Privacy Policy
What QuantQns collects, why, who else sees it, and how to get it deleted. We collect as little as we can and we do not sell data.
Last updated 27 August 2026 · QuantQns, Singapore
1. Who is responsible
QuantQns (Singapore) is the data controller for personal data collected through this site. Contact: figolee2127@gmail.com
2. What we collect
If you only browse free content: nothing that identifies you personally. Our analytics are cookie-free and aggregate: page path, referrer, approximate country, and device type. We do not build a profile of you.
If you create an account: your email address, and the sign-in provider you used (magic link or Google). We never receive or store a password.
If you subscribe: your billing record — plan, amount, currency, dates, and Stripe customer and subscription identifiers — plus your current subscription status and renewal date. Card numbers go directly to Stripe and never reach our servers.
While you use premium content: a log of which questions your account viewed and when, together with the IP address of the request. This exists to detect bulk extraction and account sharing, which is what makes a small paid bank viable.
3. Why we use it (and our legal basis)
- To provide the service — signing you in, checking your subscription is active, showing you content. Basis: performance of our contract with you.
- To take payment and meet tax and accounting obligations. Basis: contract and legal obligation.
- To protect the content — rate limiting, abuse detection, and watermarking. Basis: our legitimate interest in preventing theft of the product.
- To email you about your subscription — receipts, access details, renewal reminders, and material changes to these policies. Basis: contract.
- To understand traffic in aggregate. Basis: legitimate interest, using cookie-free analytics that do not identify individuals.
We do not use your data for advertising, and we do not sell or rent it to anyone.
4. Watermarking of premium content
Every premium solution you view is marked with an identifier tied to your account, including within the text itself. If premium content is republished without permission, this lets us trace which account it came from. That identifier is personal data and is covered by this policy.
5. Who else processes your data
We use a small number of providers, each only for the purpose listed:
- Stripe — payment processing. Stripe is the controller of your payment details and applies its own privacy policy.
- Supabase — database, authentication, and hosting of account records.
- Our hosting and email providers — serving the site and sending transactional email such as sign-in links and receipts.
- Umami — privacy-preserving, cookie-free traffic analytics.
These providers may process data outside your country. Where that happens, we rely on the transfer safeguards each provider has in place.
6. Cookies
We use one essential cookie to keep you signed in, and one to remember your interface language. There are no advertising cookies, no third-party trackers, and no cross-site profiling. Because our analytics do not use cookies, there is no consent banner to click through.
7. How long we keep it
- Account records: while your account exists, then deleted within 30 days of your request.
- Billing records: seven years, because tax and accounting rules require it. This is the one category we cannot delete on request.
- Premium view logs: 12 months, then deleted.
- Aggregate analytics: retained indefinitely, but not linked to any individual.
8. Your rights
You can ask us to give you a copy of your data, correct it, delete it, or restrict how we use it, and you can object to processing based on legitimate interest. Email figolee2127@gmail.com from the address on your account and we will respond within 30 days.
Deleting your account ends your access. If your subscription is still active, deletion forfeits the remaining time unless you request a refund first under the refund policy.
9. Security
Data is encrypted in transit. Access to premium content is enforced on the server and at the database layer, not in the browser. Administrative accounts use two-factor authentication, and the database is backed up daily.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority as required by law.
10. Children
This service is aimed at university students and working professionals. It is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has created an account, email us and we will delete it.
11. Changes
If this policy changes materially, we will update the revision date above and email active subscribers.
Questions about this policy? Email figolee2127@gmail.com. We reply within 48 hours.