Last updated: 6 October 2026 (version 2026-10-06.2)
Quantum Mind is a private academy run by Allinners LLC (“Allinners”, “the Academy” or “we”). This policy explains which personal data we process when you use the Quantum Mind mobile app and the website https://quantum-mind.mgquantumsystems.com, why we process it, how long we keep it and which rights you have. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”).
1. Who we are
The data controller is Allinners LLC, a company registered in Sharjah Media City, United Arab Emirates (Office 10, Level 1, Sharjah Media City, Sharjah, UAE — PO Box 487177).
For any privacy question and to exercise your rights you can write to support@mgquantumsystems.com.
This policy is addressed to students who use the app, to invited people who have not yet activated their account, to visitors of the website and to people who contact support. The management panel of the website is reserved for the Academy’s authorised staff.
Allinners is based in the United Arab Emirates but offers the service to people located in the European Union, mainly in Italy: for this reason it processes data in compliance with the GDPR (Art. 3(2)). It also complies, to the extent applicable, with United Arab Emirates Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (“PDPL”).
2. In short
- Quantum Mind is reserved for enrolled students: accounts are created by the Academy, there is no self-registration and the app is for adults.
- No payment takes place in the app or on the website: we do not collect card or bank account data.
- We use no advertising or tracking tools and no third-party analytics services: internal statistics are calculated on our own data and shown in aggregated form (section 4). We do not sell or hand over your data and we do not use it to profile you for commercial purposes.
- Data is hosted in European Union data centres (the Netherlands).
- Reserved content carries a personal watermark with your name, your email and an identification code: it protects the Academy’s work (section 5).
- Your journal and your exercise answers are private: by default no member of staff can read them (section 6).
- From the app you can download your data and delete your account immediately: Profile, Privacy and data (sections 10 and 11).
3. Which data we process and where it comes from
3.1 Data entered by our staff
When our staff creates or invites your account it enters: email address, first name, last name (if provided), phone number (optional, visible only to staff and not shown in the app), language, time zone, the programme you are enrolled in with the status and dates of the enrolment, and any internal staff notes (for example the reason for a suspension). You do not enter this data in the app: staff take it from the information you gave us when you enrolled, which happens outside the app. Internal notes are personal data: you can ask for a copy.
3.2 Data you provide
- Your password, which we store only as an irreversible cryptographic hash, and your optional two-step verification (we store the secret in encrypted form and the recovery codes as hashes).
- Changes to your profile: first name, last name, language and time zone.
- Exercise answers and the private journal: free text up to 20,000 characters, choices and ratings from 0 to 10.
- Your acceptance of the legal documents: version, date and time, IP address, user agent and device.
- The messages you send to support.
- Optional: your consent to push notifications (token) and, on your device, the email remembered for sign-in.
3.3 Data generated by using the service
- Progress: modules opened, acknowledged and completed; status and percentage of contents; pages viewed; audio segments played; listening position.
- Live sessions: first and last join, number of joins and the device used.
- Devices: a random key generated by the app (on the server we store only a hash of it), platform, the device name set in the operating system (it may contain your name), model, operating system and app version, date of last use, last IP address and its country (where detectable).
- Sessions and sign-ins: date and time, IP address, country (where detectable), user agent and outcome of every sign-in, including failed attempts and the email address typed, even when it does not match any account.
- Security events (section 5.3) and action log (audit): the log records, with date and time, IP address and user agent, the actions carried out with the account, for example sign-ins and sign-outs, password changes, profile edits, revocation of devices and sessions, opening of documents and audio, joining live sessions, acknowledgement and completion of modules, acceptance of the legal documents, registration of notification tokens, data export and deletion, as well as actions by staff on your account (section 9).
3.4 Website and technical logs
The public pages of the website (home, policies, support, account deletion) set no cookies, load no third-party resources and contain no analytics tools. The hosting provider records technical data of each request (for example IP address, date and time, requested address, user agent) to run and protect the service. Our application logs record for each request the method, requested address, request identifier, outcome and response time, without IP address; they are scrubbed of passwords, tokens and codes and may contain technical errors and internal account identifiers. For the cookies of the sign-in pages and of the panel, see the Cookie Policy.
3.5 Data exchanged with Expo: notifications and app updates
- Push notifications: if you turn them on (with “Remind me” on a live session or with the “Live reminders” switch in Profile, Notifications), the app obtains a notification token from Expo. To do so it sends Expo an installation identifier, the native device token (Apple or Google), the app identifier and the Expo project identifier. The token is then saved on our servers together with your account, the platform and the device. When a live session of your programme is about to start, our servers send Expo your token and the text of the notification (the title of the session and the minutes left before it starts), which Expo forwards to Apple (APNs) or Google (FCM) to deliver it to your device. The text contains neither the Zoom link nor the access code. Once you have turned them on on a device, the app renews the token at every launch without asking you again, until you turn them off or sign out; signing out deletes the token and, at the next sign-in (also with another account), notifications stay off until you turn them on again. The permission granted in the device settings alone does not turn them on. Reminders reach only devices where your account has an active session: once you are signed out, also because the session expired or was revoked, that device no longer receives them.
- App updates (EAS Update): at each launch the app checks whether an update of the code and resources only is available. The request contains a random installation identifier, the platform, the app version, the identifiers of the updates in use or that failed and, if the app closed abnormally last time, a short excerpt (up to 1,024 characters) of the error log, in addition to the IP address and user agent, which are unavoidable in any request. It does not contain your email, name or account identifiers.
3.6 Data we do not collect
We do not collect payment data (no payment takes place in the app or on the website), GPS location, contacts or photos, and we do not access the camera or the microphone. We do not use advertising identifiers. The app contains no third-party advertising, analytics or crash-reporting tools. If you add a live session to the calendar, the event is written only to your device’s calendar: we do not read the events you already have and we receive nothing.
4. Why we process data and on which legal bases
For each purpose we indicate the legal basis provided by Article 6 of the GDPR.
- Managing your account and providing the service: creating and inviting the account, giving you access to the content of your programme (guided audio, workbooks, exercises), saving answers and journal, calculating progress and the unlocking of modules, managing live sessions and attendance. Legal basis: performance of our relationship with you as an enrolled student (Art. 6(1)(b)).
- Authentication and account security: password, any two-step verification, sessions, authorised devices and their limit, temporary lockout after failed sign-in attempts, password reset. Legal basis: point (b) for authentication; point (f), our legitimate interest in preventing abusive access, for the protective measures.
- Protecting the content and the service: personal watermark, risk signals and score, audit log, request rate limits. Legal basis: legitimate interest (Art. 6(1)(f)), with the balancing described in section 5.
- Proof of acceptance: keeping a record of the version of the legal documents you accepted or acknowledged. Legal basis: point (b) for the Terms and Conditions; point (f) for the proof, to defend our rights.
- Invitation and password reset: delivering your invitation link and reset links. Today the system does not send them by email: our staff hand them to you through the channel agreed with you and, if you have forgotten your password, you can ask for one by writing to support@mgquantumsystems.com. If we turn on automatic email sending in future, through a transactional email provider that will act as our processor, we will name it in this policy. Legal basis: point (b).
- Support and requests about your data: answering your messages and handling the exercise of your rights. Legal basis: points (b) and (f) for support; point (c) to comply with the obligations on the exercise of rights.
- App updates and maintenance: distributing fixes and improvements to the app code only, without a new store release. Legal basis: point (f), our interest in keeping the service secure and working.
- Internal statistics: processing aggregated data, for example how many students complete a module or attend a live session, shown to staff in aggregated form, to improve the programmes. Legal basis: point (f).
- Live session reminders by push notification (optional): registering the token and using it to send you a single notification for each live session of the programmes you are enrolled in, normally between 25 and 30 minutes before it starts (an automatic check runs every 5 minutes; if a session is created or moved to less than 30 minutes before its start, the notification goes out at the next check). The content is the title of the session and how many minutes are left before it starts. If the Academy moves the time of a session, you receive a new reminder for the new time. A copy of the notification also appears in the notification list of the app. You receive no reminder until you turn them on yourself on that device, even if the notification permission is already granted in the settings, and today we use push notifications for nothing else. Legal basis: your consent (Art. 6(1)(a)), which you can withdraw at any time with the “Live reminders” switch in Profile, Notifications or by signing out of the app (both delete the token from our servers), or from your device’s notification settings. If you turn notifications off from the device only, you stop receiving them, but the token stays registered until you use the switch, sign out of the app, it becomes invalid or 12 months pass without the app registering it again.
- Legal obligations and defence of rights: answering requests from authorities, establishing or defending a right. Legal basis: points (c) and (f).
We do not use your data for advertising, commercial profiling or marketing, and we do not sell it.
Live sessions, Zoom and recordings
Live sessions take place on Zoom. The link and the access code are shown in the app only to enrolled students who have accepted the legal documents, from 30 minutes before the start (unless set otherwise) until the end of the session. When you join we record your attendance (first and last join, number of joins, device). We send Zoom no data about your account: the name you use in Zoom and what Zoom collects are processed by Zoom under its own privacy notice.
Some sessions may be recorded and made available as replays to enrolled students. If you take part with your microphone or camera on, or speak or write in the chat, your voice, your image and your contributions may appear in the recording. Zoom notifies participants when recording is in progress: if you do not wish to appear, keep your microphone and camera off and do not speak. Legal basis: legitimate interest in making lessons available to those who could not attend (Art. 6(1)(f)). You can object and ask us to remove or obscure your contribution by writing to support@mgquantumsystems.com.
5. Content protection, watermark and security controls
5.1 Personal watermark
PDF documents and workbook pages are shown as images generated at the time of the request, with a personal watermark that shows your name (or, if missing, your email), your email and a six-character code derived from your account identifier (“ID”); on content with reinforced protection it also shows the wording “Quantum Mind — Confidential” and the date and time (UTC) of viewing. A similar line (“Licensed to …”, with name, email, ID and the same wording) is overlaid on the screen over documents and the audio player. The watermark is generated each time and is not stored. On content with the highest protection level it may be denser and include a nearly invisible marking with your ID code. If reserved content were disclosed without authorisation, this information makes it possible to trace the account it came from.
5.2 Blocking of screenshots and screen recordings
On screens that show protected content the app asks the operating system to prevent or blank screenshots and screen recordings and to hide the preview in the app switcher, where the system allows it. On iOS and on Android 14 or later the app notices on the device that a screenshot was taken while protected content is open and shows you a warning: the event is not recorded or sent to our servers and the app does not see what you captured. Traceability depends solely on the personal watermark.
5.3 Security signals and risk score
The system records “security events” when it detects anomalous signals: a number of devices above the limit or an attempt to exceed it; simultaneous sign-ins from different IP addresses; a sign-in from a country different from those used before (only where the country can be detected); unusually numerous or fast requests for pages or audio segments, typical of automated copying; repeated failed sign-in attempts; reuse of a session token that had already been replaced, a possible sign of theft; a request for content from an IP address different from the one it was authorised for. Each signal is assigned a score and the sum of the open signals of the last 30 days forms the account’s risk score.
The score only serves to flag the situation to authorised staff, who assess it case by case, for example by asking you for clarifications. No account is suspended, blocked or restricted automatically because of the score: we do not take decisions based solely on automated processing that produce legal effects on you or similarly significantly affect you (Art. 22 GDPR). The score is a form of profiling limited to security (Art. 4(4)): you can object and ask for a person to intervene (section 10).
There are, however, automatic technical protective measures: temporary lockout after repeated failed sign-in attempts, closing a session if a token that had already been replaced is reused, a limit on the number of authorised devices (normally three) and rate limits on requests. They do not assess you as a person and apply to everyone in the same way; if you find yourself locked out by mistake write to support@mgquantumsystems.com.
5.4 The balancing of interests
For the watermark, the security signals and the audit log we rely on legitimate interest (Art. 6(1)(f)). The interest is to protect reserved educational material, the result of the work of the Academy and its authors, from unauthorised copying and disclosure, and to ensure the security of accounts and of the service. We consider the processing necessary and proportionate because:
- it shows each person only information that already concerns them (name and email) and only on the content they access;
- it does not read what is on your screen, nor your files or your other apps;
- the watermark is not stored and the risk score produces no automatic decision;
- access to this data is limited to authorised staff and actions are logged;
- the data is kept for limited periods (section 9);
- less intrusive measures would not offer equivalent protection.
For this reason we consider that your interests and rights do not override ours. You can nevertheless object to the processing on grounds relating to your particular situation (section 10): we will assess the request case by case.
6. Private journal and exercises
Your exercise answers and your journal are yours and private. We use them only to save them, show them to you, calculate whether an exercise is completed and include them in the export of your data.
By default the Academy’s management tools do not allow any member of staff to read the content of your journal. There is a setting, switched off, which, if the Academy turned it on, would allow reading only to accounts of the highest administration level (super administrator) holding a specific permission; every read would be recorded in the audit log and, before turning it on, we would update this policy. Ordinary administrators, support staff and instructors do not have this permission. Staff can only see progress data (for example whether you completed a module) and aggregated statistics. A data export carried out by staff at your request also leaves out the journal under the same conditions: you can always export it yourself from the app.
The journal is a free space. We invite you not to write information that is not needed for your programme, in particular data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, data concerning health or sex life or sexual orientation, or identifiable data of other people. If you choose to write it, we process it only to keep it and show it back to you, on the basis of your explicit consent (Art. 9(2)(a)). You can withdraw it at any time by deleting your account or by writing to support@mgquantumsystems.com to ask for your answers to be erased; withdrawal does not affect the lawfulness of processing already carried out.
7. Who can access the data
7.1 Academy staff
Authorised staff access data according to their role and only as far as needed. Administrators and support see profile, enrolments, devices, sessions, sign-in history, security events and acceptances; instructors manage the content and see only aggregated statistics; access to the journal is described in section 6. Staff accounts require two-step verification, sensitive operations require the password to be confirmed again and actions are logged.
7.2 Providers and other recipients
- Railway Corporation (United States): hosting of the web and API services, the database, content storage, backups and technical logs. The data is hosted in the European Union (the Netherlands, with storage in Amsterdam). It acts as processor (Art. 28 GDPR).
- Expo, 650 Industries, Inc. (United States): push notification and app update service (EAS Update); it receives the data described in section 3.5, including the text of live session reminders (title and minutes left). It acts as processor.
- Apple (APNs) and Google (Firebase Cloud Messaging): deliver notifications to iOS and Android devices and receive the native device token and the text of the notifications, which passes through their servers. The Apple App Store and Google Play distribute the app and process data under their own notices. They act as independent controllers for their own services.
- Zoom Video Communications, Inc. (United States): only when you choose to take part in a live session. It processes data under its own terms and privacy notice, which we invite you to read.
- Transactional email provider: today no automatic email sending is active, so no email provider receives any data. If the Academy turns it on to send invitations and password reset links, it will appoint the provider as processor and we will name it in this policy.
- WhatsApp (Meta) or your email provider: only if you choose to contact us through those channels; they handle the data as independent controllers.
- Authorities and advisers: only where the law requires it or where necessary to establish or defend a right.
We do not sell or hand over your data for advertising or marketing and we do not share it with advertising networks, data brokers or social networks.
8. Transfers of data outside the European Economic Area
Data is hosted in the European Union. Some providers, however, are based in the United States (Railway, Expo, Zoom, Apple, Google) and may receive data or access it from outside the Union. For these transfers we rely, depending on the provider, on the European Commission’s adequacy decision on the EU-US Data Privacy Framework, where the provider participates in it, or on the standard contractual clauses adopted by the European Commission (Art. 46 GDPR), together with the necessary supplementary measures.
Allinners is based in the United Arab Emirates, a country for which there is no European Commission adequacy decision, and its staff access from there the data hosted in the Union. Because Allinners is directly subject to the GDPR (Art. 3(2)), it applies the GDPR safeguards to this data; where the access amounts to a transfer, we base it on appropriate safeguards under Articles 46 and following (in particular the standard contractual clauses) or, in the limited cases where they apply, on the derogations of Article 49, such as a transfer necessary for the performance of the contract with you.
You can ask for information on the safeguards adopted by writing to support@mgquantumsystems.com.
9. How long we keep data
We keep data only for as long as needed for the purposes stated. An automatic operation run every day deletes data that has passed the following terms.
- Account and programme data (profile, enrolments, progress, answers and journal, attendance at live sessions, acceptances of documents): for as long as the account exists; deleted or anonymised immediately when you delete the account (section 11).
- Sign-in sessions: 30 days after the session expires or is revoked; history of refresh tokens already replaced: 30 days after replacement.
- Invitation and password reset links already used or expired: 30 days.
- Sign-in history (outcome, IP address, user agent, email typed): 12 months.
- Security events: 24 months.
- Audit log (relevant actions, including failed sign-ins, with author and email, IP address and user agent): 24 months.
- Devices: deleted 12 months after last use.
- Push notification tokens: removed when you turn reminders off with the switch in Profile, Notifications, when you sign out of the app or when Expo reports that they are no longer valid; otherwise deleted after 12 months without the app registering them again.
- In-app notifications (including the copy of live session reminders): 12 months from creation, or immediately if you delete your account.
- App update data held by Expo: under Expo’s terms.
- Technical logs of the hosting service: for the period set by the provider’s settings and in any case only for as long as strictly necessary for security and for diagnosing malfunctions.
- Correspondence with support: for as long as needed to handle the request and, afterwards, for the period strictly necessary to protect our rights.
- Backup copies: the database is copied periodically and the copies are kept for a limited period and then overwritten. After an account is deleted its data may remain in backup copies until they rotate; if a backup had to be restored, the deletions already carried out would be applied again.
We do not automatically delete inactive or never-activated accounts. After the relationship with the Academy ends, the account can be anonymised by staff at your request or on their own initiative when the data is no longer needed. If you were invited and do not want to activate the account, write to support@mgquantumsystems.com and we will delete your data.
10. Your rights and how to exercise them
You have the right to:
- access your data and obtain a copy (Art. 15);
- rectification of inaccurate or incomplete data (Art. 16);
- erasure (Art. 17);
- restriction of processing (Art. 18);
- portability of the data you gave us, in a structured, machine-readable format (Art. 20);
- object to processing based on legitimate interest, on grounds relating to your particular situation (Art. 21);
- withdraw consent at any time, without affecting processing already carried out (Art. 7(3)): for notifications with the “Live reminders” switch in Profile, Notifications, by signing out of the app or from your device settings;
- not be subject to decisions based solely on automated processing with legal or similar effects (Art. 22): we do not make them.
How to exercise them
- From the app, in Profile, Privacy and data: “Download my data” immediately produces a JSON file with a copy of your data (up to 3 requests per hour) and “Delete my account” deletes the account. In Profile you can also edit your first name, last name, language and time zone and manage Authorized devices, Active sessions and Notifications.
- By email to support@mgquantumsystems.com, also to rectify your email address or phone number, ask for restriction or object, or obtain the intervention of a person. If you no longer have the app you can also find the instructions to request deletion on the page https://quantum-mind.mgquantumsystems.com/account-deletion.
The export includes your profile data, enrolments (including any internal staff notes), progress, journal, attendance, devices, sessions, sign-in history, acceptances, security events, notifications and the audit log entries that concern you. It does not include your password, security secrets or data of other people. The file is created temporarily on your device and handed to the system share sheet: you choose where to save it or whom to send it to; the app removes it shortly afterwards.
We reply without undue delay and in any case within one month of the request. The term may be extended by a further two months if the request is complex or if we receive many: in that case we will tell you. To protect you we may ask you to verify your identity, for example by replying from the account’s email address. Exercising your rights is free of charge, except for manifestly unfounded or excessive requests.
If you believe the processing breaches the law you can lodge a complaint with a supervisory authority: in Italy the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome, https://www.garanteprivacy.it) or the authority of the European Union country where you live, work or where the alleged infringement took place. We ask you, if possible, to write to us first so that we can resolve the matter. If you are subject to the UAE PDPL you can exercise the rights it grants through the same channels.
11. What happens when you delete your account
Deletion from the app is immediate and irreversible: there is no review by staff. To confirm we ask for your password (and the verification code, if you turned on two-step verification). Staff accounts cannot be deleted from the app: write to support@mgquantumsystems.com.
- We delete: sessions, devices and notification tokens, invitation and reset links, recovery codes, sign-in history (also for the email you had used) and security events about you, notifications and preferences, exercise answers and journal, progress, attendance and enrolments.
- We anonymise the account: the email is replaced by an unusable placeholder address, password and two-step verification are removed, the name becomes “Utente eliminato”, phone and internal notes are removed. You will no longer be able to sign in.
- We keep, in pseudonymised form, the acceptances of the legal documents (version and date, without IP address, user agent and device, linked only to an internal identifier of a now anonymous account) as proof to defend our rights (Art. 17(3)(e)). The audit log entries generated by your actions remain until the 24 months expire, but without email, IP address and user agent; in email-change entries the old and new addresses are removed. Entries generated by staff actions on your account (for example a suspension or a change to an enrolment) also remain for up to 24 months; they may carry a reason written by staff but not your email.
- On the device: the app signs out of the account and removes the session token, the remembered email and the notification token.
- Backup copies: see section 9.
12. Data security
- Communications between the app or the browser and our servers are encrypted (HTTPS); traffic between our own services stays on the hosting provider’s private network.
- Passwords are stored only as strong cryptographic hashes and session tokens on the server only as hashes; the secret of two-step verification is encrypted.
- In the app the refresh token is kept in the system’s secure storage (Keychain on iOS, Keystore on Android), accessible only while the device is unlocked and not transferable to other devices; the access token stays in memory only and protected content is not saved on the device.
- Two-step verification is mandatory for staff and, when active on an account, is requested at sign-in; reuse of a session token causes the session to be revoked.
- Permissions are assigned by role, sensitive operations require the password to be confirmed again and relevant actions are recorded in a log protected against unauthorised changes.
- Audio is served encrypted and without providing the original files; content is kept in private storage, never public.
- Application logs contain no passwords, tokens or codes.
In case of a personal data breach that results in a risk to your rights and freedoms we will notify the competent authorities and, if the risk is high, we will also inform you, in the ways and within the times required by law.
13. Minimum age
The service is reserved for people who are at least 18 years old. We do not knowingly collect data of minors: if we find that an account belongs to a minor, we may suspend it and delete the data. If you think this has happened, please write to us.
14. Mandatory and optional data
To create and keep the account we need the data provided by the Academy (email and name) and the password: without them we cannot give you access. Some technical data (IP address, user agent, device data) is unavoidable to run and protect the service. Notifications, the email remembered on the device and adding live sessions to the calendar are optional; what you write in the exercises and the journal is up to you.
15. Changes to this policy
The version in force is always the one published on the website and in the app, with its date and version number. In case of substantial changes, for example new purposes, new recipients or new retention periods, we ask you to acknowledge them in the app before you continue to use it.
16. Contacts
Allinners LLC, a company registered in Sharjah Media City, United Arab Emirates (Office 10, Level 1, Sharjah Media City, Sharjah, UAE — PO Box 487177). Email for privacy and support: support@mgquantumsystems.com. Website: https://quantum-mind.mgquantumsystems.com.