Privacy Policy
Last updated: 30 July 2026
This Privacy Policy explains what information ZKSF (“we”, “us” or “our”) holds in connection with the Service, why it is held, the basis on which it is processed, and the rights available to you. By creating an account or submitting a job, you confirm that you have read and understood this Policy. If you do not accept it, you must not use the Service.
1. Our Position in Summary
The following statements are made expressly and are intended to be relied upon:
- We do not sell, rent, trade or licence your data to any third party.
- We do not share your data for advertising, marketing, profiling or data brokerage.
- We do not use the contents of your circuits or your results to train models made available to others.
- We claim no ownership of, and no publication rights over, your research.
- We collect only what is necessary to execute, bill and support the jobs you submit.
2. Why We Hold Your Information
The information described below is collected and stored because you have instructed us to execute your jobs, and because the Service cannot run, price, bill or return a job without it. This is inherent to how the Service is designed. It is not possible to use the Service while withholding that authorisation, and no alternative mode of operation is offered in which submitted circuits and account data are not processed. All information submitted is collected and processed strictly as required by you in order to use the Service. We do not sell or share any information with third parties, save for the transmission of a circuit to a hardware provider that you have expressly selected, as described in Section 4.
3. Information We Collect
- Account information: email address, display name and securely hashed authentication credentials.
- Job content: the circuits you submit, expressed as serialised gate lists, together with the execution parameters you specify and the results computed for you.
- Job metadata: qubit counts, circuit depths, methods selected, runtimes, resource consumption, error estimates and timestamps.
- Billing records: the fact, amount, date and reference of a transaction. Payments are processed by an external provider certified to PCI DSS, which manages card data security and may collect and hold payment and identity information under its own privacy policy. We never receive or store full card numbers.
- Technical information: IP address, user agent and API request logs, retained for security and abuse prevention.
4. How We Use It
- To execute your jobs and return results, which is the core function of the Service.
- To use job metadata, and never circuit contents, to calibrate cost estimates, improve routing and publish aggregate statistics that cannot identify you or your research.
- To send transactional messages such as receipts, job failure notices and security notifications. Marketing messages are sent only with your consent and always carry an unsubscribe facility.
- To detect and prevent abuse, fraud and activity that threatens the availability or integrity of the Service.
- Where you expressly route a job to third party quantum hardware, to transmit the circuit to that hardware provider so that it may be executed. That transmission occurs only on your instruction and is subject to the provider’s own terms.
5. Lawful Basis for Processing
Where data protection legislation applies, we process personal data for the performance of our contract with you in respect of account administration and job execution, on the basis of our legitimate interests in respect of security, abuse prevention and service improvement, for compliance with a legal obligation in respect of accounting and tax records, and on the basis of consent where you have given it, which you may withdraw at any time.
6. Service Providers
We engage a limited number of established commercial service providers to perform defined functions necessary to operate the Service, covering hosting and compute, authentication and account security, payment processing, and delivery of transactional messages. Each provider acts strictly as a processor on our written instructions, is bound by a data processing agreement and by confidentiality obligations, and is prohibited from using your information for any purpose other than performing the function for which it is engaged.
We do not publish the identity, location or configuration of the systems that make up our infrastructure. Disclosure of that detail would materially assist an attacker and would itself constitute a security risk. Such information is made available to regulators, and to enterprise customers under confidentiality, where there is a legitimate need.
7. Disclosure
We disclose personal data only where required by binding legal process, where necessary to establish, exercise or defend legal claims, where necessary to prevent imminent harm, or in connection with a corporate transaction in which the acquiring party assumes the obligations set out in this Policy. We do not disclose your information for any commercial purpose of a third party.
8. Security, Storage and Retention
- Data is encrypted in transit and at rest, and access is controlled on a least privilege basis.
- API access requires per account tokens. You are responsible for safeguarding your tokens and for all activity carried out under them.
- Job records and results are retained while your account is active or until you delete them. Operational logs are retained for a limited period proportionate to their security purpose and are then deleted.
- On account deletion, personal data and stored circuits and results are removed within thirty days, save for the minimal records we are required to retain for tax and accounting purposes.
- No system can be guaranteed impenetrable. Where a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected individuals, within the periods prescribed by law.
9. International Transfers
Where personal data is transferred across borders, we rely on appropriate safeguards recognised under applicable data protection law, including standard contractual clauses where required, supported by encryption in transit and at rest.
10. Cookies and Analytics
- The marketing site uses no advertising trackers and no third party advertising cookies.
- The application uses strictly necessary cookies and local storage for session continuity and security.
- If privacy respecting aggregate analytics are adopted in future, this Policy will be updated before they are introduced.
11. Your Rights
Subject to applicable law, you may request access to the personal data we hold about you, rectification of inaccurate data, erasure, restriction of processing, portability, or object to processing carried out on the basis of our legitimate interests. Where processing is based on consent, you may withdraw that consent at any time.
- Users in the European Union and the United Kingdom hold the rights conferred by the General Data Protection Regulation. Our lawful bases are set out in Section 5.
- Users in California hold the rights conferred by the California Consumer Privacy Act as amended. We do not “sell” or “share” personal information as those terms are defined in that legislation.
- Requests may be made through the application or by writing to info@zksf.org, and will be answered within the period prescribed by applicable law. We may require verification of identity before acting.
- Complaints may be directed to your local supervisory authority. We would welcome the opportunity to resolve the matter first.
12. Account Deletion
- To delete your account, write to info@zksf.org from the address held on the account.
- Before requesting deletion, you should download or otherwise preserve any certificates, job history and results you wish to keep. Once the account is deleted this information is permanently erased and cannot be recovered or reissued.
- You have seven days from the date of your request in which to preserve what you need. On the seventh day the account and all associated data are deleted.
13. Children
The Service is not directed to children under sixteen years of age and we do not knowingly collect their personal data. Where we become aware that we have done so, it will be deleted without undue delay.
14. Changes to This Policy
This Policy may be updated to reflect changes in the Service, in our practices or in applicable law. The date at the head of this page records the current version. Material changes are notified by email before taking effect. Continued use of the Service after that date constitutes acceptance.
15. Contact
Questions, requests and complaints concerning this Policy should be addressed to info@zksf.org.