Privacy Policy
Effective July 5, 2026 · Controller: Pauli, Inc., a Delaware corporation · hello@pauli.xyz
1. What we collect
- Account data: legal name (individual and, if applicable, entity), email address, declared country, workspace name.
- Compliance data: restricted-party screening inputs and results, IP addresses and derived geolocation at signup and job submission, routing and denial decisions, and an append-only audit log of each screening decision.
- Service data: quantum circuits you submit, execution results, job metadata (device, shots, timing, cost).
- Payment data: handled by Stripe; we receive transaction status and last-4/card brand, never full card numbers. Stripe’s privacy policy governs its processing.
- Technical data: standard server logs (IP, user agent, timestamps).
We do not use advertising cookies or sell personal information.
2. How we use it
To provide and bill the Service; to comply with U.S. export-control and sanctions law (screening, geolocation blocking, recordkeeping, and government reporting where required); to secure and debug the Service; and to communicate service notices. Legal bases (where GDPR applies): contract performance, legal obligation, and legitimate interests in security and abuse prevention.
3. Sharing
- Hardware providers: your circuits and job metadata are transmitted to the third-party provider operating the selected device and are processed outside our infrastructure, solely to execute your job.
- Processors: Stripe (payments), cloud hosting and storage, screening-list data sources.
- Legal: government authorities where required by law (including export and sanctions authorities), and to protect rights, safety, or the Service.
- Corporate events: a merger, acquisition, or asset sale, with notice.
4. Retention
- Compliance records (screening decisions, denials, geolocation determinations, transaction records): retained at least 10 years after the transaction, as required by U.S. sanctions regulations (31 C.F.R. § 501.601), and by default indefinitely in our append-only audit log. These records are exempt from deletion requests to the extent retention is legally required.
- Circuits and results: retained while your account is active and for 90 days after closure, then deleted, except data embedded in compliance or billing records.
- Account and billing data: life of the account plus the compliance retention period.
5. Your rights
Depending on your jurisdiction (for example, California CCPA/CPRA, EU/UK GDPR) you may request access, correction, deletion, portability, or restriction, and you may not be discriminated against for exercising rights. Submit requests to hello@pauli.xyz; we verify identity before acting. Deletion requests are honored except where retention is required by law (Section 4). California residents: we do not sell or share personal information as defined by the CPRA. EU/UK users: transfers to the United States rely on Standard Contractual Clauses; you may complain to your supervisory authority.
6. Security
Encryption in transit and at rest, access controls, and least-privilege administration. No method is 100% secure; we will notify you of breaches as required by law. The specific controls are described on the security page.
7. Children
The Service is not directed to anyone under 18; we do not knowingly collect their data.
8. Changes and contact
We will post updates here and notify material changes by email. Contact: hello@pauli.xyz.