Privacy Policy

Effective July 5, 2026 · Controller: Pauli, Inc., a Delaware corporation · hello@pauli.xyz

1. What we collect

  • Account data: legal name (individual and, if applicable, entity), email address, declared country, workspace name.
  • Compliance data: restricted-party screening inputs and results, IP addresses and derived geolocation at signup and job submission, routing and denial decisions, and an append-only audit log of each screening decision.
  • Service data: quantum circuits you submit, execution results, job metadata (device, shots, timing, cost).
  • Payment data: handled by Stripe; we receive transaction status and last-4/card brand, never full card numbers. Stripe’s privacy policy governs its processing.
  • Technical data: standard server logs (IP, user agent, timestamps).

We do not use advertising cookies or sell personal information.

2. How we use it

To provide and bill the Service; to comply with U.S. export-control and sanctions law (screening, geolocation blocking, recordkeeping, and government reporting where required); to secure and debug the Service; and to communicate service notices. Legal bases (where GDPR applies): contract performance, legal obligation, and legitimate interests in security and abuse prevention.

3. Sharing

  • Hardware providers: your circuits and job metadata are transmitted to the third-party provider operating the selected device and are processed outside our infrastructure, solely to execute your job.
  • Processors: Stripe (payments), cloud hosting and storage, screening-list data sources.
  • Legal: government authorities where required by law (including export and sanctions authorities), and to protect rights, safety, or the Service.
  • Corporate events: a merger, acquisition, or asset sale, with notice.

4. Retention

  • Compliance records (screening decisions, denials, geolocation determinations, transaction records): retained at least 10 years after the transaction, as required by U.S. sanctions regulations (31 C.F.R. § 501.601), and by default indefinitely in our append-only audit log. These records are exempt from deletion requests to the extent retention is legally required.
  • Circuits and results: retained while your account is active and for 90 days after closure, then deleted, except data embedded in compliance or billing records.
  • Account and billing data: life of the account plus the compliance retention period.

5. Your rights

Depending on your jurisdiction (for example, California CCPA/CPRA, EU/UK GDPR) you may request access, correction, deletion, portability, or restriction, and you may not be discriminated against for exercising rights. Submit requests to hello@pauli.xyz; we verify identity before acting. Deletion requests are honored except where retention is required by law (Section 4). California residents: we do not sell or share personal information as defined by the CPRA. EU/UK users: transfers to the United States rely on Standard Contractual Clauses; you may complain to your supervisory authority.

6. Security

Encryption in transit and at rest, access controls, and least-privilege administration. No method is 100% secure; we will notify you of breaches as required by law. The specific controls are described on the security page.

7. Children

The Service is not directed to anyone under 18; we do not knowingly collect their data.

8. Changes and contact

We will post updates here and notify material changes by email. Contact: hello@pauli.xyz.