The Quantum Spaces Project

Privacy Policy

Version 1.1 Updated May 8, 2026 Effective May 8, 2026

FRIENDLYPHOTONS BY QUANTUM SPACES

PRIVACY POLICY

Version: 1.1 Last Updated: May 8, 2026 Effective Date: May 8, 2026

This Privacy Policy describes how The Quantum Spaces Project, Inc. (“Quantum Spaces,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects your information when you use the FriendlyPhotons mobile application, the FriendlyPhotons web app (https://app.friendlyphotons.ai), the FriendlyPhotons marketing site (https://friendlyphotons.ai), the Quantum Spaces website (https://quantumspaces.ai), related software, APIs, data services, and all associated documentation (collectively, the “Platform”).

This Privacy Policy is incorporated into and governed by our End User License Agreement (“EULA”). Capitalized terms used but not defined in this Privacy Policy have the meanings given to them in the EULA.

Please read this Privacy Policy carefully. By using the Platform, you acknowledge that you have read and understood this Privacy Policy and agree to our collection, use, and disclosure of your information as described below.


1. WHO WE ARE

The Quantum Spaces Project, Inc. is the data controller responsible for your Personal Data. FriendlyPhotons is our community-powered electromagnetic radiation (EMR) mapping platform.

Contact: - General legal inquiries: legal@quantumspaces.ai - Privacy-specific inquiries: privacy@quantumspaces.ai - Address: San Diego, California, USA - App: https://app.friendlyphotons.ai - FriendlyPhotons site: https://friendlyphotons.ai - Quantum Spaces site: https://quantumspaces.ai


2. DATA WE COLLECT

We organize the data we process into three categories. Understanding these categories will help you understand what we collect, why we collect it, and what happens to it.

Category A — Environmental Signal Data (Contributed Data)

This is the core of the Platform. It includes:

  • EMR readings — electromagnetic field measurements (values in µT, mG, µW/m²), frequency band data, and measurement metadata
  • Location data — GPS coordinates, addresses, business names, space types, place identifiers, and photographs submitted in connection with EMR readings or location creation
  • Measurement metadata — timestamps, meter make and model, field type, measurement mode, and duration

How it is collected: You actively submit this data when you take an EMR reading or create a location on the Platform. GPS coordinates are collected through your device’s location services when you submit a reading or create a location. You initiate this action and are aware of the data being collected.

How long it is kept: Permanently. Environmental Signal Data forms the community dataset and is retained indefinitely, even after account deletion. This is because EMR readings describe a place, not a person. See Section 9 (Account Deletion) for details.

Commercial use: Environmental Signal Data may be commercially licensed to third parties in anonymized and aggregated form. Your personal identity is not included in any commercial dataset, and our anonymization process is designed to prevent re-identification.

Category B — Identity and Behavioral Data (Personal Data)

This is the data that identifies you personally. It includes:

Account data (collected at registration and profile editing): - Username, email address, password (stored as a bcrypt hash — we never store your actual password) - First name, last name - Country, gender, mobile phone number - Profile image URL, bio, display name preference - Google ID or Apple ID (if you use social sign-in) - Authentication provider (email, Google, or Apple) - Account status flags (active, verified, archived, deleted)

Login history (collected at every login): - IP address - User agent (browser and device information) - Timestamp - Authentication method used

Technical metadata (collected during authentication events and content actions): - IP address (derived from your connection) - Device type and operating system (parsed from your user agent) - Browser name and version (parsed from your user agent) - Full user agent string - GPS coordinates (collected only when you submit an EMR reading or create a location — not during other actions) - The type and identifier of the record associated with the action (e.g., a discussion post or EMR reading)

Discussion content: - Posts, comments, and replies you create in Platform discussion forums (referred to as “User Content” in the EULA)

Legal acceptance records (collected when you accept legal agreements): - EULA acceptance: user ID, EULA version, timestamp, IP address, user agent - Community Guidelines acceptance: user ID, guidelines version, timestamp, IP address, user agent - Cookie consent: user ID, consent version, timestamp of consent given, timestamp of any withdrawal, IP address, user agent

Email logs (collected when we send you transactional emails): - Recipient email address, sender address, subject line, email type - Delivery status, message ID, delivery timestamps - Error messages (if delivery fails)

Cookie consent records: - Whether you have acknowledged the cookie notice, and when

How long it is kept: - Account data: retained while your account is active; deleted upon account deletion (subject to a 30-day processing window) - Login history: retained for 90 days, then automatically deleted - Technical metadata: retained for 90 days, then automatically deleted - Discussion content: retained while your account is active; anonymized (not deleted) upon account deletion - Legal acceptance records: retained indefinitely for legal compliance and accountability purposes - Email logs: retained for 90 days, then automatically deleted - Cookie consent records: retained indefinitely for legal compliance

Commercial use of Category B data. Category B data is used to operate the Platform — to provide your account, maintain security, support the user experience, and comply with legal obligations. We do not currently sell, share with advertisers, or include Category B data in commercial data products.

Category C — Derived Intelligence Data

This is data that Quantum Spaces creates from aggregated and anonymized Contributed Data. It includes:

  • Location EMR profiles and composite scores
  • Confidence scores based on reading count and contributor diversity
  • Longitudinal trend analyses
  • Geographic heatmaps
  • Infrastructure correlation data

How it is created: Algorithmically, from aggregated Environmental Signal Data contributed by the community.

Your relationship to it: You do not provide this data directly. It is generated by Quantum Spaces and is our exclusive intellectual property, as described in the EULA (Section 7). Derived Intelligence Data contains no personally identifiable information.


3. HOW WE USE YOUR DATA

We use your data for the following purposes:

To operate the Platform: - Create and manage your account - Authenticate your identity when you log in - Display your profile and contributions to other users - Process and display EMR readings and locations - Power discussion forums - Send transactional emails (account verification, password resets)

To maintain security and integrity: - Detect and prevent fraud, abuse, and unauthorized access - Monitor for fake or fabricated EMR readings - Maintain audit trails of administrative actions - Log authentication events for security monitoring

To build and improve the community dataset: - Aggregate and anonymize Contributed Data - Generate confidence scores, ratings, heatmaps, and trend analyses - Improve data quality and measurement accuracy

To comply with legal obligations: - Maintain records of legal agreement acceptances - Respond to lawful data access requests - Meet data protection and privacy law requirements

To commercially license anonymized data: - License aggregated, anonymized Environmental Signal Data and Derived Intelligence Data to third parties including researchers, real estate platforms, hospitality companies, insurers, and government agencies - Operate certification programs and API data services


If you are in the European Economic Area (EEA) or the United Kingdom, we rely on the following legal bases under the General Data Protection Regulation:

Data Legal Basis
Account data Contract performance (Article 6(1)(b)) — necessary to provide the service you signed up for
Session cookies Strictly necessary — no consent required under ePrivacy Directive Article 5(3)
GPS coordinates on EMR readings and location creation Consent through deliberate user action (Article 6(1)(a)) — you actively choose to submit a geolocated reading
Login history (IP, user agent) Legitimate interests (Article 6(1)(f)) — security monitoring and fraud detection
Technical metadata (IP, device, browser on auth and content events) Legitimate interests (Article 6(1)(f)) — security monitoring and platform integrity
Legal acceptance audit trails Legal obligation and accountability (Article 5(2), Article 7)
Email logs Legitimate interests (Article 6(1)(f)) — delivery reliability and debugging
Discussion content Contract performance (Article 6(1)(b)) — you choose to post content as part of using the Platform
Commercial licensing of anonymized Contributed Data Legitimate interests (Article 6(1)(f)) — operating and funding the Platform

Where we rely on legitimate interests, we have conducted balancing assessments to ensure our interests do not override your rights and freedoms. You have the right to object to processing based on legitimate interests (see Section 8).


5. COOKIES AND LOCAL STORAGE

We use one strictly-necessary session cookie (qsession) and a small number of local storage entries to keep the Platform functional. We do not use any tracking cookies, advertising cookies, third-party analytics, or session-replay tools.

For the full inventory — every cookie and local storage item we set, why each one exists, how long it persists, what we explicitly do not use, and how to control them — see our Cookie Policy, which is incorporated by reference into this Privacy Policy.


6. THIRD-PARTY DATA PROCESSORS

We share your data with the following third-party service providers, each of which processes data on our behalf and under our instructions:

SendGrid (Twilio Inc.)

  • Data shared: Your email address, email subject, and email body content
  • Purpose: Transactional email delivery (account verification, password resets)
  • Location: United States
  • Privacy policy: https://www.twilio.com/legal/privacy

OpenStreetMap Nominatim

  • Data shared: GPS coordinates (latitude and longitude)
  • Purpose: Reverse geocoding — converting GPS coordinates into human-readable addresses when you submit an EMR reading or create a location
  • Note: This is a free, open-source service. The GPS coordinates you submit as part of an EMR reading are sent to OpenStreetMap’s servers to look up the corresponding address. OpenStreetMap’s Nominatim service does not retain query data for commercial use, but the transfer of coordinates does occur.
  • Privacy policy: https://wiki.osmfoundation.org/wiki/Privacy_Policy

Google Sign-In (Google LLC)

  • Data shared: Authentication tokens during the sign-in flow
  • Data received: Your name, email address, and Google user ID (only if you choose to sign in with Google)
  • Purpose: OAuth authentication — allowing you to create an account or log in using your Google account
  • Location: United States
  • Privacy policy: https://policies.google.com/privacy

Apple Sign-In (Apple Inc.)

  • Data shared: Authentication tokens during the sign-in flow
  • Data received: Your name, email address (or a private relay address, at your choice), and Apple user ID (only if you choose to sign in with Apple)
  • Purpose: OAuth authentication — allowing you to create an account or log in using your Apple ID
  • Location: United States
  • Privacy policy: https://www.apple.com/legal/privacy/

Neon (Neon Inc.)

  • Data shared: All data stored in the Platform’s database
  • Purpose: Managed PostgreSQL database hosting — this is where the Platform’s data is stored
  • Location: United States
  • Privacy policy: https://neon.tech/privacy

Cloud hosting and object storage providers

  • Data shared: All Platform data in transit and at rest, including account information, EMR readings, and user-uploaded photos
  • Purpose: Application hosting, request handling, and storage of user-uploaded photos (avatars, meter photos, location photos)
  • Location: United States
  • Note: Providers in this category operate under standard cloud-services data processing terms. Specific vendor identities are available upon request to privacy@quantumspaces.ai.

Beyond the providers listed above, we do not currently share Personal Data with analytics platforms, advertising networks, data brokers, or social media companies. We do not currently sell Personal Data.


7. DATA SECURITY

We implement technical and organizational measures to protect your data, including:

  • Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS/HTTPS
  • Password hashing: Passwords are stored using bcrypt hashing — we never store or have access to your actual password
  • HTTP-only cookies: Our session cookie cannot be accessed by client-side JavaScript, reducing the risk of cross-site scripting attacks
  • Secure cookie flags: Session cookies are marked Secure (transmitted only over HTTPS) and SameSite=None with appropriate protections
  • Server-side session storage: Session data is stored in our database, not in the cookie itself
  • Administrative audit trails: All administrative actions, including any impersonation of user accounts, are logged with timestamps, IP addresses, and reasons

No system is perfectly secure. While we take reasonable precautions, we cannot guarantee absolute security of your data. If we become aware of a security breach affecting your Personal Data, we will notify you and any applicable regulators as required by law.


8. YOUR DATA RIGHTS

Rights Under the GDPR (EEA and UK Residents)

If you are in the European Economic Area or the United Kingdom, you have the following rights:

  • Right of access — You can request a copy of all Personal Data we hold about you.
  • Right to rectification — You can ask us to correct any inaccurate Personal Data.
  • Right to erasure (“right to be forgotten”) — You can request deletion of your Personal Data. Note: this applies to Personal Data (Category B). Contributed Data (Category A) is anonymized and retained as part of the community dataset, as described in Section 9 and in EULA Section 5.4.
  • Right to data portability — You can request your Personal Data in a structured, commonly used, machine-readable format.
  • Right to restriction of processing — You can ask us to temporarily stop processing your Personal Data in certain circumstances.
  • Right to object — You can object to our processing of your data where we rely on legitimate interests as a legal basis. We will stop processing unless we can demonstrate compelling legitimate grounds.
  • Right to withdraw consent — Where we process data based on your consent, you can withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before you withdrew consent.
  • Right to lodge a complaint — You have the right to lodge a complaint with your local data protection authority. A list of EEA data protection authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en. The UK authority is the Information Commissioner’s Office (https://ico.org.uk).

Rights Under the CCPA (California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act:

  • Right to know — You can request that we disclose the categories and specific pieces of Personal Data we have collected about you, the sources of that data, our purposes for collecting it, and the categories of third parties with whom we share it.
  • Right to delete — You can request deletion of your Personal Data, subject to certain exceptions (including our retention of anonymized Contributed Data).
  • Right to opt out of the sale of Personal Data — Under the CCPA, you have the right to opt out of the sale of your Personal Data. We do not currently sell Personal Data. We do commercially license aggregated, anonymized Environmental Signal Data (Category A) and Derived Intelligence Data (Category C), which contain no personally identifiable information and do not constitute a “sale” of Personal Data under the CCPA. If we change this practice in the future, we will provide notice and an opt-out mechanism in compliance with applicable law.
  • Right to non-discrimination — We will not discriminate against you for exercising any of your CCPA rights.

How to Exercise Your Rights

To exercise any of these rights, contact us at:

  • Email: privacy@quantumspaces.ai
  • Response time: We will respond to verified requests within 30 days (or within the timeframes required by applicable law). Complex requests may require up to 60 additional days, in which case we will notify you.

We may need to verify your identity before processing your request. We will never charge a fee for processing a legitimate data rights request unless the request is manifestly unfounded or excessive.


9. ACCOUNT DELETION

You may delete your account at any time through the Platform’s account settings. The deletion process is designed to give effect to your erasure rights immediately, while preserving a brief window during which the action can be reversed.

Day 0 — at the moment of deletion. When you confirm the deletion:

  • Your name, email address, profile information, login history, technical metadata, email log records, OAuth identifiers (Google ID, Apple ID, if any), and password hash are immediately removed from the active database
  • An encrypted snapshot of your identity data is placed in a private restore vault, separated from the active database, and accessible only to authorized administrators for the purpose described below
  • Your username is immediately released and may be claimed by another user
  • All your active sessions are terminated and you are signed out of all devices

Day 1 through Day 30 — restore window. During this 30-day window, you may contact privacy@quantumspaces.ai to request reversal of your deletion. If we restore your account:

  • Your identity data is restored from the encrypted snapshot and your account is reactivated
  • You will be required to set a new password — your previous password hash is destroyed at Day 0 and cannot be recovered
  • Your username will be available again only if it has not been claimed by another user during the window; otherwise you will be prompted to choose a new one
  • Restoration restores identity only. It does NOT re-attribute your prior Contributed Data or User Content to you. Those records remain anonymized per the policies described below

After Day 30 — final deletion. At Day 30, the encrypted identity snapshot is securely purged. Deletion is then irreversible and your account cannot be restored.

Anonymized and retained — independent of the deletion timeline above.

  • Your Contributed Data (EMR readings, location data, photographs, and associated measurement metadata) is retained as Platform research data under the GDPR Article 17(3)(d) research exception described in EULA §5.5, which you agreed to when you created your account. Your direct identifiers are dissociated and your contributions are attributed to a unique anonymous placeholder. The dataset’s integrity — describing places, not people — depends on the permanence of contributed measurements.
  • Your User Content (discussion posts, comments) is attributed to the same anonymous placeholder. The content itself is retained to preserve the coherence of community discussions.

Retained for compliance. Records of your legal agreement acceptances (EULA, Community Guidelines, Cookie Policy, cookie consent records) are retained as required for legal accountability. These records are stored separately, anonymized at deletion, and are not publicly visible.

Photo removal request. If a specific photograph you have submitted incidentally contains personal information unrelated to its research purpose, you may request its review and removal at privacy@quantumspaces.ai — see EULA §5.5 for the criteria.


10. CHILDREN’S PRIVACY

The Platform is not directed at children. We do not knowingly collect Personal Data from:

  • Anyone under 13 years of age (United States)
  • Anyone under 16 years of age (European Economic Area)

If you are a parent or guardian and believe your child has provided us with Personal Data, please contact us at privacy@quantumspaces.ai. If we discover that we have collected Personal Data from a child below the applicable age threshold, we will delete that data promptly.


11. INTERNATIONAL DATA TRANSFERS

The Platform is operated from and data is stored in the United States. If you are accessing the Platform from outside the United States, your data will be transferred to and processed in the United States.

The United States may not provide the same level of data protection as your home country. By using the Platform, you consent to the transfer of your data to the United States.

For users in the European Economic Area or the United Kingdom, we rely on the following mechanisms for international data transfers:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable
  • Adequacy decisions, where available
  • Your explicit consent to the transfer, provided when you create your account

If you have questions about international transfers, contact us at privacy@quantumspaces.ai.


12. DATA RETENTION SUMMARY

Data Type Retention Period
Account data (name, email, profile) Cleared from active database at Day 0 of deletion request; encrypted snapshot held in private restore vault for 30 days; purged at Day 30
Session cookies 24 hours
Password reset tokens 1 hour
Email verification tokens 1 hour
Login history (IP, user agent) 90 days
Technical metadata (IP, device, browser, OS) 90 days
Email logs 90 days
Notifications 90 days
EMR readings and location data (Contributed Data) Permanent — anonymized on account deletion (GDPR Article 17(3)(d) research exception, EULA §5.5)
Discussion content (User Content) Anonymized at account deletion and retained
Legal acceptance audit trails (EULA, Community Guidelines, Cookie Policy) Indefinite — anonymized at deletion (legal compliance)
Cookie consent records Indefinite — anonymized at deletion (legal compliance)
Administrative audit logs (admin actions, content reports, security events) 2 years

13. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the Platform (for example, through a notification or a re-acceptance prompt) and update the “Last Updated” date at the top of this policy.

We encourage you to review this Privacy Policy periodically. Your continued use of the Platform after changes are posted constitutes your acceptance of the updated Privacy Policy.


14. ADVERTISING AND TRACKING POSTURE

The Platform does not currently include third-party advertising, ad networks, or behavioral profiling. The third parties that receive your data are the service providers listed in Section 6, used only for the specific operational purposes described there. If we introduce new third-party processors or analytics in the future, we will update this Privacy Policy and provide notice through the Platform.


15. GOVERNING LAW

This Privacy Policy is governed by the laws of the State of California, without regard to conflict-of-law principles. Any legal action arising from this Privacy Policy shall be brought exclusively in the state or federal courts located in San Diego County, California.

This provision does not affect your rights under GDPR to lodge a complaint with your local data protection authority, or any other rights that cannot be waived under applicable law.


16. CONTACT US

If you have questions about this Privacy Policy, want to exercise your data rights, or have a privacy concern, contact us:

The Quantum Spaces Project, Inc. San Diego, California

  • Privacy inquiries: privacy@quantumspaces.ai
  • Legal inquiries: legal@quantumspaces.ai
  • App: https://app.friendlyphotons.ai
  • FriendlyPhotons site: https://friendlyphotons.ai
  • Quantum Spaces site: https://quantumspaces.ai