1. Who we are
This policy covers the Questify mobile app for iOS and Android (the "App"), the Questify backend service it talks to, and this website (together, the "Service"). "Questify", "we", "us" and "our" mean the developer of the App, as named on its App Store and Google Play listings, who is the controller of your personal data.
Questions about privacy go to evil.monkey.corporation@gmail.com. We usually reply within a few days, and always within the time the law requires.
2. What we collect
Information you give us
Account details
A unique account ID. If you sign in with Apple or Google: your email address (with Sign in with Apple this can be a private relay address). You can also start without signing in — then no email is collected.
Why: To create your account, keep your data synced and let you sign back in.
Profile
Optional nickname, your emerald balance, and your time zone and language preferences.
Why: To personalise the App and count your days correctly.
Your content
Quests (title, notes, difficulty, icon, colour, schedule, reminder times), vows, rewards (title, description, price), and the history of completions, streaks, earnings and redeemed rewards.
Why: This is the App — we store it so it works on any of your devices and is never lost.
Feedback and support messages
Anything you write in "Send feedback" or email to us, linked to your account ID.
Why: To answer you and improve the App.
Information collected automatically
Usage analytics (Google Analytics for Firebase and PostHog)
Which screens and features are used (e.g. onboarding steps, session start and end), app version, device model, OS version, language, approximate country/region, and an app-instance identifier. The same events go to PostHog, hosted in the EU.
Why: To understand which features help people and which confuse them. We do not use advertising identifiers (IDFA/AAID) and do not use analytics for ads.
Crash and error reports (Sentry)
Stack traces, device and OS details, app version, and your account ID so we can match a crash to the request that caused it. We configure it not to send your email or nickname.
Why: To find and fix bugs.
Remote configuration (Firebase Remote Config)
A Firebase installation ID.
Why: To roll out features and settings without an app update.
Website analytics (PostHog)
Pages visited on this website, referrer, browser and device type, and approximate country/region. Nothing is recorded when your browser sends Do Not Track.
Why: To understand which pages help people find the app.
Technical logs
IP address, request time and path, and error details, recorded by our servers.
Why: To keep the Service secure, prevent abuse (rate limiting) and debug problems.
Stored only on your device
App settings such as theme, sounds, language and number format, and the reminders you schedule, live on your device. Reminders are local notifications — their content is not sent to us.
3. What we don't collect
- No precise location, contacts, photos, camera, microphone or health data.
- No advertising identifiers and no advertising SDKs.
- No payment details — the App has no in-app purchases today. If we add paid features, payments will be handled by Apple or Google, and we will never see your card.
4. How we use your information
- Provide the Service: your account, quests, streaks, emeralds, rewards and sync.
- Send you reminders you've set up (on your device).
- Respond to support requests and feedback.
- Keep the Service secure and reliable: detect abuse, fix crashes and bugs.
- Understand aggregate usage to improve the App.
- Comply with legal obligations and enforce our Terms of Service.
We don't sell your personal data, we don't "share" it for cross-context behavioural advertising, and we don't make decisions about you based solely on automated processing that have legal or similarly significant effects.
5. Legal bases (EEA, UK and Switzerland)
If you're in the EEA, the UK or Switzerland, we rely on these legal bases under the GDPR:
- Contract — to provide the Service you signed up for (account, content, sync, support).
- Legitimate interests — security, abuse prevention, crash reporting and product analytics, weighed against your interests and limited to what's necessary. You can object at any time (see Your rights).
- Legal obligation — when the law requires us to keep or disclose data.
- Consent — for notifications (you grant this in your device settings and can withdraw it there anytime).
7. International transfers
Our servers and database are hosted in the EU (Finland). Some of our providers, such as Sentry and parts of Google Firebase, process data in the United States. When we transfer personal data from the EEA, the UK or Switzerland to them, we rely on the European Commission's Standard Contractual Clauses (and the UK/Swiss equivalents) or on the provider's certification under the EU-U.S. Data Privacy Framework. You can ask us for a copy of the relevant safeguards.
8. How long we keep it
- Account and content — for as long as your account exists. When you delete your account, it is removed from our database and from Firebase Authentication immediately.
- Backups — any database backups we keep for disaster recovery rotate out within 30 days, so deleted data disappears from them by then.
- Data exports — the download link for a data export expires 24 hours after it's ready.
- Crash reports — up to 90 days.
- Analytics — event data is kept for up to 14 months, then deleted automatically.
- Server logs — a short period, typically no more than 30 days.
- Support emails — as long as needed to help you, and no longer than 2 years.
Guest accounts: if you use the App without signing in, your data is tied to that install. Link Apple or Google in Settings to keep it; otherwise deleting the App means we can't reconnect you to it. You can still ask us to delete it by emailing us.
9. Deleting your account
In the App: Settings → Delete Account. This permanently deletes your account and all your quests, vows, rewards, history and statistics. It can't be undone — use Settings → Export my data first if you want a copy.
No longer have the App? See how to request deletion without the App.
10. Your rights
Depending on where you live, you have the right to:
- Access and portability — get a copy of your data. Use Settings → Export my data for a machine-readable ZIP (JSON), or email us.
- Correction — edit your content and nickname in the App, or ask us.
- Deletion — delete your account in the App or on the web.
- Objection and restriction — object to processing based on legitimate interests (such as analytics), or ask us to restrict it.
- Withdraw consent — e.g. turn off notifications in your device settings.
- Complain — to your local data protection authority. We'd appreciate the chance to fix things first.
To use any right, email evil.monkey.corporation@gmail.com. We may need to verify that the account is yours (for example, by replying from the email linked to it or giving us the account ID shown in the App). We won't discriminate against you for exercising your rights.
11. US state privacy rights
If you live in California or another US state with a consumer privacy law, you have the rights to know, access, correct and delete your personal information, and to opt out of its sale, sharing for targeted advertising, and profiling. We do not sell or share personal information as those terms are defined, and we do not use or disclose sensitive personal information. In the last 12 months we collected the categories described in What we collect: identifiers (account ID, email), user-generated content, internet or network activity (usage and log data), and device information, from you and your device, for the purposes in How we use it. You may use an authorised agent to make a request.
12. Children
The Service isn't directed at children under 13 (or the minimum age required in your country, such as 16 in parts of the EEA), and we don't knowingly collect their personal data. If you believe a child has given us personal data, email us and we'll delete it.
13. Security
All traffic between the App and our servers is encrypted with TLS. Our servers run in Hetzner's access-controlled data centres, and our other providers (Google Firebase, Sentry) encrypt data at rest. Access to production data is limited to the people who need it to run and support the Service. No system is 100% secure, but we work hard to protect your data, and if a breach affects you we'll notify you and the authorities as the law requires.
14. This website
questify.day uses PostHog, hosted in the EU, to count visits and see which pages help people find the app. It respects your browser's Do Not Track setting — with DNT on, nothing is recorded. There is no advertising and no cross-site tracking. Fonts are served from our own server. Like any website, our host processes your IP address to deliver the page and protect against abuse.
15. Changes to this policy
We'll update the date at the top when this policy changes. For material changes, we'll let you know in the App before they take effect.
16. Contact
Email evil.monkey.corporation@gmail.com. If you're in the EEA or UK, you can also contact your local data protection authority.