Quantum

Privacy

This notice describes how Quantum handles your data. It describes the whole of the system, including the parts that are built but not yet serving readers, so that nothing here has to be revised the week a feature arrives.

The controller is Frank Zickert, 13503 Berlin, Germany, mail@pyqml.com. The imprint carries the same details.

The short version

Quantum has no accounts and no sign-in. It runs no advertising, sells no data, embeds no trackers from other companies, and builds no profile of you — here or anywhere else. There is no reader identity on this site and there is not going to be one.

Everything it keeps is listed below, in full.

What Quantum stores itself

If you subscribe to the email, we store your email address, the time you confirmed, which page you signed up from, and — only if you chose to tell us — where you found the site. That is the whole record. The legal basis is your consent, Art. 6(1)(a) GDPR. We keep it until you unsubscribe, which every email we send links to, which is also possible on this site without signing in, and which takes effect immediately.

If you enter your address and never confirm it, we hold it for seven days so the confirmation link works, and then delete it. Nothing is sent to that address in the meantime except the one confirmation email.

As you read, we store nothing about you: no account, no session, no behavioural event, and no identifier of any kind is ever written down. What we do keep is a count: per day, how many visits the site had, how many different visitors made them, how many of those visitors looked like a person rather than an automated program, and how many of those were reading on a phone or tablet rather than at a desk. Pages one visitor opens within half an hour of each other count as one visit. Whether a visitor looks like a person is judged from what their browser asks for and from whether it goes on to load the page's own styles and pictures; whether they are on a phone is judged from what their browser says it is. Both are guesses about a group, never findings about you. To tell visitors apart within that day, your network address and the name your browser gives itself are turned into a code with a key that exists only in the server's memory, and that code is held there with the time of the last page opened. None of it is ever written down, and at the end of the day the key is destroyed along with every code made from it. We also count, per day, how many people asked to join the list, how many completed the confirmation, and how many gave each answer to where they found us. Only these daily totals are written down. They say nothing about you, and nothing about you can be recovered from them. The legal basis is Art. 6(1)(f) GDPR: knowing whether the site is read at all.

The subscriber record lives in Quantum's own database, on the server described below. No other party receives it except where this notice says so.

Cookies and similar storage

Quantum sets no cookies at all — none for advertising, none for analytics, and none for anything else. It writes nothing to your browser's storage either. Nothing about you is kept on your side, and nothing is kept on ours beyond what this notice lists.

Who else receives data

Each of these processes data on Quantum's behalf under a processing agreement, or as an independent controller where the law makes them one.

  • Contabo — Server hosting. Receives: Everything this site stores, and web-server logs including addresses. Why: Running the site. Where: The European Union.
  • Checkdomain — Transactional email. Receives: The address a message is sent to, and the message itself. Why: Delivering subscription confirmations. Where: Germany.
  • Substack — Subscriber email. Receives: The email address of a confirmed subscriber. Why: Delivering the email that goes out when something new is published. Where: The United States.
  • Bunny Stream — Video hosting. Receives: A viewer's address, and which video they watched. Why: Serving the video, once a reader presses play. Where: Frankfurt, Singapore, New York and Los Angeles, and the delivery edge nearest a viewer.

That is the complete list. Everything else this site runs on — its database and its object storage — runs on the server above and is not a separate recipient.

Bunny Stream is the only one your own browser ever contacts, and only when you press play on a video. Everything else a page loads — the text, the images, the files, and the still picture standing in for a video before you play it — comes from Quantum itself. So reading a page that has a video on it sends nothing to anyone; watching that video tells Bunny Stream your address and which video it was.

Where data is processed

Where each recipient processes your data is listed against it above. Where that is outside the European Union, the transfer rests on the European Commission's standard contractual clauses.

Server logs

The server that runs Quantum keeps web-server logs — the request, the time, and the requesting address — for the short period needed to operate the service securely. The legal basis is Art. 6(1)(f) GDPR.

When you submit the subscription form, we briefly count recent submissions from your network address, so the form cannot be used to send mail to people who did not ask for it. That count is held in memory for an hour and never written down. The legal basis is the same.

Your rights

You may request access to your data, correction, erasure, restriction of processing, and portability, and you may object to processing based on legitimate interest. Where processing rests on consent, you may withdraw it at any time, which does not affect what was lawful before. Write to mail@pyqml.com. You may also complain to a supervisory authority.