QEMICA PRIVACY POLICY
Version 2026-07-22
Controller: Qemica Lab, an independent software developer based in the
Republic of Korea ("we").
Contact: feedback.qemica@gmail.com · Data protection contact: the same
email address (we are a one-person operation and have not appointed a
separate data protection officer). Email is our contact channel; we
publish no postal address.
1. SCOPE
This policy covers the Qemica desktop application and its optional
online features. Qemica is local-first: your projects, molecules,
and results live in files on YOUR computer. Data leaves your machine
only through the online features below, the one-time engine setup
(which downloads the uv installer from astral.sh, the engine wheel
from our release host, and Python dependencies from PyPI — those
hosts see your IP address like any download), and any third-party
services you connect yourself (EULA Section 9: IBM Quantum, the
Anthropic research assistant, SSH/HPC hosts, PubChem lookups).
2. WHAT WE COLLECT, AND WHY
a. ACCOUNT (optional; required for sign-in features)
- Email address and authentication identifiers, processed by our
hosting provider Supabase (see Section 5).
- Records of your license acceptance (policy version, acceptance
time, and the app version you accepted in), kept with the
account as an audit trail.
- Why: sign-in and plan entitlement.
- Legal basis: contract.
b. CALCULATION CONTRIBUTIONS (FREE PLAN ONLY)
- Contribution collection is NOT YET ACTIVE: today, no
calculation data leaves your machine. This subsection describes
what will be collected once it launches; the app will tell you
before collection begins.
- What (once active): input structure (atoms, coordinates,
charge/multiplicity), calculation settings, computed results,
engine provenance (component versions, timings), and the app
version.
- NOT collected: user-assigned project/molecule names, notes,
file paths, or any personal identifiers. Contributions will be
severed from your account identity at ingestion and stored
under a random contribution ID. Because they cannot be traced
back to you afterwards, they cannot be individually retrieved
or deleted on request.
- Why: (i) to evaluate, benchmark, and improve calculation
methodology and the Software; and (ii) to train, fine-tune, and
validate machine-learning models, including models we may make
available in or outside the Software.
- WE DO NOT sell contributions or use them for advertising.
- Because contributions are severed from your identity at
ingestion and models are trained on the pooled corpus, a model
trained on your contributions cannot be untrained on request;
withdrawing consent stops future collection and future use of
your contributions, but does not reverse training already
performed.
- Legal basis: consent (the in-app consent dialog); the Free plan
is conditioned on this contribution.
c. DEVICE MIGRATION (local export/import)
- The Software can export your projects, results, and settings
into a single archive file saved where you choose, and import
such an archive on another device. This is a local file
operation: the archive is never uploaded to us and no data
leaves your machine.
d. LAUNCH-TIME NETWORK REQUESTS
- UPDATE CHECK (off unless you turn it on). The Software asks on
first run whether it may check for updates at launch; the box is
unchecked by default, and declining is a complete answer. Until
you turn it on, no update request is made. When enabled, it
fetches a small release manifest from our release host (GitHub
Pages) once per launch. You can change your answer at any time
in Config → General → Updates.
- Legal basis: consent, which you may withdraw at any time by
turning the setting off.
- ANNOUNCEMENTS. The Software fetches broadcast notices (such as
release announcements) from our account service (Supabase) once
at launch. This runs whether or not you are signed in; it reads
a public table and sends no information about you beyond the
request itself.
- Legal basis: legitimate interest (telling users about
significant changes to software they run).
- Like any web request, both of the above expose your IP address
transiently to the host. No profile is built from them, and we
do not log them to track individual users.
e. WHAT WE DO NOT COLLECT
- No advertising identifiers, no behavioral analytics, no crash
uploads without asking, no scanning of files outside your
Qemica projects.
- Third-party API credentials you enter (e.g. an IBM Quantum
token, an Anthropic API key, an SSH password) are stored in your
operating system keychain where available (otherwise in an
encrypted store on your device) and used only to call that service
directly from your machine; we never receive them. Fees those
services charge are between you and the provider (see EULA
Section 9).
3. PAYMENTS
Premium is not yet available for purchase. When it launches,
billing will be handled by Paddle (Paddle.com Market Ltd) as
merchant of record; we will receive plan status, not your card
details. See Paddle's privacy policy.
4. RETENTION
- Account data: kept while the account exists; deleted within
30 days of account deletion.
- Free-plan contributions (once collection is active): retained
indefinitely in de-identified form (see 2b), including as training
data and within models derived from them.
- Local files on your computer are never touched by us.
5. PROCESSORS AND TRANSFERS
- Supabase (authentication and account database). Account data is
stored in Supabase's Asia Pacific (Tokyo) region, ap-northeast-1,
in Japan. Supabase Inc. is established in the United States and
may access data from there for support and administration.
- GitHub (release host). Serves the update manifest and the
installer download; sees your IP address when your app or browser
requests them.
- Paddle (payments, merchant of record — only once Premium purchase
launches; not in use today).
INTERNATIONAL TRANSFERS. We are based in the Republic of Korea and
your account data is processed in Japan, so it will usually leave the
country you live in.
- For users in the EU/EEA: both Japan and the Republic of Korea are
covered by European Commission adequacy decisions, which the
Commission has determined provide protection essentially
equivalent to EU law. Where a processor handles data outside those
countries (for example Supabase's US-based support access), we
rely on the data processing terms we have with that processor,
which incorporate the European Commission's standard contractual
clauses.
- For users elsewhere: the same processors and locations apply.
If you want to know where your data sits before creating an account,
email us — or simply do not create one: Qemica's modeling,
calculation, and analysis features work without an account, and your
projects and results never leave your computer.
6. YOUR RIGHTS
Depending on your jurisdiction (GDPR, KR PIPA, etc.) you may have
rights to access, correct, delete, or export your account data, and
to lodge a complaint with a supervisory authority. Contact
feedback.qemica@gmail.com.
WITHDRAWING CONSENT. Where we rely on consent you can withdraw it at
any time, without giving a reason, and without affecting the
lawfulness of anything done beforehand:
- the update check: turn it off in Config → General → Updates;
- calculation contributions: collection is not active today, so there
is nothing to withdraw yet. Before any collection begins the
Software will tell you and give you an in-app control to decline,
and switching to Premium also stops contributions.
Note the de-identification limit in Section 2b: past contributions
cannot be traced back to you and therefore cannot be individually
retrieved or deleted on request, and models already trained on the
pooled corpus are not retrained or withdrawn when you withdraw
consent.
7. SECURITY
Transport encryption (TLS) for all traffic; access tokens stored in
your operating system keychain where available (otherwise in an
encrypted store on your device), never in plain text; row-level
security on account tables.
8. CHILDREN
The Software is not directed to children under 14 (under 16 in the
EU/EEA).
9. CHANGES
Material changes are presented in the app for re-acceptance before
taking effect. The version date above identifies the text you
accepted.