Privacy Policy
Last updated: 1 September 2026
Who we are and what this covers
Aperis is operated by Doviatech LLC, which is the data controller.
This policy covers aperis.io, the Aperis dashboard at app.aperis.io, and the Aperis API at api.aperis.io. It replaces a policy that covered only a single landing page and an email form.
What we collect
Your account. Your email address and a hash of your password. Your account belongs to a personal organisation, whose name is a neutral label and does not contain your address.
Keeping your account secure. Session tokens (stored only as hashes), a record of failed sign-in attempts against the address submitted, and the IP address of requests to our sign-in endpoints, used to limit how often anyone can try.
Your work. The circuits you submit, the results returned, the devices you select, and the identifiers the provider assigns to your jobs. Job names and API key names are text you choose. We store what you type, so avoid putting personal information in them.
Your provider credentials. Encrypted with a key held in AWS KMS, and stored only in that form. We keep a short non-secret fragment so you can tell which key is which.
A record of what happened. An audit log of significant actions: signing in, creating or revoking an API key, storing or deleting credentials, submitting or cancelling a job. Each entry records the acting account, the action, and the time.
We do not use analytics, advertising or tracking of any kind, and we do not sell personal data.
If you do not have an account
This section exists because most people would not expect it.
When a sign-in attempt fails, we record the email address that was submitted. We do so whether or not any account exists for it. If you mistype your address, or someone else mistypes theirs and it happens to be yours, a short-lived record is created against an address with no account behind it.
We do this because it is the only way to limit repeated guessing at a specific address without revealing whether that address is registered. The record contains the address, a count, and timestamps. Nothing else. It is deleted automatically 24 hours after the last attempt, and you can ask us to delete it sooner.
Your circuits and results
A quantum circuit is often the substance of unpublished research, and we treat it that way.
We store it. Your circuit, its results and the job’s metadata are held in our database so the dashboard and API can show them to you.
We transmit it to the provider you chose, IonQ or Amazon Braket, using your own credentials. The job therefore runs on your account with that provider, under the agreement you hold with them directly. We are not a reseller standing between you and the hardware, and the provider’s own privacy terms apply to what reaches them.
One consequence to be plain about: if you ask us to delete your data, we delete our copy. We cannot delete the job from your provider’s systems, because it is on your account and not ours. Use that provider’s own controls for it. If you ask us to erase your data we will give you the provider’s own job identifiers first, so you can act on this.
Who else receives your data
| Recipient | What they receive | Where | Why |
|---|---|---|---|
| Amazon Web Services | Everything in our database, and the keys protecting your credentials | US East (N. Virginia) | Hosting and key management |
| Amazon Braket | The circuit, shot count and device you selected, submitted with your credentials | Depends on the device you choose (see below) | Running the job you asked for |
| IonQ | The same, when you select an IonQ device directly | Depends on the device you choose (see below) | Running the job you asked for |
| Resend | Your email address and the message body | Ireland (eu-west-1) | Account email, such as verification |
| Netlify | Ordinary web request data for aperis.io and app.aperis.io | Global edge network | Serving the site |
We use no analytics provider, no advertising network and no data broker.
Netlify also injects a script of its own into the pages it serves, which we did not add. See “Cookies and local storage” below.
Where your circuits go depends on the device you choose. Amazon Braket hardware is region-specific, and we submit your job to the region that hosts the device you selected. Today that is one of US East (N. Virginia), US West (N. California), US West (Oregon), Europe (Stockholm) or Europe (London). If the region your work is processed in matters to you, it is determined by the device you pick, and the device list shows which is which.
IonQ publishes a location for each device, and we report what they say. This policy previously said IonQ published nothing, and that was wrong. As of 1 September 2026 IonQ reports College Park, Maryland for most of its hardware, Basel, Switzerland for Forte Enterprise 1, and Distributed Cloud for the simulator. Where your circuit runs therefore depends on which IonQ device you select, exactly as it does for Amazon Braket. We report the provider’s own words and infer nothing beyond them.
The per-device answer is the authoritative one. IonQ can add or move hardware without telling us, so a list of countries in this policy would go stale the way the previous claim did. That is why we point at the device rather than at a list. We do not yet show the location beside each IonQ device in the app; until we do, IonQ’s own device listing is where to look. If the execution location is contractually important to you, confirm it with IonQ directly.
Where everything else is held. Aperis runs in Amazon Web Services’ US East (N. Virginia) region. If you are in the EU or the UK, your data is therefore processed in the United States. Doviatech LLC is a United States company, and this policy is written on the basis that we are the controller and that data reaches the US directly rather than being exported from an EU establishment.
Why we are allowed to hold it
- To provide the service you asked for (contract): your account, your credentials, your jobs and results, your API keys.
- To keep accounts secure (legitimate interest): failed sign-in records and rate-limit data, so that repeated guessing can be slowed. We consider this proportionate because the data is minimal, short-lived, and used for nothing else.
- To keep a record of significant actions (legitimate interest, and legal obligation where one applies): the audit log.
We rely on consent for nothing. Every basis above is contract or legitimate interest, so there is no consent for you to withdraw and no processing that stops if you withdraw one. This is stated rather than left as an absence: a policy that simply omits consent is indistinguishable from one that forgot it.
How long we keep it
| What | How long |
|---|---|
| Failed sign-in records | 24 hours after the last attempt |
| Rate-limit records | Swept hourly |
| Verification links | 24 hours, and single-use |
| Session tokens | Expired and revoked tokens are removed within the hour. A revoked token is kept for 7 days first, so that an attempt to reuse it can still be detected |
| Account, credentials, jobs and results | Until you delete them, or your account |
| Audit log | Retained after account deletion, with your identity removed |
| Backups | Database snapshots are kept for 30 days, then expire automatically |
Your rights, and what deletion actually does
You may ask us to access, correct, export or delete your personal data, or to object to processing based on legitimate interest. Write to support@aperis.io and we will respond within 30 days.
Deletion is performed by us on request rather than by a button in the product today. That is a real difference and we would rather state it than imply otherwise. We keep a record that an erasure was carried out, and that record contains no information identifying you.
What is deleted: your account and password, your session tokens and verification links, your provider credentials, your API keys, your jobs and their results, and any failed sign-in records for your address.
What is anonymised instead of deleted:
- The audit log. The entries stay; your identity is removed from them. They are the record of what happened on the platform and we are not willing to lose that. A technical identifier stays on the entries so that one actor’s remain grouped together. It resolves to nothing: once your account is gone, there is nothing left in the live service that connects it to you.
- Your personal organisation. The row itself survives, because the audit log cannot exist without it. Its name is a neutral label that does not contain your address, so nothing in it identifies you.
What we cannot delete: jobs on your provider’s systems, which are on your own account, and data already captured in backups, which expires on its own schedule. Rate-limit records are not deleted on request either. They are keyed by activity rather than by account, and expire within the hour.
If you share an organisation with other people, we will not delete it. An organisation that others work in is not yours alone to remove, and deleting it would take away their jobs, credentials and history along with yours. Transfer ownership to another member first; we will then erase your personal data and leave the organisation with them.
If you are the only member, the organisation goes with your account.
Cookies and local storage
aperis.io stores nothing on your device. No cookies, no local storage, and no analytics of ours.
The pages of this site ship no JavaScript. Our hosting provider, Netlify, injects one small script of its own into the pages it serves. We did not add it, we do not use it, we receive no data from it, and we have asked Netlify to remove it. We would rather describe it than let you find it in your browser and wonder why this page did not mention it.
The dashboard at app.aperis.io stores two things, both necessary for it to work and neither used for tracking:
- a session token, so you stay signed in;
- your theme preference, kept for the duration of your browser session and discarded when you close it. We store it only if you choose one; until you do, nothing about your appearance settings is read or kept.
We treat both as strictly necessary for a service you explicitly requested, so we do not ask for consent for them. We set nothing else: no analytics, no advertising, no third-party storage of any kind.
Contact, and complaints
support@aperis.io for any request under this policy, or any question about it.
If you are in the EU or UK and believe we have handled your data improperly, you may complain to your national supervisory authority, for example the CNIL in France or the ICO in the United Kingdom. You may do so without contacting us first.
Doviatech LLC
1331 Brickell Bay Dr, Suite 2708
Miami, FL 33131, USA