Legal

QMask Data Protection

The safeguards that protect your information, starting with a design that keeps your secrets out of our reach.

01Our approach

Data protection in QMask begins with a structural decision rather than a promise. The wallet is built so that the most sensitive material is held only by you. We protect what we cannot see by ensuring there is nothing for us to see.

This page sets out the safeguards that apply to the limited information involved in using the wallet and this website, and the rights you hold over any personal data.

02Scope

This statement covers the QMask browser extension, the QMask mobile application, and this website. It does not cover third party applications you choose to connect to, or the public Quantova network itself, each of which operates independently.

03Data minimisation

We collect as little as possible. The wallet does not ask for your name, your address or an identity document in order to operate. Where information is genuinely required for a feature to work, it is limited to what that feature needs and nothing more.

04Lawful basis for limited processing

Where the website or wallet processes a small amount of information, for example a network request needed to display your balance or to send a transaction you approved, the basis is the performance of the service you have asked for. Any optional contact you choose to share is processed on the basis of your consent.

05Protected on your device

Your secrets are sealed on your device before anything is written to storage, and they can be unlocked only by you. There is no readable copy of your recovery phrase or your keys at rest.

Because QMask is a self custody wallet built for a post-quantum network, this protection sits entirely on your device. Quantova holds no copy to protect, and there is no central store of user secrets that could be breached.

06No organisational access to secrets

Quantova as an organisation does not hold your password, your recovery phrase or your private keys. They are generated on your device, sealed on your device and used only on your device. There is no recovery route that passes through us.

On mobile, secrets are kept in the platform keychain and released only while the device is unlocked by you, with biometric protection where the device supports it.

07Categories of data

The limited information that may be involved falls into these categories:

  • On device data, such as your encrypted store and settings, which never leaves the device
  • Network data, such as your public Q address and signed transactions, sent to broadcast and read state
  • Market data requests, made by asset symbol only
  • Optional contact details, only if you choose to provide them

08Purposes of processing

Information is used only to provide the wallet and the website. That means showing balances and prices, signing and broadcasting the transactions you approve, remembering your preferences, and responding to a request you send us. It is not used to profile you or to advertise to you.

09Sharing and processors

We do not sell personal data. We share the minimum necessary with infrastructure that runs the service, such as a network node or a market data source, and only for the purpose described above. We never share your keys, your recovery phrase or your password, because we never hold them.

10International transfers

The wallet communicates with the Quantova network, which is a distributed system spanning many independent operators. Public blockchain data is by its nature visible across the network. Personal data, in the limited sense described here, is handled in line with this statement wherever it is processed.

11Retention

Information that lives on your device remains under your control and is removed when you remove the wallet or clear its storage. Any limited operational information that reaches us is kept only for as long as it is needed for the purpose it was collected, and is then deleted.

12Security measures

Beyond on device protection, the wallet applies a series of safeguards to keep the signing path safe. A website must be approved before it can ever request a signature. The wallet exposes no key material to web pages, checks the origin of requests, and rate limits incoming calls.

Every transaction is authorised with a NIST approved post-quantum signature, so the protection holds against a future adversary equipped with a large quantum computer. These measures are reviewed as part of the project security process and updated as the threat landscape changes.

13Your rights

Depending on your jurisdiction, you may have rights over personal data that an organisation holds about you. These can include:

  • Access a copy of any personal data we hold about you
  • Ask us to correct information that is inaccurate
  • Ask us to delete information where there is no overriding reason to keep it
  • Restrict or object to certain processing
  • Ask for your data in a portable form
  • Withdraw consent you have previously given
  • Complain to your data protection authority

Because the wallet is self custody, these rights cannot extend to your on device secrets, since we never receive them.

14Automated decisions

We do not use your personal data to make automated decisions that produce legal or similarly significant effects about you.

15Children

QMask is not intended for children. It is meant for people old enough to be responsible for their own digital assets in their jurisdiction.

16Changes

We may update this statement as the product develops or as the law requires. When we do, we will revise the date shown on this page.

17Making a request

To exercise a right or to ask a question about data protection, use the contact channel published on the official Quantova website. We will respond within the period required by the law that applies to you.