Skip to main content
KetQat

Appearance

Privacy

Last updated 2026-09-09.

What we collect

  • Account data: your GitHub-provided name, email, avatar, and a username you choose, via GitHub OAuth.
  • Published content: artifacts, benchmark runs, and profile fields (bio, website) you choose to submit.
  • Follows: the accounts you follow and when you followed them. Following and follower lists and counts are public. Your home timeline uses these relationships to show public work from those accounts.
  • API tokens: stored only as a SHA-256 hash, never in plaintext. The raw token is shown to you once at creation and cannot be retrieved again.
  • Basic server logs: hosting-provider request metadata, which can include URL, status, timestamp, IP address and browser information, for operating and securing the service. We do not run third-party analytics or advertising trackers.

What we don't collect

We never see or store your GitHub password, and we do not request write access to your repositories. We do not store QPU-provider or cloud-provider credentials -- that's explicitly out of scope for KetQat.

How it's used

Account data authenticates you and attributes content you publish. Published content is served to visitors per its visibility setting (see Terms). Logs are used for debugging, abuse prevention, and capacity planning, and are not sold or shared with advertisers.

Product measurement

KetQat records a small set of counts about how the product is used: that an assessment draft was started, that one was submitted, that an estimate ran, that a report was generated, that a reference case was cloned, and that a review was requested or decided.

Each application event contains only a name from a fixed list: no account identifier, assessment slug, circuit, baseline figure or entered contents. These are event counts, not counts of people. Repeated actions, tests and automation can contribute to them. Hosting logs have their own request metadata, so this does not mean all server logs are anonymous.

When enabled, the Qiskit quickstart also offers voluntary feedback: the sample worked, your own circuit worked, or you could not get it working. It sends only the selected choice when you click, without account cookies, free text, circuit data or reports. No identifier is created in your browser. Do Not Track and Global Privacy Control disable this feedback. Skipping it has no effect on access. The local CLI never sends these events automatically.

Operators can aggregate existing request logs for a fixed set of product pages and Checkout/upload endpoints. The aggregate excludes raw URLs, IP addresses, account and repository identifiers, and browser strings. Request counts and unverified feedback do not establish unique visitors, successful payments, scientific validity or customer adoption. Internal feedback is labeled separately by server configuration; public feedback may still include internal actors, repeated answers or bots.

There is no third-party analytics script on any page of this site — no Google Analytics, no tag manager, no session recorder. A third-party tag would send your page views to somebody else from pages that can carry private assessments.

Third parties

The application is hosted on Google Cloud Run and its PostgreSQL database is hosted by Supabase. Authentication uses GitHub OAuth. These providers receive only the data needed to operate the service.

Your controls

  • Unfollow an account from its profile or the People directory to remove that relationship. Account deletion removes its incoming and outgoing follows.
  • Revoke any API token at any time in Settings.
  • Edit your profile fields, or set artifacts/runs you own to PRIVATE, at any time.
  • Export anything you own: every assessment offers its full JSON bundle, its Decision Report as JSON, and a CSV of the scenario comparison, from the assessment's Report section. Those are the same bytes the API returns, so an export is not a reduced copy.
  • Request account or data deletion by opening an issue on github.com/ketqat. Public content already reused by others under its license (see Licensing) cannot be retroactively un-shared.

Changes

This policy may change as KetQat grows. Material changes will be reflected here with an updated date.