Quest

Privacy Policy

Last updated: [DATE TO SET]

Draft — pending legal review before publication. Bracketed items ([…]) must be filled in (legal entity, address, jurisdiction, sub-processors, date).

Quest is a private journaling app. This policy explains what data we process, why, where it is stored, and your rights. Our starting principle: you own your data — no ads, no reselling, ever.

1. Data controller

[LEGAL ENTITY], [ADDRESS]. Contact: ns@theresidency.io.

2. Data we process

3. Local use without an account

The app works fully offline, with no account. In that case your data stays on your device and is never sent to us. An account only exists to sync your journal across multiple devices.

4. Where and how it is stored

5. Encryption — honest threat model

The text fields of your synced content are encrypted at rest on the server. However, that encryption uses a server-readable key: it is not end-to-end (E2E). This means we can technically access content to provide features such as account recovery and future optional AI features. End-to-end encryption is a goal for a later version (V1). We prefer to be honest about this rather than promise privacy the current implementation does not guarantee.

6. What we never do

7. Retention and deletion

A deleted entry first goes to trash, then is permanently erased after 30 days. You can delete your account at any time in Settings → Account; this removes your server-side data.

8. Your rights

9. Sub-processors

10. Minors

The app is not directed to people under [16].

11. Changes

If anything changes, we will update the date above and, where appropriate, notify you in the app.