Qemica
QemicaQuantum-ready chemistry workbenchChembookOffline chemistry reference for iPhone
Guide
BlogAnnouncements & updatesForumAsk & discuss
QEMICA PRIVACY POLICY
Version 2026-07-22

Controller: Qemica Lab, an independent software developer based in the
Republic of Korea ("we").
Contact: feedback.qemica@gmail.com  ·  Data protection contact: the same
email address (we are a one-person operation and have not appointed a
separate data protection officer). Email is our contact channel; we
publish no postal address.

1. SCOPE
   This policy covers the Qemica desktop application and its optional
   online features. Qemica is local-first: your projects, molecules,
   and results live in files on YOUR computer. Data leaves your machine
   only through the online features below, the one-time engine setup
   (which downloads the uv installer from astral.sh, the engine wheel
   from our release host, and Python dependencies from PyPI — those
   hosts see your IP address like any download), and any third-party
   services you connect yourself (EULA Section 9: IBM Quantum, the
   Anthropic research assistant, SSH/HPC hosts, PubChem lookups).

2. WHAT WE COLLECT, AND WHY

   a. ACCOUNT (optional; required for sign-in features)
      - Email address and authentication identifiers, processed by our
        hosting provider Supabase (see Section 5).
      - Records of your license acceptance (policy version, acceptance
        time, and the app version you accepted in), kept with the
        account as an audit trail.
      - Why: sign-in and plan entitlement.
      - Legal basis: contract.

   b. CALCULATION CONTRIBUTIONS (FREE PLAN ONLY)
      - Contribution collection is NOT YET ACTIVE: today, no
        calculation data leaves your machine. This subsection describes
        what will be collected once it launches; the app will tell you
        before collection begins.
      - What (once active): input structure (atoms, coordinates,
        charge/multiplicity), calculation settings, computed results,
        engine provenance (component versions, timings), and the app
        version.
      - NOT collected: user-assigned project/molecule names, notes,
        file paths, or any personal identifiers. Contributions will be
        severed from your account identity at ingestion and stored
        under a random contribution ID. Because they cannot be traced
        back to you afterwards, they cannot be individually retrieved
        or deleted on request.
      - Why: (i) to evaluate, benchmark, and improve calculation
        methodology and the Software; and (ii) to train, fine-tune, and
        validate machine-learning models, including models we may make
        available in or outside the Software.
      - WE DO NOT sell contributions or use them for advertising.
      - Because contributions are severed from your identity at
        ingestion and models are trained on the pooled corpus, a model
        trained on your contributions cannot be untrained on request;
        withdrawing consent stops future collection and future use of
        your contributions, but does not reverse training already
        performed.
      - Legal basis: consent (the in-app consent dialog); the Free plan
        is conditioned on this contribution.

   c. DEVICE MIGRATION (local export/import)
      - The Software can export your projects, results, and settings
        into a single archive file saved where you choose, and import
        such an archive on another device. This is a local file
        operation: the archive is never uploaded to us and no data
        leaves your machine.

   d. LAUNCH-TIME NETWORK REQUESTS
      - UPDATE CHECK (off unless you turn it on). The Software asks on
        first run whether it may check for updates at launch; the box is
        unchecked by default, and declining is a complete answer. Until
        you turn it on, no update request is made. When enabled, it
        fetches a small release manifest from our release host (GitHub
        Pages) once per launch. You can change your answer at any time
        in Config → General → Updates.
      - Legal basis: consent, which you may withdraw at any time by
        turning the setting off.
      - ANNOUNCEMENTS. The Software fetches broadcast notices (such as
        release announcements) from our account service (Supabase) once
        at launch. This runs whether or not you are signed in; it reads
        a public table and sends no information about you beyond the
        request itself.
      - Legal basis: legitimate interest (telling users about
        significant changes to software they run).
      - Like any web request, both of the above expose your IP address
        transiently to the host. No profile is built from them, and we
        do not log them to track individual users.

   e. WHAT WE DO NOT COLLECT
      - No advertising identifiers, no behavioral analytics, no crash
        uploads without asking, no scanning of files outside your
        Qemica projects.
      - Third-party API credentials you enter (e.g. an IBM Quantum
        token, an Anthropic API key, an SSH password) are stored in your
        operating system keychain where available (otherwise in an
        encrypted store on your device) and used only to call that service
        directly from your machine; we never receive them. Fees those
        services charge are between you and the provider (see EULA
        Section 9).

3. PAYMENTS
   Premium is not yet available for purchase. When it launches,
   billing will be handled by Paddle (Paddle.com Market Ltd) as
   merchant of record; we will receive plan status, not your card
   details. See Paddle's privacy policy.

4. RETENTION
   - Account data: kept while the account exists; deleted within
     30 days of account deletion.
   - Free-plan contributions (once collection is active): retained
     indefinitely in de-identified form (see 2b), including as training
     data and within models derived from them.
   - Local files on your computer are never touched by us.

5. PROCESSORS AND TRANSFERS
   - Supabase (authentication and account database). Account data is
     stored in Supabase's Asia Pacific (Tokyo) region, ap-northeast-1,
     in Japan. Supabase Inc. is established in the United States and
     may access data from there for support and administration.
   - GitHub (release host). Serves the update manifest and the
     installer download; sees your IP address when your app or browser
     requests them.
   - Paddle (payments, merchant of record — only once Premium purchase
     launches; not in use today).

   INTERNATIONAL TRANSFERS. We are based in the Republic of Korea and
   your account data is processed in Japan, so it will usually leave the
   country you live in.
   - For users in the EU/EEA: both Japan and the Republic of Korea are
     covered by European Commission adequacy decisions, which the
     Commission has determined provide protection essentially
     equivalent to EU law. Where a processor handles data outside those
     countries (for example Supabase's US-based support access), we
     rely on the data processing terms we have with that processor,
     which incorporate the European Commission's standard contractual
     clauses.
   - For users elsewhere: the same processors and locations apply.
   If you want to know where your data sits before creating an account,
   email us — or simply do not create one: Qemica's modeling,
   calculation, and analysis features work without an account, and your
   projects and results never leave your computer.

6. YOUR RIGHTS
   Depending on your jurisdiction (GDPR, KR PIPA, etc.) you may have
   rights to access, correct, delete, or export your account data, and
   to lodge a complaint with a supervisory authority. Contact
   feedback.qemica@gmail.com.

   WITHDRAWING CONSENT. Where we rely on consent you can withdraw it at
   any time, without giving a reason, and without affecting the
   lawfulness of anything done beforehand:
   - the update check: turn it off in Config → General → Updates;
   - calculation contributions: collection is not active today, so there
     is nothing to withdraw yet. Before any collection begins the
     Software will tell you and give you an in-app control to decline,
     and switching to Premium also stops contributions.
   Note the de-identification limit in Section 2b: past contributions
   cannot be traced back to you and therefore cannot be individually
   retrieved or deleted on request, and models already trained on the
   pooled corpus are not retrained or withdrawn when you withdraw
   consent.

7. SECURITY
   Transport encryption (TLS) for all traffic; access tokens stored in
   your operating system keychain where available (otherwise in an
   encrypted store on your device), never in plain text; row-level
   security on account tables.

8. CHILDREN
   The Software is not directed to children under 14 (under 16 in the
   EU/EEA).

9. CHANGES
   Material changes are presented in the app for re-acceptance before
   taking effect. The version date above identifies the text you
   accepted.
Qemica

A computational chemistry workbench for the people who actually run the calculations — built for the quantum era, useful today.

Products

QemicaChembookQuantum-readyPricingDownload

Science

WorkflowStackMethodsAnalysis

Company

BlogForumGuideFAQChangelogCite QemicaContact
© 2026 Qemica Lab · EULA · Privacy · Chembook privacy