Privacy Policy
Last updated: August 23, 2026
1. Introduction
QuestRunner ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our application. By using QuestRunner, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Account Information
- Email address (required for account creation)
- Password (stored in hashed form, for accounts created with email and password only; we never see your plain-text password)
- Display name (from your email, or from your Apple or Google profile where provided)
Sign in with Apple's Hide My Email produces a relay address. An account created that way is a separate account from one created with your real address. We cannot link them, because we never see the underlying address.
2.2 Quest Data
- Quest titles, descriptions, and locations you create
- Due dates, start dates, and completion status
- Quest categories, types, difficulty levels, and XP rewards
- Sub-tasks within quests
- Recurring quest patterns and completion history
2.3 Analytics and Diagnostics
An earlier version of this policy said QuestRunner used no analytics, and that this would change when in-app analytics was introduced, before it shipped. It has now shipped. This section is that change.
QuestRunner records how the app is used, so we can see which parts work and which are broken. This is handled by PostHog on its EU Cloud, acting as our data processor. The data is stored in the European Union. Section 4.4 has the detail.
- Product events. A closed, fixed list of 27 events covering signing in, onboarding, the guided walkthrough, creating, completing, abandoning and archiving quests, and daily-quest interactions. The list is set in the app's code and does not grow on its own.
- Crash reports and diagnostics. Crashes, errors, and performance data, so we can find faults and fix them.
- Automatic properties. Each event carries the app version, build number, device model and locale, which the analytics SDK attaches for us.
- Generation logs. When you generate a quest, our own server records the timing, the model used, token counts and whether the request succeeded, for reliability and cost monitoring. This is first-party: it stays in QuestRunner's own database and is not sent to PostHog.
How events are tied to you. Before you sign in, events carry an anonymous identifier scoped to your device. When you sign in, that identifier is replaced by your account's user id, so activity from before you signed in is joined to your account. Signing out resets it, so a different account used later on the same device is never merged with the previous one.
Turning it off. Analytics is on by default and can be turned off at any time inside the app, at Profile → Privacy. The setting belongs to the device rather than to the account, and it survives account deletion, so signing in as someone else on the same device will not quietly switch it back on.
2.4 Information We Do NOT Collect
- No advertising and no ad networks. We do not use advertising cookies.
- No cross-app or cross-site tracking. QuestRunner never shows an App Tracking Transparency prompt and does not use the IDFA; its App Store privacy manifest declares tracking as false.
- No session recording and no session replay. These are disabled at the PostHog project level, not merely left switched off in the app.
- No IP addresses. IP anonymization is enabled, so the address your events arrive from is not retained.
- We do not collect device location data.
2.5 Sign-in Providers
You can create and access your account with email and password, Sign in with Apple, or Sign in with Google.
If you sign in with Apple or Google using an email address that matches an existing verified account, the two are linked into one account.
3. How We Use Your Information
- To provide and maintain the QuestRunner service
- To authenticate your account and manage sessions
- To store and sync your quest data
- To generate quests from prompts you write, and from the onboarding answers and quest history that form your generation profile
- To understand which parts of the app are used, and to find and fix crashes and faults, as described in section 2.3
4. Third-Party Services
4.1 Supabase
We use Supabase for authentication, database hosting, and session management. Your account data and quest data are stored on Supabase's infrastructure. Supabase's privacy policy is available at supabase.com/privacy.
4.2 Google
We use Google OAuth for sign-in only. When you sign in with Google, Google shares your email and basic profile information with us. Google's privacy policy is available at policies.google.com/privacy.
4.3 OpenAdapter
AI quest generation is performed by OpenAdapter, a third-party AI provider we pay for, which routes requests to open-weight language models. What is sent: the prompt you write, your onboarding answers, and your generation profile (your recent quest titles, whether active, completed or abandoned; any free-text context you provided; and a difficulty calibration derived from how you've been completing quests, showing which attributes are being made easier or harder for you). For daily quests, the prompt is app-authored rather than something you write, and it includes how many quests you've completed per attribute over the last 30 days. What is not sent: your email address, your password, or your account identifier.
OpenAdapter states that it does not store, log, or retain the content of prompts or model responses. Requests pass through its infrastructure only to be routed onward. It retains request metadata (timestamps, endpoints, response codes) for 90 days. OpenAdapter's privacy policy is available at openadapter.dev/privacy.
OpenAdapter routes requests onward to third-party inference providers. Its policy names Chutes, 0G and OpenRouter, and states that these providers operate under their own privacy policies and may use anonymized or aggregated data for their own purposes, including model improvement. We never use your data to train anything, and OpenAdapter states that it does not either, but we cannot make that promise on behalf of the inference provider that ultimately runs the model. If that matters to you, do not put anything in a quest that you would not want a third party to process.
4.4 PostHog
We use PostHog for product analytics and crash reporting, as described in section 2.3. PostHog is our data processor: it processes that data on our instructions under a data processing agreement signed on August 23, 2026. Events are sent to and stored on PostHog's EU Cloud (eu.i.posthog.com), inside the European Union. Session recording and replay are disabled at the project level, and IP addresses are anonymized. PostHog's privacy policy is available at posthog.com/privacy.
Analytics and crash data is retained for 12 months and then deleted. If you delete your QuestRunner account, the PostHog person record holding your events is deleted with it, which removes that data sooner. You can stop the collection at any time at Profile → Privacy.
5. Cookies
We use only essential cookies managed by Supabase to maintain your authentication session. We do not use advertising cookies. The analytics described in section 2.3 happens inside the iOS app through a native SDK, not through cookies, and it is not used to follow you across other apps or websites.
5.1 This Website
This website measures its own usage with PostHog, running in cookieless mode. It stores nothing on your device: no cookies, no local storage, no session storage. That is why you are not asked to accept anything — there is no consent banner because there is nothing to consent to.
What is measured: page views, and three tagged interactions along the see-it-work → contact path — the demo section coming into view, a click on the demo call-to-action, and a click on a contact link. Nothing else on the page is recorded; there is no session replay and no automatic capture of every click.
This is aggregate measurement. No profile is built and nobody is identified. In cookieless mode PostHog does not keep an identifier on your device or hand one back to us; instead each event is grouped under a value it computes on its own servers by hashing the site, the day, your IP address and your browser's user agent, using a secret that is discarded every day. A visit tomorrow therefore counts as a new visitor, and we have no way to connect the two.
To be precise about what that means: your IP address and user agent do reach PostHog, because they are the inputs to that hash. They are used to compute it and are not retained against you, and no location lookup is performed on them. So this is not "nothing leaves your browser" — it is that nothing is left behind in it.
6. Data Retention
You can delete your account at any time from Profile → Danger Zone inside the app. Deletion is immediate and permanent: your profile, every quest, all completion history and your generation usage records are destroyed. There is no grace period and no recovery. Your PostHog person record, and the analytics and crash events held against it, are deleted at the same time.
If you do not delete your account, analytics and crash data is retained for 12 months and then deleted. Your analytics opt-out at Profile → Privacy is stored on the device, so deleting your account does not undo it.
7. Your Rights
- Access: You can view all your quest data within the app at any time.
- Deletion: You can delete individual quests at any time.
- Revocation: You can revoke Google's access to your account at myaccount.google.com/permissions.
- Account deletion: delete your account yourself, from inside the app, at any time, at Profile → Danger Zone.
- Analytics opt-out: You can turn analytics and crash reporting off at any time at Profile → Privacy. It is on by default, and the choice is remembered on the device.
8. Data Security
We implement appropriate technical and organizational measures to protect your data. Authentication is handled by Supabase with industry-standard encryption. All data in transit is encrypted via HTTPS. Your password is never stored in plain text. However, no method of transmission over the Internet is 100% secure.
9. Children's Privacy
QuestRunner is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Your continued use of the service after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy, please contact us at support@questrunner.net or visit our support page.