Last updated: June 29, 2026
Deducr ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application, web application, and related services (collectively, the "Service"). Please read this policy carefully. If you disagree with its terms, please discontinue use of the Service.
Qityol is built on a privacy-first architecture. The following sections describe the technical safeguards that protect your identity at every layer of our system.
Qityol employs a zero-knowledge identity masking system. When you create an account, your real email address is immediately replaced with a randomly generated anonymous identifier in our user directory. This anonymous identifier has no connection to your real email and cannot be reversed.
This means our user directory never contains your real email address. Even Qityol team members with database access see only anonymous, meaningless identifiers — never personal emails.
Your real email address is stored exclusively in a hardware-secured encrypted vault protected by AES-256-GCM encryption — the same standard trusted by banks, governments, and military organizations worldwide. Key safeguards include:
When Qityol needs to send you a service email (password reset, verification code, or account notification), our Mail Relay operates as follows:
Your real email exists in readable form only for the fraction of a second required to send the message.
In the unlikely event of a data breach, an attacker would find:
| Data Layer | What They See |
|---|---|
| User Directory | Random anonymous identifiers — no real emails |
| Encrypted Storage | Military-grade encrypted data — unreadable without hardware-managed keys |
| Application Logs | Anonymous identifiers only — real emails are never logged |
| Audit Records | Timestamps and anonymous IDs — no personal information |
The result: A full data breach yields zero personally identifiable email addresses.