Privacy Policy
Draft — effective at launch. Quest is not yet generally available. This policy describes the shipped architecture and takes effect when the service does. It has not yet had legal review.
What we store
- Account data. A stable account identifier and, if you provide it, your email address. Authentication is handled by our own identity service (id.getquest.gg); if you sign in with Google, Google confirms your identity to us and learns that you signed in — nothing more is exchanged.
- Your workspace. Boards, goals, canvas cards and the links between them, stored in our sync database and access-controlled to your identity at the row level. This content is not end-to-end encrypted today; the security page describes exactly what that means.
- Your files. Envelope-encrypted at rest, in a storage namespace that belongs to you alone. Deleted files are purged from the index after 30 days in trash.
- Operational events. Per-account event streams (for sync) scoped to your identity.
What we never do
- No third-party trackers, analytics scripts, or ad pixels — on this site or in the app. This website makes no external requests and runs no third-party code; its only JavaScript is a few inline snippets (theme, scroll animation) readable in the page source.
- No external font or CDN requests; assets are self-hosted.
- No selling or sharing of your data. There are no advertising partners.
- No reading your workspace to build profiles, train models, or “improve the service.”
Sessions
Session tokens are held in memory only — never in localStorage or cookies. Closing the tab ends the session.
Your rights, as endpoints
Export and deletion are implemented in the product, not just promised here: you can export your vault in full, and you can delete your data outright. Deletion of your storage namespace is immediate; trashed files age out after 30 days.
Changes
If this policy changes, the change lands here with a new “last updated” date before it takes effect.
Contact
Questions about this policy: hello@getquest.gg.