This policy explains what information Quantum collects when you create an account, pair the desktop app, and use the Senior Level Coding and Executive Assistant modes, how we use it, and your rights regarding that data. It is provided in accordance with the EU General Data Protection Regulation (GDPR) and the Law on Legal Protection of Personal Data of the Republic of Lithuania.
Data controller: Multiuniversal UAB, Giruliu g. 10, Vilnius LT-12112, Lithuania. Company code 305002969. Email: privacy@multiuniversal.com
- What we collect
- Legal basis for processing
- How we use it
- How we share it
- Cookies and tokens
- How we store and secure it
- Your rights and choices
- Contact us and supervisory authority
What we collect
Account information: When you register, we collect your name, email address, and a password (which we never store in plain text — see "How we store and secure it" below).
Desktop pairing data: When you pair the desktop app, we issue a long-lived access token to that device. We store a one-way hash of the token (never the token itself, which is shown to you only once), along with a device label and the timestamps of when it was paired and last used.
Chat conversations: Messages you send through Senior Level Coding or Executive Assistant mode — and the AI's responses, including any tool calls made on your behalf — are stored so you can resume a conversation and review its history. Conversation content is encrypted at rest and is not shared with third parties for advertising or analytics purposes.
Billing information: If you subscribe, our payment processor Stripe collects your payment card details directly — we never see or store your card number ourselves. We do store your Stripe customer and subscription identifiers, and the status/renewal dates of your subscription.
Information collected automatically: When you visit our website or call our API, we process your IP address, browser type, and request timestamps as an inherent part of operating and securing our servers.
Legal basis for processing
We process personal data only where we have a lawful basis to do so. The table below maps each processing activity to its legal basis under GDPR Article 6.
| Processing activity | Legal basis |
|---|---|
| Creating and maintaining your account | Art. 6(1)(b) — necessary to perform our contract with you |
| Processing subscription payments via Stripe | Art. 6(1)(b) — necessary to perform our contract with you |
| Storing chat conversations to power conversation history | Art. 6(1)(b) — necessary to provide the feature you've requested |
| Desktop pairing and access-token issuance | Art. 6(1)(b) — necessary to provide the service across your devices |
| Server access logs and rate limiting | Art. 6(1)(f) — legitimate interest in operating and securing the service |
| Session cookie | Art. 6(1)(f) — strictly necessary for website functionality; exempt from consent under the ePrivacy Directive |
Where we rely on legitimate interest, we have assessed that our interests do not override your rights and freedoms. You have the right to object to any such processing at any time.
How we use it
To provide the service: Your account, chat, and pairing data are used to authenticate you, power the Senior Level Coding and Executive Assistant modes, and keep your conversation history available across sessions and devices.
To process payments: Billing information is used to create and manage your subscription through Stripe and to send you billing-related notices.
To secure our systems: Server logs and rate-limiting records are used to detect and investigate abuse and security incidents, such as repeated failed login attempts.
We do not use your information for advertising, profiling, or automated decision-making that produces legal or similarly significant effects.
How we share it
We do not sell your personal data. We share it only with the processors necessary to run the service:
Payment processing: Stripe, Inc. processes your payment details and subscription billing on our behalf. Stripe is a PCI-DSS-compliant payment processor; we never receive or store your full card number.
AI processing: Your chat messages are sent to the AI infrastructure that powers Quantum's Senior Level Coding and Executive Assistant modes in order to generate a response. This processing happens solely to serve your request.
Email delivery: Account, verification, and password-reset emails are sent through our SMTP provider, which processes your email address and message content solely to deliver that email on our behalf.
Legal disclosure: We may disclose personal data where required by law, court order, or to protect our legal rights.
Cookies and tokens
We use one first-party session cookie and one device-side access token:
| Name | Type | Duration | Purpose |
|---|---|---|---|
quantum_sid | Cookie — strictly necessary | Browser session | Maintains your signed-in website session and CSRF protection token. Deleted when you close the browser. |
| Desktop access token | Stored on your device by the desktop app | Until revoked | Authenticates the paired desktop app to your account. Only a one-way hash is ever stored on our servers. |
We do not use advertising cookies, tracking cookies, or any third-party cookies on the Quantum website.
You can configure your browser to block or delete cookies at any time; blocking quantum_sid will prevent you from staying signed in. You can revoke a paired device's access token at any time from your account page.
How we store and secure it
Your data is stored on our own servers, protected with encrypted connections (HTTPS/TLS) and access controls. Passwords are hashed with Argon2id — we never store or have access to your plain-text password. Chat message content is encrypted at rest with AES-256-GCM. Desktop access tokens are stored only as a one-way SHA-256 hash, so the original token cannot be recovered from our database even if it were somehow accessed.
Retention periods:
- Account data: for as long as your account is active, and for a reasonable period afterward to handle any outstanding legal or billing obligations
- Chat conversation history: for as long as your account is active, or until you request deletion
- Desktop pairing tokens: until you revoke the device or delete your account
- Billing and subscription records: for as long as required by applicable tax and accounting law after your subscription ends
Your rights and choices
Under GDPR, you have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Rectification — request correction of inaccurate data (you can update your name directly from your account page)
- Erasure — request deletion of your account and associated data ("right to be forgotten")
- Restriction — request that we restrict processing in certain circumstances
- Portability — request your data in a structured, machine-readable format
- Object — object to processing based on legitimate interest at any time
To exercise any of these rights, email us at privacy@multiuniversal.com. We will respond within 30 days. We may ask you to verify your identity before acting on a request.
Contact us and supervisory authority
For questions or concerns about this policy or our data practices, contact us:
Multiuniversal UAB
Giruliu g. 10, Vilnius LT-12112, Lithuania
Email: privacy@multiuniversal.com
If you are not satisfied with our response, you have the right to lodge a complaint with the competent supervisory authority:
State Data Protection Inspectorate (VDAI)
Valstybinė duomenų apsaugos inspekcija
L. Sapiegos g. 17, Vilnius LT-10312, Lithuania
Email: ada@vdai.lrv.lt
Website: vdai.lrv.lt
If you are based in another EU member state, you may also lodge a complaint with your local supervisory authority.
Changes to this policy: We may update this policy from time to time. Material changes will be reflected in the date at the top of this page.