Privacy Policy
Last updated: [DATE TO SET]
Quest is a private journaling app. This policy explains what data we process, why, where it is stored, and your rights. Our starting principle: you own your data — no ads, no reselling, ever.
1. Data controller
[LEGAL ENTITY], [ADDRESS]. Contact: ns@theresidency.io.
2. Data we process
- Account (optional): your email address. If you use “Sign in with Apple” or “with Google”, the identifier and email those providers share.
- Journal content: your entries (text), moods, optional location you attach, photos and audio you add, your quests, characters, and the links between them.
- Technical data: a device identifier used to coordinate sync, and authentication tokens.
- Diagnostics: pseudonymous crash and error reports (if enabled), to fix bugs.
3. Local use without an account
The app works fully offline, with no account. In that case your data stays on your device and is never sent to us. An account only exists to sync your journal across multiple devices.
4. Where and how it is stored
- On your device: a local database (SQLite), protected by the operating-system sandbox and an optional biometric lock.
- On our servers (if you have an account): a PostgreSQL database hosted in [REGION]; files (photos, audio) on object storage ([PROVIDER, e.g. AWS S3]). All traffic uses HTTPS.
5. Encryption — honest threat model
The text fields of your synced content are encrypted at rest on the server. However, that encryption uses a server-readable key: it is not end-to-end (E2E). This means we can technically access content to provide features such as account recovery and future optional AI features. End-to-end encryption is a goal for a later version (V1). We prefer to be honest about this rather than promise privacy the current implementation does not guarantee.
6. What we never do
- No advertising.
- No reselling of your data.
- No cross-app tracking, no ad profiling.
7. Retention and deletion
A deleted entry first goes to trash, then is permanently erased after 30 days. You can delete your account at any time in Settings → Account; this removes your server-side data.
8. Your rights
- Export: you can export your entire journal (Markdown / TXT / JSON) at any time, for free.
- Access, rectification, erasure, portability and objection under GDPR ([and applicable laws]).
- To exercise these rights: ns@theresidency.io. You may also contact your competent supervisory authority.
9. Sub-processors
- Hosting and object storage: [PROVIDER].
- Crash diagnostics: [e.g. Sentry], if enabled.
- Third-party sign-in: Apple, Google, when you choose those methods.
10. Minors
The app is not directed to people under [16].
11. Changes
If anything changes, we will update the date above and, where appropriate, notify you in the app.