ZKSF logo, a neon quantum brainZKSF

Privacy Policy

Last updated: 24 September 2026

This Privacy Policy explains what information ZKSF (“we”, “us” or “our”) holds in connection with the Service, why it is held, the basis on which it is processed, and the rights available to you. By creating an account or submitting a job, you confirm that you have read and understood this Policy. If you do not accept it, you must not use the Service.

1. Our Position in Summary

The following statements are made expressly and are intended to be relied upon:

  • We do not sell, rent, trade or licence your data to any third party.
  • We do not share your data for advertising, marketing, profiling or data brokerage.
  • We do not use the contents of your circuits or your results to train models made available to others.
  • We claim no ownership of, and no publication rights over, your research.
  • We collect only what is necessary to execute, bill and support the jobs you submit.

2. Why We Hold Your Information

The information described below is collected and stored because you have instructed us to execute your jobs, and because the Service cannot run, price, bill or return a job without it. This is inherent to how the Service is designed. It is not possible to use the Service while withholding that authorisation, and no alternative mode of operation is offered in which submitted circuits and account data are not processed. All information submitted is collected and processed strictly as required by you in order to use the Service. We do not sell or share any information with third parties, save for the transmission of a program to a QPU provider that you have expressly selected, as described in Section 4.

3. Information We Collect

  • Account information: email address, display name and securely hashed authentication credentials.
  • Job content: the programs you submit, being circuits, pulse sequences, photonic programs, Hamiltonians, error correction parameters or measurement records, together with the execution parameters you specify and the results computed for you.
  • Job metadata: qubit counts, circuit depths, methods selected, runtimes, resource consumption, error estimates and timestamps.
  • Billing records: the fact, amount, date and reference of a transaction. Payments are processed by an external provider certified to PCI DSS, which manages card data security and may collect and hold payment and identity information under its own privacy policy. We never receive or store full card numbers.
  • Technical information: IP address, user agent and API request logs, retained for security and abuse prevention.
  • API keys: a name you choose, the key’s leading characters so that you can tell keys apart, and its creation and expiry dates. The full key is shown to you once, when it is created.
  • Mobile application: the Android application stores your session in the device’s secure storage and requests only network access. It reads a file only when you choose one to upload, and it does not access your location, contacts, camera or advertising identifier, or include advertising or analytics software.

4. How We Use It

  • To execute your jobs and return results, which is the core function of the Service.
  • To use job metadata, and never circuit contents, to calibrate cost estimates, improve routing and publish aggregate statistics that cannot identify you or your research.
  • To send transactional messages such as receipts, job failure notices and security notifications. Marketing messages are sent only with your consent and always carry an unsubscribe facility.
  • To detect, investigate and prevent abuse, fraud, unlawful use and activity that threatens the availability or integrity of the Service, and to enforce our Terms of Service, including the acceptable use provisions.
  • Where you expressly route a job to a third party quantum processing unit (QPU), to transmit the program to that QPU provider so that it may be executed. That transmission occurs only on your instruction and is subject to the provider’s own terms.

5. Lawful Basis for Processing

Where data protection legislation applies, we process personal data for the performance of our contract with you in respect of account administration and job execution, on the basis of our legitimate interests in respect of security, abuse prevention, the enforcement of our terms and service improvement, for compliance with a legal obligation in respect of accounting, tax records and lawful requests from authorities, and on the basis of consent where you have given it, which you may withdraw at any time.

6. Service Providers

We engage a limited number of established commercial service providers to perform defined functions necessary to operate the Service, covering hosting and compute, authentication and account security, payment processing, and delivery of transactional messages. Each provider acts strictly as a processor on our written instructions, is bound by a data processing agreement and by confidentiality obligations, and is prohibited from using your information for any purpose other than performing the function for which it is engaged.

We do not publish the identity, location or configuration of the systems that make up our infrastructure. Disclosure of that detail would materially assist an attacker and would itself constitute a security risk. Such information is made available to regulators, and to enterprise customers under confidentiality, where there is a legitimate need.

7. Disclosure

We disclose personal data only where required by binding legal process, where necessary to establish, exercise or defend legal claims, where necessary to prevent imminent harm, or in connection with a corporate transaction in which the acquiring party assumes the obligations set out in this Policy. We do not disclose your information for any commercial purpose of a third party.

Where we reasonably believe that the Service has been used for fraud or other unlawful activity, or in serious breach of the acceptable use provisions of our Terms of Service, we may preserve the relevant account information, job records, request logs and payment references, and disclose them to law enforcement, regulatory or other competent authorities, including on our own initiative, to the extent permitted by applicable law.

8. Security, Storage and Retention

  • Data is encrypted in transit and at rest, and access is controlled on a least privilege basis.
  • API access requires per account tokens. You are responsible for safeguarding your tokens and for all activity carried out under them.
  • Job records and results are retained while your account is active or until you delete them. Operational logs are retained for a limited period proportionate to their security purpose and are then deleted.
  • When an account is deleted, its sign-in credentials, email address and balance record are removed immediately. Its job records, including the circuits and results they contain, are retained for thirty days so that we can retrieve them for you on request. After thirty days the circuits and results are permanently removed and can no longer be retrieved; only the minimal records we are required to keep for tax and accounting purposes remain. Certificates already issued remain public.
  • Where an account has been suspended or terminated for misuse, or records are subject to a legal hold, investigation or legal claim, the relevant records may be retained beyond the periods above for as long as necessary for that purpose, including after the account is deleted.
  • The Service is not a backup service. Keep your own copies of any programs, results and certificates you need; our retention periods describe when data is removed, not a guarantee that it will remain available until then.
  • No system can be guaranteed impenetrable. Where a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected individuals, within the periods prescribed by law.

9. International Transfers

Where personal data is transferred across borders, we rely on appropriate safeguards recognised under applicable data protection law, including standard contractual clauses where required, supported by encryption in transit and at rest.

10. Cookies and Analytics

  • The marketing site uses no advertising trackers and no third party advertising cookies.
  • The application uses strictly necessary cookies and local storage for session continuity and security.
  • If privacy respecting aggregate analytics are adopted in future, this Policy will be updated before they are introduced.

11. Your Rights

Subject to applicable law, you may request access to the personal data we hold about you, rectification of inaccurate data, erasure, restriction of processing, portability, or object to processing carried out on the basis of our legitimate interests. Where processing is based on consent, you may withdraw that consent at any time.

  • Users in the European Union and the United Kingdom hold the rights conferred by the General Data Protection Regulation. Our lawful bases are set out in Section 5.
  • Users in California hold the rights conferred by the California Consumer Privacy Act as amended. We do not “sell” or “share” personal information as those terms are defined in that legislation.
  • Requests may be made through the application or by writing to legal@zksf.org, and will be answered within the period prescribed by applicable law. We may require verification of identity before acting.
  • Complaints may be directed to your local supervisory authority. We would welcome the opportunity to resolve the matter first.

12. Account Deletion

  • You may delete your account at any time from Profile in the application: select Delete my account, type DELETE to confirm, and select Delete permanently. Deletion takes effect immediately and cannot be reversed.
  • On deletion, every API key issued to the account is revoked, and the sign-in credentials, the email address held on the account and the account’s credit balance record are removed.
  • An account that holds unused credit cannot be deleted until that credit has been refunded. To arrange the refund, write to legal@zksf.org, after which the account may be deleted.
  • Before deleting, download any job history, results and certificates you wish to keep, as access to them ends with the account. Certificates already issued remain publicly verifiable and contain no personal data.
  • For thirty days after deletion we can retrieve your job history, circuits and results for you: write to legal@zksf.org from the address that held the account. After thirty days they are permanently removed and we cannot support a retrieval request.
  • If deletion cannot be completed in the application, write to legal@zksf.org from the address held on the account and we will complete it.

13. Children

The Service is not directed to children under sixteen years of age and we do not knowingly collect their personal data. Where we become aware that we have done so, it will be deleted without undue delay.

14. Changes to This Policy

This Policy may be updated to reflect changes in the Service, in our practices or in applicable law. The date at the head of this page records the current version. Material changes are notified by email before taking effect. Continued use of the Service after that date constitutes acceptance.

15. Contact

For anything concerning this Policy or your personal data, including questions, requests and complaints, write to legal@zksf.org.