Privacy Policy
How we collect, use, and protect your information.
Last updated: September 29, 2026 · Version 1.2
Effective date: September 29, 2026 · Version: 1.2 · Previous versions: available on request at nothingserious.team@gmail.com
1. Who we are and what this Policy covers
1.1 This Privacy Policy describes how Nothing Serious LLC, a Delaware limited liability company with its principal place of business in New York, New York ("Nothing Serious," "we," "us"), collects, uses, shares, and protects personal information when you use the Quests apps for iOS and Android, the Quests web app, and thequestsapp.com (together, the "Service").
1.2 Contact. Email nothingserious.team@gmail.com · Mail: Nothing Serious LLC, 2810 North Church Street #457193, Wilmington, DE 19802 · In-app: Settings → Support → Send Feedback · Web: thequestsapp.com/contact.
1.3 Related documents. Our Terms of Service govern your use of the Service. Our Consumer Health Data Privacy Policy is a separate document required by Washington, Nevada, and Connecticut law that describes how we handle information that could identify your health status; where it and this Policy overlap, that document controls for consumer health data.
2. Age
2.1 During our initial rollout, Quests is intended for adults who live in the United States, so that we can manage reward shipping and other operations; users must be at least 13 years old. Users between 13 and 17 may use Quests with a parent or guardian's permission. Purchases and reward redemption are limited to users 18 or older. When you create an account you confirm that you meet these requirements.
2.2 We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will close the account and delete the information, except where the law requires us to keep it. If you believe a child under 13 is using Quests, email nothingserious.team@gmail.com.
2.3 Where Apple or Google provides an age signal for your account (for example, under Texas law), we use it only to confirm eligibility and for legal compliance and safety, and then delete it.
3. Information we collect
3.1 Information you give us
- Account: mobile phone number (used to sign in), display name, and an optional profile photo and short bio.
- Photos: photos you choose to attach to your profile, quests, or check-ins, if you allow the app to use your camera or photo library.
- Age confirmation: your confirmation at sign-up that you meet the age requirements in Section 2.1.
- Quests and check-ins: the quests you create or join, their titles, descriptions, and categories, your check-ins and notes, streaks, and reactions and comments. If you organize a community quest, the settings you choose.
- Rewards: when you redeem a reward we may ask for an email address (to deliver confirmations and, where we offer gift-card rewards, gift-card codes), a shipping name and address (for merchandise), and, if reward values reach a reporting level, tax information such as a Form W-9.
- Support and correspondence: what you send us when you contact us, report content, appeal a decision, or exercise a privacy right.
- Marketing preferences: whether you have opted in to marketing texts or unsubscribed from marketing email.
3.2 Information collected automatically
- Device and app data: device model and operating system, app version, language and time zone, a device identifier we generate, push-notification token, IP address, and crash and performance diagnostics.
- Usage data: which screens and features you use, when you open the app, and interactions such as taps and scrolls, collected so we can understand and improve the Service.
- Attribution information: on iOS, we do not ask for permission to track you or collect the advertising identifier (IDFA); install attribution uses Apple's SKAdNetwork for aggregate campaign results. Android version 3.0.1 (build 21) does not collect the Google advertising ID. It uses Google Play Install Referrer information and a restricted Singular integration to measure installations and a limited set of events (Section 5.3). This may include app/device attribution identifiers, IP address, basic device information, and event timestamps. Our website uses no advertising identifiers (Section 11).
3.3 Information from other sources
- App stores: purchase and subscription receipts, and age-range or parental-consent signals where a platform provides them.
- Payment and billing providers: confirmation of payments and subscription status. We never receive or store your full card number.
- Attribution partners: which ad or link brought you to Quests (Section 5.3).
- Other users: for example, when someone adds you to a quest or mentions you.
3.4 Contacts and invitations
Contacts are optional. You can use Quests without giving it access to your contacts. If you allow access, the app reads the phone numbers and names in your address book on your device to show you whom you can invite and which of your contacts already use Quests.
Contact sync. When contact syncing is on, the app converts each phone number in your address book into a hash (a coded form of the number) on your device and sends those hashes to our servers, where they are stored securely with your account and compared with the hashed phone numbers of Quests members. While syncing is on, the app sends hashes of new numbers from time to time, for example when you open it. We use the hashes only to show you which of your contacts use Quests, to help you invite the ones who don't, and to tell you when one of your contacts joins Quests. We treat these hashes as personal information. We do not upload or store the names in your address book, and your contact information is never sold or sent to advertising or attribution partners (Section 5.3). Earlier versions of the app (2.x) may send the phone numbers and names themselves; our server converts each number into a hash when it arrives and discards the original number and the name before anything is stored.
Your choices. Newer versions of the app ask you to turn on Contact sync before any contact information leaves your device. You can turn it off at any time with the Contact sync switch in Settings, which stops syncing and deletes the contact hashes we hold for you. In app versions without that switch, syncing runs whenever contacts access is allowed: turn off contacts access in your device settings to stop it, and email nothingserious.team@gmail.com to have the hashes we hold deleted. Turning off contacts access in your device settings stops new syncing but does not delete hashes already stored.
How long we keep them. Hashes that match a Quests member are kept while contact syncing is on. Hashes that match no member are deleted 6 months after they were first synced. All of your contact hashes are deleted when you turn off Contact sync, ask us to delete them, or delete your account.
If you don't use Quests. If someone who uses Quests has your phone number in their contacts and syncs them, we may hold a hash of your number stored with their account. We use it only to tell that person if you join Quests and, once you join, to show them that you are on Quests (Section 5.1). If you have not joined, it is deleted 6 months after it was synced, or sooner if that person turns off Contact sync or deletes their account. We never use it to contact you. To have hashes of your number deleted sooner, email nothingserious.team@gmail.com with the number; we will convert it the same way to find and delete matching entries.
Invitations. You send invitations yourself, from your own device, through your phone's share sheet or messaging app. Android version 3.0.1 may also transmit selected recipient phone numbers when saving a community-quest draft. Our server removes that recipient-number field before storing the draft. Address-book names are not uploaded with the draft. Your own account phone number is stored separately so you can sign in and receive verification codes.
Older versions of the app could send an invitation text on your behalf, from a Quests phone number, to a contact you selected. We retired that feature for all app versions on September 28, 2026. While it was in use, we stored the invited phone number for up to 14 days so that, if the person joined, we could add them to the quest; we deleted all remaining invited numbers on September 28, 2026, and we no longer store them.
If you are not a Quests user and received an invitation text from a Quests number, we no longer hold your phone number for that invitation. Write to nothingserious.team@gmail.com with any question about it.
3.5 Habit data can be health-related
Some quests are about exercise, sleep, food, mood, medication, sobriety, or other things that can reveal information about your physical or mental health. When you do those quests, the quest content and your check-ins are health-related information. Section 6 and our separate Consumer Health Data Privacy Policy describe how we treat it. We do not integrate with Apple Health or Google Health Connect at this time; if we add that, we will ask for your permission first and will never send that data to any advertising or analytics partner.
3.6 What we do not collect
We do not collect precise geolocation. We do not store the names in your address book, and current versions of the app do not send them (Section 3.4). We do not collect biometric identifiers. We do not collect government identification numbers except a taxpayer identification number on a Form W-9 when the law requires it (Section 3.1).
4. How we use information
We use personal information to:
- Run the Service, create and secure your account, verify your phone number, deliver quests, track check-ins and streaks, show your activity to the people you share it with, and provide support.
- Operate the Points program, credit and verify Points, detect fraud, fulfill rewards, and keep the records the program requires (Section 16).
- Bill you, process Quests Pro subscriptions and in-app purchases, send receipts, renewal reminders, and price-change notices, and keep records of your consent to subscription terms.
- Generate quest content, send limited, non-identifying prompts to our AI provider to generate and safety-screen quest text (Section 15).
- Communicate, send service messages (verification codes, security alerts, receipts, changes to terms) and, with your separate consent, marketing messages (Section 17).
- Improve and secure the Service, analyze usage, fix bugs, prevent abuse, and protect users.
- Measure acquisition and advertising, use limited installation, session, registration, subscription, revenue, and invitation events to understand which campaigns and links bring people to Quests, through the platform-specific arrangements in Section 5.3.
- Comply with law, respond to legal requests, keep tax and sanctions records, and enforce our Terms.
De-identified and aggregated data. We may create de-identified or aggregated data from personal information (for example, how many people completed a quest this week) and use it for any purpose. We keep that data in a form that cannot reasonably be linked to you, we commit not to try to re-identify it, and we require anyone we give it to to make the same commitment.
Annex A lists each category of information, the purposes we use it for, and who receives it.
We do not use your information to make decisions that produce legal or similarly significant effects about you, and we do not build health profiles about you for advertising.
5. Who we share information with
5.1 Other users
Your display name, profile photo, bio, and the activity in quests you share are visible to the people in those quests, and, if you choose a public profile, to other Quests users. You control sharing settings in the app. Check-in notes are visible to the members of the quest you post them in.
Share links. If you share a quest or your profile using a Quests link, anyone who opens that link, including people who are not Quests users, sees a preview page showing the quest name and your display name and profile photo and, for a profile link, your Points total and current streak. Share links only with people you want to see that.
Finding you by phone number. When you create an account, people who already have your phone number in their synced contacts may get a notification that you joined Quests. After that, people who have your phone number in their contacts can see that you are on Quests and send you a friend request, unless you turn that off in the app's privacy settings.
5.2 Service providers (processors)
We use companies that process information on our behalf, under contracts that limit what they can do with it and require them to protect it. Annex B lists them by category. They include our hosting and database provider, our text-message provider, our push-notification delivery service, our error-monitoring provider, Singular for attribution measurement as described in Section 5.3, our payment and subscription-billing providers, our email provider, our merchandise printer and shipper, our gift-card provider, and the AI services that generate quest text and screen posts. These providers may not use your information for their own purposes. Every company that receives personal information from us is bound by contract to protect it with at least the same level of protection described in this Privacy Policy and required by the App Store Review Guidelines.
5.3 Advertising and attribution partners: exactly what we send
Singular. We use Singular to measure installations and limited conversion events, including registrations, invitations, subscriptions, and revenue. Singular processes app-user information on our behalf under its Data Processing Addendum. Its privacy policy describes its handling of platform information and service providers.
Android version 3.0.1 (build 21). We use Google Play Install Referrer information and Singular's restricted SDK with limited data sharing enabled. The app does not collect the Google advertising ID or send a Quests account ID to Singular. The information used for measurement may include installation and session information, the conversion events above, product and price or revenue details, app/device attribution identifiers, IP address, basic device information, and timestamps. Our current Android configuration does not enable onward event reporting to advertising networks.
iOS and advertising networks. iOS install attribution uses Apple's SKAdNetwork, which gives advertisers campaign results only in aggregate, and the app does not collect IDFA. We do not send device-level installation, session, or event information about iOS users to advertising networks.
Information excluded from attribution events. We do not send quest content or categories, check-ins or notes, streaks, wellness behavior or health status, phone numbers, names, or contacts to Singular or advertising networks. Our custom conversion events are limited to a reviewed list. The Singular SDK also processes the installation and session information needed for attribution.
Your choices. To request an advertising or attribution opt-out, email nothingserious.team@gmail.com with the subject "Advertising opt-out." We handle requests using the privacy-request process in Section 12 and work with the relevant providers to apply available restrictions and deletion controls. Android build 21 does not use the advertising ID, and iOS does not use IDFA. We will update this section if these arrangements change.
5.4 Reward partners
- Merchandise: we send your name and shipping address to our print-on-demand provider so it can produce and ship the item.
- Gift cards (where offered): we send the reward type to our gift-card provider; we deliver the code to you. The brand that issued the card receives no information from us about you unless you redeem the card with the brand.
- Charities: we send donations in aggregate. We do not share your identity with charities.
5.5 Legal, safety, and enforcement
We share information when we believe in good faith it is necessary to comply with a law, regulation, subpoena, or government request; to enforce our Terms; to investigate fraud or security issues; or to protect the rights, property, or safety of anyone.
5.6 Business transfers
If Nothing Serious is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
5.7 We do not sell personal information
We do not sell personal information for money, and we do not sell sensitive personal information (including health-related information) to anyone. Section 13 explains how state laws that define "sale" and "share" more broadly apply to the advertising measurement described in Section 5.3.
5.8 Charities
We do not share your personal information with charities. For charity quests, we keep participation counts so we can calculate and document the donations we make.
6. Health-related information
6.1 Because Quests is a wellness app, some of the information you give us, quest content, categories, check-ins, and streaks for health-related habits, may identify your past, present, or future physical or mental health status.
6.2 Our rules for it. We collect it only to deliver the quests you chose, to run the Points program, and to keep you safe (Section 4). We never send it to advertising, attribution, or analytics partners. We never sell it. Our service providers may process it only to provide their service to us. We do not use it to infer health conditions about you.
6.3 Consent. Where the law requires it, we ask for your separate, opt-in consent before collecting health-related information beyond what is needed to deliver the quest you chose, and separately again before sharing it with anyone other than a service provider, which we do not currently do. Consent is never bundled into accepting the Terms of Service.
6.4 The separate policy. Our Consumer Health Data Privacy Policy (thequestsapp.com/health-privacy) sets out the categories of consumer health data we collect, why, where it comes from, whom we share it with, and how to exercise your rights. Washington, Nevada, and Connecticut law require it to be a separate document. Rights under it are handled through the same channels as Section 12.
7. Where information is stored
During our initial rollout, the Service is offered in the United States, so that we can manage reward shipping and other operations, and we store and process personal information in the United States. If you use Quests from outside the United States, your information is transferred to, stored, and processed in the United States. We do not transfer personal information internationally except to the extent a service provider in Annex B operates infrastructure outside the United States under a contract with us.
8. How long we keep information, and how deletion works
8.1 Retention schedule. We keep personal information only as long as needed for the purposes in Section 4 and to meet legal obligations. Our current schedule:
| Information | Kept for |
|---|---|
| Account, profile, quests, check-ins, streaks, Points ledger | Life of the account, then deleted within 30 days of deletion request |
| Hashes of your contacts' phone numbers that match a Quests member (only while contact syncing is on) | Until you turn off Contact sync, ask us to delete them, or delete your account |
| Hashes of your contacts' phone numbers that match no Quests member | 6 months after first sync, or sooner if you turn off Contact sync, ask us to delete them, or delete your account |
| Selected recipient phone numbers included in Android community-quest draft requests | Removed from the request data before the draft is stored |
| Phone numbers invited by text through older app versions | No longer stored; the remaining numbers were deleted on September 28, 2026 |
| Phone-verification (OTP) logs | 90 days |
| Crash and error diagnostics | 90 days, with personal identifiers removed |
| Advertising-measurement events | 12 months |
| Subscription, payment, and consent records | 7 years (tax, consumer-protection, and accounting requirements) |
| Reward redemption records including fair-market value | 7 years (tax) |
| Shipping addresses | 90 days after delivery |
| Tax forms (W-9) and information returns | 7 years |
| Sanctions-screening results | 10 years (federal requirement) |
| Age confirmation | Life of the account |
| Moderation reports, copyright notices, and enforcement records | 3 years |
| Backups | Rolling 35 days, then overwritten |
8.2 Deleting your account. Go to Settings → Danger Zone → Delete Account. If you no longer have the app, email nothingserious.team@gmail.com with the subject "Delete account" from the phone number or email on your account. We will ask you to confirm and re-verify your phone number. Deleting your account cancels a web subscription billed by us at the end of the current period; it does not cancel an Apple or Google subscription, so cancel those through the store you bought them in. Deleting your account permanently extinguishes unredeemed Points and unlocked items.
8.3 What happens. We deactivate the account immediately and permanently delete it within 30 days, including from our service providers and from advertising partners through their deletion mechanisms. We will confirm by text message or, if you gave us one, email.
8.4 What survives. We keep the records in the schedule above that the law requires us to keep (for example, payment and reward-value records for tax purposes), in a form that is no longer linked to your profile where possible; information subject to a legal hold; content you shared that other users have kept in their quests, which is de-identified; and information in backups until the backup is overwritten.
9. Security
We maintain a written security program with administrative, technical, and physical safeguards designed to protect personal information appropriate to the size of our business and the sensitivity of the data, including encryption in transit and at rest, access controls and least-privilege access, logging, vendor contracts that require safeguards, and periodic risk assessment. No system is perfectly secure, and transmissions over the internet are never completely private; please keep your device and verification codes safe.
10. If there is a breach
If a security incident affects your personal information, we will notify you and any regulators the law requires, within the time the law requires (for example, within 30 days for New York and California residents), using the email address on your account unless the law requires another method.
11. Cookies, tracking, and browser signals
11.1 What we use. thequestsapp.com is a static website: it sets no cookies of its own, runs no analytics, and runs no advertising pixels. Our web checkout, which is hosted by our subscription-billing provider, uses strictly necessary cookies to complete your purchase and keep it secure. Annex C lists them.
11.2 Cross-site tracking. We do not send device-level information about you to advertising networks, and we do not combine it with information from other services for advertising. Android build 21 uses the separate restricted attribution arrangement described there, with no onward advertising-network event reporting enabled. We do not provide health-related information for advertising or attribution.
11.3 Browser signals. We do not currently respond to "Do Not Track" or Global Privacy Control browser signals, because our website does not run third-party advertising pixels. You can opt out of advertising measurement at any time by emailing nothingserious.team@gmail.com. If we add advertising pixels to our website, we will honor Global Privacy Control signals and update this Section.
11.4 Browser controls. You can block or delete cookies in your browser settings. Blocking strictly necessary cookies may prevent you from signing in.
12. Your choices and rights
12.1 In the app. Settings lets you edit your profile, control who sees your activity, turn off Contact sync (in newer app versions; this deletes the contact hashes we hold for you), manage notifications, and delete your account. Other requests, including advertising opt-outs, can be sent to us as Section 12.3 describes.
12.2 Rights you can exercise. Regardless of where you live in the United States, you can ask us to:
- confirm whether we process your personal information and access it;
- correct inaccurate information;
- delete your personal information;
- export a copy of the information you provided in a portable format;
- opt out of the use of your information for targeted advertising, "sale," or "sharing," and of any profiling that produces legal or similarly significant effects (we do none);
- withdraw consent you have given, including consent relating to health-related information, as easily as you gave it.
12.3 How to ask. Use the in-app tools, the contact page at thequestsapp.com/contact, or email nothingserious.team@gmail.com with the subject "Privacy request." We will verify your request through your account (for example, by sending a code to your phone). If you are not a user, we will verify you in a reasonable way, such as a code to the email or phone number you give us. You may authorize an agent to act for you; we will ask for proof of authorization.
12.4 Timing. We respond within 45 days. If we need more time we will tell you why and take up to 45 more days. Requests are free up to twice a year; beyond that we may charge a reasonable fee or decline manifestly excessive requests.
12.5 Appeal. If we deny your request, we will tell you why. You can appeal by replying to our decision or emailing nothingserious.team@gmail.com with the subject "Privacy appeal" within 45 days. A different person will review it and respond within 45 days with a written explanation. If we deny your appeal, you may contact your state Attorney General; we will give you the contact information for your state in our response.
12.6 No discrimination. We will not deny you the Service, charge you a different price, or provide a different level of service because you exercised a privacy right. The Points program is a loyalty program under Section 16, and participating in it is not conditioned on giving up any right.
13. State-specific notices
13.1 California residents
This section supplements the rest of the Policy for California residents. We are not currently a "business" under the California Consumer Privacy Act because we do not meet its revenue or volume thresholds, but we follow its practices.
- Categories collected (last 12 months): identifiers (phone number, display name, device or attribution identifiers, IP address; advertising identifiers only where collected by earlier versions); customer records (shipping name and address, email for reward delivery, tax forms where required); commercial information (subscription and reward history); internet and app activity (usage data); geolocation inferred from IP address only (coarse, not precise); sensory data (profile photo, if you add one); inferences used to show you relevant quests; and sensitive personal information, information that may reveal health (Section 6) and, if you provide a W-9, a taxpayer identification number.
- Sources: you, your device, app stores, payment and attribution providers, other users.
- Purposes: Section 4.
- Disclosed for a business purpose to: the categories of service providers in Annex B.
- "Sale" and "sharing": we do not sell personal information. We do not share personal information for cross-context behavioral advertising. Singular processes attribution information as our service provider under the arrangements described in Section 5.3. You can opt out by emailing nothingserious.team@gmail.com. We do not sell or share sensitive personal information, and we use sensitive personal information only for the purposes California law permits without a right to limit.
- Minors: we do not knowingly sell or share the personal information of anyone under 16, and we do not knowingly collect personal information from children under 13.
- Rights: access, deletion, correction, portability, opt-out of sale/sharing, limit use of sensitive personal information, and non-discrimination, exercised under Section 12. You may use an authorized agent.
- Notice of financial incentive: the Points program is described in Section 16.
13.2 Texas, Nebraska, Minnesota, and Florida residents
We do not sell sensitive personal data. (Florida: NOTICE, this website does not sell your sensitive personal data.) We will not process sensitive data for any new purpose without your consent.
13.3 Washington and Nevada residents
Our Consumer Health Data Privacy Policy (thequestsapp.com/health-privacy) applies to consumer health data. It is linked separately from this Policy, from the legal pages of thequestsapp.com, in the app, and in our app-store listings.
13.4 Colorado, Virginia, Oregon, Montana, Delaware, New Jersey, New Hampshire, Maryland, Rhode Island, Kentucky, Indiana, Iowa, Tennessee, Utah, and other states with comprehensive privacy laws
Section 12 describes the rights those laws provide and how to exercise and appeal them. We do not process personal data for targeted advertising beyond the measurement in Section 5.3, which you can opt out of; we do not sell personal data; we do not engage in profiling in furtherance of decisions that produce legal or similarly significant effects.
13.5 New York residents
We maintain the data-security program described in Section 9 as required by the New York SHIELD Act and will notify you of a breach of private information as Section 10 describes.
14. Minors
See Section 2. If you are a parent or guardian and believe your child has an account, contact us and we will close it and delete the data.
15. AI features
15.1 Some quest text and tips are generated by artificial-intelligence models operated by third-party providers: our AI provider OpenRouter routes requests to models from OpenAI and Moonshot AI. AI-written Quest plans are shown to you to review and edit before you save them. We also use OpenAI's moderation service to screen user posts and photos for safety before they are published.
15.2 What is sent: to generate content, the Quest name and description you enter and its length, schedule, and category; topic keywords from them may also be used to search public research sources. We do not send your name, phone number, contacts, photos, or profile. To screen content, the text or image being checked, without your account identity.
15.3 Training: we use these services under terms that do not permit the providers to use the content we send to train their models, and we do not use your personal data to train any model.
15.4 The AI feature is a one-shot generator; it does not hold conversations or remember previous requests.
16. The Points program (loyalty program disclosure)
16.1 The Points program is a loyalty program. To run it we process: your account identifier, your quest completions and check-ins (the "qualifying activity"), the tier you were on when Points were earned, your Points ledger, your redemptions and their fair-market value, and the fulfillment information in Section 3.1.
16.2 Participation is not conditioned on sharing any information beyond what running the program requires, and we do not exchange your personal information with third parties in return for Points. We do not sell program data. Where a state's loyalty-program or financial-incentive rules apply, you may leave the program at any time by deleting your account; Points have no cash value and are not a payment for data.
16.3 Health-related information from qualifying activity is used only to credit Points and prevent fraud, never for advertising (Section 6).
17. Marketing communications
17.1 Email. Every marketing email has an unsubscribe link and our postal address. Service emails (receipts, security alerts, renewal reminders, legal notices) continue as long as you have an account.
17.2 Text messages. We send verification codes and security alerts by text as part of the Service. We send marketing texts only if you separately opt in by checking an unchecked box; consent is never a condition of using the Service. Reply STOP to any marketing text to stop, or HELP for help; we honor STOP and any other reasonable request promptly and within 10 business days. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. We never share your mobile phone number or your text-messaging opt-in with third parties or affiliates for their marketing or promotional purposes.
17.3 Push notifications. Control them in Settings and in your device settings.
18. Links to other sites and services
The Service links to third-party sites and services, for example, brands that issue gift cards, charities, and app stores. Their privacy policies, not this one, govern what they collect.
19. Changes to this Policy
We may update this Policy. If we make a material change, for example, collecting a new category of information, sharing information with a new type of recipient, or changing how we treat health-related information, we will notify you by email and by in-app notice at least 30 days before the change takes effect, and where the law requires consent for a new use, we will ask for it. Non-material changes take effect when posted. The effective date at the top tells you when the current version took effect.
20. Contact us
Nothing Serious LLC · 2810 North Church Street #457193, Wilmington, DE 19802 · nothingserious.team@gmail.com · thequestsapp.com/contact · Settings → Support → Send Feedback
Annex A: What we collect, why, and who receives it
| Category | Examples | Purposes (Section 4) | Recipients |
|---|---|---|---|
| Account and profile | Phone number, display name, photo, bio | 1, 5, 6, 8 | Hosting; SMS provider (verification); other users (profile); anyone who opens a share link you create (display name, photo, Points, streak) |
| Contacts (optional) | Hashes of the phone numbers in your address book, stored with your account for matching and join notifications; selected recipient numbers in Android draft requests are removed before storage (Section 3.4) | 1, 5 | Hosting |
| Age confirmation | Your confirmation that you meet the age requirements; app-store age signal | 1, 8 | Hosting |
| Quests, check-ins, streaks, comments | Quest titles, categories, notes, completions | 1, 2, 4, 6 | Hosting; AI services (moderation of text and images, without identity); other users in the quest |
| Health-related activity | Content of health-related quests and check-ins | 1, 2, 6 | Hosting only. Never advertising/attribution partners. See Consumer Health Data Privacy Policy |
| Device and diagnostics | Device model, OS, app version, IP, crash logs, push token | 1, 6 | Hosting; error monitoring; push-notification delivery service and Apple/Google push services |
| Usage data | Screens viewed, features used, taps | 6 | Hosting; internal reporting tools (aggregate counts only) |
| Attribution and measurement events | Install Referrer or SKAdNetwork information; installation/session and registration/invitation/subscription/revenue events; app/device attribution identifiers, IP address, device information, timestamps. Android build 21 excludes the advertising ID and Quests account ID | 6, 7 | Singular as a service provider; advertising networks receive iOS campaign results only in aggregate through Apple's SKAdNetwork |
| Subscription and payment | Plan, price, transaction IDs, consent records, receipts | 3, 8 | Billing provider; payment processor; Apple/Google (their purchases); email provider |
| Reward fulfillment | Email for codes; shipping name and address; tax forms | 2, 8 | Gift-card provider (reward type only); merchandise provider (name, address); email provider; tax authorities where required |
| Points ledger and reward values | Earned/redeemed Points, tier tag, fair-market value | 2, 8 | Hosting |
| Sanctions screening | Name and address at redemption | 8 | Screening records retained internally |
| Support, reports, appeals, privacy requests | Messages you send us; report details | 1, 6, 8 | Hosting; email provider |
| Marketing preferences | Opt-in/opt-out status per channel | 5 | SMS provider; email provider |
Annex B: Categories of recipients
Service providers (act only on our instructions, under contracts that restrict their use of your information): hosting, database, and authentication infrastructure; SMS, push-notification, and email delivery; error and crash monitoring; payment processing and subscription management (your card is held by the payment processor, not by us); print-on-demand fulfillment for merchandise rewards (name, shipping address, order details); gift-card code provisioning; AI services that generate quest text and screen posts for safety (no account identity is sent with prompts); Singular for the attribution processing described in Section 5.3; and internal reporting tools that receive aggregate statistics only.
Independent third parties (use information for their own purposes as well): Apple and Google (app distribution, purchases, push notifications, age signals); the brands that issue gift cards you redeem (nothing from us, only what you give the brand when you use the card); and recipient charities (aggregate amounts only, never your identity).
You may request the current list of named providers by emailing nothingserious.team@gmail.com with the subject "Providers."
Annex C: Cookies and similar technologies on the web
| Type | Purpose | Examples | Duration |
|---|---|---|---|
| Strictly necessary (web checkout only) | Completing your purchase and keeping the checkout session secure | Session and security cookies set by our billing provider's hosted checkout | Session |
thequestsapp.com itself sets no cookies, and we use no analytics or advertising cookies on the web. Learn more about managing cookies at allaboutcookies.org.
End of Privacy Policy.