Skip to content

Privacy Policy

Last reviewed

TL;DR

The short version

We collect as little as possible. Our scanners and MCP tools process the code and inputs you give them to produce a result, then discard them — we do not store your source code, and we never use it to train anything. The only personal data we keep is the minimum needed to run the service: the email and profile from your sign-in, the access token issued to you, and anything you send through a contact or booking form so we can reply. Analytics run only if you accept the cookie banner. All of our code is open source and auditable (links below).

This Privacy Policy explains what personal data quantakrypto ("we", "us", "our") collects when you use our website (quantakrypto.com), our hosted Model Context Protocol service (mcp.quantakrypto.com), and our open-source tools — and how we handle it. It applies to all of those together. If you have any question, email [email protected].

Our approach: data minimisation

quantakrypto is a post-quantum cryptography practice — keeping data we do not need would be at odds with everything we advise. We design our systems to hold the least personal data possible, and because our tooling is open source you can verify that for yourself: see the pqc-tools and mcp-gateway repositories.

What we collect, and why

  • Website analytics — we use Google Analytics 4, and it loads only after you accept the cookie banner. If you decline, no analytics cookies or scripts load at all. When enabled, it measures page views and traffic sources so we can improve the site; we do not use it for advertising or cross-site tracking.
  • Contact & booking forms — when you request a discovery call or book a slot, we collect the details you enter (such as name, email, company, and your message) and send them to ourselves by email so we can respond. Forms are protected by Google reCAPTCHA to prevent spam. We keep these messages only as long as needed to handle your enquiry and our records.
  • MCP gateway accounts — when you sign in to the hosted MCP (mcp.quantakrypto.com) with Google or GitHub, we receive the basic profile those providers share (your email address, name, and avatar). We store your account and the API access token we issue you so we can authenticate your requests. Tokens expire after 30 days, and you can revoke them or delete your account at any time.
  • Content you send to the MCP tools — code snippets, dependency names, and similar inputs you pass to a tool are processed to generate the response and are not retained, logged as content, or used to train any model.
  • Operational logs — like any web service, our servers keep short-lived technical logs (e.g. IP address, timestamp, request path) for security, abuse-prevention, and debugging.

Sign-in with Google and GitHub (OAuth)

The hosted MCP uses OAuth 2.1 for sign-in. When you choose "Continue with Google" or "Continue with GitHub", you authenticate on that provider's own page — we never see your password. The provider returns only the profile scope we request (email, name, avatar). Your use of those providers is also governed by their policies: Google Privacy Policy and the GitHub Privacy Statement. You can revoke quantakrypto's access from your Google or GitHub account settings at any time.

Cookies and analytics

We use only essential cookies plus, with your consent, Google Analytics. Nothing analytical loads until you click "Accept" on the banner; choosing "Decline" keeps it off. You can change your mind at any time by clearing the site's cookies, which resets the banner. We do not use advertising cookies. Google Analytics and reCAPTCHA are provided by Google — see how Google uses data.

Who processes your data

We keep the third parties involved to a short, deliberate list. Each only receives what it needs to perform its function:

  • Google — Analytics (consent-gated), reCAPTCHA (form anti-spam), and OAuth sign-in. See the Google Privacy Policy.
  • GitHub — OAuth sign-in for the MCP. See the GitHub Privacy Statement.
  • Resend — sends our transactional email (form notifications, sign-in verification). See Resend's privacy policy.
  • Cloudflare — DNS, CDN, and edge protection for our domains. See the Cloudflare Privacy Policy.
  • Our hosting provider — runs the servers and the account database, located in the EU.

Legal bases (GDPR / UK GDPR)

  • Consent — for analytics cookies (you can withdraw it at any time).
  • Legitimate interests — for security, abuse prevention, operating the service, and responding to enquiries you send us.
  • Performance of a contract — to create and run your MCP account and provide services you request.
  • Legal obligation — where we must retain certain records.

How long we keep it

Enquiry and booking emails are kept only as long as needed to handle your request and for reasonable business records. MCP accounts are kept until you delete them; issued access tokens expire after 30 days. Analytics data follows Google Analytics' retention settings. Operational logs are short-lived.

International transfers

Some of our processors (Google, GitHub, Resend, Cloudflare) are based in the United States and may process data there. Where personal data leaves the EEA/UK, it is covered by the safeguards those providers offer, such as Standard Contractual Clauses.

Your rights

Depending on where you live, you have rights to access, correct, delete, port, or object to the processing of your personal data, and to withdraw consent. For the MCP you can revoke your token or delete your account directly; for anything else, email [email protected] and we will action it. You may also complain to your local data-protection authority.

Security

We serve everything over TLS, store access tokens as hashes rather than in the clear, and keep our attack surface small. Because our code is open source, you can audit exactly how authentication and data handling work in the mcp-gateway and pqc-tools repositories.

Children

Our services are intended for professional use and are not directed at children under 16. We do not knowingly collect their data.

Changes to this policy

We may update this policy as our services evolve. Material changes will be reflected here with a new review date; the current version is always the one on this page.

  • Controller: Dandelion Labs JSC (operating quantakrypto), Vietnam
  • Contact: [email protected]
  • Last reviewed: 21 July 2026