This Privacy Policy explains how Quest ("we," "us," "our") collects, uses, and protects information when you use Quest, the mental health companion application, and related websites including questapp.ai (the "Service"). Privacy is core to what Quest is for. We've tried to keep this document plain enough that you can actually read it.
1. Information We Collect
Information you give us
- Account information: email address, name (if provided), age range, and similar profile details you choose to share during onboarding.
- Onboarding answers: the responses you give to the quiz questions when you sign up (for example, what brings you to Quest, your goals, how you're feeling).
- Conversations and journal entries: the messages you send to Quest, voice recordings (where used), and any journal entries you create.
- Mood and habit data: mood check-ins, streaks, and other in-app activity you choose to log.
- Payment information: we use third-party processors (Stripe, the App Store) to handle payment. We do not store full card numbers on our servers.
- Customer support: the messages you send us when you contact hello@questapp.ai.
Information collected automatically
- Device and usage: device type, operating system, app version, IP address, language, timezone, and basic interaction events (sessions, screens viewed, features used).
- Cookies and similar technologies: on our websites, we use cookies and similar technologies. See our Cookie Policy for details.
- Crash and performance data: diagnostic data to help us find and fix bugs.
Information from third parties
If you sign in with Apple or Google, we receive a token from that provider and the basic profile information you authorize. If you arrive from an ad, we may receive a click identifier (for example, gclid, fbclid) from the ad platform so we can measure ad performance.
2. How We Use Your Information
We use the information we collect to:
- Provide the Service, including delivering AI responses, remembering things you've shared, and personalizing your experience.
- Process payments and manage subscriptions.
- Send you transactional messages (account, billing, security) and, with your permission, occasional product updates.
- Improve the Service: understanding which features help, fixing bugs, and measuring whether marketing is working.
- Protect the Service and our users: detecting fraud, abuse, and violations of our Terms.
- Comply with legal obligations.
3. AI Training and Your Conversations
We do not sell your data, and we do not share the contents of your personal conversations or journal entries with third parties for advertising. We use AI models from third-party providers (such as OpenAI) to generate responses. Those providers process your messages on our behalf under contracts that prohibit them from using your content to train their general models.
We may use aggregated, anonymized data (for example, "users who do X tend to retain better than users who do Y") to improve Quest. Aggregated data does not identify you.
4. How We Share Information
We share information only in the following limited circumstances:
- Service providers: trusted vendors who help us run the Service (cloud hosting, payment processing, AI inference, analytics, email delivery, customer support tools). They are contractually bound to use your data only for the purpose we hire them for.
- Legal: if required by law, valid legal process, or to protect rights, safety, or property.
- Business changes: if Quest is involved in a merger, acquisition, or asset sale, your information may transfer as part of that transaction, subject to this Privacy Policy.
- With your consent: in any case where you direct us to share.
5. Data Retention
We keep your information for as long as your account is active and as long as needed to provide the Service. You can delete your account at any time. After deletion, we remove or anonymize your personal data within 90 days, except where we are required by law to retain it (for example, tax records) or where we need it to protect against fraud or abuse.
6. Your Rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you;
- Correct inaccurate information;
- Delete your account and associated data;
- Export a copy of your data in a portable format;
- Object to or restrict certain processing;
- Withdraw consent where processing is based on consent;
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email hello@questapp.ai from the address tied to your account.
For California residents (CCPA / CPRA)
You have the right to know what personal information we collect, the right to request deletion, the right to correct, and the right not to be discriminated against for exercising any of these rights. We do not sell your personal information.
For EU/UK residents (GDPR / UK GDPR)
We process your information under one or more of the following legal bases: your consent, performance of our contract with you, our legitimate interests (improving the Service, preventing fraud), and compliance with legal obligations.
7. Security
We use industry-standard measures to protect your information, including TLS encryption in transit, encryption at rest for sensitive data, and access controls. No system is perfectly secure. If we ever learn of a breach affecting your data, we will notify you and the appropriate authorities as required by law.
8. Children
Quest is not for anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us at hello@questapp.ai and we will delete it.
9. International Transfers
Quest is operated from the United States. If you access the Service from outside the US, your information will be transferred to, stored, and processed in the US. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for international transfers.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you in the app or by email. The "Last updated" date at the top of this page reflects the most recent revision.
11. Contact
For privacy questions, email hello@questapp.ai.