policy, do not use the Service.
This policy applies to personal information we handle as a controller or business. When an organization uses the Service to process data on its behalf, that organization controls the data and we generally act as its processor or service provider. In that situation, the organization’s privacy notice and any applicable data processing agreement also govern the processing.
2. Definitions
“Personal Information” or “Personal Data” means information that identifies, relates to, describes, or can reasonably be linked to an individual or household. It does not include information that has been aggregated or de-identified so that it cannot reasonably be linked to an individual.
“Customer Data” means data, content, and materials submitted to, transmitted through, connected to, or generated through use of the Service by a customer or its authorized users. Customer Data can include personal information.
“Processing” means any operation performed on Personal Information, such as collecting, storing, organizing, using, transmitting, disclosing, or deleting it.
3. Personal Information We Collect
The information we collect depends on how you interact with the Service, the features you use, and the choices made by you or your organization.
3.1 Information You Provide
We collect information you provide directly to us, including:
- Contact information, such as your name, work email address, telephone number, company, and job-related information.
- Account information, such as login details, profile information, organizational membership, role, permissions, and authentication records.
- Communications, including contact-form messages, support requests, survey responses, Feedback, and other correspondence.
- Newsletter information, including your email address and subscription preferences.
- Billing and transaction information, such as billing contact details, subscription plan, invoices, and payment status. Payment card details are handled directly by our payment processor when applicable.
- Customer Data that you choose to submit, connect, capture, evaluate, or govern through the Service.
3.2 Information Collected Automatically
When you access the Service, we and our infrastructure and security providers may automatically collect technical and usage information, including:
- Internet Protocol address, browser type and version, device type, operating system, language, and approximate location inferred from an IP address.
- Pages or features accessed, referring page, dates and times, request identifiers, diagnostic events, and performance information.
- Authentication, audit, security, and activity logs associated with an account, organization, integration, or API credential.
- Cookie and local-storage preferences, including whether you accepted or declined the cookie notice and your display preferences.
- Information used by Cloudflare Turnstile to distinguish legitimate visitors from abusive or automated activity when you use our forms.
3.3 Information from Organizations and Third Parties
We may receive information from an organization that invites you to its account, from an administrator who manages your access, from a referral or business partner, from authentication and payment providers, and from Connected Services that you or your organization configure.
If your organization manages your account, its Admin Users may provide, access, configure, export, or delete information associated with your organizational account.
4. Customer Data and AI Content
Customer Data may include prompts, model inputs and outputs, retrieved knowledge, datasets, policies, configurations, evaluations, feedback, traces, logs, metadata, and evidence records. Customers decide what Customer Data is submitted and are responsible for having the rights and lawful basis necessary to process it.
We process Customer Data to provide, maintain, secure, support, and improve the Service; follow customer instructions and configurations; prevent fraud or misuse; and comply with law. We do not acquire ownership of Customer Data.
We will not use Customer Data to train a general-purpose AI model unless the customer expressly enables that use or separately agrees to it in writing.
If you are an individual seeking to exercise rights relating to Customer Data controlled by one of our customers, please contact that customer first. We will assist the customer as required by applicable law and our agreement with it.
5. How We Use Personal Information
We use Personal Information for the following purposes:
- Provide, operate, maintain, and support the Service and requested integrations.
- Create and administer accounts, organizations, roles, permissions, subscriptions, and API credentials.
- Process requests, transactions, billing, renewals, and account notices.
- Respond to questions, support requests, security reports, and other communications.
- Protect the Service, customers, and third parties; authenticate users; detect fraud, abuse, and security incidents; and enforce our agreements.
- Monitor reliability, troubleshoot issues, understand feature use, and improve the performance, accessibility, and design of the Service.
- Develop and evaluate new features using aggregated, de-identified, synthetic, or otherwise lawfully available information.
- Send product news, educational content, or marketing communications where permitted by law and honor opt-out preferences.
- Comply with legal obligations, respond to lawful requests, establish or defend legal claims, and complete business transactions.
- Carry out another purpose disclosed when information is collected or with your direction or consent.
6. Legal Bases for Processing
Where applicable law requires a legal basis, we rely on one or more of the following:
- Performance of a contract, including providing the Service and managing an account or subscription.
- Our legitimate interests, including securing and improving the Service, communicating with customers and prospects, preventing abuse, and operating our business, where those interests are not overridden by your rights.
- Your consent, including for certain marketing or optional technologies. You may withdraw consent at any time without affecting prior processing.
- Compliance with a legal obligation or protection of vital interests.
- Another lawful basis available under applicable law.
7. How We Disclose Personal Information
We may disclose Personal Information in the following circumstances:
- Service providers and contractors. We use providers for hosting, infrastructure, security, authentication, communications, customer support, payment processing, and related operations. They may process information only to provide services to us and under appropriate contractual obligations.
- Form and communication providers. Cloudflare supports bot protection, Loops processes newsletter subscriptions, and Resend delivers contact-form messages and confirmations.
- Connected Services. We exchange information with models, model providers, cloud services, repositories, databases, and other integrations as directed by a customer’s configuration or use of the Service.
- Organizational accounts. Admin Users and other authorized personnel may access information associated with their organization and its users.
- Affiliates and professional advisers. We may disclose information to affiliates, auditors, insurers, lawyers, accountants, and advisers who need it for legitimate business purposes.
- Legal and safety purposes. We may disclose information when we believe it is necessary to comply with law or legal process, protect rights or safety, investigate fraud or abuse, or secure the Service.
- Business transactions. Information may be disclosed or transferred in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate safeguards.
- At your direction or with your consent.
7.1 No Sale or Targeted Advertising
We do not sell Personal Information for money. We do not share Personal Information for cross-context behavioral advertising, and we do not use third-party advertising cookies on the marketing site.
8. Cookies and Similar Technologies
The marketing site currently uses local storage to remember your cookie-notice choice and display preferences. We do not currently use third-party analytics or advertising cookies on the marketing site.
Cloudflare Turnstile may use technical signals and similar technologies when you interact with a protected form to help distinguish legitimate activity from bots and abuse.
You can control cookies and site data through your browser. Blocking necessary storage or security technologies may affect Service functionality. Because there is not yet a consistent industry standard for browser “Do Not Track” signals, we do not respond to them uniformly. Where required by law, we recognize applicable opt-out preference signals such as Global Privacy Control.
9. Data Retention
We retain Personal Information only for as long as reasonably necessary for the purposes described in this policy, including to provide the Service, maintain security and audit records, comply with legal obligations, resolve disputes, and enforce agreements.
Retention periods vary depending on the type of information, account settings, feature documentation, applicable Orders, contractual commitments, legal requirements, and whether the information is needed for security or dispute resolution.
When Personal Information is no longer required, we delete, de-identify, or securely isolate it, subject to backup cycles and legal requirements. Customers are responsible for exporting Customer Data they need before account termination.
10. International Data Transfers
We are based in the United States, and we and our providers may process information in the United States and other countries where privacy laws may differ from those in your location.
When required, we use appropriate safeguards for international transfers, such as contractual protections, approved standard contractual clauses, adequacy decisions, or another lawful transfer mechanism. You may contact us for more information about applicable safeguards.
11. Data Security
We use reasonable administrative, technical, and organizational safeguards designed to protect Personal Information against unauthorized access, loss, misuse, alteration, or disclosure. Safeguards may include access controls, encryption in transit, logging, monitoring, credential protections, and vendor review, as appropriate to the nature of the information.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you are responsible for protecting your account, devices, and API Credentials and promptly reporting suspected compromise.
12. Your Rights and Choices
Depending on where you live and subject to applicable exceptions, you may have the right to:
- Request access to or confirmation of the Personal Information we process about you.
- Request correction of inaccurate Personal Information.
- Request deletion of Personal Information.
- Receive a portable copy of certain Personal Information.
- Object to or request restriction of certain processing.
- Withdraw consent where processing is based on consent.
- Opt out of marketing communications at any time using the unsubscribe link or by contacting us.
- Opt out of a sale, sharing for cross-context behavioral advertising, or targeted advertising where applicable. We do not currently engage in those activities.
- Appeal a decision we make concerning a privacy request where applicable.
- Not receive discriminatory treatment for exercising a privacy right.
12.1 Submitting a Request
Submit a request by emailing hello@inquantum.ai or using our contact page. Describe the right you want to exercise and the information the request concerns.
We may need to verify your identity and authority before completing a request. Authorized agents may submit requests where permitted by law, but we may request proof of authorization and verification directly from the individual. We will respond within the period required by applicable law.
13. European, UK, and Swiss Privacy Rights
If you are in the European Economic Area, United Kingdom, or Switzerland, you may have rights to access, correct, erase, restrict, or port your Personal Data; object to processing based on legitimate interests; withdraw consent; and lodge a complaint with your local supervisory authority.
Where we act as controller, you may contact us to exercise these rights. Where we process Personal Data for a customer, please direct your request to that customer. You may also contact your local data protection authority if you believe our processing violates applicable law.
14. United States State Privacy Notices
Residents of California and certain other U.S. states may have rights to know, access, correct, delete, and obtain a copy of Personal Information; opt out of certain sales, sharing, targeted advertising, or profiling; limit certain uses of sensitive Personal Information; and appeal a denied request, subject to applicable law.
The categories of Personal Information we may have collected during the preceding twelve months are described in Section 3 and may include identifiers, customer records, commercial information, internet or electronic activity, professional information, account credentials, communications, and Customer Data. The sources, purposes, and categories of recipients are described throughout this policy.
We do not sell Personal Information or share it for cross-context behavioral advertising. We do not use or disclose sensitive Personal Information for purposes that require a separate right to limit under California law. We do not offer financial incentives in exchange for Personal Information.
California residents may also request information about certain disclosures for direct marketing under California’s “Shine the Light” law. We do not disclose Personal Information to third parties for their own direct marketing purposes.
15. Children’s Privacy
The Service is not directed to individuals under eighteen (18), and we do not knowingly collect Personal Information from children under thirteen (13). If you believe a child has provided Personal Information to us, contact us so we can investigate and take appropriate action.
16. Third-Party Services and Links
The Service may link to or interoperate with websites, AI models, and services operated by third parties. Their privacy practices are governed by their own policies, not this policy. We encourage you to review the privacy notice of every third party you use.
We are not responsible for a third party’s content, security, availability, or privacy practices. Customers are responsible for choosing and configuring Connected Services and determining whether their data practices are appropriate.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the “Last updated” date. If a change materially affects how we use Personal Information or your rights, we will provide additional notice when required by law, such as by email or a prominent Service notice.
We encourage you to review this policy periodically. Changes take effect when stated in the updated policy or, if no date is stated, when posted.
18. Contact Us
The entity responsible for this Privacy Policy is InQuantum, Inc. If you have a question, privacy request, or complaint, email us at hello@inquantum.ai or use our contact page.