Organizational publisher with no invented personal credentials.
We keep data flows clear and as short as possible
This policy explains what information is processed when you visit bytequant.org and how the in-browser tools work. In the current version, tool inputs are not sent to ByteQuant servers.
See the publisher, method, and correction route at a glance
Method, examples, errors, and acceptance checks are reviewed before release.
Reports arrive by email; confirmed fixes link tests and Git history.
1. Scope, controller, and contact
This policy covers the ByteQuant site, tools, guides, and contact channels. ByteQuant is the controller for this service. Privacy questions and data-subject requests can be sent to [email protected]; only identity and request information needed to answer a request is collected.
Tool input is not transferred to ByteQuant and cannot be centrally accessed. If you contact us by email, the contact details and message you provide are processed to answer the request and retain necessary records.
2. Tool input, Local Agent, installable app, and browser processing
Prompt, text, JSON, CSV, Regex, password, image, PDF, and similar inputs are processed in your browser. They are not sent to ByteQuant servers, linked to an account, or stored in localStorage by default. Refreshing or closing the page removes active-session input.
Local Agent offers two local modes. Fast mode uses multilingual semantic rules. On WebGPU devices, and only after you opt in, Apache-2.0 Qwen3 model assets are downloaded from the open-source Hugging Face and MLC distribution endpoints and retained in browser cache. Your goal and chat text are not added to those download requests, and no remote LLM or AI inference API is called. Generative inference runs on-device in a separate Web Worker. The runtime accepts only the reviewed WebLLM version and model/WASM URLs; HTTPS and those distribution hosts remain the first-download trust boundary, and ByteQuant does not claim complete SRI coverage for every model weight. Fast mode remains available without a download, and clearing site data removes the cached model.
The plan and latest twelve conversation summaries stay in the open tab's sessionStorage. Voice input activates only after the browser verifies on-device processing and never falls back to remote recognition.
Adding ByteQuant to a home screen or desktop is a browser feature that opens the site in its own window; it is not a separately downloaded Android APK. If an old-Android warning appears, cancel, update the browser, remove the stale ByteQuant shortcut, and reinstall from the current browser menu.
Copying or downloading creates a new copy on your device. Temporary object URLs used during image/PDF conversion stay in tab memory and are released when a result is cleared or the tab closes. Clipboard history and downloaded files on shared devices remain under your control.
2A. Workstation, encrypted projects, P2P, and recipe links
Projects you explicitly save in Workstation stay in the bytequant-workspaces IndexedDB database. Project documents are encrypted with AES-GCM-256 and a non-extractable device key stored in the same database. ByteQuant cannot remotely access the key or project. This protection does not make a compromised device, malicious extension, or hostile same-origin code safe.
During tool navigation, bytequant:workstation-active:v1, bytequant:workstation-handoff:v1, and the explicitly selected Agent goal in bytequant:workstation-agent-goal:v1 provide temporary bounded same-tab handoff and are cleared on return. File selection, password fields, code execution, and downloads are never automated.
Serverless collaboration uses WebRTC DataChannel and browser DTLS, with no ByteQuant signaling server, STUN, or TURN. Single-use invitation and answer codes expire after 10 minutes and can contain connectivity candidates. Live sharing is off by default and cannot start until both people compare the same safety code through a separate channel. The code helps detect an active intermediary but is not real-world identity verification. NAT, firewalls, or browser policy may still prevent a connection.
Recipe links always exclude output and exclude input by default. If you opt in to include input, that data becomes visible in the URL, browser history, clipboard, messaging service, and recipient's device. Never include sensitive, personal, or confidential data in a recipe URL.
3. Cookies, local storage, and consent
ByteQuant uses no analytics SDK. bq-consent-v1 remembers the on-device personalization choice for 180 days, while bq-theme delivers the color theme you explicitly request. The Google AdSense tag loads for advertising and Google may process online identifiers or cookies; advertising consent is separate from this local-personalization record.
bq-tool-usage-v1 and bq-tool-favorites-v1 activate only after consent. They contain tool slugs, counts, last-use time, or pinned tool IDs—never input, files, passwords, or output. Withdrawing consent deletes both records.
Cross-tool output handoff stays in bytequant:tool-transfer:v1 in the same tab for at most 20 minutes. Local Agent conversation context and Workstation plan handoff also use sessionStorage only and end with the tab session.
3A. Project activity, global community, and updates feed
The home-page project-health card is static and makes no GitHub API request. Opening workflow or commit-history links visits GitHub, which may process ordinary connection data under its own policy. No tool input, favorites, or usage counts are transferred.
Global Community connects to selected third-party relays over the open Nostr protocol only after you choose Connect global feed. A relay operator may process your IP address, connection time, and public signed profile and posts under its policy. ByteQuant operates no relay and cannot control network-wide retention or moderation. Your profile secret is stored in localStorage as AES-GCM ciphertext, protected by a key derived from your device passphrase with PBKDF2-SHA-256; the public key, display name, and biography are public by design. The secret is wiped from active memory after 15 minutes of inactivity or when the tab is hidden. A downloaded profile backup carries the private key only as ciphertext. ByteQuant cannot recover a lost passphrase or identity.
Global posts, replies, likes, and reposts can remain public after relays accept them, and removing every copy may be impossible. Do not publish personal data, secrets, or infringing material. Event signatures, time/size bounds, the on-device abuse-secret-spam filter, rate limits, and block list are assistive controls, not network-wide moderation. The legacy device archive and safety-code P2P chat remain optional and are separate from the global feed.
At build time, Updates reads allowlisted official HTTPS feeds and shows titles, dates, source links, and no more than 24 words of a feed description. Invalid or future dates, duplicates, URL-bearing summaries, and suspicious spam patterns are rejected. When a description is absent, ByteQuant displays a clearly limited metadata note rather than inventing source reporting. Article bodies and images are not republished; saving stores only the card ID on this device.
4. Technical access logs and GitHub Pages
The site is designed for static hosting on GitHub Pages. Hosting and network providers may process standard connection records—IP address, timestamp, request path, and user agent—for security and delivery under their own policies. Tool input is not included in those requests.
Independent processing by GitHub, domain, or network providers is governed by their current privacy notices.
5. Advertising, analytics, and external links
Advertising areas are clearly separated from content and tool controls. The Google AdSense tag for publisher ca-pub-4158794981134847 loads on site pages. Google may process IP address, device/browser data, online identifiers, and cookies under its policies for delivery, frequency capping, security, and measurement. ByteQuant uses no analytics SDK and never sends tool input to advertising systems.
For the EEA, UK, and Switzerland, Google advertising requires a Google-certified CMP integrated with IAB TCF, where vendors, purposes, retention, and personalization choices must be disclosed. X and Instagram receive a request only if you follow their external links.
6. Legal bases, retention, and rights
Optional local personalization relies on GDPR Article 6(1)(a) consent, which can be withdrawn at any time. Contact requests are handled as pre-contract steps where relevant or under the legitimate interest in operating a secure and accessible service. Email records are kept for no more than 12 months after the last meaningful contact unless a legal duty or dispute requires longer.
Where applicable, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent by emailing [email protected], and may complain to a competent supervisory authority. Tool input is not retained on a server and therefore cannot be centrally accessed or erased.
7. International transfers, security, children, and changes
When the static site is delivered through GitHub Pages and network infrastructure, technical connection data may be processed outside the EEA. Where applicable, the provider's data-protection terms, standard contractual clauses, or other valid safeguards must be assessed. Tool input is not part of that transfer.
Static architecture and minimization reduce risk but cannot guarantee absolute security. The service is not directed specifically to children. Material policy or data-flow changes will be reflected in this page and consent interface before they take effect.