Privacy Policy
Last Updated: August 14, 2026
At QuantC, your privacy is our absolute priority. This Privacy Policy explains our zero-knowledge approach, what limited data we collect, why, and your rights under Indian law.
Zero-Knowledge Architecture
QuantC is built on a zero-knowledge architecture. This means we do not have access to your files, your encryption keys, or your data. All encryption and decryption processes occur locally in your browser using AES-256-GCM. The server never sees your plaintext files or passwords.
Data We Collect
While QuantC does not require user accounts or registration, we collect the following limited data for security and legal compliance:
- IP Addresses: Temporarily logged for rate limiting, DDoS protection, and abuse detection. IP addresses are considered personal data under the Digital Personal Data Protection (DPDP) Act, 2023.
- Server Logs: Timestamped security event logs (e.g., failed authentication attempts, rate limit triggers) are maintained for a statutory period of 180 days as mandated by CERT-In Directions 2022.
- Session Metadata: Encrypted chunk URLs, salts, and iteration counts are stored in our database for up to 48 hours to facilitate file transfer. This metadata cannot be used to reconstruct your original files without the password.
Data Retention
Encrypted file shards are stored temporarily to facilitate transfer and are automatically and permanently deleted after 48 hours. Server security logs (including IP addresses) are retained for 180 days as required by CERT-In Directions 2022, after which they are automatically and permanently purged. We cannot recover deleted files or access the contents of stored files.
Third-Party Services
QuantC uses the following third-party infrastructure providers to operate the service:
- Cloudinary: Stores encrypted file chunks. Cloudinary receives only AES-256-GCM encrypted binary data and cannot decrypt it.
- MongoDB Atlas: Stores session metadata (encrypted chunk URLs, cryptographic salts). No plaintext file data is stored.
- Google Analytics: Used on select pages for aggregate traffic analysis. Google may collect IP addresses, browser type, and device information. You can opt out using browser extensions.
Cross-Border Data Transfer
Encrypted data shards and session metadata may be processed by third-party infrastructure providers whose servers are located outside India (including the United States and European Union). In accordance with Section 16 of the DPDP Act, 2023, we ensure that all data leaving your browser is encrypted with AES-256-GCM before transmission, and no third party possesses the decryption keys.
Your Rights Under the DPDP Act, 2023
As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the following rights:
- Right to Access: You may request information about what personal data we hold about you.
- Right to Correction & Erasure: You may request correction or deletion of your personal data. Note: Server logs containing IP addresses are legally required to be retained for 180 days under CERT-In Directions 2022 and cannot be erased before this statutory period expires.
- Right to Nominate: You may nominate another person to exercise your data rights on your behalf.
- Right to Grievance Redressal: You may contact our Grievance Officer at s4sahiko@gmail.com for any data-related concerns.