Privacy Policy
Effective date: August 18, 2026
Overview
This policy covers QSEL Enterprise websites and services and the QSEL Authenticator mobile application. QSEL Authenticator is a non-custodial security app: it approves logins and signs wallet actions on your device. Your private keys are generated on your device, stay on your device, and are never transmitted to us or anyone else. We do not run third-party analytics or advertising SDKs in the app.
What the App Accesses, and Why
- Camera. Used only to scan QR codes for login approvals and wallet pairing. Images are processed on-device in real time; no photos or video are stored, and nothing from the camera is uploaded.
- Biometrics (fingerprint / face unlock). Used to unlock the app and to approve individual security actions. Biometric matching happens entirely inside your device's secure hardware (Android Keystore / StrongBox). We never receive, store, or transmit biometric data — the app only learns "approved" or "not approved."
- Internet. Used to communicate with QSEL servers over HTTPS to deliver login requests, session approvals, and on-chain transaction requests for your review.
Information We Process
- Public blockchain identifiers. Wallet addresses, public keys, and on-chain account identifiers (including compressed NFTs that represent sessions, pairings, and guardians). These are public by nature and are used solely to provide app functionality. They are not sold or shared for marketing.
- Session and approval records. When you approve or deny a login or transaction, we process the request metadata (site, time, approval result) to complete the flow and protect your account.
- Device-local secrets. Encryption keys and pairing material are stored encrypted on your device (AES-256-GCM, NaCl box, and post-quantum KEM). We cannot read them. Uninstalling the app destroys them.
We do not collect your location, contacts, SMS, photos, or browsing history. We do not sell personal data. We do not serve ads.
Security
All network traffic uses HTTPS (TLS). Sensitive material is encrypted at rest on your device and, where applicable, in transit with end-to-end encryption (AES-256-GCM and post-quantum key encapsulation). The app refuses cleartext connections and only trusts system certificate authorities.
Data Retention & Your Choices
- Revoking a session or pairing in the app invalidates it immediately, including burning the associated on-chain record where applicable.
- Uninstalling the app permanently destroys the device-local keys. Blockchain records are public and immutable by design and cannot be deleted by anyone.
- To ask questions or request deletion of server-side records associated with your wallet address, contact us at the address below.
Changes & Contact
We will update this page when the policy changes and revise the effective date above. Questions and privacy requests: privacy@qselenterprise.com.