Skip to main content
QbitHealth

Privacy Policy

Effective Date: To be set at publication

Last Updated: July 18, 2026 (Draft v1.3)

Applies to: qbit.health (web) and Qbit app on Pi Browser


Who We Are

Qbit is a healthcare analytics and education platform built by Kenneth Nguyen. Qbit helps students, researchers, and healthcare professionals learn from real hospital data using AI-powered analysis tools.

Our platform is available in two forms: a web application at qbit.health and an app accessible through Pi Browser. This policy covers both.

Contact for privacy questions: privacy@qbit.health


What We Collect and Why

We collect only the data necessary to provide our platform's features. We do not sell, share, or disclose your personal data to third parties.

Account Information

Qbit uses Pi Network as its only sign-in method. We do not operate email-and-password accounts, so we never collect, store, or ask you for a password, and we do not send password-reset emails.

Your Pi Network username reaches us directly from Pi's SDK when you sign in — you do not type it in and we do not ask you to self-report it.

When you use Qbit through Pi Browser, Pi Network's SDK provides us with your Pi User ID and Pi username. Your Pi User ID is a pseudonymous identifier — it does not contain your name, email, or other personal details. We use it to link your Qbit account to your Pi identity so your saved work carries across sessions.

When you first log in through Pi Browser, we ask for your explicit consent before linking your Pi identity to your Qbit account. If you decline, we do not create an account and you are not signed in — because Pi is our only sign-in method, there is no email-based alternative to fall back to. Declining leaves you with no account and no data stored with us.

We check your KYC verification status through Pi's SDK when you log in to determine payment eligibility, but we do not store your KYC status or any KYC documents. Your Pi session token exists only in your device's memory during your session and is never saved to our servers.

Healthcare Analytics Data

When you use Qbit's analysis tools, we store your questions and the results the system generates. These are your work product — you created them, and they belong to you. We store them so you can return to your analyses later.

Your healthcare queries and analysis results are private to your account. They are not visible to other users, not used to build profiles or recommendations, and not shared with anyone.

The hospital data you analyze through Qbit comes from publicly available datasets published by the US Centers for Medicare & Medicaid Services (CMS). This is aggregate, hospital-level data — not individual patient records. We do not collect or process personal health information as defined under Ontario's Personal Health Information Protection Act (PHIPA).

Payment Information (Pi Browser Users)

If you purchase credits through Pi Browser, we record the transaction: a payment ID, the amount in Pi, and the payment status. These records are necessary for credit allocation and financial record-keeping under Canadian tax law.

We do not access your Pi wallet balance, private keys, or transaction history with other apps. Our credit system tracks service entitlements within Qbit — it is not a wallet and does not hold Pi on your behalf.

Refunds: Qbit does not process refunds for completed Pi payments. If a technical issue prevents credit delivery after a successful payment, contact support@qbit.health and we will manually credit your account. We retain payment records for 7 years per Canadian financial record-keeping requirements regardless of any dispute resolution.

What We Do Not Collect

We do not collect your IP address at the application level, your physical location, your device fingerprint, your browsing history on our site, or any health insurance or personal medical information. We do not use tracking cookies, analytics pixels, or third-party advertising tools — in fact, Qbit sets no cookies at all, not even for signing you in. See Cookies and Local Storage below for exactly what does and does not live on your device.


How Long We Keep Your Data

DataRetention Period
Account informationAs long as your account is active. When you delete your account it is deactivated immediately and permanently removed after a short retention window.
Saved analyses and resultsAs long as your account is active. You can delete individual analyses at any time.
Pi payment records7 years from transaction date, per Canadian financial record-keeping requirements.
Session tokensHeld in your device's memory only, for as long as the page stays open. Never written to a cookie or browser storage; discarded when you close or reload the tab.
Error logs (no personal data)30–90 days.

Your Rights

Access Your Data

You can request a copy of all personal data we hold about you by emailing privacy@qbit.health. We will respond within 30 days. We are building a self-service data export feature for a future release.

Correct Your Data

Your Qbit profile holds no email address and no password — Pi is our only sign-in method, so there is nothing of that kind for you to correct. Your Pi username reaches us from Pi Network's SDK and is refreshed each time you sign in, so it always reflects your current Pi account. If anything else we hold about you is inaccurate, email privacy@qbit.health and we will correct it.

Delete Your Data

You can delete your account at any time from your account settings, or by emailing privacy@qbit.health. When you delete your account, it is deactivated immediately and you are signed out; your personal information and saved analyses are then permanently removed after a short retention window. This cannot be undone. Pi payment records are retained for the legally required 7-year period but are disassociated from your identity.

Removing Your Pi Identity

Pi Network is your only sign-in method, so there is no separate way to “unlink” Pi while keeping your account — without your Pi identity there would be no way to sign in. Removing your Pi identity from Qbit therefore means deleting your account. To do that, see Delete Your Data above and delete your account from your account settings.

Raise a Concern

If you believe we are handling your data improperly, contact us at privacy@qbit.health. Kenneth Nguyen, the platform's founder, reviews all privacy complaints personally. You also have the right to file a complaint with the Office of the Privacy Commissioner of Canada.


How We Protect Your Data

We take the security of your data seriously. Our technical safeguards include:

  • Authentication via industry-standard JSON Web Tokens (JWT) with ES256 signing
  • All credentials stored using SecretStr patterns that prevent accidental exposure in logs or error messages
  • Structured logging with automatic PII redaction
  • Data stored in Canadian infrastructure (Azure Canada Central)
  • Rate limiting and bounded caches to prevent abuse
  • Non-root container execution in our server infrastructure
  • Automated security scanning in our development pipeline

Cookies and Local Storage

Qbit sets no cookies. Not for signing you in, not for analytics, not for advertising. We use no tracking pixels and no third-party analytics services.

How your sign-in works instead: your Pi session token is held only in your device's memory, for as long as the page stays open. It is never written to a cookie, to local storage, or to session storage. Closing or reloading the tab discards it, and you sign in through Pi again. This is a deliberate design choice: a token that is never written down cannot be read back off your device by another site or left behind on a shared computer.

What we do store on your device: two things, neither of which identifies you and neither of which ever reaches our servers. Your display preferences — your chosen theme and whether you use dark mode — are saved in your browser's local storage so the site looks the way you left it. A single counter is kept in session storage so an introductory animation does not replay as you move around the Explore page; it is discarded when you close the tab. You can clear both at any time through your browser's settings.


Children's Privacy

Qbit is designed for healthcare students, researchers, and professionals. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact us at privacy@qbit.health and we will delete it.


Future: Health Data Contribution Program

Qbit is designing a voluntary health data contribution program for future phases of the platform. This program is not active today. When it launches, it will operate under a tiered consent model where each level of data sharing requires separate, explicit enrollment.

We will update this privacy policy with full details before the program becomes available, and participation will never be required to use Qbit's core features.


Changes to This Policy

If we make material changes to this policy, we will notify you through an in-app notice at least 14 days before the changes take effect.


Contact

Kenneth Nguyen

Qbit Platform

Privacy questions: privacy@qbit.health

This privacy policy applies to Qbit V2.0. The platform is currently in development and not yet publicly available. This policy will be published at qbit.health/privacy when the platform launches.