Privacy Policy
1. Who we are
QuestBourne is a personal goal-tracking app run by Ernests Pulks, an individual based in Latvia (European Union). For the purposes of the EU General Data Protection Regulation (GDPR), Ernests Pulks is the data controller for any personal data the app processes about you.
Contact: support@questbourne.app
2. Who can use the app
You must be at least 16 years old to use QuestBourne. We do not knowingly collect data from children under 16. If you believe a child has signed up, contact us and we will delete the account.
3. What we collect
Account data
- Email address (for sign-in, email verification, and password reset)
- Password, if you use one (stored only as a salted scrypt hash, never as plain text)
- If you use Sign in with Apple: the name and email Apple shares with us (this may be a private relay address), Apple's identifier for you, and a token we use only to disconnect the app from your Apple ID when you delete your account
- If you use Sign in with Google: the name and email Google shares with us, and Google's identifier for you
- When you accepted the Terms, and which version
Profile data (you provide)
- Username and @username (see section 11)
- Age and gender
- Height, only if you set a weight goal
- Your answers about where you are now in four life areas (Body, Mind, Money, Soul)
- Optional notes about yourself that help the app suit you: physical limits or injuries, how you learn and focus, your life situation, your financial situation, and dietary needs or allergies. Some of these may be sensitive; see section 6.
- Character choice (cosmetic), pace settings, time zone, and reminder time
Activity data (created as you use the app)
- Missions (goals) and sub-missions you create, including numbers you log for them, such as weight, savings, or distance
- Roadmaps and quests generated for you, and whether you completed or skipped them
- Answers and notes you write on quests, and questions you ask about a quest
- Weekly reflections you write, and how much energy you said you had that day
- A short summary of your goals and situation, written by the AI from the above, so later quests stay consistent
- Which days you opened the app, streaks, XP, and badges
- Your Tribe list, @username and friend code
- Feedback or bug reports you send from inside the app, with the app version and platform
- Your subscription status and trial dates
Device and technical data
- A push notification token from your phone, if you allow notifications
- Server logs: HTTP method, request path, status code, response time, timestamp. We do not log request or response bodies.
- On the website: a session cookie (connect.sid), strictly necessary to keep you signed in
- In the iPhone app: a sign-in token stored on your device, strictly necessary to keep you signed in
- On your device: display preferences, which tips you have dismissed, and your answer to the analytics question
- Product analytics (PostHog, see section 5): only if you tap Accept when the app asks. It then stores an anonymous ID on your device, in a cookie and in local storage, so your events can be counted together. If you tap Decline, or never answer, analytics does not run and nothing is stored. You can change your answer at any time with the Anonymous analytics switch in Settings; switching it off stops analytics and deletes the anonymous ID from your device.
- Error reports (Sentry, see section 5): sent when the app crashes, to fix bugs. They store nothing on your device.
4. How we use it
- To create and run your account, and to sign you in
- To generate your roadmaps, daily quests, lessons, and feedback using AI, based on your profile, goals, and recent activity
- To show your progress, streaks, and stats, and to show friends the summary described in section 11
- To send the daily reminder you asked for, at the time you chose
- To send verification and password-reset emails, and to reply to feedback you send
- To manage your subscription and make sure each email address gets one free trial
- To detect and fix errors, and to understand which features work
We do not sell your data. We do not use it for advertising. We do not share it with anyone except the service providers listed in section 5, or where the law requires us to.
5. Service providers (sub-processors)
We use a small number of third-party services to run the app. Each one only receives the data it needs for its job.
| Provider | What it does | Data location |
|---|---|---|
| Anthropic (Claude API) | Writes your roadmaps, quests, lessons, feedback, and answers. Receives your profile, the notes about yourself from section 3, your goals and logged numbers, recent activity, reflections, and what you write on quests. Does not receive your email or password. | United States. Anthropic may keep requests for up to 30 days for trust and safety, and does not use them to train its models. |
| Apple | Sign in with Apple, in-app payments, and delivering push notifications to your iPhone. | Apple's own locations, under Apple's privacy policy. |
| Sign in with Google, only if you choose it. Google confirms who you are and shares your name and email with us. | Google's own locations, under Google's privacy policy. | |
| RevenueCat | Checks and records your App Store subscription. Receives your anonymous user ID and your purchase records from Apple. Does not receive your email or anything you write. | United States. |
| Resend | Sends account emails (verification, password reset) and forwards feedback you send us. Receives your email address and, where relevant, your name or your feedback message. | European Union or United States, depending on routing. |
| Neon (PostgreSQL hosting) | Stores your account, profile, missions, quests, and all other app data. | United States (AWS us-east-1, Virginia). |
| Railway | Hosts the application server. | Region as configured in our Railway account. |
| Cloudflare Turnstile | On our website only: checks that a sign-up or password-reset request comes from a person, not a bot. Receives technical data from your browser. | Global network. |
| Sentry | When switched on, captures crashes and errors so we can fix bugs. Configured not to send IP addresses or other personal data by default. | European Union (Frankfurt, Germany). |
| PostHog | Records a small set of product events: signup, onboarding complete, mission created, quest completed, subscription started. Identifies you only by an anonymous user ID. Does not record page views, click-trails, or session replays. Does not receive your email or anything you write. | European Union. |
Where data is transferred outside the European Economic Area (EEA), we rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses, as offered in each provider's data processing agreement.
6. Sensitive information
Some things you may choose to tell the app can be sensitive under GDPR Article 9: for example injuries or physical limits, weight and height, a health or learning condition such as ADHD, a hard life event, or a diet linked to your health or religion. All of these are optional.
We use them for one purpose only: so the AI can suggest quests that fit you and avoid ones that do not. By choosing to enter this information and save it, you give us your explicit consent to process it for that purpose, including sending it to Anthropic as described in section 5. You can change or clear any of it at any time in the app, and it is deleted with your account. Withdrawing consent does not affect processing that already happened.
7. Legal bases (GDPR Articles 6 and 9)
- Performance of a contract (Art. 6(1)(b)) - to create your account, run your missions, generate your quests, send the reminders you asked for, show friends your summary, and manage your subscription.
- Legitimate interests (Art. 6(1)(f)) - to keep the app working and secure (error tracking, bot checks, server logs), to improve it (product analytics with the privacy settings described above), and to prevent the free trial being claimed repeatedly (see section 9). You can object to this processing by emailing us.
- Consent (Art. 6(1)(a) and Art. 9(2)(a)) - to process the sensitive information in section 6, and to send push notifications.
- Legal obligation (Art. 6(1)(c)) - to keep limited records where the law requires.
8. Automated processing and AI
Your roadmaps and daily quests are written by an AI model (Claude by Anthropic). It sees your profile, your goals, the notes about yourself you chose to add, your recent activity, and your recent reflections. It writes a plan and we save the result.
No legal or similarly significant decisions are made about you by automated processing under GDPR Article 22. Your quests are suggestions; you choose whether to do them, and you can always skip or swap them.
9. How long we keep your data
- Account, profile, missions, quests, reflections, friends, device tokens: for as long as your account exists. When you delete your account, they are removed from our database straight away, and from backups within 30 days.
- Free trial record: to make sure each email address gets one free trial, we keep a one-way, secret-keyed fingerprint of your email address and the date your trial ended, even after you delete your account. It cannot be turned back into your email address and is not linked to anything else about you.
- Feedback you send us: kept until we have dealt with it. Email us if you want it deleted sooner.
- Sign-in: website session cookie and app sign-in token, 7 days from when they are issued, or until you sign out.
- Password reset links: 1 hour. Email verification links: 24 hours.
- Server logs: a short rolling window at our hosting provider (Railway) for debugging.
- Error reports (Sentry): per Sentry's default retention (typically 90 days).
- Product events (PostHog): per PostHog's default retention.
- Anthropic requests: up to 30 days, as part of Anthropic's standard trust-and-safety retention.
- Subscription records: Apple and RevenueCat keep purchase records under their own policies and tax law.
10. Your rights
Under GDPR you have the right to:
- Access your personal data (Art. 15)
- Correct inaccurate data (Art. 16) - most things are editable in the app; for anything else, email us
- Erase your data (Art. 17) - use Settings → Delete Account, which removes your account and all linked data from our database and disconnects Sign in with Apple
- Restrict or object to certain processing (Art. 18, 21)
- Data portability (Art. 20) - download your data from Settings on our website, or email us and we will send you a copy in a machine-readable format
- Withdraw consent at any time, where processing is based on consent - for example by clearing the notes in section 6 or turning notifications off
- Lodge a complaint with your local supervisory authority. The Latvian authority is Datu valsts inspekcija (dvi.gov.lv).
We answer requests within one month.
11. Friends
Everyone gets an @username. Other users can find you by searching it, or through your invite link, and add you to their Tribe. When someone adds you, we tell you, and you can add them back. Anyone who has added you can see your username, @username, character, streaks, quest and XP counts, and badge count. We never show them your email, name, goals, quests, notes, or anything you write. Removing someone takes them off your own Tribe. You can make your profile private in Settings, so nobody can find you in search or add you by @username; your invite link still works. You can block anyone: they leave your Tribe and can no longer see, find or add you, and they are not told. You can unblock them in Settings. You can also report a username; we keep the report with your account id so we can check it and remove the account if it breaks the rules. Deleting your account removes you from everyone's.
12. Security
Data travels over encrypted connections (HTTPS). Passwords and sign-in tokens are stored only as one-way hashes. No system is perfectly secure; if a breach affects your data, we will tell you and the authority as the law requires.
13. Children
QuestBourne is not intended for anyone under 16. We do not knowingly process data from children. If you believe we hold data about a child, contact us and we will delete it.
14. Changes to this policy
If we make material changes to how we handle your data, we will tell you in the app or by email. The "Last updated" date at the top of this page shows when this version was published.
15. Contact
Questions, requests, or complaints about your data: support@questbourne.app