XQuantum
// LEGAL

Privacy Policy

Effective date: October 4, 2026 · Service: CIAG Quantum LENS

This Privacy Policy describes how CIAG Global, LLC, a Minnesota limited liability company ("Company," "we," "us"), collects, uses, and shares information in connection with the CIAG Quantum LENS document-extraction service (the "Service"). It supplements, and should be read together with, our Terms of Service. By using the Service, you agree to the collection and use of information as described here.

In short: we don't store the documents you upload or the data we extract from them — they're processed in memory and discarded once the result is returned to you. The main thing we do keep is standard account and billing information (your email, a hashed password, and a record of what you were charged), and the AI provider we use to perform extraction (OpenAI) briefly retains what it processes, under its own policy, for abuse-monitoring purposes only — not to train its models. Details below.

1. Information We Collect

Account & Signup Information

When you create an account, we collect your email address, a password (which we store only as a one-way bcrypt hash — we never store or transmit your actual password), an optional company name, and the IP address you signed up from. We also record the fact and timestamp that you accepted our Terms of Service, tied to your account, so that acceptance is a verifiable record rather than just a client-side assumption.

Documents You Upload

When you submit a document for extraction, it is read into memory, converted into the images our AI provider needs, and sent to that provider to perform the extraction you requested. We do not write your document to disk and we do not store it, or the extraction result, in our own database. Once the result is returned to your browser, our copy of it is discarded. (Our AI provider's own, separate retention of what it processes is described in Section 3.)

Payment Information

If you purchase additional Quanta, your payment is handled entirely by Stripe through its own hosted checkout — we never see or store your card number or other payment credentials. We retain only Stripe's checkout session identifier, the purchase amount, the Quanta credited, and the purchase status, so we can reconcile your balance.

Usage & Billing Data

For every extraction you run, we record the number of pages processed, the AI tokens consumed, and the resulting Quanta cost, tied to your account. This is our billing ledger — it reflects what you were charged, not the content of what you processed.

Technical & Log Data

We log basic request metadata (such as IP address and timestamps) for security and anti-abuse purposes — for example, limiting how many accounts can be created from one IP address per day, and blocking known disposable-email signups. These operational logs do not contain the content of your documents or extraction results.

2. How We Use This Information

  1. To provide and operate the Service — authenticating you, running your extractions, and billing Quanta against your balance;
  2. To verify your email address and process password-reset requests;
  3. To detect and prevent fraud and abuse of the Service, including free-trial abuse, automated signups, and rate-limit circumvention;
  4. To maintain a record of your acceptance of our Terms of Service and to enforce those Terms; and
  5. To maintain, secure, and improve the Service.

We do not use the content of documents you upload, or data we extract from them, for any purpose other than returning the result to you.

3. How Information Is Shared

We do not sell your personal information. We share information only with the service providers below, each acting on our behalf to help operate the Service, or as required by law.

ProviderPurposeWhat it receives
OpenAIAI-based document extractionThe document images you submit for extraction, and the resulting output. Processed under OpenAI's API terms: not used to train OpenAI's models, but retained by OpenAI for up to 30 days for abuse-monitoring purposes under its own data usage policy. We do not currently have a zero- or reduced-retention agreement in place with OpenAI.
StripePayment processingWhatever Stripe's own hosted checkout collects directly from you (card details, billing contact). Governed by Stripe's own privacy policy and terms.
Our email delivery providerSending account-verification and password-reset emailsYour email address and the content of those transactional emails only — we do not send marketing email through this channel.
Cloudflare (Turnstile)Distinguishing real signups from automated/bot signupsLimited technical/browser signals needed to perform that check, under Cloudflare's own privacy policy.
Microsoft Azure & NeonApplication hosting and database hostingAll data described in Section 1, as our infrastructure providers. Both are located in the United States.

We may also disclose information if required by law, subpoena, or other legal process, or where we reasonably believe disclosure is necessary to protect the rights, property, or safety of the Company, our users, or others.

4. Data Retention

  1. Documents and extraction results are not retained by us at all — see Section 1. OpenAI's own, separate retention of what it processes is described in Section 3.
  2. Account information is retained for as long as your account is active, and for a reasonable period afterward as needed for accounting, fraud-prevention, and legal-compliance purposes.
  3. Billing and usage ledger records are retained as permanent accounting records of what was charged to your account, consistent with standard bookkeeping practice.

5. Data Security

Passwords are stored only as bcrypt hashes with a unique salt per password — never in plain text, and never logged. Email-verification and password-reset links are single-use and are stored server-side only as a one-way hash of the token, so the raw link cannot be reconstructed from our database. All traffic to the Service is encrypted in transit. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

6. Cookies & Local Storage

The Service does not use advertising or analytics trackers. Your sign-in session is kept in your browser's local storage, solely to keep you logged in between visits — clearing it will sign you out. Cloudflare's Turnstile widget, used on signup, may set its own cookies as part of performing its bot-check, under Cloudflare's own policy.

7. Your Choices and Rights

  1. You can review and update your account information by logging in, or by emailing us at will@ciag-global.com.
  2. You may request deletion of your account and associated personal information by emailing will@ciag-global.com. Some records — such as billing ledger entries and the record of your Terms acceptance — may need to be retained even after account closure for legitimate accounting, fraud-prevention, or legal-compliance purposes.
  3. We do not currently send marketing email; the only emails the Service sends are transactional (signup verification, password reset, and similar account notices).

8. Children's Privacy

The Service is not directed to, and we do not knowingly collect personal information from, anyone under 18 years old, consistent with the eligibility requirement in our Terms of Service. If you believe a minor has provided us with personal information, contact us at will@ciag-global.com and we will take appropriate steps to delete it.

9. International Users

The Service and the infrastructure it runs on are located in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those of your jurisdiction.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice — such as by posting an updated effective date on this page, or emailing the address on your account. Continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.

11. Contact

CIAG Global, LLC, a Minnesota limited liability company
Contact: will@ciag-global.com
Address: 330 S Second Ave, Suite 200 1900, Minneapolis, MN 55401