Privacy Policy

Last updated: 1 August 2026

This Privacy Policy explains how Quantum Reports (“we”, “us”, “our”) collects, uses, and protects your personal data when you use our website at quantumreports.io. We are committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

Quantum Reports is a financial news aggregation and AI analysis service. For data protection purposes, we are the data controller for the personal data we collect about you.

Contact: For all data protection enquiries, please email privacy@quantumreports.io

ICO Registration No. ZC169897

2. Personal Data We Collect

Data you provide directly

Data we collect automatically

3. How We Use Your Data and Legal Basis

Purpose Legal Basis
Providing your account and the core service Performance of contract (UK GDPR Art. 6(1)(b))
Processing subscription payments Performance of contract (UK GDPR Art. 6(1)(b))
Sending transactional emails (verification, password reset, account deletion) Legitimate interest (UK GDPR Art. 6(1)(f))
Sending email digests and marketing communications Consent (UK GDPR Art. 6(1)(a)); you may withdraw at any time
Improving the service and monitoring for abuse Legitimate interest (UK GDPR Art. 6(1)(f))
Retaining payment records for legal compliance Legal obligation (UK GDPR Art. 6(1)(c))

4. Data Retention

5. Third Parties We Share Data With

We do not sell your personal data to any third party.

6. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

To exercise any of these rights, please email privacy@quantumreports.io. We will respond within one calendar month.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk/concerns.

7. Cookies and Tracking Technologies

We use the following types of cookies:

You can manage your cookie preferences at any time using the Cookie Preferences panel.

8. Data Security

We use industry-standard security measures including TLS encryption for all data in transit, bcrypt password hashing, HTTP-only cookies for session tokens, and Content Security Policy headers. Access to personal data is restricted to essential service operations only.

9. International Transfers

Our service providers (Stripe, Resend, Anthropic, Supabase, Railway) may process data in the United States. We rely on Standard Contractual Clauses and/or the UK International Data Transfer Agreement where applicable to ensure adequate protection.

10. Children

Quantum Reports is not directed at children under 18 years of age. We do not knowingly collect data from anyone under 18. If you believe a minor has registered, please contact us at privacy@quantumreports.io and we will delete the data.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users by email of any material changes. The date at the top of this page shows when the policy was last updated. Continued use of the service after changes constitutes acceptance of the updated policy.

12. Governing Law

This Privacy Policy is governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

13. QuantumAI Browser Extension

QuantumAI is also available as a separate browser extension that connects to your Quantum Reports account. This section describes what the extension itself collects; the rest of this policy, including Section 5's description of how Anthropic PBC processes QuantumAI messages, continues to apply to the underlying QuantumAI service.

What the extension collects

Why we collect it

This data is used solely to provide the QuantumAI feature within the extension: the token authenticates each request as coming from your account, and the selected text is what QuantumAI analyses to produce a response. It is not used for any other purpose. Legal basis: performance of contract (UK GDPR Art. 6(1)(b)), the same basis under which we provide QuantumAI within the main service (Section 3).

Where the token is stored

The raw extension token is generated once, at connection time, and stored only in your browser’s local extension storage — it is never stored on any third-party service. On our servers we store only a bcrypt hash of the token, the same one-way hashing used for account passwords (Section 2), so the raw token cannot be recovered even from our own database.

Retention and revocation

The token remains valid until you revoke it from Account Settings → Connected Devices, or until your Premium subscription lapses — either of which cuts off extension access on the very next request, with no separate expiry. Text you submit via “Ask QuantumAI” is sent to Anthropic PBC (Section 5) to generate a response and is not otherwise logged or stored by us; our servers record only a running count of how many messages you’ve sent that day, not their content, to enforce the daily usage limit.

We do not sell or transfer this data to any third party, and we do not use it for any purpose beyond providing the QuantumAI extension feature described above.

Host permission scope

The extension’s only content script runs on quantumreports.io/extension/authorize, and its sole function is to relay a one-time connection code back to the extension when you connect your account. It does not run on, read, or interact with any other website.


For all privacy-related enquiries: privacy@quantumreports.io