# Privacy Policy — Quantum Discord

**Effective Date:** [DATE]
**Last Updated:** [DATE]
**Version:** 1.0

> ⚠️ **Before publishing:** This document is a structured first draft, not legal advice. Have it reviewed by a lawyer licensed in India (and, if you have meaningful EU/UK/US traffic, someone versed in GDPR/CCPA) before it goes live. Placeholders in [BRACKETS] must be filled in with your actual legal details.

---

## Quick Summary (Plain-Language, Non-Binding)

This summary is for convenience only — the full policy below is what legally applies.

- We collect account info (name, email), usage data (progress, quiz scores), and code you run in our Coding Lab sandbox.
- We do **not** sell your personal data.
- You can request a copy of your data or ask us to delete it at any time.
- We use cookies for login sessions and basic analytics.
- If you're under 18, a parent or guardian should review this policy with you.
- Questions? Contact [PRIVACY_EMAIL].

---

## 1. Who We Are

Quantum Discord ("**Quantum Discord**," "**we**," "**us**," "**our**") is a quantum computing education platform operated by [LEGAL ENTITY NAME], a company registered in [STATE], India, with its registered office at [REGISTERED ADDRESS] ("**Company**").

This Privacy Policy applies to:
- The Quantum Discord website and web application (thequantumdiscord.com or equivalent domain)
- Our Coding Lab, Learning platform, Workshop pages, and any associated mobile or desktop applications
- Any other product, service, or feature we release under the Quantum Discord brand, now or in the future (see Section 14, *Future Services*)

**Grievance Officer (required under Indian IT Rules, 2021):**
Name: [GRIEVANCE OFFICER NAME]
Email: [GRIEVANCE_EMAIL]
Address: [ADDRESS]

---

## 2. Definitions

- **"Personal Data"** — any information relating to an identified or identifiable natural person.
- **"User," "you"** — anyone who accesses or uses the Service, whether registered or not.
- **"Service"** — collectively, all Quantum Discord products, current and future.
- **"Content"** — course material, simulations, and other material we provide.
- **"User Content"** — code, forum posts, feedback, or other material you submit.
- **"Processing"** — any operation performed on Personal Data (collection, storage, use, deletion, etc.)

---

## 3. Information We Collect

### 3.1 Information you provide directly
| Category | Examples | Purpose |
|---|---|---|
| Account information | Name, email address, password (hashed), profile details | Account creation, authentication (JWT-based login) |
| Payment information *(future)* | Billing name, address, payment method (processed by a third-party payment processor — we do not store full card numbers) | Processing paid subscriptions or one-time purchases |
| Communications | Support requests, feedback form submissions, survey responses | Customer support, product improvement |
| User-generated content | Forum posts, comments, code submitted in the Coding Lab | Delivering the Service, community features |

### 3.2 Information collected automatically
| Category | Examples | Purpose |
|---|---|---|
| Usage data | Pages visited, modules completed, quiz/assessment scores, time spent, feature interaction | Progress tracking, personalization, product analytics |
| Device/log data | IP address, browser type, device identifiers, operating system, referring URLs | Security, fraud prevention, debugging |
| Cookies & similar technologies | Session cookies, analytics cookies | See Section 8 (Cookies) |
| Code execution metadata | Submitted code, execution logs, resource usage (CPU/memory/time) within our Docker-sandboxed execution environment | Running the Coding Lab feature, abuse prevention, infrastructure capacity planning |

We do **not** intentionally collect sensitive personal data (health, biometric, religious, political, or similar special-category data) and ask that you do not submit such data through free-text fields (e.g., support messages).

### 3.3 Information from third parties
If you sign in via a third-party provider (e.g., Google Sign-In) *(if/when implemented)*, we receive basic profile information (name, email) as authorized by you via that provider.

---

## 4. How We Use Your Information

We process your Personal Data for the following purposes, under the following legal bases:

**Under India's Digital Personal Data Protection Act, 2023 (DPDP Act)** — our primary governing framework as an Indian data fiduciary — we process your Personal Data on the basis of your **consent** (for most processing) or for **"legitimate uses"** recognized under the Act (e.g., where you have voluntarily provided data for a specified purpose and not indicated non-consent, or where processing is necessary to comply with a legal obligation). Where we rely on consent, you may **withdraw it at any time** with effect for future processing, as easily as you gave it, by [emailing PRIVACY_EMAIL / using account settings — implement a consent-withdrawal mechanism]. Withdrawal does not affect processing already carried out, or continued processing needed to meet a legal obligation.

**Under GDPR/UK GDPR** (relevant if you are in the EEA/UK), the equivalent legal bases are:

| Purpose | Legal Basis (GDPR, where applicable) |
|---|---|
| Provide, maintain, and operate the Service | Contractual necessity |
| Authenticate accounts and prevent fraud/abuse | Legitimate interest |
| Track learning progress and issue completion badges/certificates | Contractual necessity |
| Run and sandbox user-submitted code securely | Contractual necessity / legitimate interest (security) |
| Send service-related communications (password resets, security alerts) | Contractual necessity |
| Send optional marketing/product updates | Consent (opt-out available at any time) |
| Analyze aggregate usage to improve curriculum and platform | Legitimate interest |
| Comply with legal obligations | Legal obligation |

We do **not** use your Personal Data to make solely automated decisions that produce legal or similarly significant effects on you.

### 4.1 Our Obligations as a Data Fiduciary (DPDP Act)

As a "Data Fiduciary" under the DPDP Act, we commit to: processing Personal Data only for the specified, lawful purpose for which it was collected; maintaining reasonable security safeguards; providing a clear and accessible means to give and withdraw consent (a "Consent Manager" interface, as required); notifying you and the Data Protection Board of India of any personal data breach without undue delay, in the form and manner prescribed under the Act; and, where applicable, appointing a **Nominee** you may designate to exercise your rights in the event of your death or incapacity. You may designate a Nominee via [account settings / by emailing PRIVACY_EMAIL].

**Consent Manager:** [If/when implemented — describe how users manage consent centrally, e.g., "You can view, grant, and withdraw consent for each processing purpose via your Privacy Dashboard."]

---

## 5. AI-Generated Content and Features

Some features of the Service — including code feedback, hints, explanations, assessment support, or a chatbot (current or future) — may use artificial intelligence systems to generate output. AI-generated outputs may contain inaccuracies, and should be independently verified, especially for anything safety-critical or graded. Input you provide to an AI-powered feature (e.g., a question you ask a chatbot, or code you request feedback on) may be processed by that feature, including, where applicable, by a third-party AI provider under contractual confidentiality terms. We do not use identifiable user data to train third-party foundation models without your consent.

---

## 6. Code Execution & Sandbox Data — Special Notice

Because Quantum Discord's Coding Lab executes user-submitted code in a Docker-sandboxed environment:

- Submitted code and its output may be temporarily stored to display results back to you and for a limited retention period for debugging/abuse investigation (see Section 9).
- Do not submit code containing secrets, credentials, personal data of third parties, or malicious payloads. Doing so violates our Terms of Service and this Policy does not create an obligation for us to protect data you were not authorized to submit.
- We monitor sandbox resource usage (not code content, except where necessary for abuse/security investigation) to prevent denial-of-service and cryptomining abuse.

---

## 7. How We Share Your Information

We do **not sell** your Personal Data. We may share it with:

- **Service providers / processors** — hosting (DigitalOcean), database and infrastructure providers, email delivery services, analytics providers, and (in future) payment processors — each bound by contractual confidentiality and data-protection obligations.
- **Legal & safety** — where required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Quantum Discord, our users, or the public.
- **Business transfers** — in connection with a merger, acquisition, financing, or sale of assets, your information may be transferred, subject to this Policy (or a materially similar one).
- **With your consent** — for any other purpose disclosed to you at the time of collection.

A current list of material third-party sub-processors is available at [SUBPROCESSOR_LIST_URL] and will be updated as our vendor stack evolves.

---

## 8. Data Retention

| Data type | Retention period |
|---|---|
| Account data | Until account deletion, plus [30/90] days for backup rotation |
| Usage/progress data | Duration of account, or as needed for aggregate analytics (anonymized thereafter) |
| Code execution logs | [30–90] days, unless retained longer for an active abuse/security investigation |
| Payment records *(future)* | As required by applicable tax/financial law (typically 7–8 years in India) |
| Support communications | [24 months] from last contact |
| Server, authentication, and CDN access logs | [90 days], unless needed longer for an active security investigation |
| Encrypted backups | Rolling [30-day] backup window, then overwritten |

We periodically review and delete or anonymize data no longer needed for the purposes above.

---

## 9. Cookies & Tracking Technologies

We use:
- **Strictly necessary cookies** — session/authentication tokens (JWT), load balancing.
- **Analytics cookies** — to understand aggregate usage patterns (e.g., [Google Analytics / Plausible / other — specify]).
- **Preference cookies** — remembering UI/theme settings.

We do not currently use third-party advertising cookies. If this changes, we will update this Policy and provide a cookie consent mechanism compliant with applicable law. You can control cookies through your browser settings; disabling essential cookies may break login functionality.

---

## 10. Your Rights

Depending on your location, you may have the right to:

- **Access** — request a copy of the Personal Data we hold about you.
- **Correction** — request correction of inaccurate data.
- **Deletion / Erasure** — request deletion of your account and associated Personal Data, subject to legal retention obligations.
- **Portability** — request your data in a structured, machine-readable format.
- **Withdraw consent** — where processing is based on consent (e.g., marketing emails).
- **Object / Restrict** — object to or request restriction of certain processing based on legitimate interest.
- **Grievance Redressal** (India, IT Rules 2021) — contact our Grievance Officer (Section 1) with any complaint; we aim to acknowledge within 24 hours and resolve within 15 days.
- **Nodal/Data Protection Officer contact** (if applicable under DPDP Act) — [DPO_EMAIL].

To exercise any right, email [PRIVACY_EMAIL] from your registered email address. We may need to verify your identity before acting on a request.

---

## 11. Children's Privacy

Quantum Discord is an educational platform that may be used by learners under 18.

- Users must be at least [13/16 — confirm per jurisdiction] years old to create an account independently.
- Users between [13/16] and 18 should have parental or guardian awareness of their use of the Service.
- We do not knowingly collect Personal Data from children under [13] without verifiable parental consent. If we learn we have done so, we will delete such data promptly. Parents/guardians may contact [PRIVACY_EMAIL] to review or request deletion of a minor's data.

*(This threshold should be set with legal input — India's DPDP Act defines a "child" as under 18 and imposes specific consent requirements; COPPA in the US sets the bar at 13; GDPR generally sets it at 16 unless a member state lowers it to 13.)*

---

## 12. Security

We implement technical and organizational measures appropriate to the risk, including:

- Encryption in transit (HTTPS/TLS) for all Service traffic
- Password hashing (never stored in plaintext)
- JWT-based authentication with token expiry
- Docker-based sandbox isolation for code execution
- Access controls and logging on production infrastructure
- Regular dependency and security review (e.g., OWASP-aligned practices)
- Server, authentication, and CDN access logs retained for security monitoring (see retention periods in Section 8)
- Encrypted backups, rotated on a defined schedule and subject to the same access controls as production data

No system is perfectly secure. In the event of a data breach affecting your Personal Data, we will notify affected users and relevant authorities as required by applicable law — including, under the DPDP Act, notification to the Data Protection Board of India and to affected Data Principals (users) in the manner and timeframe prescribed by the Act — and, where applicable, CERT-In's reporting timelines (currently within 6 hours of noticing a covered incident).

---

## 13. International Data Transfers

Our infrastructure is hosted via DigitalOcean, which may process data in data centers located outside your home country (including outside India, the EU, or the US, depending on configuration). Where we transfer Personal Data internationally, we rely on appropriate safeguards (such as standard contractual clauses, where applicable) to protect it consistently with this Policy.

If you are located in the EEA/UK, you may have additional rights under GDPR; if you are a California resident, you may have additional rights under the CCPA/CPRA (including the right to know, delete, and opt out of "sale/sharing" of Personal Data — which we do not engage in).

---

## 14. Changes to This Policy

We may update this Policy as our Service evolves. Material changes will be notified via email or an in-app notice at least [14] days before taking effect. The "Last Updated" date at the top reflects the most recent revision. Continued use of the Service after changes take effect constitutes acceptance.

---

## 15. Future Services (Forward-Compatibility Clause)

This Policy is written to extend automatically to new features and offerings we may introduce, including but not limited to: paid subscription tiers, enterprise/team accounts, mobile applications, API access, physical or cloud-based quantum hardware access, referral or affiliate programs, and community/forum features. Where a new feature involves materially different data collection, we will issue a supplemental notice or update this Policy before or at launch of that feature.

---

## 16. Contact Us

**General privacy inquiries:** [PRIVACY_EMAIL]
**Grievance Officer:** [GRIEVANCE_EMAIL]
**Postal address:** [REGISTERED ADDRESS]

---

*This Privacy Policy should be read together with our [Terms of Service](./TERMS_OF_SERVICE.md).*

**Planned companion documents (to be published as relevant features launch):** Cookie Policy, Copyright/DMCA Notice Policy, Data Processing Agreement (for institutional/enterprise customers).
