Effective date: September 7, 2026 · Last updated: September 7, 2026
1. Information We Collect
Information you provide
- Account information: Email address and organization name when you request API access.
- Contact forms: Name, email, and message content when you use our contact form.
- Enterprise inquiries: Business details and compliance requirements shared during sales conversations.
Information collected automatically
- API usage metadata: Request timestamps, endpoint paths, and response codes for billing and abuse prevention.
- Security telemetry: Turnstile challenge results and abuse signals for bot mitigation.
- Server logs: IP addresses, user-agent strings, and request paths retained for 30 days.
2. How We Use Your Information
We use collected information to:
- Provide and operate the QSG entropy delivery service
- Process access requests and manage API keys
- Detect and prevent abuse, fraud, and security threats
- Communicate about service changes, incidents, and security advisories
- Comply with legal obligations
3. Data Retention
- API keys: Retained until you revoke them or your account is closed.
- Audit records: Entropy draw provenance records are retained for the lifetime of the service and cannot be deleted (they are integrity-verified chain entries).
- Server logs: Automatically purged after 30 days.
- Contact submissions: Retained for up to 2 years, then deleted unless ongoing correspondence requires retention.
4. Data Sharing
We do not sell your data. We may share information with:
- Service providers: Cloudflare (infrastructure, DDoS protection, Turnstile bot verification).
- Legal requirements: When required by law, regulation, or valid legal process.
5. Security
All API traffic is encrypted with TLS 1.3. Sensitive data at rest is encrypted. Our post-quantum key encapsulation (ML-KEM-1024 + X25519) protects entropy delivery against both classical and quantum threats. We maintain a coordinated vulnerability disclosure program at quantumsecuregateway.com/security.
6. Your Rights
You may request access to, correction of, or deletion of your personal data by contacting [email protected]. We will respond within 30 days. Note that audit chain entries cannot be deleted as they are integrity-verified records.
7. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of the service after changes constitutes acceptance.
8. Contact
For privacy questions: [email protected]
For security concerns: [email protected]